Leadership
Built by practitioners, not by a holding company.
Threatsys was founded in 2014 by engineers who were tired of security reports nobody could act on. That is still who runs it.
Deepak Kumar Nath
Managing Director & CEO
- Best Cyber Security Entrepreneur of India, 2024
- Youngest Entrepreneur of Odisha, IIT Bhubaneswar
- TEDx speaker, IIIT Bhubaneswar
- Advisor to law enforcement agencies
- Brand Ambassador, Cyber Safety Campaign Odisha
As we celebrate this milestone, my sincere gratitude goes to our clients, employees and partners who are the foundation of Threatsys’ success. What began as a vision to strengthen India’s cybersecurity is now a trusted brand protecting businesses and citizens globally. We remain guided by our commitment to excellence, innovation and resilience. Together, we are building a safer digital future.
Deepak Kumar Nath, Managing Director & CEO
Recognition and representation
- 2026
Official Business Delegate to London, United Kingdom
Part of the official Indian business delegation covering cybersecurity and data privacy frameworks, the India and UK Free Trade Agreement and CETA, and cross-border digital collaboration.
- 2026
Official Business Delegate to France
Represented India in Paris on the Government of India delegation, signing strategic MoUs and meeting officials of the Paris Region.
- 2026
Indian Delegate, India and Romania Business Forum
Represented India at the forum hosted by FICCI at FICCI Bhawan, New Delhi.
- 2025
CF100, among India's top cybersecurity influencers and leaders
Recognised by CyberFrat and the CF100 Club for contribution to community building and thought leadership.
- 2025
National Financial Inclusion Conclave, Special Guest
Joined the 7th conclave on digital banking, fintech innovation and cyber resilience.
- 2025
Chief Guest at Aditya Birla Group, Advancing Cyber Security in the AI Era
Keynote on emerging threats, AI-driven security challenges and building resilient digital enterprises.
- 2025
Speaker at ESCA 2025, Energy, Semiconductor, Cybersecurity and AI Conclave
On the evolving cybersecurity landscape, emerging threats in the AI era, and building resilient digital ecosystems.
- 2022
Chief Judge, Smart India Hackathon
Evaluated and recognised the winning team at the nationwide initiative organised by the Ministry of Education, with the honour awarded by the Prime Minister of India.
- 2020
Guest Keynote Speaker, Women in Cyber Security
At the WOH Harmony event hosted by Annapurna Microfinance.
- 2019
Guest Keynote Speaker on Cyber Security
Invited by NASSCOM to speak on the latest hacks facing IT professionals.
- 2018
Keynote Speaker, Tech Bhubaneswar 2.0
Presented Hack 2 Xplore, a live technical session covering the OWASP Top 10, SQL injection, CMS exploitation, PCI DSS and live SIEM exploitation.
- 2023
Keynote Speaker, Odisha Tourism Conclave
On cybersecurity in travel and tourism, and protecting customer data and financial transactions in the sector.
- 2024
Best Cyber Security Entrepreneur of India
Awarded to our CEO and MD, Deepak Kumar Nath.
- 2017
Youngest Entrepreneur of Odisha
Conferred on our CEO by the Director of IIT Bhubaneswar.
- Ongoing
Hall of Fame recognition from global platforms
Our founder has been credited in the security Hall of Fame by Facebook, Microsoft, Mastercard and Sony for responsibly disclosed vulnerabilities.
- 2025
Best Cyber Security Personality of the Year
Awarded to our founder by a leading national magazine.
- Ongoing
Advisor to law enforcement agencies
Providing expert guidance on cybercrime investigation, with more than 48,000 students, professionals and officers trained to date.
- 2017
TEDx speaker, IIIT Bhubaneswar
Followed by keynotes at the NextGen ICT Conclave 2019 with Cisco, the Odisha Tourism Conclave and Tech Bhubaneswar 2.0.
- 2025
COO Shrutiksha Nayak Nath speaks at TEDx SITB
On Harmony in Equilibrium, balancing cybersecurity leadership, entrepreneurship and family, drawing on her experience as a Femina Miss India finalist.
- 2025
Vision Beyond Business, CEO Conclave
Our CEO represented Threatsys and Odisha's emerging cyber leadership at the CEO Conclave with Interview Times.
- 2024
National media commentary on the CrowdStrike outage
Our CEO briefed national and regional news channels on the global disruption, cloud resilience and proactive security posture.
- 2025
Speaker, National Conclave on Energy, Semiconductors, Cyber Security and AI
Organised by the Trident Group and the VLSI Society of India, on cyber security, data privacy and cyber defence.
The wider leadership team
Practice leads for offensive security, compliance, managed detection, cloud and privacy. We are adding their profiles and photography here; in the meantime you will meet the relevant lead on your scoping call, not a salesperson.
Meet the team on a callThe people behind the work
21 named leaders across executive, practice and delivery, out of more than 150 security engineers. You are told which of them is leading your engagement before you sign anything.
Executive
The four people accountable for the firm.
- Deepak Kumar NathManaging Director and CEOFounded the firm in 2014. Advises law enforcement on cyber crime and has trained officers in investigation technique, which is why our forensics work is built to a standard police and courts recognise.
- Shrutiksha NayakChief Operating OfficerOwns delivery across every engagement, and has spoken on cyber security at TEDx.
- Kali Prasad SahaniChief Information Security OfficerHolds our own security posture. We are certified to the standards we audit clients against, and that is his to defend.
- George MakoriChief Business Development OfficerLeads international growth across Africa, the Gulf and beyond.
Practice leadership
The people who own how the work is actually done, and who you will meet on an engagement.
- Jay MaruPrincipal AuditorLeads certification audits. Has taken organisations through ISO 27001, SOC 2 and PCI DSS from the assessor's side of the table.
- Sailesh D MajhiVAPT ManagerRuns the offensive testing practice, including the CERT-In empanelled engagements.
- Shakti R MohantyLead Security Manager
- Ashutosh SharmaSOC Operations ManagerOwns round the clock monitoring coverage and the escalation path that has to work at three in the morning.
- Gaurav SharmaCompliance Manager
- Sudhakar KarriVice President, PartnershipsHolds the OEM relationships behind the marketplace, from licensing through to the day the tool stops working.
Delivery and operations
The people who keep engagements moving, evidence collected and invoices correct.
- Abhinash NayakAVP Finance
- Manas BindhaniAccounts Manager
- Bikram RoutAssistant Delivery Manager
- Krishnakant KAssistant Operations Manager
- Jagadiswar MAssistant Compliance Manager
- Asim PradhanAssistant GRC Manager
- Swaraj SAssistant GRC Manager
- Ayush PatraAssistant SOC Manager
- Arnak GaraiAssistant SOC Manager
- Ayusha SahooAssistant Project Manager
- Rajalaxmi BaduAssistant Admin Manager
What people ask before working with us
How long have you been doing this?
Since 2014. Long enough to have been wrong about things and corrected them, which is a more useful qualification than it sounds. Over 6,200 projects delivered for more than 500 client organisations.
Are you actually CERT-In empanelled?
Yes, and it matters for most government work, RBI and SEBI submissions and a growing amount of enterprise procurement. We are also certified to ISO 27001, ISO 20000 and SOC 2 Type II ourselves, which is a different claim from auditing others against them.
Who will actually do our work?
You are told who is leading your engagement before it starts, and that person writes the report and attends the walkthrough. If they change, we tell you why. Clients mention this more often than anything else, which suggests it is rarer than it should be.
Can you work outside India?
Yes. We deliver across fifteen or more countries with presence including Doha, Dubai, London, New York, Lagos, Nairobi and Perth, and we reconcile group standards with local regulation rather than running a separate programme per market.
What size of client do you work with?
From national scale citizen platforms with beneficiaries in the crores down to companies of fifty people. The method does not change; the scope and the price do.
Are you the cheapest?
No, and we will not pretend otherwise. What we try to be is the firm whose report you can hand to a regulator, an insurer or an enterprise customer without having to explain it first. If you need the cheapest possible certificate, we are the wrong choice and we will say so on the first call.
What happens after the report?
Re-testing is included and remediation questions are answered without a new purchase order. We would rather be measured on findings closed than findings raised.
How do we start?
A thirty minute call with an engineer rather than a salesperson. If what you need is smaller than you think, or is not something we do, you will hear that on the call.
How the firm is actually organised
Titles tell you very little about who does what in a security firm, so here is the working structure. Delivery is organised into practices rather than into a single pool: offensive testing, regulatory audit and certification, managed detection, and forensics. Each has a lead who is a practitioner rather than a manager of practitioners, and who still takes engagements.
That last point is a deliberate constraint and it has a cost. A practice lead who still delivers has less time for internal process, and it slows down how fast we can scale. What it buys is that the person setting the standard for how work is done is subject to that standard, and hears from clients directly rather than through a report.
Sector knowledge cuts across the practices. The engineer testing your core banking platform has tested core banking platforms before, and that pairing is made at scoping rather than by whoever is free.
Who you will actually deal with
You are told who is leading your engagement before it starts. That person writes your report and attends your walkthrough. If they change mid-engagement, you are told why rather than discovering it from a different name on an email.
There is no account manager between you and the engineer. Commercial questions go to commercial people, and technical questions go to the person who did the work, which sounds obvious and is unusual enough that clients remark on it.
Every engagement also has a named second who has read the scope and can pick it up. This matters more than it sounds: it is the difference between a two day delay and a restart when somebody is unavailable.
How decisions get made when they are uncomfortable
The decisions that define a security firm are the ones where the correct answer and the commercially attractive answer diverge. Declining to issue a certificate. Telling a client their scope is wrong after they have budgeted for it. Delaying a report that is not ready.
On our engagements that authority sits with the person leading the work, not with commercial management. They do not need to escalate to stop. That is structural rather than cultural, because the pressure to ship runs downhill and a rule that can be overruled by whoever is closest to the invoice is not a rule.
Findings are reviewed by somebody with no commercial stake in the account before the report goes out. It is a small firm and that is easy to arrange; it would be the first thing to break at ten times the size, which is one of the reasons we are deliberate about growth.
Growth, and the ceiling we have accepted
There is a version of this firm that runs many more engagements than we do. It requires separating the people who test from the people who write, hiring faster than we can train, and accepting that the standard becomes a process document rather than a practice.
We have decided against it, and it is worth being honest that this is a trade rather than a virtue. It means we occasionally cannot take work at the time a client wants it, and it means we are not the largest firm on any empanelled list. What it preserves is that our best work and our busiest quarters are not in tension.
Where we do grow, it is into depth rather than breadth: another engineer in an existing sector practice rather than a new service line we would be learning on a client's estate.
Not sure where to start?
Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.












