Contact Us

Compliance Calendar

The dates to plan around

The DPDP Act now runs on fixed dates, and ISO 27001 on a repeating cycle. Both are here in one place.

DPDP Act rollout

228 days until full compliance

  1. Rules notified. Data Protection Board set up.
  2. Consent Manager registration opens.
  3. Every obligation applies. Full compliance due.

Every quarter

ISMS internal audit

Clause 9.2 expects a documented audit programme. Most SMEs audit a few control areas each quarter rather than everything at once.

ISO 27001

Every year

Surveillance audit

Required in each of the two years after certification. Start your internal review 8–10 weeks before the date.

ISO 27001

Every 3 years

Recertification audit

A full reassessment of your ISMS. Treat it as a fresh certification, not a renewal, and you’ll face fewer findings.

ISO 27001

Within 6 hours

Cyber incident report

Report specified cyber incidents to CERT-In within six hours of noticing them, and keep ICT logs for 180 days.

CERT-In

Within 72 hours

Personal data breach report

From 13 May 2027, send the Data Protection Board a detailed breach report within 72 hours of becoming aware.

DPDP Act

Surveillance and recertification dates depend on your own certificate. We’ll confirm the exact dates that apply to you on a call.

Threat Watch

What attackers are going after

The weaknesses that do the most damage in Indian manufacturing units right now, worst first, with one thing to do about each.

  1. Critical

    Unpatched VPN and firewall appliances

    Remote-access boxes left on old firmware let attackers in without a password, straight into ERP and SCADA networks.

    Remote accessActively exploited

    Do this weekUpdate the firmware, turn on MFA for every VPN user, and delete accounts nobody uses.

  2. Critical

    Remote desktop open to the internet

    Exposed RDP on office and ERP servers is still a leading way in for ransomware, often through a guessed or reused password.

    Servers and ERPRansomware entry point

    Do this weekTake RDP off the internet and put it behind the VPN, with MFA and account lockout.

  3. High

    Default passwords on CCTV recorders

    DVRs and NVRs still on factory logins are scanned for constantly, then used as a way into the office network.

    CCTV and DVRMass scanning

    Do this weekChange the default logins, update the firmware, and move recorders onto their own network.

  4. High

    PLCs and HMIs reachable from the office

    Shop-floor controllers with default engineering passwords can be reconfigured by anyone who reaches the same network.

    Shop floor (ICS)Mitigation only

    Do this weekSeparate the shop-floor network from the office, and change default engineering passwords.

  5. Medium

    Outdated ERP add-ons and vendor portals

    Third-party modules and web portals with injection flaws can leak vendor, payroll and pricing data without anyone noticing.

    ERPFix from your vendor

    Do this weekAsk your ERP partner for the latest add-on versions, and test customer-facing portals once a year.

  6. Medium

    Invoice and customs phishing aimed at exporters

    Fake logistics, customs-clearance and GST notices, sent by email and WhatsApp, try to redirect payments or steal logins.

    Email and WhatsAppAwareness training

    Do this weekConfirm every change to a vendor’s bank details by phone, and run a phishing drill.

A general picture drawn from public advisories such as CERT-In’s, not a scan of your systems. Ask us for an exposure check against the exact systems you run.

Guides

Frameworks, field notes and findings

Short, practical reads from our audit work. Open any guide to read it in full.

DPDP Act

What the DPDP Act actually requires of your business

The five duties that matter most before 13 May 2027, in plain English: notice and consent, people’s rights, security safeguards, breach reporting, and keeping only what you need.

228days until the main duties apply
7 min read
ISO 27001

The 93 Annex A controls, explained in plain English

Four themes, 93 controls, and where to start your gap assessment.

9 min read
Penetration Testing

Why annual penetration tests aren’t enough anymore

Attackers exploit change the day it happens. Test on change, not on the calendar.

6 min read
Human Risk

Designing a phishing simulation program employees respect

Realistic lures, coaching instead of punishment, and the metric that actually matters.

5 min read
Incident Response

The first 60 minutes of a breach determine the next 60 days

Contain first, preserve the evidence, and log every action from minute one.

8 min read
Governance

Building an internal audit function that scales with headcount

A rotating schedule, auditors who don’t mark their own work, and findings tracked to closure.

6 min read

News

Worth knowing this month

What’s changed in security and compliance, filtered for what matters to manufacturers.

Regulation

DPDP Rules are final: full compliance due 13 May 2027

The rules were notified on 13 November 2025 and the Data Protection Board is already in place. Consent Manager registration opens on 13 November 2026; everything else applies from 13 May 2027.

Source: MeitY notification, November 2025
Standards

ISO/IEC 27001:2013 certificates have expired

The move to the 2022 version closed on 31 October 2025. A certificate that wasn’t upgraded is no longer valid for tenders that ask for ISO 27001.

Source: IAF transition requirements
Ransomware

Manufacturing is still the most-targeted sector for ransomware

Industry reporting keeps manufacturing at or near the top of ransomware target lists: downtime is expensive, and shop-floor systems are often left unpatched.

Source: industry threat reports
Supply chain

More breaches now start at a vendor, not at you

A growing share of SME incidents begin with a compromised vendor or logistics partner’s portal, which is why vendor risk belongs inside your ISMS scope.

Source: industry threat reports
Workforce

CERT-In advisories keep pointing to phishing

Targeted phishing disguised as invoices, shipping papers or statutory notices remains the most common way attackers first get into Indian mid-market networks.

Source: CERT-In advisories
Cyber insurance

Insurers want proof of controls before renewal

Underwriters increasingly ask for evidence of MFA, patching and tested backups before they renew or price a policy: the same things an ISO 27001 audit checks.

Source: insurance market reporting

A curated summary, not a live feed. Message us on WhatsApp for the sources behind any item.

Resources

Frequently asked questions

Select checklists and templates are available to clients as part of an active engagement. Reach out via the contact page for access.

Yes — we run tailored workshops on secure development practices, incident response tabletop exercises, and compliance awareness.

We review it every month, using public advisories and what we see in client work. For a check against the exact software versions you run, ask us for a free security health check.

Have a specific governance question?

Our advisory desk answers scoped questions within one business day.