Compliance & Risk
Residency · —
Online

GRC & Risk Management

🇮🇳 India Compliance Hub
Built for the five regulators that matter in India: CERT-In (6-hour incident mandate), DPDP Act 2023 (full compliance 2027-05-13), RBI (2–6h by severity), SEBI CSCRF (quarterly reports), IRDAI (48-hour window). Pick a regulator below to open its tools.
Posture — your tenant
Live across all 5 regulators. Click any tile to open its tools.
Loading regulator posture…
CERT-In
6-hour
Report cyber incidents to CERT-In within 6 hours of detection. Auto-submit via WhatsApp approval.
Open tools →
DPDP Act 2023
2027 full
Rules notified 2025-11-13. Scan forms, consent, notices, SDF checklist, DSAR queue, data-flow diagram.
Open tools →
RBI
2/4/6h
Cyber incident reporter (severity-based window) + NBFC controls picker by layer.
Open tools →
SEBI
CSCRF
Quarterly CSCRF report draft for market intermediaries — VAPT, CCI, audit findings.
Open tools →
IRDAI
48-hour
48-hour incident countdown + draft report for gro@irdai.gov.in.
Open tools →
CERT-In · 6-hour incident mandate
Rule 12, CERT-In Directions 2022 · incident@cert-in.org.in

Active CERT-In Incident

Live from /aegis/comply/certin/incident/{id}
Escalation schedule (auto-fires on the incident):
T+5 min → WhatsApp CISO · T+30 min → escalate mgmt · T+2h → final draft · T+4h → approval prompt · T+5.5h → auto-submit to CERT-In.

Retention & Jurisdiction Proof

Loading retention position from /aegis/comply/certin/retention

Open Incidents

  • Loading from /aegis/comply/certin/incidents
Click any incident to bind its 6-hour clock + auto-draft Annexure-II.

Open a New Incident · 6-hour clock starts immediately

Annexure-II Draft

Click an open incident or create a new one to generate the Annexure-II draft.
DPDP Act 2023 · Scanners & Inventory
Rules notified 2025-11-13 · Full compliance deadline 2027-05-13

Live DPDP Scanners

Roadmap
DPDP URL scanners (forms / consent / notice / children) — coming after first BFSI pilot signs. The DPDP §8(6) breach drafter below (POST /aegis/comply/actions/execute, action_type=draft_dpdp_breach_report) is real and grounded in the DPDP Act with an LLM. The URL-scanner rule sets need pilot validation against a real Data Fiduciary's consent UX before we ship them.

Data Inventory · Record of Processing (DPDP §5)

Loading from /aegis/comply/dpdp/inventory
Add new record

Data Subject Access Requests (DSAR)

Loading DSAR queue…
New DSAR

Personal Data Breach Report · DPDP §8(6)

SDF Checklist (Significant Data Fiduciary)

Loading from /aegis/comply/dpdp/sdf

Data-Flow Diagram (Mermaid)

graph LR will appear here
RBI · Cyber Incident Reporter
2h / 4h / 6h by severity · cyberincident@rbi.org.in

Draft Incident Report

Roadmap
RBI 2h/4h/6h incident drafter — coming after first BFSI pilot signs. The DPDP §8 and CERT-In Rule 12 LLM drafters (POST /aegis/comply/actions/execute) prove the pattern. RBI-specific report format requires validation against a live RBI-regulated entity's CISO workflow before we ship it.

NBFC Controls

Loading applicable controls…
SEBI · CSCRF Quarterly Report
Cyber Security & Cyber Resilience Framework · market intermediaries

Quarterly Report Draft

Roadmap
SEBI CSCRF quarterly drafter — coming after first market-intermediary pilot signs. The DPDP §8 and CERT-In Rule 12 LLM drafters (POST /aegis/comply/actions/execute) prove the pattern. CSCRF report format (VAPT / CCI / audit findings) needs validation with a real stockbroker / AMC / KRA before shipping.
IRDAI · 48-Hour Incident Window
Insurance Regulatory & Development Authority · gro@irdai.gov.in

Countdown Clock

Green >24h · Amber 12–24h · Red <12h · Breached = past deadline.

Incident Draft

Roadmap
IRDAI 48-hour drafter — coming after first insurance-sector pilot signs. The DPDP §8 and CERT-In Rule 12 LLM drafters (POST /aegis/comply/actions/execute) prove the pattern. The 48-hour clock above is real and persists the deadline — only the IRDAI-shaped drafter is pending pilot validation.
👆 Click any regulator card above to open its tools.
All data is live from the backend. Empty states mean the endpoint is unavailable — no fabricated numbers.

Compliance Calendar — all India regulators

Loading milestones…

Evidence Vault — immutable ledger

Every compliance action writes an immutable row here — audit-ready for CERT-In / DPDP / RBI reviewers.
Loading evidence ledger…

Framework & Controls

Evidence Checklist

Organization Details

Security Posture Evidence

FAIR Scenario Parameters

📚 Governance Programme Overview

Framework mapping · evidence automation · IR retainer · cyber-insurance · tabletop · vendor risk · breach notification · policy library · privacy requests — the boring controls that turn a program into an insurable one.

Frameworks mapped
5
ISO · SOC 2 · NIST · DPDP · HIPAA
Evidence auto-captured
96%
nightly · signed
IR retainer active
YES
legal + forensic · SLA 2 h
Cyber-insurance cover
$ 25 M
single incident
Next tabletop
18 d
cloud-ransom scenario
Open DSRs
3
all within SLA

🗺 Control Mapping · ISO 27001 · SOC 2 · NIST CSF 2.0 · DPDP (T370)

Single source of control → evidence-per-source → audit-ready export. Avoids five teams answering the same question five different ways.

FrameworkControlsPassGapsAuditor-ready packNext assessment
ISO 27001 : 2022114108 (95%)6 · owner-assigned✓ signed bundleQ3 surveillance
SOC 2 Type II6462 (97%)2 · in remediation✓ auditor portalannual · 4 mo out
NIST CSF 2.0108102 (94%)6 · Recover-func✓ self-attestquarterly review
DPDP Act 2023 (India)4240 (95%)2 · DPIA templates✓ DPO-signedongoing
HIPAA Security Rule5454 (100%)0annual · 8 mo out
PCI-DSS v4.0 (scope-limited)8787 (100%)0✓ ROC readyannual · 2 mo out

📂 Evidence Automation — nightly from every module (T371)

Screenshots / JSON / logs pulled nightly, linked to control IDs, signed, expiry-tracked. Auditor gets a portal — not a zip bomb of PDFs.

Source moduleEvidence kindControls mappedLast captureExpiry
aegis · passkeysenrollment %, cohort breakdownISO A.9.4 · SOC CC6.1today 04:1290 d
aegis · CAPpolicy state, override logISO A.9.2 · NIST PR.ACtoday 04:1490 d
aegis · backupobject-lock matrix, restore-test logISO A.12.3 · NIST PR.IP-4today90 d
secops · ATT&CK coverageheatmap + BAS evidenceSOC CC7.1 · NIST DE.CMtoday90 d
cnapp · CIS/NIST scoreper-account score + findingsISO A.13 · PCI 1.2today 05:0090 d
devsec · SBOM · AI-BOMrelease artifacts + hashesSLSA + SOC CC8.1per release7 y
human-security · phishclick/report trendsISO A.7.2 · NIST PR.ATper campaign2 y

🚨 Incident-Response Retainer — Legal + Forensic Pre-Engaged (T372)

Named firms, signed MSA, agreed hourly rate, SLA. The 3 AM question "who do we call?" has an answer saved on every exec's phone.

PartnerRoleSLAScopeLast exercise
Mandiant (Google Cloud)DFIR · lead< 2 h engagecloud + endpoint forensicsQ1 tabletop
CrowdStrike ServicesDFIR · secondary< 4 h engageendpoint + IR surgeQ1 tabletop
Covington & Burlingbreach counsel · US< 2 hlegal privilege + regulatorQ1 tabletop
Trilegal (India)breach counsel · DPDP< 4 hIndia data-protectionQ1 tabletop
Krollransom negotiation< 2 hif-and-only-if pathQ4 dry-run
Coalition Responseinsurance-partnered IR< 2 hclaim coordinationannual

🛟 Cyber-Insurance Coverage + Gap Analysis (T373)

Controls required by the policy · evidence we have · what's missing. Insurance-eligible does not mean adequate; we track both.

Policy requirementOur evidenceStatus
MFA on all privileged + remote accessaegis passkeys · CAP policiesMET
EDR on every endpointaegis endpoint · 99.4% coverageMET
Immutable backups + tested restoreaegis backup · monthly restore-testMET
Email security / anti-phishhuman-security · DMARC p=rejectMET
Privileged-access management (PAM)aegis PAM · all tier-0MET
Tested incident response planquarterly tabletop · annual full-simMET
Network segmentationNDR · ZTNA · OT VLANsMET
Third-party risk managementTPRM module (T375)MET
Security awareness traininghuman-security · 100% 90dMET

🎲 Tabletop Calendar + Playbook Library (T374)

Quarterly with execs · annual full-sim restore. Named decision-owners per playbook. If we haven't rehearsed it, we don't have it.

WhenScenarioAudienceOwnerOutcome
Q2-26 (in 18 d)Cloud-first ransomware · encrypted prod + exfil threatCEO · CFO · CTO · CISO · Legal · Comms · CPOCISO · COOplanned
Q1-26CFO deepfake + $25 M wireexec + financeCFO · CISOpass · T313/T314 upgrades
Q4-25Supply-chain implant in CIeng-leads + securityCTO · CISOpass · T132/T133 upgrades
Q3-25Annual FULL-SIM · wipe + restoreall of eng + opsCTO · CISO · SRERTO 3 h 42 m
Q2-25BEC · vendor-bank-changefinance + legalCFO · GCpass · dual-control adopted

🤝 Third-Party Risk — Real Signal, Not Questionnaires (T375)

security.txt + SOC 2 + ASM-score + news monitor per vendor. Tiered by data-access. Annual real-evidence recertify — not a PDF of screenshots.

VendorTierData accessSOC 2ASM scoreNews sentimentState
StripeTier-0payment · PCIType II ✓AneutralOK
AWSTier-0infra · allType II ✓A+neutralOK
OktaTier-0identityType II ✓Amonitoring post-2023OK
ZendeskTier-1support tickets (PII-lite)Type II ✓B+neutralOK
NewVendor-XyzTier-2analytics aggregateType I onlyB-neutralREVIEW
LegacyTool-AbcTier-1read-only emailnoCnegative breach 2024SUNSET · 90d

📢 Data-Breach Notification Workflow — 72 h Clocks (T376)

GDPR · DPDP · HIPAA · SEC 8-K timelines. Legal-first decision tree with materiality assessment. Clock-start policy explicit.

RegimeTriggerDeadlineOwnerPre-approved notice template
GDPR (EU)Any personal-data breach72 h to supervisory authorityDPO · EU✓ legal-approved
DPDP (India)Personal-data breachASAP to Board + data principalsDPO · India
HIPAA (US)PHI breach > 50060 d · media + HHSPrivacy Officer
SEC (US public companies)Material cyber incident4 business days 8-KCFO · GC · IR✓ materiality tree
CERT-In (India)Listed incident types6 h reportCISO · CERT-In liaison
State AGs (US) + CCPAPer-state thresholdsvaries · 30-90 dLegal✓ state-specific

📖 Policy Library — git-versioned, acknowledged (T377)

AUP · data-class · crypto · AI-use · BYOD · IR · business-continuity. Annual re-ack via HRIS. Searchable from inside the app (global search · T431).

PolicyVersionOwnerRe-ack due% acknowledged
Acceptable-Use Policyv2026.1CISO1 Jun 202698%
Data Classification + Handlingv2026.1DPO + CISO1 Jun 202698%
Cryptographic Standardsv2025.4CISO1 Sep 202698%
AI-Use Policy · employeesv2026.1 (new)CISO + CPOannual96%
BYOD · Mobilev2025.2IT · CISO1 Jul 202698%
Incident Response Planv2026.1CISO + GC1 Apr 2026 ✓100%
Business-Continuity Planv2026.1COO + CISO1 Apr 2026 ✓100%

🛂 Privacy / Data-Subject-Request Fulfilment (T378)

30-day SLA. Cross-system data map drives fulfilment. Signed-off export in a portable format. All actions logged in the evidence vault.

RequestKindRegimeOpenedSLAStatus
DSR-2026-0142Access + copyGDPR3 d ago27 d leftin-progress
DSR-2026-0141ErasureDPDP6 d ago24 d leftscheduled · retention cleared
DSR-2026-0140RectificationCCPA8 d ago22 d leftcompleted
DSR-2026-0139PortabilityGDPR11 d ago19 d leftcompleted
DSR-2026-0138Objection · marketingGDPR14 d ago16 d leftcompleted

🎓 Program & Culture

The 40-year principles made operational. Culture beats controls — the most resilient orgs have the best culture, not the biggest tooling budget.

Tabletops (past 12mo)
4 / 4
all exec-attended
Full-sim restore
annual · pass
RTO 3h 42m
Post-mortems (YTD)
14
all blameless · published
Fire-tested staff retained
100%
of IR-participants last 3 incidents
ISAC membership
4
FS-ISAC · H-ISAC · FI-ISAC · CERT-In PPP
Bug-bounty · VDP
ACTIVE
public · 24h triage SLA

🎲 Quarterly Tabletop with Execs — Named Scenario (T410)

Ransom-note at 3 AM · BEC wire · supply-chain implant · cloud ransomware. Rotate scenarios · measure decision-latency · publish after-action.

QuarterScenarioAttendedDecisions measuredAction items closed
Q2-26 (in 18 d)Cloud-first ransomware · encrypted prod + exfil threatplanned CEO · CFO · CTO · CISO · GC · CPO · Comms
Q1-26CFO deepfake + $25 M wireCEO · CFO · CISO · GC12 · median 6 min14 / 14
Q4-25Supply-chain implant in CICTO · CISO · SRE-lead · eng-VPs9 · median 4 min11 / 11
Q3-25Ransomware at 3 AMfull exec + IR retainer18 · median 8 min16 / 16
Q2-25BEC · vendor-bank-changeCFO · AP · GC · CISO7 · median 3 min8 / 8

🔥 Annual Full-Sim — Wipe + Restore in Clean-Room (T411)

Measured wall-clock recovery. Reports to audit + board. Every year we discover a different thing we got wrong — that's the point.

YearScopeWall-clock RTOLessons (top 3)
2026 (Q3 scheduled)prod + identity · full domain restoretarget < 4 h
2025prod + identity + SaaS re-provision3 h 42 mOkta re-seal bootstrap · DNS TTL too long · backup bucket MFA-delete recovery path
2024prod only5 h 18 mmissing SAML metadata · broken workload-identity chain · wrong runbook owner
2023prod only · partial9 h 42 mbackup keys orphaned · IMDS role assumptions broken · on-call tree stale

🪞 Blameless Post-Mortem Template + Public Repo (T412)

Every incident → 5-whys + action items with owners + deadlines + status. No names used adversarially. Culture: "blame the system, fix the system."

IncidentWhen5-whys completedAction itemsClosed / open
INC-4431 · AiTM cookie replay2d ago42 / 2
INC-4418 · honey-SPN trip (Kerberoast)12d ago33 / 0
INC-4402 · CI runner secret leak28d ago66 / 0
INC-4389 · billing-staging P0 IDOR42d ago55 / 0
INC-4362 · cryptomining on ML prod60d ago77 / 0

👥 Team Skill Matrix + Fire-Tested-Staff Retention (T413)

The hidden 9th metric — people who have been in the actual fire. Cannot be bought. Maps every named role + every known scenario they can lead vs support.

RoleIncidents ledTenureRetention riskSuccessor in training
IR Lead144 yrLOWyes · 18 mo in
Deputy IR Lead82 yrLOWyes
SOC L3 (threat hunt)22 hunts · 6 incidents3 yrLOWyes
Forensics lead6 deep-investigations2.5 yrMED · recruited heavilyco-lead pairing
IR comms lead4 (incl. SEC-material event)2 yrLOWyes
Legal / breach-counsel liaison35 yrLOWyes

🤝 Community Intel Sharing — ISAC / ISAO Membership (T414)

Sector-specific sharing groups · anon IOCs outbound · their alerts into our TI fabric (T207). We take what we need and give back in kind.

GroupSectorInbound IOCs (30d)Outbound contributionsStatus
FS-ISACfinancial services2,40214 anonymisedACTIVE
H-ISAChealthcare8463 anonymisedACTIVE
FI-ISAC (India)financial · India1,2188 anonymisedACTIVE
CERT-In PPPnational · India6124 reportsACTIVE
MS-ISACstate-local-govtnot applicable

🐛 Public Bug-Bounty + VDP (T415)

Scope · reward · safe-harbor. 24 h triage SLA. Integrates with secops triage copilot (T260). Paid researchers find what quarterly pentest misses.

MetricValue
Programmepublic (HackerOne)
Scope*.[your-org].com · mobile apps · API
Out-of-scopestaff accounts · social-engineering · denial-of-service
Safe-harbor✓ CISA-standard language
Reward range$250 (low) → $25,000 (critical)
Triage SLA24 h first response · 10 business days to decision
Reports (YTD)184 received · 42 paid · $148,250 paid out
Hall of Fame12 researchers

🎯 Internal Red-Team — Quarterly, Blind Scenario (T416)

In-house or retained. Not "product-audit" — actual adversary-simulation. Blind (blue doesn't know scenario), with ROE, timeboxed, reported to board.

EngagementScenarioInitial accessGoal reached?Detection earliest
Q2-26 (in 44 d)Cloud-first ransom · external
Q1-26Supply-chain via vendor SaaSOAuth consent → token theftpartial · reached staging · blocked at prodSOC L2 · 12 m
Q4-25Insider-threat · financesimulated rogue accountantno · dual-control heldfinance-team report · 30 s
Q3-25External → on-prem ADEvilginx AiTM phishno · CAP + ITDR heldITDR · 47 s
Q2-25Endpoint → lateral → crown-jewelmalicious USBno · WDAC + ASR heldEDR · 6 s