Blog and insights
Analysis from the people doing the work.
Written by the engineers and consultants running the engagements, not a content agency. Regulatory analysis, threat intelligence and the occasional strong opinion.
The CERT-In six hour rule, and what it actually demands of you
Six hours is not a reporting deadline you meet with a form. It is an operational capability, and most organisations discover the gap during the incident rather than before it.
Read it- Threat intelligence2026-06-19
Deepfake CEO fraud: the controls that actually stop it
Voice cloning has made the pretext convincing. That matters less than most coverage suggests, because the control that stops the fraud was never about detecting the voice.
Read it - Guide2026-05-22
Identity and access management that survives an audit
Auditors do not ask whether you have an IAM platform. They ask you to prove that a specific person lost a specific access on a specific day, and that is where most programmes come apart.
Read it - Platform comparison2026-04-30
Choosing a SOC platform in 2026: the questions that matter
Feature grids will not tell you which platform to buy. The decision comes down to ingest economics, who tunes it after month three, and whether your evidence survives the audit.
Read it - Regulation2026-03-14
RBI cyber security expectations: what supervision actually looks for
The Master Direction on IT Governance moved the emphasis from having controls to demonstrating that the board owns them. That change is what most inspection findings now turn on.
Read it
Not sure where to start?
Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.












