Every quarter
ISMS internal audit
Clause 9.2 expects a documented audit programme. Most SMEs audit a few control areas each quarter rather than everything at once.
ISO 27001Compliance Calendar
The DPDP Act now runs on fixed dates, and ISO 27001 on a repeating cycle. Both are here in one place.
228 days until full compliance
Every quarter
Clause 9.2 expects a documented audit programme. Most SMEs audit a few control areas each quarter rather than everything at once.
ISO 27001Every year
Required in each of the two years after certification. Start your internal review 8–10 weeks before the date.
ISO 27001Every 3 years
A full reassessment of your ISMS. Treat it as a fresh certification, not a renewal, and you’ll face fewer findings.
ISO 27001Within 6 hours
Report specified cyber incidents to CERT-In within six hours of noticing them, and keep ICT logs for 180 days.
CERT-InWithin 72 hours
From 13 May 2027, send the Data Protection Board a detailed breach report within 72 hours of becoming aware.
DPDP ActSurveillance and recertification dates depend on your own certificate. We’ll confirm the exact dates that apply to you on a call.
Threat Watch
The weaknesses that do the most damage in Indian manufacturing units right now, worst first, with one thing to do about each.
Remote-access boxes left on old firmware let attackers in without a password, straight into ERP and SCADA networks.
Do this weekUpdate the firmware, turn on MFA for every VPN user, and delete accounts nobody uses.
Exposed RDP on office and ERP servers is still a leading way in for ransomware, often through a guessed or reused password.
Do this weekTake RDP off the internet and put it behind the VPN, with MFA and account lockout.
DVRs and NVRs still on factory logins are scanned for constantly, then used as a way into the office network.
Do this weekChange the default logins, update the firmware, and move recorders onto their own network.
Shop-floor controllers with default engineering passwords can be reconfigured by anyone who reaches the same network.
Do this weekSeparate the shop-floor network from the office, and change default engineering passwords.
Third-party modules and web portals with injection flaws can leak vendor, payroll and pricing data without anyone noticing.
Do this weekAsk your ERP partner for the latest add-on versions, and test customer-facing portals once a year.
Fake logistics, customs-clearance and GST notices, sent by email and WhatsApp, try to redirect payments or steal logins.
Do this weekConfirm every change to a vendor’s bank details by phone, and run a phishing drill.
A general picture drawn from public advisories such as CERT-In’s, not a scan of your systems. Ask us for an exposure check against the exact systems you run.
Guides
Short, practical reads from our audit work. Open any guide to read it in full.
The five duties that matter most before 13 May 2027, in plain English: notice and consent, people’s rights, security safeguards, breach reporting, and keeping only what you need.
Four themes, 93 controls, and where to start your gap assessment.
Attackers exploit change the day it happens. Test on change, not on the calendar.
Realistic lures, coaching instead of punishment, and the metric that actually matters.
Contain first, preserve the evidence, and log every action from minute one.
A rotating schedule, auditors who don’t mark their own work, and findings tracked to closure.
News
What’s changed in security and compliance, filtered for what matters to manufacturers.
The rules were notified on 13 November 2025 and the Data Protection Board is already in place. Consent Manager registration opens on 13 November 2026; everything else applies from 13 May 2027.
Source: MeitY notification, November 2025The move to the 2022 version closed on 31 October 2025. A certificate that wasn’t upgraded is no longer valid for tenders that ask for ISO 27001.
Source: IAF transition requirementsIndustry reporting keeps manufacturing at or near the top of ransomware target lists: downtime is expensive, and shop-floor systems are often left unpatched.
Source: industry threat reportsA growing share of SME incidents begin with a compromised vendor or logistics partner’s portal, which is why vendor risk belongs inside your ISMS scope.
Source: industry threat reportsTargeted phishing disguised as invoices, shipping papers or statutory notices remains the most common way attackers first get into Indian mid-market networks.
Source: CERT-In advisoriesUnderwriters increasingly ask for evidence of MFA, patching and tested backups before they renew or price a policy: the same things an ISO 27001 audit checks.
Source: insurance market reportingA curated summary, not a live feed. Message us on WhatsApp for the sources behind any item.
Resources
Select checklists and templates are available to clients as part of an active engagement. Reach out via the contact page for access.
Yes — we run tailored workshops on secure development practices, incident response tabletop exercises, and compliance awareness.
We review it every month, using public advisories and what we see in client work. For a check against the exact software versions you run, ask us for a free security health check.
Our advisory desk answers scoped questions within one business day.