Risk Practice

Cybersecurity and Privacy

Protecting organisations in an era of accelerating cyber threats and tightening data privacy regulation. From cyber risk assessments and DPDP Act compliance to security architecture, ISO 27001 advisory, and incident response planning.

5
Core Service Lines
DPDP
India Data Protection Act
ZT
Zero Trust Architecture

Service Lines

What we deliver.

  • Cyber risk assessment framework (NIST, ISO 27005)
  • Threat landscape analysis: sector-specific threat actors and vectors
  • VAPT scoping and oversight
  • Risk register development and prioritisation
  • Cyber maturity benchmarking against peers
  • Board-level cyber risk reporting framework
  • DPDP Act obligations assessment and applicability mapping
  • Personal data inventory and data flow mapping
  • Consent management framework design
  • Data principal rights management process design
  • Data localisation strategy and cross-border transfer advisory
  • Privacy policy and notice drafting support
  • ISO 27001:2022 gap assessment and implementation roadmap
  • Information Security Management System (ISMS) design
  • RBI IT Framework compliance advisory
  • SEBI Cyber Security Framework advisory
  • SOC 2 Type II readiness advisory
  • Audit support and evidence preparation
  • Zero Trust Architecture (ZTA) design and roadmap
  • Cloud security architecture advisory (AWS, Azure, Oracle Cloud)
  • Identity and Access Management (IAM) strategy
  • Network segmentation and micro-segmentation design
  • Endpoint security and device management strategy
  • Security operations model and SOC advisory
  • Incident Response Plan (IRP) development
  • Tabletop exercise design and facilitation
  • Business Continuity Plan (BCP) for cyber scenarios
  • Crisis communication plan for cyber incidents
  • Regulatory notification framework (CERT-In, IRDAI, RBI)
  • Post-incident review and lessons-learned process
  • Third-party cyber risk assessment framework
  • Vendor cybersecurity questionnaire and assessment process
  • Critical vendor identification and tiering
  • Contractual security requirements (DPAs, SLAs)
  • Continuous third-party monitoring strategy

Coverage

Sectors and scope.

Regulatory Frameworks: DPDP Act 2023, RBI IT Master Direction, SEBI Cyber Security Framework, IRDAI Information Security, CERT-In Directions, IT Act 2000. International Standards: ISO 27001:2022, NIST Cybersecurity Framework, SOC 2 Type II, GDPR, CIS Controls v8, COBIT 2019. Sectors: BFSI and Banking, Insurance, Healthcare and Pharma, Government and PSUs, Manufacturing, IT and ITES

Why Strategy TheFuture

Risk-Based, Business-Aligned
We connect security to business risk, not technical compliance checklists. Every recommendation is framed in terms of business impact and proportional to your risk appetite.
India Regulatory Specialists
Deep expertise in DPDP Act, RBI IT Framework, SEBI Cyber Framework, and CERT-In, the specific regulatory landscape that Indian organisations must navigate.
Advisory Independence
We advise without selling security products or implementation services, ensuring our recommendations are driven by your needs, not our revenue interests.

Related Practices

Discuss this practice area.

Every engagement begins with a senior-led, obligation-free conversation.

Engage Us ← Customer and HR Transformation Capability Building →