Cyber Security
Enterprise cyber security services in Kolkata
Layered defences, sensible access control and the evidence trail you need when a regulator or an auditor asks.
Where we start: identity, endpoints and email
Most breaches of mid-sized Indian organisations do not begin with an exotic exploit. They begin with a reused password, a shared administrator account, an unpatched laptop or a convincing invoice email. So we start there rather than with an expensive appliance.
Identity work means single sign-on where the estate supports it, phishing-resistant multi-factor authentication for administrators, removal of standing privilege, and a joiner-mover-leaver process that actually revokes access on the day someone leaves.
Endpoints get managed patching, disk encryption, an endpoint detection and response agent, and a baseline configuration. Email gets SPF, DKIM and an enforced DMARC policy, which also stops your domain being used to defraud your own customers.
Network segmentation and the perimeter that still matters
Flat networks are the reason a single compromised machine becomes an organisation-wide incident. We segment by function, put servers and finance workstations in their own zones, and restrict administrative protocols to jump hosts rather than leaving them open across the office.
Remote access moves from ad hoc port forwarding to brokered access with device posture checks. Cloud accounts get guardrails: no public storage buckets by default, enforced logging, and separation between production and everything else.
The 2025 edition of the OWASP Top 10 places security misconfiguration second, ahead of injection. That matches what we find in the field, and it is why configuration review is a standing item rather than a one-off project.
Monitoring, logging and being ready to report
Detection depends on logs existing before the incident. We make sure authentication, administrative action, endpoint and firewall logs are collected centrally, retained for a defined period, and synchronised to a reliable time source so a timeline can be reconstructed.
The CERT-In directions of April 2022 require covered entities to report qualifying cyber incidents within six hours of noticing them, to maintain logs within India, and to synchronise system clocks to NIC or NPL time servers. Those are concrete engineering requirements, and we build to them.
Where personal data is involved, the Digital Personal Data Protection Act 2023 and the DPDP Rules notified in November 2025 add their own notification obligations to affected individuals and to the Data Protection Board, so the same log discipline serves two masters.
People, policy and the parts technology cannot fix
We write policies people can follow: an acceptable use policy in plain language, an access control standard, a backup and restore standard with tested recovery objectives, and an incident response plan with named roles and a call tree.
Awareness training is short, frequent and specific to your business, with simulated phishing that teaches rather than punishes. Finance teams get a documented verification step for payment instruction changes, which is the single cheapest control against business email compromise.
For organisations pursuing ISO 27001 certification or working under sector rules such as the SEBI cyber security and cyber resilience framework, we map the technical work to the controls so the audit is a formality rather than a scramble.
What you get with enterprise security
- Security posture assessment with a prioritised remediation roadmap
- Identity hardening including single sign-on, MFA and privilege review
- Managed patching, disk encryption and endpoint detection deployment
- Email authentication with SPF, DKIM and an enforced DMARC policy
- Network segmentation design and brokered remote access
- Central log collection with defined retention and time synchronisation
- Written incident response plan with named roles and escalation paths
- Staff awareness training and simulated phishing programme
How an engagement runs
Every project goes through the same six stages, so you always know what happens next and what it costs.
01
Requirement analysis
We map what you actually need before proposing anything.
02
Strategic planning
Scope, milestones and a fixed number, agreed in writing.
03
Implementation
Built in the open, with a live staging link from week one.
04
Quality assurance
Functional, security and performance testing before sign-off.
05
Deployment
A launch plan with rollback, monitoring and zero surprises.
06
Continuous support
We stay on for as long as you use what we built.
FAQ
Enterprise Security: questions we are asked
It covers identity and access control, endpoint protection and patching, email authentication, network segmentation, central logging and an incident response plan, plus the policies and staff training that hold it together. The mix depends on your estate. We assess first and give you a prioritised roadmap rather than selling a fixed bundle.
The CERT-In directions issued in April 2022 require service providers, intermediaries, data centres, body corporates and government organisations to report listed cyber incident types within six hours of noticing them. They also require Indian log retention and clock synchronisation. We help you build the logging and process needed to comply.
The Digital Personal Data Protection Act 2023, operationalised by the DPDP Rules notified in November 2025, requires data fiduciaries to apply reasonable security safeguards, retain logs, notify affected individuals and inform the Data Protection Board of a personal data breach. In practice that means encryption, access control, monitoring and a rehearsed notification process.
The label is about rigour, not headcount. A thirty-person firm still needs multi-factor authentication, patched laptops, tested backups and DMARC, and those controls cost very little. We scope to the size of your estate so you are not paying for a security operations centre you cannot use.
Yes. We map your technical controls to the ISO 27001:2022 requirements and its ninety-three Annex A controls, close the gaps, and prepare the documentation set your certification body will ask for at stage one and stage two. The certificate itself is issued by an accredited body, not by us.
Often bought together
What pairs well with enterprise security
Cyber Security
Penetration Testing
Identifying vulnerabilities before hackers do.
Cyber Security
Security Consultancy
Strategic advice on security posture and risk management.
Cyber Security
Emergency Service
24/7 incident response for active security threats.
Compliance Services
Accreditation
Helping you achieve industry-standard certifications and quality marks.
Get a written quote for enterprise security.
Tell us what you are trying to achieve and we will come back with scope, timeline and a fixed number — or tell you honestly that we are not the right team.
Talk to a specialist