Skip to content

ISO 27001, SOC 2, the DPDP Act and manual VAPT. Book a Free Scoping Call

Blog

Notes From Our Engagements

Guidance our consultants give during compliance programmes and security testing, written up in public. Framework explainers, testing notes and the checklists we work from.

Latest Article

Latest Article

DPDP Act

DPDP Act Breach Notification: What Applies Now and What Starts in 2027

There are two breach clocks in Indian law and only one of them is running. CERT-In's six-hour incident report has been live since 2022. The DPDP Act's duty to intimate the Data Protection Board and every affected Data Principal, with the contents Rule 7 prescribes, commences in May 2027. This guide sets out what a breach obliges you to do today, what lands in 2027, and what to build in between so the new duty costs you nothing when it arrives.

17 min readBy Sachin Shirish, Director

Read Article

9 articles

DPDP Act

Consent, notices, audits and the deadlines set by the 2025 Rules.

  • DPDP Act17 min read

    DPDP Act Breach Notification: What Applies Now and What Starts in 2027

    There are two breach clocks in Indian law and only one of them is running. CERT-In's six-hour incident report has been live since 2022. The DPDP Act's duty to intimate the Data Protection Board and every affected Data Principal, with the contents Rule 7 prescribes, commences in May 2027. This guide sets out what a breach obliges you to do today, what lands in 2027, and what to build in between so the new duty costs you nothing when it arrives.

    Read Article
  • DPDP Act: DPDP Act consultant in Noida. Illustrated cover by SecureRoot Risk Advisory.
    DPDP Act12 min read

    DPDP Act Consultant in Noida: What They Do and What Compliance Costs

    The Digital Personal Data Protection Rules were notified on 13 November 2025. Consent Manager registration opens in November 2026. Penalties become enforceable on 13 May 2027. That is the real clock, and it is shorter than it looks once you count backwards through …

    Read Article
  • DPDP Act: Do you need a DPO? Illustrated cover by SecureRoot Risk Advisory.
    DPDP Act10 min read

    Data Protection Officer Services in India: Do You Need a DPO?

    The DPDP Act, 2023 expects many businesses to appoint a Data Protection Officer, but hiring a full-time expert is costly and slow. Data protection officer services in india give you that expertise on demand, without the headcount.

    Read Article
  • DPDP Act: The DPDP compliance audit. Illustrated cover by SecureRoot Risk Advisory.
    DPDP Act10 min read

    DPDP Compliance Audit in India: Process, Checklist & Cost

    A policy on paper means nothing until someone tests it. A dpdp compliance audit in india independently verifies that your controls actually meet the Digital Personal Data Protection Act, 2023 – not just that they exist on a slide.

    Read Article
  • DPDP Act: Consent under the DPDP Act. Illustrated cover by SecureRoot Risk Advisory.
    DPDP Act10 min read

    Consent Management Under India’s DPDP Act: A Practical Guide

    Consent is the backbone of India’s data law, and getting it wrong invalidates everything built on top. dpdp consent management in india is how businesses capture, record and honour user consent exactly as the DPDP Act, 2023 demands.

    Read Article
  • DPDP Act: Find your DPDP gaps fast. Illustrated cover by SecureRoot Risk Advisory.
    DPDP Act10 min read

    DPDP Gap Analysis in India: Find Your Compliance Gaps Fast

    Before you spend on tools or consultants, find out where you actually stand. A dpdp gap analysis in india measures your current controls against the DPDP Act, 2023 and shows exactly what is missing.

    Read Article
  • DPDP Act: 12 steps after the 2025 Rules. Illustrated cover by SecureRoot Risk Advisory.
    DPDP Act10 min read

    DPDP Act Compliance Checklist: 12 Steps After the 2025 Rules

    The Digital Personal Data Protection Act, 2023 is dense, but compliance becomes manageable when you break it into steps. A clear dpdp act compliance checklist turns the law into actions your team can tick off, system by system.

    Read Article
  • DPDP Act: Choosing a DPDP consultant. Illustrated cover by SecureRoot Risk Advisory.
    DPDP Act10 min read

    DPDP Consultants in India: What They Do, Cost & How to Choose

    Why Indian Businesses Hire DPDP Consultants in India Since the DPDP Rules took effect, DPDP consultants in India have become the practical bridge between a dense new law and a working compliance system. They translate the Digital Personal Data Protection Act, 2023 into …

    Read Article
  • DPDP Act: DPDP compliance, the complete guide. Illustrated cover by SecureRoot Risk Advisory.
    DPDP Act21 min read

    DPDP Services in India: The Complete Compliance Guide (Tools, Steps and Partners)

    Every business handling Indian personal data now faces defined timelines for consent, breach reporting and governance under the DPDP Act. This guide covers what DPDP services include, the tools and steps that make compliance provable, who is in scope, what it costs and how to choose the right partner.

    Read Article

4 articles

SOC 2

Readiness, audit and Type 2 reporting for teams selling to enterprise buyers.

  • SOC 2: SOC 2 Type 1 or Type 2 first? Illustrated cover by SecureRoot Risk Advisory.
    SOC 214 min read

    SOC 2 Type 1 vs Type 2 for Indian Companies: Which to Get First

    A Type 1 report tests control design on one date; a Type 2 tests whether those controls operated across an observation period. Here is how Indian companies choose between them, and what each costs in time and money.

    Read Article
  • SOC 2: Choosing a SOC 2 consultant. Illustrated cover by SecureRoot Risk Advisory.
    SOC 210 min read

    SOC 2 Consultants: What They Do and How to Choose One

    A SOC 2 report has a hundred moving parts, and most engineering teams have never built one. soc 2 consultants bridge that gap – turning the AICPA Trust Services Criteria into controls, evidence and an audit your team can actually pass.

    Read Article
  • SOC 2: What SOC 2 costs in India in 2026. Illustrated cover by SecureRoot Risk Advisory.
    SOC 211 min read

    SOC 2 Certification Cost in India: 2026 Pricing Breakdown

    Indicative SOC 2 audit costs in India, up front: Rs 2,00,000 to Rs 5,00,000 for Type I and Rs 5,00,000 to Rs 12,00,000 for Type II, plus what drives those ranges and what the audit fee does not cover.

    Read Article
  • SOC 2: SOC 2 in India, end to end. Illustrated cover by SecureRoot Risk Advisory.
    SOC 228 min read

    SOC 2 Services in India: The Complete Guide to Audit, Readiness and Type 2

    Enterprise buyers ask for a SOC 2 report before they sign. This guide covers what SOC 2 services in India include, how the audit works, what a readiness assessment finds, how the Type 2 observation window runs, and how a startup gets there without enterprise overhead.

    Read Article

3 articles

ISO 27001

Scoping, cost, timelines and how the standard compares with SOC 2.

  • ISO 27001: How long ISO 27001 really takes. Illustrated cover by SecureRoot Risk Advisory.
    ISO 2700112 min read

    ISO 27001 Certification Timeline in India: Phases and Realistic Durations

    Most organisations reach ISO 27001 certification in three to six months. This guide walks through the six phases that make up that time, what each one produces, why some phases stretch and what you can do before day one to shorten the whole programme.

    Read Article
  • ISO 27001: ISO 27001 certification cost, 2026. Illustrated cover by SecureRoot Risk Advisory.
    ISO 270019 min read

    ISO 27001 Certification Cost in India: What Drives It

    Ask for an ISO 27001 quote and the range can be startling. iso 27001 certification cost in India depends on your size, scope, maturity and chosen certification body – so understanding the drivers helps you scope sensibly rather than overpay.

    Read Article
  • ISO 27001: ISO 27001 or SOC 2? Illustrated cover by SecureRoot Risk Advisory.
    ISO 270019 min read

    ISO 27001 vs SOC 2: Which Framework Do You Need?

    If buyers are asking for security proof, you have probably hit the iso 27001 vs soc 2 question. Both show you protect data, but they differ in format, audience and how they are assessed – and the right choice depends on who is asking.

    Read Article

2 articles

PCI DSS

The twelve requirements, scope reduction and what assessors check.

  • PCI DSS: PCI DSS scope reduction. Illustrated cover by SecureRoot Risk Advisory.
    PCI DSS11 min read

    PCI DSS Scope Reduction: SAQ Types, Segmentation and What Auditors Check

    The fastest way to cut the effort of a PCI DSS assessment is to have less environment in it. This guide covers how cardholder data flow mapping sets the scope, how segmentation and tokenisation reduce it, which self-assessment questionnaire the result points to, and what an assessor checks before accepting a reduced scope.

    Read Article
  • PCI DSS: The 12 PCI DSS requirements, made simple. Illustrated cover by SecureRoot Risk Advisory.
    PCI DSS9 min read

    PCI DSS Compliance Checklist: The 12 Requirements Made Simple

    If you touch payment card data, a pci dss compliance checklist turns a dense standard into a clear, workable plan. It shows exactly what to fix, in what order, before an assessor or acquiring bank asks.

    Read Article

2 articles

Regulatory Compliance

What RBI, SEBI and other sector regulators require, and by when.

  • Regulatory Compliance: SEBI CSCRF, category by category. Illustrated cover by SecureRoot Risk Advisory.
    Regulatory Compliance17 min read

    SEBI CSCRF Compliance Guide: Categories, Audits, VAPT and SOC

    SEBI's Cybersecurity and Cyber Resilience Framework replaced the older sector circulars with one graded regime. This guide sets out which category you fall in, the deadlines after each extension, and what VAPT, cyber audit and SOC work each category owes.

    Read Article
  • Regulatory Compliance: What RBI's 2026 Directions changed. Illustrated cover by SecureRoot Risk Advisory.
    Regulatory Compliance14 min read

    RBI Cybersecurity Directions 2026: What Regulated Entities Must Do Now

    On July 31, 2026 the RBI issued separate Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions for commercial banks, small finance banks and NBFCs, repealing the earlier IT governance and cyber instructions for those entities. This guide sets out what changed and what to do first.

    Read Article

8 articles

Penetration Testing

Testing types, pricing, OWASP coverage and where red teaming differs.

  • Penetration Testing16 min read

    CERT-In Incident Reporting: The Six-Hour Runbook

    The CERT-In Directions give you six hours from noticing a listed incident. This is the execution side: what starts the clock, which of the 20 Annexure I types are reportable, the channels and fields, who is allowed to submit, and what to send when the facts are still moving at hour five.

    Read Article
  • Penetration Testing: How often to run VAPT. Illustrated cover by SecureRoot Risk Advisory.
    Penetration Testing13 min read

    How Often Should VAPT Be Done? Annual Baseline, Change Triggers and Regulator Cadence in India

    Once a year is the floor, not the plan. This guide sets out when VAPT must be repeated after change, what RBI, SEBI, IRDAI and PCI DSS each require, and how to set a risk-based cadence by asset type.

    Read Article
  • Penetration Testing: CERT-In Directions, in practice. Illustrated cover by SecureRoot Risk Advisory.
    Penetration Testing14 min read

    CERT-In Directions Compliance in India: 6-Hour Reporting, Logs and NTP

    The CERT-In Directions of 28 April 2022 apply to almost every organisation running ICT systems for Indian users. This guide walks through each obligation, what CERT-In's own FAQs clarify, and how VAPT and log monitoring make the 6-hour clock achievable.

    Read Article
  • Penetration Testing: API security testing. Illustrated cover by SecureRoot Risk Advisory.
    Penetration Testing12 min read

    API Security Testing Services: OWASP API Top 10 Coverage and Retesting

    APIs fail on authorisation and business logic far more than on classic injection bugs, and a scanner cannot tell whether one tenant can read another's data. This guide sets out what a manual API security test covers, how each OWASP API Security Top 10 category is tested, what the report and the verified retest contain and what an engagement costs.

    Read Article
  • Penetration Testing: Red team or penetration test? Illustrated cover by SecureRoot Risk Advisory.
    Penetration Testing9 min read

    Red Team vs Penetration Testing: Key Differences Explained

    The terms get used interchangeably, but red team vs penetration testing is a real distinction. One measures how vulnerable a system is; the other measures how well your organisation detects and responds to a determined attacker.

    Read Article
  • Penetration Testing: Types of penetration testing. Illustrated cover by SecureRoot Risk Advisory.
    Penetration Testing9 min read

    Types of Penetration Testing: A Complete Guide

    Not all security tests are the same. The types of penetration testing differ by how much the tester knows and what they target – and choosing the right one decides whether a test finds real risk or just ticks a box.

    Read Article
  • Penetration Testing: OWASP Top 10, explained with fixes. Illustrated cover by SecureRoot Risk Advisory.
    Penetration Testing9 min read

    OWASP Top 10 Vulnerabilities Explained (With Fixes)

    If you build or run web applications, the OWASP Top 10 vulnerabilities are the risks most likely to get you breached. They represent the consensus of the global security community on where web apps fail most often.

    Read Article
  • Penetration Testing: Penetration testing cost in India, 2026. Illustrated cover by SecureRoot Risk Advisory.
    Penetration Testing11 min read

    Penetration Testing Cost in India: 2026 Pricing Guide

    Real numbers, not a sales pitch. Indicative penetration testing price ranges by engagement type, the five factors that move a quote, and the warning signs of a test priced too low to be real.

    Read Article

2 articles

Cloud Security

Configuration, identity and logging practice for cloud estates.

  • Cloud Security: AWS audit checklist for Indian SaaS. Illustrated cover by SecureRoot Risk Advisory.
    Cloud Security11 min read

    AWS Cloud Security Audit Checklist for Indian SaaS Teams

    Most AWS security checklists you will find were written for a US audience. They cover IAM hygiene and public S3 buckets well, and they say nothing about the two requirements that will actually appear in your next India audit: a six hour incident reporting clock and …

    Read Article
  • Cloud Security: Cloud security best practices, 2026. Illustrated cover by SecureRoot Risk Advisory.
    Cloud Security24 min read

    Cloud Security Best Practices: A Practical 2026 Guide

    Most cloud guides stop at advice. This one names the control, gives the command on all three providers, maps it to the CIS Benchmark and NIST CSF item an auditor will ask for, and adds the India layer that global guides leave out.

    Read Article

1 article

Virtual CISO

Security leadership without a full-time hire.

  • Virtual CISO: Security leadership on demand. Illustrated cover by SecureRoot Risk Advisory.
    Virtual CISO9 min read

    Benefits of a Virtual CISO: Security Leadership on Demand

    Every business needs security leadership, but few can justify a full-time chief information security officer. That gap is exactly why the benefits of a virtual CISO have made vCISO services one of the fastest-growing options in security.

    Read Article

1 article

Phishing Simulation

Measuring and reducing click rates with authorised simulations.

  • Phishing Simulation: Phishing simulation: process, metrics, cost. Illustrated cover by SecureRoot Risk Advisory.
    Phishing Simulation11 min read

    Phishing Simulation Services in India: Process, Metrics and Cost

    The average click rate for untrained employees sits at roughly 33 percent. After a year of regular simulation and training, organisations typically get that under 5 percent. Those two numbers are why phishing simulation exists as a service category. They are also why most programmes stall. …

    Read Article

1 article

Managed SOC

What round-the-clock monitoring includes and how to buy it.

  • Managed SOC: What 24/7 monitoring actually includes. Illustrated cover by SecureRoot Risk Advisory.
    Managed SOC12 min read

    Managed SOC Services in India: What 24/7 Monitoring Actually Includes

    Managed SOC proposals all promise 24/7 monitoring. What that phrase covers varies enormously, from an alert-forwarding service to analysts who investigate, contain and report. This guide sets out the six things a managed SOC should include, how to compare it with building your own, and what to ask before signing.

    Read Article

1 article

DevSecOps

Building security into the pipeline rather than bolting it on.

  • DevSecOps: Security in every release. Illustrated cover by SecureRoot Risk Advisory.
    DevSecOps9 min read

    DevSecOps Best Practices: Build Security Into Every Release

    Security bolted on at the end slows releases and misses flaws. DevSecOps best practices fix that by building security into every stage of development – so teams ship faster and safer at the same time.

    Read Article

Have a Question About This?

If this raised something specific to your environment, a scoping call is the fastest way to get a direct answer.