Tenth Floor Labs

Secure — Cybersecurity Audit & Risk Assessment

A cybersecurity audit that tells you what to fix first

Our cybersecurity audit and risk assessment shows where your business stands today. We check your systems, cloud, apps and policies against ISO 27001 and NIST CSF, review CERT-In readiness and give you a ranked 90-day remediation plan. It is a sensible first step for most growing businesses.

Mon–Sat · 9am–8pm IST
Starting from
₹37.5k
one-time · fixed price
Timeline
2–4 weeks
typical
After launch
Optional quarterly re-assessment or a vCISO retainer to drive the fixes
Maulik Gupta, Founder & Lead Engineer
Maulik Gupta
Founder & Lead Engineer · you'll talk to me

Sound familiar?

"We know we should do something about security, but we don't know where to start."

  • Everyone has an opinion on what's risky, but nobody has looked at the whole picture.
  • A customer or investor asked for our security posture, and we had nothing to show.
  • We've heard about CERT-In's 6-hour reporting rule and don't know if we can meet it.
  • Our cloud, laptops and SaaS tools grew fast, and access was never cleaned up.
  • We don't want a 300-page report. We want a short list of what to do next.

Built for

Startups and SMEs doing their first serious security reviewCompanies planning ISO 27001, SOC 2 or DPDP work who need a baselineBusinesses asked by a customer, investor or insurer for a security assessmentFintech, health-tech and e-commerce firms that handle personal or payment dataTeams that recently had a security scare and want an honest checkNew leadership wanting an independent view of security posture

What we do

What's included in Cybersecurity Audit & Risk Assessment.

01

Security Maturity Assessment

We score your security across people, process and technology, so you can see your strengths, weak spots and progress over time.

02

ISO 27001 Gap Analysis

A control-by-control check against ISO/IEC 27001:2022 Annex A, showing what you already do and what's missing for certification.

03

NIST CSF Assessment

Your current and target profile against the NIST Cybersecurity Framework 2.0, which many US and global customers recognise.

04

CERT-In Directions Readiness Check

We check whether you can report specified incidents within 6 hours, keep ICT logs for 180 days in India and sync clocks as required.

05

Cloud & Access Review

A focused look at admin accounts, MFA, shared logins, offboarding and risky cloud settings, where most real problems hide.

06

90-Day Remediation Plan

A prioritised plan with owners, effort and cost estimates, plus a plain-language summary for founders and detail for your tech team.

Who delivers this

Senior security people, not juniors.

Every engagement is led and advised by our security team — a serving CISO with 31+ years in technology, and a partner with security experience across India, Europe and the USA.

Principal Security Advisor

Leads this service
Serving CISO · 31+ years in technology

A serving CISO at a global European telecom and IT services group, with 31+ years of making security a business advantage.

Serving CISO31+ years in technologyMulti-country security governanceBoard-level risk reporting

ISO 27001 · NIST CSF · GDPR · NIS2 · Risk & governance

Security & Compliance Partner

Advises
India · Europe · USA

A hands-on security specialist across India, Europe and the USA, covering cloud, privacy and penetration testing.

3 continentsCloud & privacy securityPublished IoT security researcherAzure security certified

GDPR · DPDP Act · Europrivacy · OWASP · Azure security · GRC

Pricing

Transparent packages. Fixed quotes.

Your final quote is fixed after a 20-minute call — no surprise bills.

Essentials

₹37.5k
one-time · up to ~50 staff · 2 weeks
  • Security maturity assessment
  • Gap analysis vs ISO 27001 or NIST CSF
  • CERT-In Directions readiness check
  • Access and MFA review
  • 90-day remediation plan
  • Findings walkthrough call
Get this quote
Recommended

Comprehensive

₹1.5L
one-time · 3–4 weeks
  • Everything in Essentials
  • Cloud configuration review (one account)
  • Light security testing of your main web app
  • Policy and process review
  • Vendor and SaaS risk snapshot
  • Board-ready summary deck
Get this quote

Multi-site

₹3L+
scoped after a call
  • Multiple offices, entities or business units
  • Several cloud accounts and applications
  • On-site visits where needed
  • Consolidated group-level risk view
Get this quote

Ongoing costs after launch

No surprises: here's everything you may pay every month, stated upfront.

With us

Optional quarterly re-assessment or a vCISO retainer to drive the fixes

See all ongoing plans
Paid to third parties, at cost, no markup

None

  • —Full penetration testing is a separate service (see VAPT), though Comprehensive includes light testing of one app.
  • —Fixing the issues found is quoted separately. We can do it, or your team can.
  • —Travel for on-site visits outside Bengaluru is billed at cost, only if needed.
  • —Where a regulator requires an audit by a CERT-In empanelled auditor, the empanelled partner's fee is paid separately.

Want a quick estimate for your exact project? Try the cost estimator.

Process

From first message to launch.

Clear stages, a live preview link every week, and payments tied to milestones you approve.

  1. Step 01Day 1

    Scoping call

    We agree what's in scope, who we'll talk to and what access we need. You get a fixed price.

  2. Step 02Week 1

    Interviews & evidence

    Short interviews with your team and a review of documents, cloud settings and access lists.

  3. Step 03Weeks 2–3

    Analysis

    We map findings to ISO 27001, NIST CSF and CERT-In requirements and rank them by real business risk.

  4. Step 04Weeks 2–4

    Report & plan

    A walkthrough of the report and your 90-day plan, with time for questions from founders and engineers.

Technology

Tools we trust.

ISO 27001:2022NIST CSF 2.0CIS Controls v8CERT-In DirectionsDPDP Act 2023AWS Security HubMicrosoft Secure ScoreGoogle Workspace securityProwler

Our promises

Working with us is low-risk.

Fixed quote

A clear, fixed price after a 20-minute call. No surprise bills.

Pay in milestones

Projects: 40% to start, 30% on design approval, 30% at launch.

You own everything

Code, domain, ad accounts, WhatsApp number and data — in your name.

Weekly previews

See real progress on a live link every week, not just status updates.

30 days of free fixes

Anything not working as agreed after launch, we fix at no cost.

Talk to the builder

No account managers. You speak with the engineers doing the work.

FAQ

Questions, answered.

What decides the cost of a cybersecurity audit?+

Mainly team size, the number of offices, cloud accounts and apps in scope, and how deep you want the technical checks to go. Most startups and SMEs fit the ₹37.5k or ₹1.5L packages.

How long does it take, and how much of our time?+

Two to four weeks end to end. Your team spends about 4–8 hours in total on interviews and sharing access. We work around your schedule.

Is this a certification audit?+

No. It's an independent assessment that shows your gaps and what to fix. Certification audits for ISO 27001 are done by accredited certification bodies. Our report is often the first step towards one.

Are you CERT-In empanelled?+

No, and we say so plainly. Most businesses don't need an empanelled auditor for a risk assessment. If your regulator or a customer requires a report from a CERT-In empanelled auditor, we coordinate the work with an empanelled partner firm.

Will you sign an NDA? What access do you need?+

Yes, we sign an NDA before we start. We prefer read-only access and screen-share walkthroughs, and we remove our access when the assessment ends.

What happens after the report?+

You can fix the issues yourself using the plan, ask us to fix them (we're engineers too) or move to a vCISO plan that drives the work. A re-assessment after 6–12 months shows your progress.

What results should we expect?+

A clear picture of your risks, a short ranked list of fixes and answers you can reuse for customer questionnaires. Many clients close their biggest gaps, like missing MFA or old admin accounts, in the first two weeks.

Let's scope your project.

One message is enough. You'll speak directly with the engineer who builds your system — and get a fixed quote, not a sales pitch.

Call WhatsApp us