Resources
Written to be cited, dated to be trusted
Guides, playbooks and direct answers for teams answerable to a regulator. Every piece carries a review date.
Guides
Guides
SEBI CSCRF readiness checklist
The CSCRF control set organised into a readiness sequence: what to evidence first, what auditors ask for, and where ISO 27001 programmes usually fall short.
Reviewed September 2026
ISO 27001 to CSCRF: how much you've already done
The crosswalk between Annex A and CSCRF, where the real gaps concentrate, and how to quantify coverage before planning anything.
Reviewed September 2026
Playbooks
Playbooks
The 6-hour clock: incident reporting under CSCRF, step by step
From detection to notification inside SEBI's six-hour window: what to prepare before the incident, and what the record must show after it.
Reviewed September 2026
DPDP for security teams: what the DPO will ask you for
The security safeguards half of DPDP is your desk. What the DPO needs from security, and how to answer with evidence instead of estimates.
Reviewed September 2026
Answers
Answers
Why agentic GRC fails audits, and what to demand instead
The auditor does not ask what the AI did. The auditor asks who approved it, on what evidence, and where that is recorded.
Reviewed September 2026
The evidence rot audit: a 20-minute self-assessment
Twenty minutes, five questions, one uncomfortable finding: how much of your evidence stopped being true since you filed it.
Reviewed September 2026
