Skip to content

ISO 27001, SOC 2, the DPDP Act and manual VAPT. Book a Free Scoping Call

Industries

Industries We Work With: Where We Spend Most of Our Time

Regulators, buyers and attackers ask different questions of every sector. We bring the context with us, so you are not paying us to learn your business on the first week.

01

Financial Services

Banks, NBFCs, fintechs and market intermediaries ship features weekly while RBI, SEBI and IRDAI watch closely. We keep the release train moving and the audit file complete at the same time.

The rules changed in 2026. On 31 July 2026 the RBI issued separate Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions for commercial banks, small finance banks and NBFCs, repealing the earlier IT governance instructions for each. The testing cadence carried over: for critical systems and customer-facing systems in the DMZ, a vulnerability assessment at least every six months and a penetration test at least every 12 months, by independent experts.

Market intermediaries answer to SEBI's Cybersecurity and Cyber Resilience Framework instead, where VAPT frequency follows your category, the report is due within a month, findings must close within three months and revalidation within five. Both sit alongside CERT-In's six-hour incident reporting. We scope testing to the instrument that applies to you, and prepare the evidence before the formal audit rather than after it.

What This Sector Asks For

  • RBI and SEBI audit readiness
  • Application and API VAPT
  • PCI DSS scope reduction
  • Continuous monitoring and response

02

Healthcare

Hospitals, diagnostics chains and health-tech platforms hold the most sensitive personal data there is. We build DPDP Act and HIPAA programmes that fit clinical reality instead of interrupting it.

Most Indian healthcare data work now runs to a deadline. The DPDP Rules, 2025 were notified on 13 November 2025, and most duties for Data Fiduciaries, including notices, security safeguards, breach intimation and data principal rights, apply from 13 May 2027. Hospitals, diagnostics chains and health-tech platforms need consent, retention and breach processes that work inside clinical operations, not beside them.

Where you serve US providers or insurers, HIPAA arrives through a business associate agreement that your client audits, covering the security risk analysis, safeguards and 60-day breach rules. Suppliers to Dutch healthcare meet NEN 7510 instead, where access logging under NEN 7513 is usually the gap. We run whichever applies on one control set rather than three programmes.

What This Sector Asks For

  • DPDP Act readiness across facilities
  • HIPAA for US partnerships
  • Medical device and application testing
  • Breach response playbooks

03

SaaS and Technology

Enterprise buyers ask for SOC 2 and ISO 27001 before the second call. We get product teams certified quickly, then keep security running at the speed you release.

Enterprise procurement decides the order. US buyers ask for a SOC 2 report, which only a licensed CPA firm can issue, while European, Indian and Gulf buyers more often accept ISO 27001. The controls overlap heavily, so one control set with one evidence trail usually serves both, and the sequence follows whichever deal is waiting.

Two things increasingly join that list. If you process personal data for EU clients you carry GDPR processor duties by contract, and transfers to India rely on the Standard Contractual Clauses with a transfer impact assessment. If your product ships AI features, the EU AI Act may apply to you as provider or deployer, with high-risk obligations now falling due on 2 December 2027 after the 2026 amendment.

What This Sector Asks For

  • SOC 2 and ISO 27001 on one control set
  • Product and API security testing
  • DevSecOps pipeline integration
  • Customer security questionnaires

04

E-Commerce and Retail

Card data, traffic that spikes on a schedule and margins that leave no room for downtime. We shrink PCI scope, harden the checkout path and keep customer data obligations under control.

Card data is the first question. PCI DSS v4.0.1 is the current standard and the requirements introduced as future-dated became mandatory on 31 March 2025. In India the RBI's card-on-file tokenisation rules have, since 1 October 2022, kept most merchants from storing card numbers at all, which removes a large part of the old storage scope but not PCI DSS itself: the pages and systems that transmit card data stay in scope.

Customer data is the second. The DPDP Act's duties apply from 13 May 2027, and consent, notice and deletion have to work across checkout, marketing tools and analytics rather than in a policy page. We usually start by shrinking PCI scope, then test the checkout path and the APIs behind it, then bring the same evidence into the privacy programme.

What This Sector Asks For

  • PCI DSS v4.0 compliance
  • Web and mobile VAPT
  • Cloud configuration review
  • DPDP Act for customer data

Frameworks We Take Clients Through

See the Compliance Practice
ISO 27001
Certified ISMS, built to fit how you work
SOC2AICPA
Type I and Type II, readiness to attestation
PCI DSS
v4.0 scope reduction and validation
Digital Personal Data Protection Act 2023
India readiness, consent and data rights
GDPR
EU privacy programmes and DPO support
HIPAA
Safeguards for US healthcare partnerships

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

Do you only work with these four sectors?

No. These are the four where most of our work sits, so we carry the context into an engagement rather than learning it on your budget. We also work with manufacturing, logistics, education, professional services, government suppliers and non-profits, and the methodology does not change: the same testing, the same compliance programmes and the same managed services, scoped to what your regulators, customers and risk actually demand. What changes with an unfamiliar sector is the discovery, where we spend longer understanding your operations, obligations and the questions your buyers ask before proposing scope. If your sector is not listed, the scoping call is the fastest way to find out whether we are the right fit, and we will say plainly if a specialist would serve you better than we would. Sector familiarity is a head start, not a prerequisite, and we would rather be honest about that than claim expertise we have not earned.

How does sector context actually change an engagement?

It changes what we test first, how findings are ranked and what the report has to prove. A bank and a SaaS company can run identical technology, but one answers to a supervisory inspection with a fixed testing cadence and the other to a customer's security questionnaire before a contract. That shapes scope, timing around change freezes or settlement cycles, and how a report is written. Sector context also decides which overlaps are worth planning: PCI DSS scope reduction for a retailer, a shared control set for a SaaS company pursuing SOC 2 and ISO 27001, or evidence that serves both an RBI inspection and an ISO 27001 audit. Without that context, engagements produce technically correct findings that do not answer the question being asked of you. We ask about your regulators, your customers and your last audit on the scoping call precisely so the engagement answers those questions rather than a generic checklist.

We operate across several of these sectors. Does that mean several programmes?

It should not. A health-tech platform selling to US providers, an e-commerce group with a lending arm, or a SaaS company serving banks will face requirements from more than one direction, but the underlying controls are largely the same: access management, change control, logging, incident response, vendor management and risk assessment. We build one control set and one evidence trail, then add what each framework or regulator uniquely requires on top, such as PCI DSS testing, HIPAA business associate obligations or a regulator's report format. That way a single access review or incident record answers several audits. Running separate programmes per sector duplicates policies, evidence and audit effort, and it is the most common reason compliance costs more than it should. We map each requirement to the control that already satisfies it, so you can see the overlap before deciding what to build next.

Where should a company in our sector start?

Start with whatever is blocking a deal, an audit or a deadline, because that usually reveals the rest. For financial services it is normally the testing cycle the applicable RBI or SEBI instrument sets, with governance and monitoring following. For healthcare it is DPDP Act readiness, or the business associate agreement a US client has asked you to sign. For SaaS it is the certification a waiting customer named, most often SOC 2 or ISO 27001. For e-commerce it is PCI DSS scope reduction, since shrinking scope reduces everything that follows. In each case the first engagement is a scoping call, and the first deliverable is a written scope with a fixed price, so you can see the whole path before committing to the first step. If none of those apply to you yet, the honest answer is often that a penetration test of your main application tells you more than any certification would.

Ready When You Are

Tell us what is due and who is asking. You will leave the call with a written scope, a timeline and a fixed price, and an honest answer if we are not the right firm for it.