Cyber Security

Enterprise cyber security services in Kolkata

Layered defences, sensible access control and the evidence trail you need when a regulator or an auditor asks.

Where we start: identity, endpoints and email

Most breaches of mid-sized Indian organisations do not begin with an exotic exploit. They begin with a reused password, a shared administrator account, an unpatched laptop or a convincing invoice email. So we start there rather than with an expensive appliance.

Identity work means single sign-on where the estate supports it, phishing-resistant multi-factor authentication for administrators, removal of standing privilege, and a joiner-mover-leaver process that actually revokes access on the day someone leaves.

Endpoints get managed patching, disk encryption, an endpoint detection and response agent, and a baseline configuration. Email gets SPF, DKIM and an enforced DMARC policy, which also stops your domain being used to defraud your own customers.

Network segmentation and the perimeter that still matters

Flat networks are the reason a single compromised machine becomes an organisation-wide incident. We segment by function, put servers and finance workstations in their own zones, and restrict administrative protocols to jump hosts rather than leaving them open across the office.

Remote access moves from ad hoc port forwarding to brokered access with device posture checks. Cloud accounts get guardrails: no public storage buckets by default, enforced logging, and separation between production and everything else.

The 2025 edition of the OWASP Top 10 places security misconfiguration second, ahead of injection. That matches what we find in the field, and it is why configuration review is a standing item rather than a one-off project.

Monitoring, logging and being ready to report

Detection depends on logs existing before the incident. We make sure authentication, administrative action, endpoint and firewall logs are collected centrally, retained for a defined period, and synchronised to a reliable time source so a timeline can be reconstructed.

The CERT-In directions of April 2022 require covered entities to report qualifying cyber incidents within six hours of noticing them, to maintain logs within India, and to synchronise system clocks to NIC or NPL time servers. Those are concrete engineering requirements, and we build to them.

Where personal data is involved, the Digital Personal Data Protection Act 2023 and the DPDP Rules notified in November 2025 add their own notification obligations to affected individuals and to the Data Protection Board, so the same log discipline serves two masters.

People, policy and the parts technology cannot fix

We write policies people can follow: an acceptable use policy in plain language, an access control standard, a backup and restore standard with tested recovery objectives, and an incident response plan with named roles and a call tree.

Awareness training is short, frequent and specific to your business, with simulated phishing that teaches rather than punishes. Finance teams get a documented verification step for payment instruction changes, which is the single cheapest control against business email compromise.

For organisations pursuing ISO 27001 certification or working under sector rules such as the SEBI cyber security and cyber resilience framework, we map the technical work to the controls so the audit is a formality rather than a scramble.

What you get with enterprise security

  • Security posture assessment with a prioritised remediation roadmap
  • Identity hardening including single sign-on, MFA and privilege review
  • Managed patching, disk encryption and endpoint detection deployment
  • Email authentication with SPF, DKIM and an enforced DMARC policy
  • Network segmentation design and brokered remote access
  • Central log collection with defined retention and time synchronisation
  • Written incident response plan with named roles and escalation paths
  • Staff awareness training and simulated phishing programme

How an engagement runs

Every project goes through the same six stages, so you always know what happens next and what it costs.

01

Requirement analysis

We map what you actually need before proposing anything.

02

Strategic planning

Scope, milestones and a fixed number, agreed in writing.

03

Implementation

Built in the open, with a live staging link from week one.

04

Quality assurance

Functional, security and performance testing before sign-off.

05

Deployment

A launch plan with rollback, monitoring and zero surprises.

06

Continuous support

We stay on for as long as you use what we built.

FAQ

Enterprise Security: questions we are asked

It covers identity and access control, endpoint protection and patching, email authentication, network segmentation, central logging and an incident response plan, plus the policies and staff training that hold it together. The mix depends on your estate. We assess first and give you a prioritised roadmap rather than selling a fixed bundle.

Get a written quote for enterprise security.

Tell us what you are trying to achieve and we will come back with scope, timeline and a fixed number — or tell you honestly that we are not the right team.

Talk to a specialist