Industries
Cyber security for government & public sector.
National scale citizen platforms, e-governance and CERT-In empanelled audit and certification.
What is actually going on here
Government systems carry data that citizens cannot choose to withhold and cannot take elsewhere. A citizen can leave a bank. They cannot leave the land records system. That changes the calculation on every control decision, and it is the standard we hold these engagements to.
The practical difficulty is rarely technical. It is that a citizen service is built by a system integrator, operated by a state agency, hosted somewhere else again, and audited by whoever is empanelled that year. Nobody owns the whole thing. We start by working out who actually owns each part, because you cannot fix what nobody owns.
We have been CERT-In empanelled for this work and have delivered on national and state scale platforms, including systems with crore-scale citizen enrolment. The scale changes the failure modes: a defect that affects one in ten thousand users is a headline at that size.
Who regulates you, and what they want
Tick the ones that bind you and we will pull together the evidence each of them actually asks for. Nothing is sent anywhere.
Pick one or more above to see what they expect of you.
What goes wrong in this sector
Citizen database exfiltration
The prize is the whole table, not one record. Usually reached through an admin interface exposed to the internet with weak or shared credentials, or an API that accepts an unbounded query. Both are cheap to find and cheap to fix, which is what makes them frustrating.
Aadhaar and eKYC misuse
Where a service is an AUA or KUA, the authentication path itself becomes the target. Misuse tends to come from inside the licensed entity or through a sub-agent, not from breaking the UIDAI infrastructure. Audit trails are the control that matters here.
Defacement of public facing portals
Low technical impact, very high visibility, and often the first sign that something more serious was already achieved. We treat a defacement as evidence of prior access rather than as an event in itself.
Supply chain compromise via integrators
The integrator has privileged access to many state systems at once. One compromised developer machine can reach several departments. Very few states test the integrator's access path, and it is usually the shortest route in.
How we work in this sector
- 01
Establish who owns what
We produce an ownership map across department, integrator and hosting provider before testing. On a recent state engagement this alone surfaced three systems nobody had claimed for two years.
- 02
Test at citizen scale
We look specifically for defects that only appear at volume: enumeration, rate limits, and anything where a slow script over a week extracts the whole dataset without tripping an alert.
- 03
Report for two audiences
One report the department can act on and one an integrator's engineers can implement from. The same finding, written twice, because those are genuinely different readers.
- 04
Re-test and certify
We verify fixes and issue the certification the department needs for its own reporting, with the evidence attached.
What we actually keep finding here
Not a threat list copied from a report. These are the patterns that recur across our own engagements in this sector, with an honest note on how often. Where we do not have a precise number we say so rather than inventing one.
- Most engagements
Systems nobody has claimed ownership of
Built by an integrator, hosted somewhere else, operated by a department that believes another department owns it. We routinely surface services that have had no owner for years.
- Often
An admin interface reachable from the open internet
Usually with a weak or shared credential, and usually because it was needed during rollout and never restricted afterwards.
- Most engagements
APIs that will return the whole table
An unbounded query or a missing rate limit that only matters at citizen scale, where a slow script over a week extracts everything without tripping a single alert.
- Often
The integrator's own access is the shortest way in
One compromised developer machine reaching several departments at once. Very few states test the integrator's path, and it is often weaker than the system it maintains.
Questions worth asking any provider in this sector
Including us. If a provider cannot answer these clearly, that tells you more than any capability slide will. We would rather you asked them than took our word for it.
- 1
Are you CERT-In empanelled, and can you also handle STQC and GIGW where the department needs it?
- 2
Will you test at citizen scale, specifically for enumeration and bulk extraction?
- 3
Will the report go to the department, or to the integrator who built the system?
- 4
How will you test against production without any risk to live citizen services?
- 5
Will you produce the certification the department needs for its own reporting?
What we deliver in this sector
- Risk & vulnerability assessments
- Penetration testing
- Governance, risk & compliance
- Security strategy & policy development
- e-Governance application security
- Cloud & infrastructure security audit
- Incident response & forensics
- CERT-In & regulatory compliance support
Proof
CERT-In audits for CM Dashboard Odisha and UT Dashboard J&K
Work in this sector
Named engagements where the client has agreed to be named, and anonymised ones where they have not, which is most of them. Named references are available under NDA.
- Government
Securing the data of one crore women under Subhadra Yojana
End-to-end security assessment and hardening of the citizen platform behind one of India's largest direct-benefit schemes for women.
1,00,00,000 beneficiaries
- Government / Healthcare
Securing the data of 1.2 crore BSKY card holders
Health-scheme platform assessment covering beneficiary data, hospital integrations and claim workflows.
1.2 crore card holders
- Government
CM Dashboard Odisha: CERT-In cyber security audit
Full CERT-In empanelled audit of the Chief Minister's real-time governance dashboard.
State-wide executive platform
- Client withheld
State citizen services platform
- Scope
- A multi-department portal built by a system integrator, with no single owner across department, integrator and host.
- What we found
- Three services with no claimed owner, one carrying an admin interface reachable from the internet.
- Outcome
- Ownership map established, interfaces restricted, and the department given a register it now maintains itself.
- Client withheld
Welfare scheme at crore scale
- Scope
- Beneficiary enrolment and disbursal, tested read-only against production with a masked replica for anything active.
- What we found
- An API that would return unbounded result sets, extractable slowly enough to evade alerting.
- Outcome
- Rate limiting and result bounds applied, with detection added for slow bulk extraction patterns.
Questions we get asked in this sector
Are you empanelled to do this work?
Yes, CERT-In empanelled, which is the requirement for most central and state security audits. Where a department needs STQC certification as well we scope that alongside rather than as a second engagement.
Our system was built by an integrator. Who do you report to?
The department, always, because the department carries the obligation. We give the integrator a technical annexe so they can act, but the finding and its closure sit with you. This matters when the integrator changes.
Can you handle a system with crore-scale users?
We have. The change at that scale is not the testing method, it is the care needed around anything that touches live citizen data. We work read-only against production wherever it is at all possible.
What does the six hour CERT-In window mean in practice?
Six hours from becoming aware, not from confirming. Most departments fail it not because they are slow to report but because nobody is clear who is allowed to decide something is an incident at two in the morning. That is a process fix, not a technology one.
Not sure where to start?
Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.












