Cyber Security
Cyber security consultancy in Kolkata
Advice that ends in a prioritised plan with owners and dates, not a slide deck of generic risks.
Risk assessment that reflects your actual business
We begin by mapping what would genuinely hurt: which systems, which data, which processes, and what an hour or a day of unavailability costs you. Controls chosen without that context tend to protect the wrong things thoroughly.
From there we assess the current state across identity, endpoints, network, applications, cloud, backup and supplier arrangements, and record findings with evidence rather than impressions.
The output is a risk register in your language, with likelihood, impact, existing controls and a recommended treatment, plus an owner and a target date for each item. A register nobody owns is a document, not a control.
DPDP readiness and data governance
The Digital Personal Data Protection Act 2023 became operational through the DPDP Rules notified in November 2025, which phase in obligations over the following months, with the substantive business requirements around consent, notice, retention, erasure and security safeguards arriving on the longer timeline.
Practical readiness starts with a data map: what personal data you hold, where it lives, why you hold it, who you share it with and how long you keep it. Most organisations discover copies they had forgotten, and deleting those is often the cheapest risk reduction available.
We then work through consent notices in clear language, withdrawal and grievance mechanisms, retention and erasure rules, processor contracts, and a breach notification runbook covering both the individuals affected and the Data Protection Board.
Certification and sector framework readiness
For ISO 27001:2022 we run a gap assessment against the management system clauses and the ninety-three Annex A controls, help you define scope and the statement of applicability, build the documentation set, and prepare you for stage one and stage two audits with the certification body.
For regulated sectors we map the same underlying controls onto the applicable framework, whether that is the SEBI cyber security and cyber resilience framework for market intermediaries or the CERT-In directions on logging, clock synchronisation and six-hour incident reporting.
Doing this once and mapping many-to-one avoids the common trap of running three parallel compliance programmes that all ask for the same evidence in different formats.
Ongoing advisory for organisations without a full-time CISO
Many mid-sized Indian firms need security leadership a few days a month rather than a permanent hire. We work as an outside security lead: chairing a monthly review, keeping the risk register current, reviewing architecture changes before they ship and answering customer security questionnaires.
That last item matters commercially. Enterprise buyers now send detailed security due diligence questionnaires, and a slow or weak response delays contracts. Having consistent, evidenced answers on file shortens sales cycles.
We also review supplier and vendor risk, since a large share of incidents arrive through a third party with access to your systems or your data.
What you get with security consultancy
- Current-state assessment across identity, endpoint, network, cloud and backup
- Risk register with likelihood, impact, owners and target dates
- Personal data map covering what you hold, why, where and for how long
- DPDP readiness pack including notices, retention rules and a breach runbook
- ISO 27001:2022 gap assessment, scope and statement of applicability support
- Policy set written in plain language for staff to actually follow
- Supplier and third party risk review with contract clause recommendations
- Prioritised remediation roadmap phased against your budget
How an engagement runs
Every project goes through the same six stages, so you always know what happens next and what it costs.
01
Requirement analysis
We map what you actually need before proposing anything.
02
Strategic planning
Scope, milestones and a fixed number, agreed in writing.
03
Implementation
Built in the open, with a live staging link from week one.
04
Quality assurance
Functional, security and performance testing before sign-off.
05
Deployment
A launch plan with rollback, monitoring and zero surprises.
06
Continuous support
We stay on for as long as you use what we built.
FAQ
Security Consultancy: questions we are asked
They establish what you need to protect, assess what is currently in place, and produce a prioritised plan with owners and dates. In practice that also means writing usable policies, preparing for certification or sector frameworks, answering customer security questionnaires and reviewing architecture changes before they reach production.
If you determine the purpose and means of processing digital personal data, you are a data fiduciary under the Digital Personal Data Protection Act 2023, regardless of size. The DPDP Rules notified in November 2025 phase obligations in over the following months, with core business requirements on the longer timeline, so preparation time exists but is finite.
For an organisation starting from a reasonable baseline, six to nine months to certification is realistic, covering gap assessment, control implementation, documentation, an internal audit, a management review, then the stage one and stage two audits. Certification is granted by an accredited certification body, and we prepare you for that process.
Yes. It suits organisations that need security leadership regularly but not full time. The arrangement typically covers a monthly governance review, maintenance of the risk register, architecture review for significant changes, customer security questionnaire responses and incident escalation support, scaled to an agreed number of days each month.
A penetration test tells you which specific weaknesses an attacker could exploit today. Consultancy addresses why those weaknesses keep appearing: governance, ownership, process, architecture and supplier management. Most organisations need both, and a test commissioned without anyone owning remediation tends to produce the same findings the following year.
Often bought together
What pairs well with security consultancy
Cyber Security
Enterprise Security
End-to-end security architecture for large-scale organizations.
Cyber Security
Penetration Testing
Identifying vulnerabilities before hackers do.
Compliance Services
Accreditation
Helping you achieve industry-standard certifications and quality marks.
Compliance Services
Consultation
Expert guidance on regulatory frameworks and business operations.
Get a written quote for security consultancy.
Tell us what you are trying to achieve and we will come back with scope, timeline and a fixed number — or tell you honestly that we are not the right team.
Talk to a specialist