Author
Sachin Shirish
Sachin Shirish is a Director at SecureRoot Risk Advisory LLP, where he leads the firm's compliance and offensive-security practice. A Certified Ethical Hacker and ISO 27001 Lead Auditor, he scopes and oversees ISO 27001, SOC 2 and DPDP Act programmes and the manual VAPT engagements that test them.
Credentials
- CEH
- ISO 27001 Lead Auditor
- Director
- SecureRoot Risk Advisory LLP
Articles by Sachin Shirish
Guidance written up from the engagements this author scopes and delivers.
- DPDP Act17 min read
DPDP Act Breach Notification: What Applies Now and What Starts in 2027
There are two breach clocks in Indian law and only one of them is running. CERT-In's six-hour incident report has been live since 2022. The DPDP Act's duty to intimate the Data Protection Board and every affected Data Principal, with the contents Rule 7 prescribes, commences in May 2027. This guide sets out what a breach obliges you to do today, what lands in 2027, and what to build in between so the new duty costs you nothing when it arrives.
Read Article
Regulatory Compliance17 min readSEBI CSCRF Compliance Guide: Categories, Audits, VAPT and SOC
SEBI's Cybersecurity and Cyber Resilience Framework replaced the older sector circulars with one graded regime. This guide sets out which category you fall in, the deadlines after each extension, and what VAPT, cyber audit and SOC work each category owes.
Read Article
SOC 214 min readSOC 2 Type 1 vs Type 2 for Indian Companies: Which to Get First
A Type 1 report tests control design on one date; a Type 2 tests whether those controls operated across an observation period. Here is how Indian companies choose between them, and what each costs in time and money.
Read Article
Regulatory Compliance14 min readRBI Cybersecurity Directions 2026: What Regulated Entities Must Do Now
On July 31, 2026 the RBI issued separate Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions for commercial banks, small finance banks and NBFCs, repealing the earlier IT governance and cyber instructions for those entities. This guide sets out what changed and what to do first.
Read Article
PCI DSS11 min readPCI DSS Scope Reduction: SAQ Types, Segmentation and What Auditors Check
The fastest way to cut the effort of a PCI DSS assessment is to have less environment in it. This guide covers how cardholder data flow mapping sets the scope, how segmentation and tokenisation reduce it, which self-assessment questionnaire the result points to, and what an assessor checks before accepting a reduced scope.
Read Article
ISO 2700112 min readISO 27001 Certification Timeline in India: Phases and Realistic Durations
Most organisations reach ISO 27001 certification in three to six months. This guide walks through the six phases that make up that time, what each one produces, why some phases stretch and what you can do before day one to shorten the whole programme.
Read Article
DPDP Act12 min readDPDP Act Consultant in Noida: What They Do and What Compliance Costs
The Digital Personal Data Protection Rules were notified on 13 November 2025. Consent Manager registration opens in November 2026. Penalties become enforceable on 13 May 2027. That is the real clock, and it is shorter than it looks once you count backwards through …
Read Article
PCI DSS9 min readPCI DSS Compliance Checklist: The 12 Requirements Made Simple
If you touch payment card data, a pci dss compliance checklist turns a dense standard into a clear, workable plan. It shows exactly what to fix, in what order, before an assessor or acquiring bank asks.
Read Article
ISO 270019 min readISO 27001 Certification Cost in India: What Drives It
Ask for an ISO 27001 quote and the range can be startling. iso 27001 certification cost in India depends on your size, scope, maturity and chosen certification body – so understanding the drivers helps you scope sensibly rather than overpay.
Read Article
SOC 210 min readSOC 2 Consultants: What They Do and How to Choose One
A SOC 2 report has a hundred moving parts, and most engineering teams have never built one. soc 2 consultants bridge that gap – turning the AICPA Trust Services Criteria into controls, evidence and an audit your team can actually pass.
Read Article
SOC 211 min readSOC 2 Certification Cost in India: 2026 Pricing Breakdown
Indicative SOC 2 audit costs in India, up front: Rs 2,00,000 to Rs 5,00,000 for Type I and Rs 5,00,000 to Rs 12,00,000 for Type II, plus what drives those ranges and what the audit fee does not cover.
Read Article
ISO 270019 min readISO 27001 vs SOC 2: Which Framework Do You Need?
If buyers are asking for security proof, you have probably hit the iso 27001 vs soc 2 question. Both show you protect data, but they differ in format, audience and how they are assessed – and the right choice depends on who is asking.
Read Article
DPDP Act10 min readData Protection Officer Services in India: Do You Need a DPO?
The DPDP Act, 2023 expects many businesses to appoint a Data Protection Officer, but hiring a full-time expert is costly and slow. Data protection officer services in india give you that expertise on demand, without the headcount.
Read Article
DPDP Act10 min readDPDP Compliance Audit in India: Process, Checklist & Cost
A policy on paper means nothing until someone tests it. A dpdp compliance audit in india independently verifies that your controls actually meet the Digital Personal Data Protection Act, 2023 – not just that they exist on a slide.
Read Article
Virtual CISO9 min readBenefits of a Virtual CISO: Security Leadership on Demand
Every business needs security leadership, but few can justify a full-time chief information security officer. That gap is exactly why the benefits of a virtual CISO have made vCISO services one of the fastest-growing options in security.
Read Article
DPDP Act10 min readConsent Management Under India’s DPDP Act: A Practical Guide
Consent is the backbone of India’s data law, and getting it wrong invalidates everything built on top. dpdp consent management in india is how businesses capture, record and honour user consent exactly as the DPDP Act, 2023 demands.
Read Article
SOC 228 min readSOC 2 Services in India: The Complete Guide to Audit, Readiness and Type 2
Enterprise buyers ask for a SOC 2 report before they sign. This guide covers what SOC 2 services in India include, how the audit works, what a readiness assessment finds, how the Type 2 observation window runs, and how a startup gets there without enterprise overhead.
Read Article
DPDP Act10 min readDPDP Gap Analysis in India: Find Your Compliance Gaps Fast
Before you spend on tools or consultants, find out where you actually stand. A dpdp gap analysis in india measures your current controls against the DPDP Act, 2023 and shows exactly what is missing.
Read Article
DPDP Act10 min readDPDP Act Compliance Checklist: 12 Steps After the 2025 Rules
The Digital Personal Data Protection Act, 2023 is dense, but compliance becomes manageable when you break it into steps. A clear dpdp act compliance checklist turns the law into actions your team can tick off, system by system.
Read Article
DPDP Act10 min readDPDP Consultants in India: What They Do, Cost & How to Choose
Why Indian Businesses Hire DPDP Consultants in India Since the DPDP Rules took effect, DPDP consultants in India have become the practical bridge between a dense new law and a working compliance system. They translate the Digital Personal Data Protection Act, 2023 into …
Read Article
DPDP Act21 min readDPDP Services in India: The Complete Compliance Guide (Tools, Steps and Partners)
Every business handling Indian personal data now faces defined timelines for consent, breach reporting and governance under the DPDP Act. This guide covers what DPDP services include, the tools and steps that make compliance provable, who is in scope, what it costs and how to choose the right partner.
Read Article