Insights

Thinking from
the practice.

Not content marketing, field notes. What we learn running GRC programmes, breach clocks and board packs for regulated Indian businesses, written down.

DPDPA

DPDP Rules 2025: what the commencement clock means for your consent stack

The Rules were gazetted in November 2025 with a staggered clock. Here's what becomes enforceable when, and what to build first.

8 MIN READ · GUIDEREAD ARTICLE →
CCAP

Why annual control testing is a coin toss, and what continuous assurance fixes

The maths of point-in-time audits, and the operating model that replaces them.

6 MIN READ · POVREAD ARTICLE →
RBI · SEBI

The regulator-ready board pack: five KRIs every BFSI board should see monthly

What supervisors actually ask for, and how to render it without a reporting scramble.

7 MIN READ · CHECKLISTREAD ARTICLE →
VAPT

Risk-Based Vulnerability Management: prioritising by exploitability, not just CVSS

Why raw vulnerability counts mislead, and how a risk-based model gets remediation where it matters first.

5 MIN READ · VIDEO READ ARTICLE →
Free download

Start with the DPDPA Readiness Checklist.

40 points, ten obligation clusters, every item traced to the section or rule.

Download the checklist