Secure — Cybersecurity Audit & Risk Assessment

Sound familiar?
"We know we should do something about security, but we don't know where to start."
- Everyone has an opinion on what's risky, but nobody has looked at the whole picture.
- A customer or investor asked for our security posture, and we had nothing to show.
- We've heard about CERT-In's 6-hour reporting rule and don't know if we can meet it.
- Our cloud, laptops and SaaS tools grew fast, and access was never cleaned up.
- We don't want a 300-page report. We want a short list of what to do next.
Built for
What we do
What's included in Cybersecurity Audit & Risk Assessment.
Security Maturity Assessment
We score your security across people, process and technology, so you can see your strengths, weak spots and progress over time.
ISO 27001 Gap Analysis
A control-by-control check against ISO/IEC 27001:2022 Annex A, showing what you already do and what's missing for certification.
NIST CSF Assessment
Your current and target profile against the NIST Cybersecurity Framework 2.0, which many US and global customers recognise.
CERT-In Directions Readiness Check
We check whether you can report specified incidents within 6 hours, keep ICT logs for 180 days in India and sync clocks as required.
Cloud & Access Review
A focused look at admin accounts, MFA, shared logins, offboarding and risky cloud settings, where most real problems hide.
90-Day Remediation Plan
A prioritised plan with owners, effort and cost estimates, plus a plain-language summary for founders and detail for your tech team.
Who delivers this
Senior security people, not juniors.
Every engagement is led and advised by our security team — a serving CISO with 31+ years in technology, and a partner with security experience across India, Europe and the USA.
Principal Security Advisor
Leads this serviceA serving CISO at a global European telecom and IT services group, with 31+ years of making security a business advantage.
ISO 27001 · NIST CSF · GDPR · NIS2 · Risk & governance
Security & Compliance Partner
AdvisesA hands-on security specialist across India, Europe and the USA, covering cloud, privacy and penetration testing.
GDPR · DPDP Act · Europrivacy · OWASP · Azure security · GRC
Pricing
Transparent packages. Fixed quotes.
Your final quote is fixed after a 20-minute call — no surprise bills.
Essentials
- Security maturity assessment
- Gap analysis vs ISO 27001 or NIST CSF
- CERT-In Directions readiness check
- Access and MFA review
- 90-day remediation plan
- Findings walkthrough call
Comprehensive
- Everything in Essentials
- Cloud configuration review (one account)
- Light security testing of your main web app
- Policy and process review
- Vendor and SaaS risk snapshot
- Board-ready summary deck
Multi-site
- Multiple offices, entities or business units
- Several cloud accounts and applications
- On-site visits where needed
- Consolidated group-level risk view
Ongoing costs after launch
No surprises: here's everything you may pay every month, stated upfront.
None
- —Full penetration testing is a separate service (see VAPT), though Comprehensive includes light testing of one app.
- —Fixing the issues found is quoted separately. We can do it, or your team can.
- —Travel for on-site visits outside Bengaluru is billed at cost, only if needed.
- —Where a regulator requires an audit by a CERT-In empanelled auditor, the empanelled partner's fee is paid separately.
Want a quick estimate for your exact project? Try the cost estimator.
Process
From first message to launch.
Clear stages, a live preview link every week, and payments tied to milestones you approve.
- Step 01Day 1
Scoping call
We agree what's in scope, who we'll talk to and what access we need. You get a fixed price.
- Step 02Week 1
Interviews & evidence
Short interviews with your team and a review of documents, cloud settings and access lists.
- Step 03Weeks 2–3
Analysis
We map findings to ISO 27001, NIST CSF and CERT-In requirements and rank them by real business risk.
- Step 04Weeks 2–4
Report & plan
A walkthrough of the report and your 90-day plan, with time for questions from founders and engineers.
Technology
Tools we trust.
Our promises
Working with us is low-risk.
Fixed quote
A clear, fixed price after a 20-minute call. No surprise bills.
Pay in milestones
Projects: 40% to start, 30% on design approval, 30% at launch.
You own everything
Code, domain, ad accounts, WhatsApp number and data — in your name.
Weekly previews
See real progress on a live link every week, not just status updates.
30 days of free fixes
Anything not working as agreed after launch, we fix at no cost.
Talk to the builder
No account managers. You speak with the engineers doing the work.
FAQ
Questions, answered.
What decides the cost of a cybersecurity audit?+
Mainly team size, the number of offices, cloud accounts and apps in scope, and how deep you want the technical checks to go. Most startups and SMEs fit the ₹37.5k or ₹1.5L packages.
How long does it take, and how much of our time?+
Two to four weeks end to end. Your team spends about 4–8 hours in total on interviews and sharing access. We work around your schedule.
Is this a certification audit?+
No. It's an independent assessment that shows your gaps and what to fix. Certification audits for ISO 27001 are done by accredited certification bodies. Our report is often the first step towards one.
Are you CERT-In empanelled?+
No, and we say so plainly. Most businesses don't need an empanelled auditor for a risk assessment. If your regulator or a customer requires a report from a CERT-In empanelled auditor, we coordinate the work with an empanelled partner firm.
Will you sign an NDA? What access do you need?+
Yes, we sign an NDA before we start. We prefer read-only access and screen-share walkthroughs, and we remove our access when the assessment ends.
What happens after the report?+
You can fix the issues yourself using the plan, ask us to fix them (we're engineers too) or move to a vCISO plan that drives the work. A re-assessment after 6–12 months shows your progress.
What results should we expect?+
A clear picture of your risks, a short ranked list of fixes and answers you can reuse for customer questionnaires. Many clients close their biggest gaps, like missing MFA or old admin accounts, in the first two weeks.
Often paired with
Manual and tool-based testing of web apps, mobile apps, APIs and cloud, with a free retest.
A senior security leader on a monthly plan: roadmap, policies, questionnaires and board reporting.
Get audit-ready for ISO 27001:2022 and SOC 2 Type I/II: policies, evidence and auditor coordination.
Let's scope your project.
One message is enough. You'll speak directly with the engineer who builds your system — and get a fixed quote, not a sales pitch.