Cyber Security

Cyber security consultancy in Kolkata

Advice that ends in a prioritised plan with owners and dates, not a slide deck of generic risks.

Risk assessment that reflects your actual business

We begin by mapping what would genuinely hurt: which systems, which data, which processes, and what an hour or a day of unavailability costs you. Controls chosen without that context tend to protect the wrong things thoroughly.

From there we assess the current state across identity, endpoints, network, applications, cloud, backup and supplier arrangements, and record findings with evidence rather than impressions.

The output is a risk register in your language, with likelihood, impact, existing controls and a recommended treatment, plus an owner and a target date for each item. A register nobody owns is a document, not a control.

DPDP readiness and data governance

The Digital Personal Data Protection Act 2023 became operational through the DPDP Rules notified in November 2025, which phase in obligations over the following months, with the substantive business requirements around consent, notice, retention, erasure and security safeguards arriving on the longer timeline.

Practical readiness starts with a data map: what personal data you hold, where it lives, why you hold it, who you share it with and how long you keep it. Most organisations discover copies they had forgotten, and deleting those is often the cheapest risk reduction available.

We then work through consent notices in clear language, withdrawal and grievance mechanisms, retention and erasure rules, processor contracts, and a breach notification runbook covering both the individuals affected and the Data Protection Board.

Certification and sector framework readiness

For ISO 27001:2022 we run a gap assessment against the management system clauses and the ninety-three Annex A controls, help you define scope and the statement of applicability, build the documentation set, and prepare you for stage one and stage two audits with the certification body.

For regulated sectors we map the same underlying controls onto the applicable framework, whether that is the SEBI cyber security and cyber resilience framework for market intermediaries or the CERT-In directions on logging, clock synchronisation and six-hour incident reporting.

Doing this once and mapping many-to-one avoids the common trap of running three parallel compliance programmes that all ask for the same evidence in different formats.

Ongoing advisory for organisations without a full-time CISO

Many mid-sized Indian firms need security leadership a few days a month rather than a permanent hire. We work as an outside security lead: chairing a monthly review, keeping the risk register current, reviewing architecture changes before they ship and answering customer security questionnaires.

That last item matters commercially. Enterprise buyers now send detailed security due diligence questionnaires, and a slow or weak response delays contracts. Having consistent, evidenced answers on file shortens sales cycles.

We also review supplier and vendor risk, since a large share of incidents arrive through a third party with access to your systems or your data.

What you get with security consultancy

  • Current-state assessment across identity, endpoint, network, cloud and backup
  • Risk register with likelihood, impact, owners and target dates
  • Personal data map covering what you hold, why, where and for how long
  • DPDP readiness pack including notices, retention rules and a breach runbook
  • ISO 27001:2022 gap assessment, scope and statement of applicability support
  • Policy set written in plain language for staff to actually follow
  • Supplier and third party risk review with contract clause recommendations
  • Prioritised remediation roadmap phased against your budget

How an engagement runs

Every project goes through the same six stages, so you always know what happens next and what it costs.

01

Requirement analysis

We map what you actually need before proposing anything.

02

Strategic planning

Scope, milestones and a fixed number, agreed in writing.

03

Implementation

Built in the open, with a live staging link from week one.

04

Quality assurance

Functional, security and performance testing before sign-off.

05

Deployment

A launch plan with rollback, monitoring and zero surprises.

06

Continuous support

We stay on for as long as you use what we built.

FAQ

Security Consultancy: questions we are asked

They establish what you need to protect, assess what is currently in place, and produce a prioritised plan with owners and dates. In practice that also means writing usable policies, preparing for certification or sector frameworks, answering customer security questionnaires and reviewing architecture changes before they reach production.

Get a written quote for security consultancy.

Tell us what you are trying to achieve and we will come back with scope, timeline and a fixed number — or tell you honestly that we are not the right team.

Talk to a specialist