Tenth Floor Labs

Security practice

Cybersecurity and compliance, advised by a serving CISO.

Pass the security questionnaire, get DPDP-ready before the deadline, and win enterprise deals with ISO 27001 or SOC 2 — with senior partners who can also fix the code.

Your security partners

Senior people, on every engagement.

No hand-off to a junior team after the sales call. The people below lead and advise on the work and stay accountable for it.

Principal Security Advisor

Serving CISO · 31+ years in technology
India

A serving CISO at a global European telecom and IT services group, with 31+ years of making security a business advantage.

Leads information security for international operations at a global enterprise, where security has to hold up across countries, regulators and thousands of users at once.

Brings 31+ years across IT systems integration, business process optimisation and security leadership, and advises our clients on security strategy, governance, risk and audit readiness, the way a board-level CISO would.

Serving CISO31+ years in technologyMulti-country security governanceBoard-level risk reporting
Works with
ISO 27001 · NIST CSF · GDPR · NIS2 · Risk & governance

Security & Compliance Partner

India · Europe · USA

A hands-on security specialist across India, Europe and the USA, covering cloud, privacy and penetration testing.

Has delivered cybersecurity work across India, France and the United States, so knows exactly what an EU auditor, a US enterprise buyer and an Indian regulator each expect to see.

Leads our penetration testing, cloud security reviews and privacy compliance (DPDP and GDPR), and is a published researcher in IoT security.

3 continentsCloud & privacy securityPublished IoT security researcherAzure security certified
Certified
Microsoft Certified: Azure Security Engineer Associate
Works with
GDPR · DPDP Act · Europrivacy · OWASP · Azure security · GRC

Why now

The rules and your customers are both asking.

13 May 2027

DPDP Rules: most obligations apply

Notice and consent, reasonable security safeguards, breach reporting to the Data Protection Board and data-principal rights. Penalties run up to ₹250 crore. Building these processes takes months, so start now.

In force

CERT-In Directions

Report specified cyber incidents within 6 hours and keep ICT logs for 180 days in India. CERT-In's 2025 audit guidelines expect regular, evidence-based audits.

2025–2028

RBI, SEBI & IRDAI frameworks

Cyber-resilience rules for payment operators phase in through 2028; SEBI's CSCRF and IRDAI's guidelines set audit and control expectations for regulated firms.

Every enterprise deal

SOC 2, ISO 27001 & questionnaires

US and EU buyers ask for SOC 2 or ISO 27001, a recent pentest and long security questionnaires — and EU NIS2/DORA push the same requirements down to suppliers.

Dates and penalties summarised from the DPDP Rules 2025, CERT-In Directions (28 Apr 2022) and regulator circulars as of October 2026. This is not legal advice.

Why Tenth Floor Labs

Security that actually gets fixed.

We can fix what we find

Most security firms hand over a PDF. We're also the engineers who build websites, apps and automation — so remediation actually happens.

Senior people, not juniors

Work is led by a security partner with experience across India, Europe and the USA, with a serving enterprise CISO as principal advisor.

Secure & compliant by design

Consent flows, logging, MFA and security headers built into your website, app and WhatsApp journeys from day one.

Honest about accreditation

We prepare you for ISO 27001 and SOC 2; accredited bodies and CPA firms issue the certificate or report. When a CERT-In empanelled report is required, we work with an empanelled partner.

Free tool

Start with a free security check.

See how your website looks to an attacker in 10 seconds — then send the result to our partners for a free review.

A passive check of what anyone on the internet can already see: HTTPS, security headers, cookie flags and email spoofing protection. No scanning, no load on your server.

FAQ

Questions, answered.

Who will actually work on our project?+

Our security partner leads every engagement personally, with our principal advisor, a serving enterprise CISO, guiding strategy and governance. You can speak to them directly on WhatsApp or a call.

Do you issue ISO 27001 certificates or SOC 2 reports?+

No — nobody honest can. ISO 27001 certificates come from accredited certification bodies and SOC 2 reports from licensed CPA firms. We implement the controls, run independent internal audits, prepare evidence and coordinate the external audit so you pass with fewer surprises.

Are you CERT-In empanelled?+

No. For engagements where a regulator or customer requires a report from a CERT-In empanelled auditor, we coordinate testing with an empanelled partner firm and handle remediation ourselves.

We're a small company. Do we really need this?+

If you handle customer data, take online payments or sell to larger companies, yes — the DPDP Act applies to almost every business that processes personal data. Start with a low-cost assessment and fix the highest risks first.

How do you keep our information confidential?+

We sign an NDA before any detailed discussion, use least-privilege access, and never mention client names or findings publicly without written permission.

Make security a reason customers choose you.

One message is enough. You'll speak directly with the engineer who builds your system — and get a fixed quote, not a sales pitch.

Call WhatsApp us