Knowledge Portal

Practitioner Intelligence
for Indian BFSI
Security Leaders.

Regulatory guides, checklists, and interactive tools — organised by the platform and persona they serve. No registration required.

133
items today
3
platforms
3
clicks max
For Data Protection Officers
DPDP Assurance
68 items — DPDP Act, ROPA, consent, DPIA
→
For CISOs & Risk Officers
RiskSage AI
26 items — FAIR, board risk, NIST CSF, IRDAI
→
For GRC & Audit Teams
Practitioner Toolkit
39 items — SEBI CSCRF, CyberDrill, VAPT, BCP/DR
→
Platform
Category
⌕
DPDP Assurance
68 items
🛠Tools
ToolNEW🔒 Practitioner
DPDP PETs Crossword — Privacy Enhancing Technologies Puzzle
Test your knowledge of Privacy Enhancing Technologies under India's DPDP Act. An interactive crossword on PETs, consent, ROPA, encryption and federated learning.
ToolNEW🔒 Practitioner
Consent vs Legitimate Use Quiz — DPDP Act 2023 Processing Bases
12 real scenarios. Classify each as Consent, Legitimate Use, Exempt, or Prohibited under DPDP Act 2023. Sharpen your DPO judgement on India's data protection law.
ToolNEW🔒 Practitioner
DPO Challenge Crossword — DPDP Act & Privacy Governance Terminology
15-clue crossword covering DPDP Act 2023 key terms — Data Fiduciary, consent, DPIA, breach, DPB, and more. Test your privacy governance vocabulary.
ToolNEW🔒 Practitioner
ROPA Gap Spotter — Find Missing Fields in Your Record of Processing Activities
Paste your ROPA and instantly identify 12 common gaps — missing legal basis, absent retention periods, unlisted processors, and more. Aligned to DPDP Act 2023 and ISO 27701.
ToolNEW🔒 Practitioner
Consent Fatigue Simulator — DPDP Act §6
Experience 12 real-world consent banners in 90 seconds. See how consent fatigue drives non-compliance with DPDP Act 2023 §6 — a must-try simulator for DPOs and product teams.
ToolNEW🔒 Practitioner
Data Principal Rights Quiz — DPDP Act 2023 | CreativeCyber Knowledge
10 scenario-based questions on Data Principal rights under India's DPDP Act 2023 — §§11-14, §17. Test your knowledge and get your score with DPDP Act citations.
ToolNEW🔒 Practitioner
DPDP Breach Decision Tree — CERT-In 6h vs DPB Notification
Interactive Y/N flowchart: when must you file a CERT-In 6-hour report vs notify the Data Protection Board? Walk through the dual-reporting decision logic for Indian regulated entities.
ToolNEW🔒 Practitioner
DPIA Necessity Wizard — Do You Need a DPIA Under DPDP Act 2023?
Interactive 7-question wizard that determines whether your processing activity requires a Data Protection Impact Assessment under DPDP Act 2023. Instant verdict with action steps.
ToolNEW🔒 Practitioner
DPIA Threat-to-Control Mapper | CreativeCyber Knowledge
Map 8 real privacy threats to their DPDP Act controls. Interactive tool + article for DPOs and privacy practitioners building DPIA competence.
ToolNEW🔒 Practitioner
Privacy by Design Audit Card — 24-Point DPDP Act Scorecard
Score your Privacy by Design posture across 6 domains — 24 checkpoints aligned to DPDP Act 2023 §8(1). Export your scorecard as a PDF. Built for DPOs and product teams.
ToolNEW🔒 Practitioner
Privacy Governance Sudoku — DPDP Act 2023 | CreativeCyber Knowledge
Can you complete the 4×4 Privacy Governance Sudoku? Place Policy, Control, Role, and Activity correctly across each row, column, and box. Built for DPOs and privacy practitioners.
📄Articles
ArticleNEW🔒 Practitioner
Not All Vendor Breaches Are Equal — Your TPRM Program Probably Treats Them That Way
A breach at your invoicing vendor is bad for you. A breach at the utility your whole industry depends on for identity verification is bad for everyone, simultaneously. Most TPRM questionnaires score both vendors the same way.
Article🔒 Practitioner
The DPDP Implementation Roadmap: 5 Phases, 21 Activities, and the Platform Module Behind Each One
A phase-by-phase DPDP Act 2023 implementation roadmap — Discover, Assess, Build, Operationalise, Sustain — with every activity mapped to a specific DPDP Assurance Platform module, DPDP Act section, and CAI scoring component.
ArticleNEW🔒 Practitioner
DPDP Act Penalties FAQ: How Much, Who Decides, Can You Appeal?
A plain-English FAQ on DPDP Act 2023 penalties — maximum fines by violation type, how the Data Protection Board sets the actual amount, whether you can appeal, and how it compares to GDPR.
ArticleNEW🔒 Practitioner
Your DPDP Checklist Is Complete. Your Privacy Risk Isn't Gone.
Most organisations can tick every DPDP compliance box and still ship a feature that re-identifies an 'anonymised' customer. Here's how LINDDUN privacy threat modeling finds what checklists miss — with a worked lending example.
Article🔒 Practitioner
DPDP Accountability and Scoping FAQ — DSA, BC, TPA, Co-lender
Scoping decisions and accountability allocations for DSAs, Business Correspondents, TPAs, co-lenders, and other structures under India's DPDP Act 2023. Covers BFSI, health, edtech, and marketplace models.
Article🔒 Practitioner
DPDP Consent Manager FAQ — What Small Organisations Need to Know
Do you need to become a Consent Manager? Do you need to use one? Plain answers to 12 common DPDP consent questions for small institutions and non-regulated entities.
Article🔒 Practitioner
DPDP Rules 2025 Explained: Enterprise Compliance Guide
The Digital Personal Data Protection Rules 2025 translate India's DPDP Act into operational obligations. Breach notification, consent, SDF duties, children's data — explained for BFSI compliance teams.
Article🔒 Practitioner
DPDP Third-Party Risk Assessment Framework for Data Fiduciaries
A 7-step DPDP-aligned third-party risk assessment framework covering vendor classification, DPA minimum requirements, security safeguard evidence, sub-processor governance, and BFSI sector overlays.
Article🔒 Practitioner
How AI Will Transform DPDP Compliance — And What That Means for India's BFSI Sector
AI is reshaping how Indian banks and NBFCs approach DPDP Act 2023 compliance. From automated gap analysis to AI-powered DPIA generation — here's what's changing and how CreativeCyber's DPDP Assurance Platform is built for it.
Article🔒 Practitioner
Frontier AI Is Making DPDP Compliance Significantly Harder
7 ways frontier AI — LLMs, AI agents, and generative tools — create new DPDP Act 2023 compliance gaps for India's BFSI sector. Shadow AI, cross-border LLM calls, consent bypass, and more.
Article🔒 Practitioner
“We Have Consent” Is Not Enough: DPDP Consent Architecture
Every BFSI firm says they have consent. What they have is consent forms. The DPDP Act requires something architecturally different — verifiable, purpose-linked, withdrawal-trackable records.
Article🔒 Practitioner
Employee Data Under DPDP: The Overlooked Obligation BFSI HR Teams Get Wrong
Every DPDP discussion focuses on customer data. But the Act applies equally to employee data — and most BFSI HR teams have no compliance programme in place for it.
Article🔒 Practitioner
Building a DPDP Audit Programme: A Guide for Internal Auditors at BFSI
Internal audit's role in DPDP is to independently verify that the compliance programme is real — not to implement it. Here is how to structure the programme and what red flags to look for.
Article🔒 Practitioner
DPDP Accountability & ₹250 Crore Exposure: What Every BFSI Board Must Know
Under the DPDP Act, boards cannot delegate accountability to the DPO. What every BFSI CEO and board risk committee needs to understand about penalty exposure and governance.
Article🔒 Practitioner
The CIO's DPDP To-Do List: Data Governance Before the Next Audit
The DPO asks the CIO to produce a complete inventory of every system holding Aadhaar numbers. The answer takes six weeks. This is the DPDP gap between IT and compliance.
Article🔒 Practitioner
Mapping Your Security Controls to DPDP: What CISOs at BFSI Organisations Must Document Now
Security teams spend years building controls. The DPDP Act now requires you to prove those controls exist as documented safeguards linked to specific processing activities.
Article🔒 Practitioner
Quantifying Privacy Risk Under DPDP: A CRO Framework for BFSI
Privacy risk is now a board-level financial risk. Unlike market or credit risk, you can materially reduce it through documented controls — and the penalty exposure is bounded and quantifiable.
Article🔒 Practitioner
Privacy by Design Is Not a Checkbox: What the DPDP Act Requires from Your Data Architecture
Privacy by design appears in the DPDP Act. Most engineering leaders treat it as an aspiration. It is not — it is a set of specific architectural obligations that flow from your ROPA.
Article🔒 Practitioner
Auto OEM + Dealer + Insurer: Vehicle Telematics Is Personal Data — and Warranty Consent Doesn't Cover UBI
GPS location, speed, braking patterns — all personal data. The compliant telematics architecture for OEMs, dealers, and insurers managing the DPDP three-party data chain.
Article🔒 Practitioner
Bank + Credit Bureau + BNPL: The Credit Data Ecosystem Under DPDP
CICRA mandate vs DPDP consent, AA data scope limits, BNPL model training restrictions, and credit dispute redress under the new framework.
Article🔒 Practitioner
E-Commerce Marketplace + Third-Party Sellers: Who Controls Customer Data & Handles DSAR?
Who responds to a DSAR on an e-commerce platform — the marketplace, the seller, or both? Right to erasure limits and deletion workflow architecture.
Article🔒 Practitioner
EdTech + Schools: Processing Children's Data Under §9 DPDP and the Parental Consent Architecture
Who collects parental consent — the school or the EdTech platform? AI profiling limits for minor data subjects and the k-anonymity threshold for training data.
Article🔒 Practitioner
Health Insurer + Hospital Network: Sensitive Data, TPA Role Determination, and Claims Processing Under DPDP
Is your TPA a Data Processor or a co-Fiduciary? Health data DPIA obligations, actuarial use limits, and the three-entity liability map explained.
Article🔒 Practitioner
Mobile OEM + NBFC: Who Is the Data Fiduciary in Embedded Finance?
When a smartphone OEM partners with an NBFC for embedded EMI financing, both entities are independent Data Fiduciaries. Implementation answers grounded in DPDP Act §6, §7, and RBI KYC mandates.
Article🔒 Practitioner
Payroll SaaS + HR Analytics: Is Employment Contract Consent Valid for AI Attrition Scoring?
Employment contract consent is insufficient for AI attrition profiling. Cross-border payroll data rules, employee DSAR rights to flight-risk scores, and the power imbalance problem.
Article🔒 Practitioner
Real Estate Aggregator + Developer + Home Loan Bank: The Consent Architecture That “We May Share With Relevant Partners” Cannot Provide
“We may share with relevant service providers” is not valid DPDP consent. The lead generation consent architecture real estate platforms need.
Article🔒 Practitioner
Cloud SaaS + Enterprise Tenant: Data Fiduciary vs. Processor in B2B Platforms
In B2B SaaS, who is the Data Fiduciary? Cross-border DR, breach notification chains, DSAR routing, and the DPA checklist for SaaS procurement.
Article🔒 Practitioner
Telecom + UPI App (TPAP): When SIM Activation Consent Fails the Credit Scoring Test
SIM activation consent does not cover credit scoring. The compliant consent architecture for telecom operators licensing identity to co-branded fintech apps.
Article🔒 Practitioner
DPDP Penalty Exposure: How the Data Protection Board Calculates Fines
A scenario-based guide to penalty exposure under DPDP Act 2023 — how the Data Protection Board calculates fines, which violations carry the highest risk, what mitigating factors the Board considers, and how DPOs should frame board conversations about regulatory exposure.
Article🔒 Practitioner
Your ROPA Is Incomplete. Here's What DPDP Rules 2025 Actually Demand.
78% of Indian DPOs carry GDPR residue in their ROPA. DPDP Rules 2025 mandate 11 fields — 6 are commonly missing, including Consent Artifact ID. Fix your ROPA before enforcement begins.
Article🔒 Practitioner
DPDP Meets Vendor Risk: Why Your Third-Party Contracts Are Now a Compliance Problem
DPDP §8/§9 imposes DPA obligations for every vendor processing personal data. The sub-processor problem and what an RBI inspector asks.
Article🔒 Practitioner
DPDP Act 2023 vs GDPR: A Practitioner's Comparison
A structured, clause-by-clause comparison of India's DPDP Act 2023 and the EU GDPR — lawful bases, data subject rights, breach timelines, DPO obligations, penalties, and what GDPR-trained practitioners must unlearn.
Article🔒 Practitioner
The DPO's DPIA Readiness Checklist: What RBI DPSC §4.2 Requires
Under the DPDP Act, DPOs are personally accountable for ensuring DPIAs are completed before high-risk processing begins. Here is exactly what that means in practice.
Article🔒 Practitioner
The DPO Role Under DPDP Act 2023: Independence & Responsibilities
A definitive guide to the Data Protection Officer role under India's DPDP Act 2023 — who can be a DPO, what independence means in practice, reporting lines, budget authority, protection from dismissal, and the full scope of DPO responsibilities.
Article🔒 Practitioner
DSAR Handling Playbook: Managing Data Subject Access Requests Under DPDP
A step-by-step playbook for DPOs managing Data Subject Access Requests under India's DPDP Act 2023 — from receipt and identity verification to scoping, response drafting, and partial refusals.
Article🔒 Practitioner
Running a DPDP Gap Assessment That Regulators Will Accept
A consultant's generic ISO checklist renamed DPDP Gap Assessment will not survive a regulator inquiry. Here is what a credible one looks like — question bank, scoring, and CAPA discipline.
Article🔒 Practitioner
DPDP Act vs GDPR: The Comparison India's DPOs Need
Side-by-side: 9 GDPR rights DPDP doesn't have, no legitimate interest basis, ₹250Cr penalties, and what your GDPR programme gets right for Indian law.
Article🔒 Practitioner
DPDP Consent & Notice: What Enterprises Must Document
Under India's DPDP Act 2023, consent and notice are central to lawful processing. This guide outlines what to document and how to keep evidence audit-ready.
Article🔒 Practitioner
DPDP Gap Assessment: How to Evaluate Compliance Readiness
A DPDP gap assessment evaluates your organization's readiness under the Act. This guide covers the structured approach to compliance evaluation.
Article🔒 Practitioner
DPDP Gap Assessment: The Practitioner's Playbook for RBI-Regulated Banks
A structured guide for compliance officers and DPOs running their first DPDP gap assessment — with RBI DPSC control mapping, scoring logic, and what to do with the results.
Article🔒 Practitioner
DPDP Steering Committee, KRIs & Data Discovery
Execution playbook covering governance metrics, data discovery, classification frameworks, and audit readiness for BFSI compliance programmes.
Article🔒 Practitioner
DPDP Privacy Incident Response: A Tabletop-Ready Playbook
Data breaches require a clear, repeatable response. This playbook gives you a tabletop-ready structure for DPDP incident response.
Article🔒 Practitioner
DPDP Data Retention & Deletion: How to Build an Audit-Ready Policy
Under the DPDP Act 2023, data fiduciaries must retain personal data only as long as necessary and delete or anonymise it when the purpose is fulfilled.
Article🔒 Practitioner
DPDP Act 2023 & Rules 2025: Enterprise Guide to Operational Compliance
A regulator-grade, audit-ready blueprint for DPOs, compliance leaders, CISOs, and BFSI teams to move from policy to proof under DPDP Act 2023 and Rules 2025.
Article🔒 Practitioner
DPDP Vendor & Processor Management: Practical Controls for Enterprises
When you share personal data with vendors or processors, the DPDP Act 2023 holds you accountable. This guide covers contracts, due diligence, and ongoing oversight.
Article🔒 Practitioner
Building a DPIA Programme Under DPDP Rules 2025
DPDP Rules 2025 mandate annual DPIAs for Significant Data Fiduciaries. This guide covers what counts as high-risk processing, the 9-step DPIA workflow, and what makes a DPIA regulator-defensible.
Article🔒 Practitioner
From Compliance Score to Board Assurance
A compliance score means nothing without evidence. This guide shows how DPOs and CISOs use the Assurance Centre to turn control attestations into board-ready assurance with regulator-verifiable certificates.
Article🔒 Practitioner
Is ROPA Mandatory Under DPDP Act 2023?
While DPDP does not prescribe GDPR-style ROPA, maintaining documented processing records is essential to demonstrate accountability.
Article🔒 Practitioner
ROPA as a Compliance Asset: How BFSI Firms Build Audit-Ready Processing Registers
Most BFSI organisations treat ROPA as a documentation exercise. The firms that use it as a compliance asset drive DPIA triggers, feed gap assessments, and generate policies from it.
Article🔒 Practitioner
What Is DPDP Act 2023? A Practical Guide for Enterprises
The Digital Personal Data Protection (DPDP) Act 2023 establishes India's framework for lawful personal data processing.
Article🔒 Practitioner
When Is DPIA Required Under DPDP?
High-risk personal data processing requires deeper evaluation and mitigation planning under the DPDP Act 2023.
Go to DPDP Assurance platform ↗
RiskSage AI
26 items
📄Articles
ArticleNEW🔒 Practitioner
AI Impact Assessments in BFSI: A Use-Case Guide to KYC, Fraud & Credit AI
KYC classifiers, fraud models, and credit scoring AI each carry different risk. A practical, use-case-based guide to running AI impact assessments in Indian BFSI before deployment.
ArticleNEW🔒 Practitioner
"AI Is Risky" Isn't a Line Item Your Board Can Act On
Three AI incidents made the same news cycle — a sandbox escape, an identity hijack, an infostealer compromise. Covered as 'AI is risky' a board can only nod at. Sorted onto three owners, a board can act.
ArticleNEW🔒 Practitioner
The Board Strategy Document Every CISO Writes Alone
Every CISO writes the same three-year strategy and risk appetite statement alone, once a year, under deadline. RiskSage's StrategyForge turns a six-question interview into a nine-section, board-ready document — grounded in data already sitting in the platform.
ArticleNEW🔒 Practitioner
Credential Theft Is Yesterday's Problem. This Is Today's.
A password-reset hijack, an AI agent turned against its own user, a sandbox escape — none of them involved a stolen credential. Here's the pattern connecting three 2026 incidents, and why identity risk needs a quantified home, not another MFA prompt.
ArticleNEW🔒 Practitioner
The Curious Case of Threat Exposure
A CISO's field investigation into AI-powered attacks against NBFCs — synthetic fraudsters, model-gaming adversaries, and the eight-step method for measuring your actual AI threat exposure, told as a detective story.
ArticleNEW🔒 Practitioner
Your Autonomous Defense Stopped the Attack. Your Audit Trail Didn't Survive It.
Agentic XDR and SOAR platforms now block, quarantine, and isolate without a human in the loop. Here's the governance gap between a fast autonomous decision and one you can actually defend to a regulator or a board.
Article🔒 Practitioner
26% of India's Breaches Are Now AI-Generated — Here's What STRIDE Catches That Signature Tools Don't
IBM's 2026 report: 26% of Indian breaches are AI-generated. Signature-based tools can't keep up. A practical STRIDE walkthrough showing exactly which threats slip through — and how structured threat modelling closes the gap.
ArticleNEW🔒 Practitioner
When the Model Escapes the Lab — HuggingFace Breach Mapped to RBI MRM 2026
How a frontier AI autonomously breached HuggingFace's production infrastructure in July 2026 — and every gap mapped to the RiskSage Model Risk Management module aligned to RBI FREE-AI and India AI Gov Guidelines 2025.
ArticleNEW🔒 Practitioner
RBI 2026 Decoded for CISOs — CreativeCyber Knowledge | RiskSage
A practitioner's guide to RBI (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026. 229 obligations. What changed. What it means for you. How RiskSage maps to every requirement.
Article🔒 Practitioner
CERT-In's AI-Assisted Exploitation Blueprint: A BFSI Field Guide to the Impossible Timelines
CERT-In's AI-Assisted Exploitation Blueprint (v1.0, 25.05.2026) expects 6-hour reporting, 12-hour patching of internet-facing crown jewels, and continuous adversarial validation. A practitioner's field guide to actually delivering it in BFSI.
Article🔒 Practitioner
Four CRQ Models for Indian BFSI — FAIR, FAIR-MAM, NIST 800-30 ALE, Probabilistic VaR
Which Cyber Risk Quantification model fits your Indian BFSI context? Compare FAIR v3.0, FAIR-MAM, NIST 800-30/ALE, and Probabilistic VaR — when to use each, their strengths, and how they map to SEBI CSCRF and board reporting in rupee crore.
Article🔒 Practitioner
India AI Governance Guidelines 2025 — What Indian BFSI CISOs Should Know
India's November 2025 AI Governance Guidelines (MeitY / IndiaAI Mission) are voluntary — not law. Learn what they cover, why BFSI has the highest exposure, and where binding AI obligations for banks and insurers actually come from.
Article🔒 Practitioner
What Your Board Actually Needs to See About Cyber Risk | RiskSage by CreativeCyber
India's regulators now hold boards personally accountable for cybersecurity oversight. Here's what the board cybersecurity dashboard must show — and why most boards are flying blind.
Article🔒 Practitioner
12 Hard Board Questions on Cybersecurity Answered
The 12 questions India's BFSI boards actually ask about cybersecurity — and direct, evidence-backed answers. Covers CERT-In 6-hour readiness, DPDP DPAs, IRDAI attestation, director liability, and SEBI CSCRF obligations.
Article🔒 Practitioner
The Slide That Made My CEO Stop Asking 'Are We Secure?'
Heat maps don't answer board questions. Rupees do. The exact ROSI narrative, FAIR methodology, and board slide structure that ends the 'are we secure?' loop.
Article🔒 Practitioner
Cyber Risk Quantification for BFSI Boards
Four CRQ models — FAIR v3.0, FAIR-MAM, NIST SP 800-30, Probabilistic VaR — explained for Indian BFSI boards. How to express cyber risk in ₹ crore, not red/amber/green.
Article🔒 Practitioner
Cybersecurity Maturity Assessment: BFSI Board Guide
NIST CSF 2.0 four tiers explained for Indian BFSI boards. How to assess your organisation's maturity, the Tier 2 to Tier 3 transition checklist, and the 12-month improvement path.
Article🔒 Practitioner
FAIR Cyber Risk Calculator — Breach Exposure in ₹ Crore
FAIR model for Indian BFSI CISOs. Benchmark ALE, recommended investment, and DPDP penalty exposure in rupees — with worked examples.
Article🔒 Practitioner
NIST CSF 2.0 Maturity Tiers — How Indian CISOs Use the RiskSage Dashboard
NIST CSF 2.0 added GOVERN as its sixth function. Learn how the four maturity tiers map to SEBI CSCRF and how the RiskSage CISO dashboard tracks your organisation's CSF posture in real time.
Article🔒 Practitioner
PASTA Threat Modelling for Real Banking Systems: Add-Beneficiary & Fund-Transfer Walkthrough
A 7-stage PASTA threat model walkthrough on the add-beneficiary + fund-transfer flow used by every Indian retail bank — DFD, STRIDE catalog, attack tree, risk matrix, and SEBI/RBI/DPDP control mapping.
Article🔒 Practitioner
RBI DPSC Compliance Guide: Digital Payment Security Controls
75+ mandatory RBI DPSC controls across 6 payment channels. The BFSI practitioner playbook — 10 inspection gaps, evidence pack structure, and enforcement sequence.
Article🔒 Practitioner
Why Indian BFSI Needs a Risk Graph, Not a Risk Register
Your risk register doesn't know the system changed or that a new IRDAI circular changed the obligation. A risk graph knows.
✓Checklists
Go to RiskSage AI platform ↗
Practitioner Toolkit
39 items
📄Articles
Article🔒 Practitioner
The Auditor's CyberDrill Evidence Framework: What Survives SEBI Inspection
8 evidence quality tests for SEBI CSCRF ID.5, deficiency patterns, and the 10-section audit-grade drill report structure that holds up under inspection.
Article🔒 Practitioner
The CISO's CyberDrill Playbook: Moving from Compliance Theater to Command Readiness
How CISOs design CyberDrill programs that expose command gaps, validate the CERT-In 6-hour clock, and produce SEBI ID.5 evidence that withstands inspection.
Article🔒 Practitioner
The Infra Team's CyberDrill Guide: Technical Readiness Beyond Tabletop
Log retention across 13 CERT-In sources, evidence preservation sequence, DR failover RTO testing, and NTP sync compliance for infra teams running structured cyber drills.
Article🔒 Practitioner
The AI Governance Vacuum: Building an AI Security Assessment Framework
AI adoption is outpacing security assessment in Indian enterprises. Eight AI security domains, a tiered governance model and how to report AI risk to the board.
Article🔒 Practitioner
Why Recovery Is the Weakest CSCRF Domain: Evidencing Your BCP/DR
Most organizations have recovery plans but no evidence they work. Build validated, testable BCP/DR evidence for SEBI RC.1-4 and RBI requirements.
ArticleFEATURED🔒 Practitioner
The 6-Hour Rule: CERT-In Incident Reporting in India
India's CERT-In mandates cyber incident reporting within 6 hours. RBI, IRDAI, and DPBI run in parallel from the same timestamp. Criminal penalties under IT Act §70B for non-compliance.
Article🔒 Practitioner
CERT-In 6-Hour Incident Reporting SOP for Indian Banks & NBFCs
Step-by-step CERT-In 6-hour cyber incident reporting SOP for Indian banks, NBFCs, and payment aggregators. Hour-by-hour response timeline, portal field checklist, and the most common reporting mistakes.
Article🔒 Practitioner
CSITe Portal Filing Guide: How Indian Organisations Actually Submit CERT-In Incident Reports
Step-by-step walkthrough of the CERT-In CSITe portal — registration, incident classification, the 6-hour field checklist, common rejection reasons, and what happens after you submit.
Article🔒 Practitioner
Designing Tabletop Drills That Produce SEBI and CERT-In Evidence
Most tabletop exercises produce no usable evidence. Design scenarios that test real capabilities and document findings, owners and closure for auditors.
Article🔒 Practitioner
DPDP ₹250 Crore Penalty Exposure: The Board Briefing
The DPDP penalty schedule up to ₹250 Crore, the 11 obligations for Data Fiduciaries and a compliance roadmap boards can act on before May 2027.
Article🔒 Practitioner
IRDAI's March 2025 Cybersecurity Revision: What Every Insurer Needs to Know
IRDAI's March 2025 revision tightens incident reporting to 6 hours, mandates board attestation, and expands scope to TPAs, brokers, web aggregators, ISNPs, and IMFs.
Article🔒 Practitioner
ISO 27001 Audit Readiness: Building a 93-Control SoA That Survives Scrutiny
The 2022 revision cut Annex A to 93 controls. Why auditors reject Statements of Applicability and how to build one that holds up in certification.
Article🔒 Practitioner
PASTA Threat Modeling In-House: The 7-Stage Process Without Consultants
Run the seven PASTA stages in-house with structured tooling: stage-by-stage effort, outputs and how to evidence the result to auditors.
Article🔒 Practitioner
From Circular to Closure: Tracking 30+ Annual Regulatory Directives
Indian CISOs face 30+ regulatory circulars annually from SEBI, RBI, CERT-In, and IRDAI. Learn how to build a circular-to-closure tracking system that...
Article🔒 Practitioner
The SEBI CSCRF Evidence Crisis: Why Entities Struggle to Prove Compliance
Most regulated entities discover CSCRF evidence gaps only at inspection. The anatomy of the evidence crisis across six domains and a 16-week path to...
Article🔒 Practitioner
SEBI CSCRF Maturity Assessment: Practitioner's Survival Guide
Most BFSI organizations over-score CSCRF by 1-2 levels. The practitioner's guide with evidence quality matrix, Maker/Checker workflow, and 6-month assessment calendar.
Article🔒 Practitioner
GV.3 Training Evidence: Proving Your Awareness Programme Works
SEBI CSCRF GV.3 expects evidence that awareness training works, not just attendance. Phishing metrics, knowledge checks and trend reporting for your...
Article🔒 Practitioner
Building a TPRM Programme With Teeth: A CISO and Board Guide
Vendor tiering, continuous monitoring and board reporting for a TPRM programme that goes beyond questionnaires and decaying spreadsheets.
Article🔒 Practitioner
From 80-Page Nessus Report to Actionable Risk Findings: How AI Is Changing VAPT
AI extracts every finding from VAPT reports, maps to UCL controls, sets deadlines by severity, and closes IRDAI.AUDIT.1 automatically.
Article🔒 Practitioner
VAPT Finding Recurrence: Fixing the Vulnerability Register
VAPT findings recur across assessment cycles when closure is not tracked. Build a findings register with owners, SLAs and retest evidence that auditors accept.
Article🔒 Practitioner
Building an Evidence Framework for SEBI CSCRF: What Counts, What Doesn't
Evidence in a SEBI CSCRF assessment is not just documentation — it is the proof layer between your maturity claim and a regulator's verification. Getting it...
Article🔒 Practitioner
SEBI CSCRF Maturity Scoring: What the Numbers Mean for Your RTO
Most regulated entities treat SEBI CSCRF maturity scoring as a self-certification exercise. That is the wrong frame. Maturity levels are a proxy for...
Article🔒 Practitioner
AI Governance for Indian Enterprises: Building a Framework Before the Mandate
India does not yet have binding AI regulation. But the regulatory direction is clear, the international pressure is real, and the liability exposure from...
Article🔒 Practitioner
The 8-Domain AI Security Assessment: A Practitioner's Walk-Through
AI security is not traditional IT security applied to AI systems. The threat vectors are different, the failure modes are different, and the evidence...
Article🔒 Practitioner
Preparing the CEO Declaration and Board Report Under SEBI CSCRF
The CEO Declaration under SEBI CSCRF is a formal personal attestation of the organisation's cyber security compliance posture. It carries personal...
Article🔒 Practitioner
BCP/DR Posture Assessment: Meeting RBI and SEBI RC.1–RC.4
RC.1–RC.4 show the lowest average maturity in Indian regulated entities. BIA methodology, RTO/RPO targets regulators expect, DR test evidence, and the 9 BCP gaps SEBI inspectors cite most.
Article🔒 Practitioner
ISO 27001 Statement of Applicability: Why 40% of Indian BFSI Audits Fail at the SoA Stage
A practitioner's guide to building an ISO 27001 SoA that passes certification audits. Covers Annex A control mapping, applicability justifications, and the 7 gaps auditors flag most in Indian banks.
Article🔒 Practitioner
SEBI CSCRF ID.2 Third-Party Risk: Building a TPRM Programme That Satisfies Regulators
82% of SEBI-regulated breaches involve a third party. This guide covers CSCRF ID.2 vendor classification, inherent risk tiering, contractual controls, and the evidence regulators look for during SEBI inspections.
✓Checklists
Checklist🔒 Practitioner
Board Cyber Risk Report Checklist
Complete board cyber risk report checklist: incidents and breach summary, vulnerability posture, regulatory status, risk appetite gap, budget update, and recommended board actions.
Checklist🔒 Practitioner
CRQ Board Submission Checklist
Complete CRQ board submission checklist: FAIR Monte Carlo configuration, ALE scenario construction, risk appetite alignment, and board-ready visualisations for cyber risk quantification.
Checklist🔒 Practitioner
IRDAI Annual Board Attestation Checklist
Complete IRDAI annual board attestation checklist: ICF self-assessment, evidence package assembly, board resolution requirements, CISO attestation, and Jun 29 submission deadline.
Checklist🔒 Practitioner
CERT-In Incident Reporting Checklist
Practical checklist for CERT-In mandatory incident reporting: 9-field format, 13 log categories for 180-day retention, multi-regulator deadline matrix, reportable incident triggers, and pre-incident preparation steps.
Checklist🔒 Practitioner
IRDAI VAPT Compliance Checklist
Complete IRDAI VAPT compliance checklist: CERT-In empanelment verification, severity-based remediation deadlines, board submission timeline, IRDAI.AUDIT.1 closure evidence, and IS Audit report format.
Checklist🔒 Practitioner
RBI IT Outsourcing Inspection Checklist
RBI IT outsourcing inspection checklist: mandatory contract clauses, audit rights verification, service continuity obligations, exit management provisions, and data localisation declarations.
Checklist🔒 Practitioner
SEBI CSCRF Control & Maturity Matrix
SEBI CSCRF control and maturity matrix: continuous audit mandate mapping, NIST CSF 2.0 Tier 1-4 alignment, maturity scoring per function, and CISO dashboard mandate gate items.
Go to Practitioner Toolkit ↗
Go deeper — the platforms
DPDP Assurance
India's only BFSI-native DPDP compliance platform
PIA/DPIA wizards, ROPA register, CAI score, independent audit workspace. May 2027 deadline.
Go to platform ↗
RiskSage AI
AI-native Cyber Risk Brain for Indian CISOs
FAIR Monte Carlo, CERT-In 6hr engine, IRDAI board attestation, 440+ API endpoints. Invite-only.
Go to platform ↗
Practitioner Toolkit
BFSI compliance operations workbench
SEBI CSCRF assessment, CyberDrill, TPRM, BCP/DR, AI Security — 13 tools. Invite-only.
Go to platform ↗