OSA is a specialist cybersecurity, GRC and assurance advisory. This page unpacks each block on the home page — what it is, why it matters to a regulated Indian enterprise, and where to go next.
Regulated businesses in India today sit at the intersection of a dozen overlapping mandates — RBI's cyber and outsourcing circulars, SEBI's CSCRF, IRDAI's information security guidelines, MeitY's DPDP Act rules, and CERT-In's incident reporting directive. On top of that, global customers, investors and partners still expect ISO 27001, SOC 2, PCI DSS and GDPR to be table stakes.
Our Compliance Hub is not a checklist tool. Each framework page tells you which entities it applies to, what the controls actually mean in practice, how auditors interpret them, and what evidence you need to produce — with our field notes from real audits in banking, insurance, capital markets, healthcare and critical infrastructure.
We are not resellers and we are not tied to a single OEM. Our engineers hold deep, hands-on expertise across the platforms our clients already invest in — Microsoft, AWS and Google Cloud on the technology side, and the full stack of Indian regulatory frameworks on the assurance side.
That means we can walk into an environment, understand what is already deployed, decide whether the right answer is a new tool, a better configuration or a policy change, and then deliver — architecture through implementation, troubleshooting through audit.
Every service line on our home page has a dedicated page with methodology, sub-services, deliverables, sample outputs and related resources. These are not sales brochures — they document how our teams actually run engagements, what artifacts you can expect at each phase, and where our senior consultants get involved directly.
If you are evaluating us for a specific mandate, start with the relevant service page. If you are building a security programme from scratch, start with GRC or Cyber Security and let a strategy engagement sequence the rest.
Recognition matters to us only when it reflects actual outcomes for clients. The awards and acknowledgements we highlight all come from work delivered — regulator-facing audits closed cleanly, complex programmes shipped on time, and vCISO engagements that materially moved a board's risk posture.
We publish the categories, not the client names. Confidentiality is a hard commitment; sector representation is the only detail we share.
As a personal philosophy we do not publicise our client names. However, the sectors representing the business areas of our clients are shown — you can see the mix and depth of our exposure across regulated verticals.
Every engagement is bound by strict NDA and by the professional obligations of our senior consultants, most of whom hold CISO, CISA, CISM, CIPP and CDPSE credentials.
Our senior team contributes regularly to industry press, panels and standards discussions — on regulatory shifts, incident post-mortems and evolving expectations from regulators like RBI and SEBI.
The Newsroom aggregates recent coverage, published bylines and panel appearances. It is a running record of where our thinking is showing up outside client engagements.
Our blog is authored by the OSA Research Desk — the same senior consultants who lead client engagements. It is not marketing content; every post is grounded in a real audit finding, a real control design decision or a real regulator interaction.
You will find explainers on new regulations, deep dives on control implementation, and short pieces breaking down incidents and what they mean for Indian enterprises. New posts are categorised across compliance, cloud, AI, privacy and enterprise security.
The Resources library is the downloadable, longer-form counterpart to our blog — practical guides you can share with an internal team, control mapping templates you can adapt, and anonymised case studies from real programmes.
Everything is written for someone who has to actually do the work — a CISO briefing their board, an IT lead preparing for a first ISO audit, or a compliance officer scoping a DPDP programme.
Every enterprise we work with is deploying AI faster than it can govern it — copilots, RAG systems, agentic workflows, third-party model APIs. The risks are not hypothetical: prompt injection, model exfiltration, data leakage into training pipelines, and regulatory exposure under DPDP and the emerging EU AI Act.
Our AI advisory covers governance (ISO 42001 alignment), AI-specific risk assessments, model and prompt security testing, and DPDP-aware data handling for AI workloads.
Most breaches in the cloud are not exotic zero-days — they are misconfigured buckets, over-permissioned IAM roles, unmonitored keys and stale service accounts. Our cloud security practice is built to close those gaps systematically.
We deliver secure landing-zone design, CSPM tuning, workload protection, container and Kubernetes security, and continuous compliance mapping against ISO 27001, SOC 2, PCI DSS and Indian regulatory expectations.
The best way to understand what we do is a 30-minute call with a senior consultant. No sales pitch — just a direct conversation about your risk posture, regulatory obligations and next steps.