Long-form references for the people who do the work
42 guides spanning compliance, security, privacy, and AI governance — audit methodology per framework, plus thematic deep-dives on the synthesis that ties them together. Written from field experience, source-cited, opinionated where it counts.
This week's pick
rotates weekly · independent of homepageFeatured
8 flagship guidesThe single most common privacy conversation I have had in the last eighteen months is some version of the following. An Indian SaaS…
Most CISOs do not last. The average tenure of a CISO globally has been hovering at around 18-24 months for the last decade, and in India it…
PremiumSix items worth attention for compliance, security, and privacy practitioners in the early-June window. Three are continuations of May 2026…
PremiumThere is a compliance and GRC industry. It includes consultants, certification bodies, GRC platform vendors, audit firms, training…
If you are reading this you have probably been pulled into a meeting where the financial auditor wants "the IT controls." Not the SOC 2…
PremiumData localisation is not one rule. It is a patchwork of overlapping rules from multiple regulators, in multiple jurisdictions, applying to…
PremiumMost penetration test engagements I see are bad. Not bad in the sense that the vendor was incompetent — most reputable firms have competent…
PremiumThe single most underdone activity in security and privacy operations is the tabletop exercise. Not the doing of them — most regulated…
Recent
latest 8 published or refreshedBrowse by category
9 categoriesDPDPA, GDPR, cross-border, SDF readiness, children, consent, DPO mechanics
- DPDP Act 2023 + DPDP Rules 2025
- DPDPA × GDPR for Indian SaaS exporting to Europe PREMIUM
- DPO mechanics under DPDPA — role, reporting line, budget, RACI
- DPDPA Significant Data Fiduciary readiness
- DPDPA consent — granularity, withdrawal, and the Consent Manager ecosystem
- DPDPA children's data and Section 9 obligations
- Cross-border data flows — DPDPA + sectoral overlays for India
- The data localisation matrix — where each rule actually bites PREMIUM
ITGC, SOC 2, ISO audit prep, pre-audit, Stage 1 & 2 mechanics
- SOC 2 Trust Services Criteria
- ISO/IEC 27001:2022 + Amd 1:2024
- ITGC: what the financial auditor actually tests
- SOC 2 Type 2 — what twelve months of observation actually looks like PREMIUM
- Preparing for an ISO audit — Stage 1 and Stage 2 mechanics for 27001 / 27701 / 42001
- Ten things to do in the four weeks before any compliance audit
RBI, SEBI, IRDAI, CERT-In, NCIIPC, MeitY
- RBI Cyber Security Framework
- RBI ITGRCA Master Direction 2023
- RBI Master Direction on Outsourcing of IT Services 2023
- RBI Digital Lending + PA-PG Master Directions
- SEBI CSCRF
- SEBI Cloud Services Framework
- SEBI CSCRF five-tier model and 2025 amendments
- IRDAI Information & Cyber Security Guidelines 2026
- CERT-In Directives + CISG-2025-02
- NCIIPC Critical Information Infrastructure Guidelines
- Co-lending and multi-lender arrangements — November 2025 provisions
- Unified incident reporting across CERT-In, RBI CIMS, SEBI, IRDAI, DPBI
- Third-party risk management for India
- Third-party risk management for Indian regulated entities — integrated regulatory perspective
- Reading regulator inspection letters — decoding the soft language in RBI, SEBI, IRDAI findings PREMIUM
EU AI Act, ISO 42001, AI vendor risk, NIST AI RMF
Pen testing, business logic vulnerabilities, SDLC
Budgets, cyber insurance, ROI math, vendor pricing, what to actually buy
First 100 days, last 100 days, board updates, vCISO operating model
- The first 100 days as a CISO — a practitioner playbook
- The last 100 days as a CISO — the exit handover playbook PREMIUM
- The board update that actually works — CISO and DPO playbook
- Board update operational playbook — the quarterly mechanics
- The vCISO operating model — running 8-12 client programmes PREMIUM
Tabletops, multi-regulator reporting, IR retainer, IR maturity
Monthly bulletins on what moved across regulators
Monthly bulletins on what moved across the regulatory landscape
EU AI Act, DPDPA enforcement, RBI inspections, SEBI CSCRF, US state privacy — the regulator movements that change how auditors look at your programme. One email per month. No marketing.