Regional presence
India headquartered. Globally delivered.
Ten locations and delivery coverage across 15+ countries, anchored by our Bhubaneswar headquarters. Every key on the map is a place our engineers work from.
Regional presence
Our cybersecurity footprint across the globe.
10 locations and delivery coverage across 15+ countries, anchored by our Bhubaneswar headquarters. Every key on the map is a place our engineers work from.
IndiaCorporate Office IndiaHeadquarters of global security operations
3rd Floor, F3, Ryan Tower, Technology Corridor, near Trident Academy, Chandaka Industrial Estate, Infocity, Chandrasekharpur, Bhubaneswar, Odisha 751024
Our offices
IndiaCorporate Office IndiaHQ3rd Floor, F3, Ryan Tower, Technology Corridor, near Trident Academy, Chandaka Industrial Estate, Infocity, Chandrasekharpur, Bhubaneswar, Odisha 751024
Headquarters of global security operations
+91 96682 00222
IndiaThreatsys Educational WingPlot No. 155, 1st Floor, Infocity Ave, Chandrasekharpur, Patia, Bhubaneswar, Odisha 751024
Training, skilling and the LMS 360 academy
+91 96682 00222
IndiaNew Delhi IndiaPlot No. B28, 1st Cross Street, Block B, Sector 1, Noida, Uttar Pradesh 201301
North India delivery and government liaison
+91 96682 00222
QatarQatarRing Road, Zone 44, Street #250, Building #189, 2nd Floor, Doha, Qatar
Gulf financial services and regulatory compliance
+91 96682 00222
NigeriaNigeriaPlot No. 21 Ahmed Onibudo Street, Victoria Island, Lagos, Nigeria
West African banking and fintech security
+91 96682 00222
AustraliaAustraliaLevel 25, 108 St Georges Terrace, Perth WA 6000, Australia
APAC compliance and managed services
+91 96682 00222
Additional delivery coverage
We deliver in these markets through regional teams. Contact us for an in-country meeting.
- DubaiUnited Arab Emirates
- NairobiKenya
- LondonUnited Kingdom
- New YorkUnited States
Why the map matters more than it looks
Plenty of firms list offices they visit twice a year. Every key on this map is somewhere our engineers actually work from, and that changes three practical things when you engage us.
Testing runs in your working hours
Security testing needs your team available to grant access, answer questions and watch findings being reproduced. A tester eight hours out of phase turns a two week engagement into a month of overnight email.
Incident response arrives faster
The first two hours of an incident decide how much of the estate you keep. Regional presence means mobilising in hours rather than waiting on a visa and a long-haul flight.
Local regulation is read locally
Saudi PDPL, UAE data residency, Nigerian NDPR and the CERT-In Directions all differ in ways that matter to architecture. We reconcile them into one control set rather than running a separate programme per market.
Delivering somewhere not on this list?
We have delivered in more countries than we hold offices in, which is the normal shape of this business. Tell us where the systems are and where the regulator sits, and we will tell you honestly whether we can serve it well or whether you are better served by someone local. We have said the latter before.
Why a location on this map is not a sales office
Plenty of firms list offices they do not staff. A pin on a map costs nothing and implies a great deal, so it is worth saying what ours mean. Every location listed is somewhere our people actually work from, and the distinction that matters commercially is between the places where delivery happens and the places where a client relationship is held.
Bhubaneswar is where the majority of engineering sits. It is our headquarters, the centre of our public sector practice, and where most reports are written. If your engagement is delivered remotely, it is very likely delivered from here.
Our other Indian presence exists because certain clients, particularly in banking and in government, need somebody in the room. Regulated engagements involve scoping conversations that go better in person, evidence handovers that some institutions will not do over email, and walkthroughs where having the engineer physically present changes the quality of the argument.
International locations follow the work rather than leading it. We did not open in a market and then look for clients; we took engagements and then established presence where the volume justified it. That is a slower way to expand and it means the map is a truthful description of where we operate rather than an aspiration.
How delivery actually works across a distance
The realistic picture for most engagements is hybrid. Testing is largely remote, because that is how an attacker would reach you and because the tooling has no geography. What is not remote is the beginning and the end.
Scoping benefits enormously from being in the room where it is practical, because the conversation that changes the scope is usually the one where somebody mentions a system in passing. Walkthroughs benefit for the same reason: your engineers argue more freely in person, and findings get corrected in both directions during that session.
For clients under RBI, SEBI or IRDAI supervision, or for government platforms, we plan on-site presence into the engagement from the start rather than treating it as an extra. Supervisory expectations around evidence handling and access frequently require it, and discovering that halfway through is expensive.
Where a client is in a market we do not have presence in, we say so and quote the travel honestly rather than pretending that everything can be done from a screen. Occasionally the right answer is that a local firm should do the on-site component and we should do the testing. We have made that recommendation.
Time zones, working hours and getting hold of someone
Our delivery day runs on India Standard Time, which sits conveniently between our Gulf and Australian clients and awkwardly against West Africa. We do not pretend otherwise, so here is what it means in practice.
Gulf clients overlap with us for most of the working day, and engagements there run effectively as though we were local. Australian clients get a morning overlap that covers stand-ups and urgent decisions, with reports and findings landing overnight in their time, which most find works well. African engagements have a genuine afternoon overlap and we schedule the conversations that need both parties inside it rather than at the edges.
Testing windows for production systems are a separate question from working hours, and they are set by your change control rather than by our convenience. If your maintenance window is 02:00 on a Sunday, that is when the testing happens, and it is scoped and staffed accordingly.
For an active incident, the routing is different from everything above and it is deliberately simple: the number on this page, at any hour. An incident line that only answers in business hours is not an incident line.
Data residency, which is a location question with legal weight
Where the work is done and where the data sits are separate questions, and only the second one is regulated. For Indian clients, engagement data stays in India by default. That is not a preference; it is what the CERT-In Directions require for log retention and what supervised entities are asked about directly during inspection.
For clients outside India, data residency is agreed at contract rather than assumed. Several jurisdictions we work in have their own requirements and they do not all point the same way, so we ask rather than apply a default.
Findings, reports and reproduction evidence are the sensitive artefacts here, not the correspondence. They are retained on the clock set in your contract and destroyed on it. If you need a shorter retention than our standard, say so at scoping and it goes into the engagement rather than becoming an exception somebody has to remember.
What to expect when you visit, or when we visit you
Client visits to Bhubaneswar are welcome and more common than you might expect, particularly from regulated clients conducting their own supplier assessment. If you want to see where your data sits and how access to it is controlled, that is a reasonable request and we would rather you made it than took our word.
When we come to you, our engineers arrive with their own equipment, built to our standard rather than borrowed, because plugging an unmanaged laptop into a client network is exactly the behaviour we would write up as a finding. Where your policy requires us to use your hardware instead, that is workable and needs to be agreed in advance so the tooling is in place.
On-site testing has one requirement that catches people out: written authorisation naming the systems, the window and the people, held by both sides before anybody touches anything. We will not begin without it, and that is as much for your protection as ours.
Not sure where to start?
Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.












