Handbooks
The handbooks, in full.
One per console, written for the people who will operate it rather than the people who will buy it. What it does, what it needs from you, and the decisions that stay with a person.
- Detect, investigate, respond
AI SOC 360
How the detection layer is built, what the AI assembles before an analyst opens an alert, and the containment decisions that stay with a person.
- Log sources, onboarding and what good coverage looks like
- Detection content, tuning and how rules are retired
- Triage: what is assembled automatically and what is not
- Containment, and why it needs a human approval
- Reporting against CERT-In, RBI and SEBI expectations
- Assess, evidence, certify
GRC 360
Risk, policy and audit run as one cycle, with the evidence collected continuously rather than in the fortnight before an assessment.
- Building a control set that serves several frameworks at once
- Risk register mechanics: owners, dates and review points
- Evidence automation, and what still has to be collected by hand
- Internal audit and management review that survive scrutiny
- Surveillance audits and avoiding drift after certification
- Map, consent, honour
DPDP 360
The Digital Personal Data Protection Act 2023 turned into workflows: inventory, retention, consent, data principal rights and breach notification.
- Discovery: finding personal data nobody documented
- Retention and deletion that actually runs
- Consent architecture, withdrawal and propagation to processors
- Rights workflows and the clocks attached to them
- Breach notification, and how it differs from the CERT-In duty
- Scan, verify, prove
AppSec 360
SAST, DAST, API testing and penetration testing as a service, with every finding verified before it reaches a developer.
- Pipeline integration without stopping delivery
- Filtering scanner output down to what is real
- Manual verification, and why it is the expensive half
- Authorisation and business logic testing
- Retesting, and measuring how many fixes were partial
- Capture, qualify, close
CRM 360
The engagement side: how scoping, proposals and delivery records are kept so an assessment can start from what is already known.
- Scoping conversations and the questions that change the number
- Proposal structure: effort broken out by activity
- Engagement records and continuity between assessments
- Handover, walkthrough and retest scheduling
- Client data handling and retention
- Train, test, certify
LMS 360
Security awareness and role based training, with assessment records an auditor will accept as evidence.
- Role based curricula rather than one course for everyone
- Phishing simulation done without punishing people
- Developer secure coding, tied to findings from real tests
- Completion records as audit evidence
- Measuring whether behaviour actually changed
Want the walkthrough rather than the document? A thirty minute call runs the console against your own frameworks and findings instead of a prepared demo environment.
Not sure where to start?
Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.












