Learn More

The story behind every section of our home page.

OSA is a specialist cybersecurity, GRC and assurance advisory. This page unpacks each block on the home page — what it is, why it matters to a regulated Indian enterprise, and where to go next.

Compliance & Regulations Hub

Every framework that matters to Indian and global enterprises

Regulated businesses in India today sit at the intersection of a dozen overlapping mandates — RBI's cyber and outsourcing circulars, SEBI's CSCRF, IRDAI's information security guidelines, MeitY's DPDP Act rules, and CERT-In's incident reporting directive. On top of that, global customers, investors and partners still expect ISO 27001, SOC 2, PCI DSS and GDPR to be table stakes.

Our Compliance Hub is not a checklist tool. Each framework page tells you which entities it applies to, what the controls actually mean in practice, how auditors interpret them, and what evidence you need to produce — with our field notes from real audits in banking, insurance, capital markets, healthcare and critical infrastructure.

ISO 27001
The global ISMS standard — Annex A 2022 controls, statement of applicability, internal audit programme and certification readiness.
SOC 2 Type II
Trust Services Criteria for SaaS and cloud-hosted services, control design + operating effectiveness over a review period.
RBI Compliance
Cyber security framework for banks, NBFCs, PSPs and PAs. PAPG SAR, CSITE, TPRA, AUA/KUA obligations end-to-end.
SEBI CSCRF
Cyber security and resilience framework for MIIs, RIAs, brokers and mutual funds — Category-wise applicability and audit.
DPDP Act
Digital Personal Data Protection Act 2023 — data fiduciary obligations, consent architecture, DPO role and breach reporting.
GDPR
EU privacy compliance for Indian exporters and multinationals — lawful basis, DPIA, cross-border transfer and Article 30 records.
IRDAI
IRDAI information & cyber security guidelines — ISNP audits, CSF alignment and periodic assurance requirements.
IFSC
IFSCA regulations for GIFT City entities — cyber, outsourcing and business continuity mandates.
Technology Expertise

Architect, implement, troubleshoot and audit best-in-class security platforms

We are not resellers and we are not tied to a single OEM. Our engineers hold deep, hands-on expertise across the platforms our clients already invest in — Microsoft, AWS and Google Cloud on the technology side, and the full stack of Indian regulatory frameworks on the assurance side.

That means we can walk into an environment, understand what is already deployed, decide whether the right answer is a new tool, a better configuration or a policy change, and then deliver — architecture through implementation, troubleshooting through audit.

Microsoft Security
Defender for Endpoint / Cloud / Identity, Sentinel SIEM, Purview DLP & IRM, Entra ID governance.
AWS Security
GuardDuty, Security Hub, Macie, KMS, IAM Access Analyzer, WAF and Config-based drift detection.
Google Cloud
Security Command Center, Chronicle SIEM, BeyondCorp Enterprise, VPC Service Controls and CIS benchmarks.
RBI Compliance
PAPG, CSITE, TPRA, AUA/KUA and outsourcing audits for banks, NBFCs and payment entities.
IRDAI Audits
ISNP audits, IRDAI CSF alignment and insurance-specific cyber assurance.
SEBI
CSCRF applicability assessment, gap analysis and full audit cycle for market intermediaries.
ISMS
ISO 27001, ISO 22301 business continuity, Business Impact Analysis and DR drills.
AI
AI ethics, AI risk management and ISO 42001 AI management system implementation.
DPDPA
DPDP Act compliance, ISO 27701 privacy audits and Privacy Impact Assessments.
Enterprise Security
Policy documentation, control reviews, security strategy and full CISO advisory.
Explore All Services

Deep-dive service pages for every capability we deliver

Every service line on our home page has a dedicated page with methodology, sub-services, deliverables, sample outputs and related resources. These are not sales brochures — they document how our teams actually run engagements, what artifacts you can expect at each phase, and where our senior consultants get involved directly.

If you are evaluating us for a specific mandate, start with the relevant service page. If you are building a security programme from scratch, start with GRC or Cyber Security and let a strategy engagement sequence the rest.

GRC
Governance, risk and compliance advisory — from board reporting to control framework design and audit readiness.
VAPT
Vulnerability assessment and penetration testing for web, mobile, API, infrastructure, cloud and red-team scenarios.
Cloud Security
Cloud security architecture, CSPM, workload protection and secure landing zone design for AWS, Azure and GCP.
Cyber Security
Enterprise cyber security programme design, SOC advisory, incident response readiness and threat management.
Email Security
Email threat protection, DMARC / DKIM / SPF hardening, phishing simulation and mailbox forensics.
Security Awareness
Behaviour-first security training, role-based curricula, phishing simulation and executive briefings.
Regulatory Compliance
End-to-end assurance for RBI, SEBI, IRDAI, IFSC, DPDP, CERT-In and sector-specific mandates.
ISO 27001
ISMS implementation, internal audit, gap remediation and certification support for Annex A 2022 controls.
Training
Corporate training on ISO 27001, DPDP, secure coding, cloud security and CISO-level topics.
Awards & Recognition

Independently recognised for regulatory and audit excellence

Recognition matters to us only when it reflects actual outcomes for clients. The awards and acknowledgements we highlight all come from work delivered — regulator-facing audits closed cleanly, complex programmes shipped on time, and vCISO engagements that materially moved a board's risk posture.

We publish the categories, not the client names. Confidentiality is a hard commitment; sector representation is the only detail we share.

Excellence in RBI PAPG SAR
Recognised for RBI Payment Aggregator / Payment Gateway System Audit Reports and the supporting tooling we have built for this niche.
Impeccable Audit Record
Clean pass-through across regulatory audits — RBI, IRDAI, SEBI and equivalents — over 20+ years of practice.
CISO's Trusted Advisor
Repeatedly retained as the outside-in reviewer for security posture, control design and board-level cyber reporting.
Sectors We Serve

Client names remain confidential under NDA

As a personal philosophy we do not publicise our client names. However, the sectors representing the business areas of our clients are shown — you can see the mix and depth of our exposure across regulated verticals.

Every engagement is bound by strict NDA and by the professional obligations of our senior consultants, most of whom hold CISO, CISA, CISM, CIPP and CDPSE credentials.

Banking & NBFCs
Cyber, PAPG SAR, CSITE and outsourcing audits for scheduled commercial banks, small finance banks, NBFCs and payment entities.
Insurance
IRDAI-mandated audits, ISNP assessments and information security programmes for life, general and health insurers.
Capital Markets
SEBI CSCRF and system audits for stock exchanges, depositories, brokers, mutual funds and RIAs.
Healthcare
Patient data protection, HIPAA-aligned controls and DPDP Act readiness for hospitals and digital health providers.
Fintech & SaaS
SOC 2 Type II, ISO 27001 and cloud security for high-growth SaaS and fintech companies.
Government & PSU
Cyber security assessments, VAPT and CERT-In empanelled work for public sector organisations.
Newsroom & Press

Coverage, contributions and industry commentary

Our senior team contributes regularly to industry press, panels and standards discussions — on regulatory shifts, incident post-mortems and evolving expectations from regulators like RBI and SEBI.

The Newsroom aggregates recent coverage, published bylines and panel appearances. It is a running record of where our thinking is showing up outside client engagements.

OSA Research Desk

Field notes from real engagements, written for practitioners

Our blog is authored by the OSA Research Desk — the same senior consultants who lead client engagements. It is not marketing content; every post is grounded in a real audit finding, a real control design decision or a real regulator interaction.

You will find explainers on new regulations, deep dives on control implementation, and short pieces breaking down incidents and what they mean for Indian enterprises. New posts are categorised across compliance, cloud, AI, privacy and enterprise security.

Resources

Whitepapers, guides, case studies and templates

The Resources library is the downloadable, longer-form counterpart to our blog — practical guides you can share with an internal team, control mapping templates you can adapt, and anonymised case studies from real programmes.

Everything is written for someone who has to actually do the work — a CISO briefing their board, an IT lead preparing for a first ISO audit, or a compliance officer scoping a DPDP programme.

AI & Emerging Risk

Governance for the systems your business is deploying today

Every enterprise we work with is deploying AI faster than it can govern it — copilots, RAG systems, agentic workflows, third-party model APIs. The risks are not hypothetical: prompt injection, model exfiltration, data leakage into training pipelines, and regulatory exposure under DPDP and the emerging EU AI Act.

Our AI advisory covers governance (ISO 42001 alignment), AI-specific risk assessments, model and prompt security testing, and DPDP-aware data handling for AI workloads.

Cloud Security

Secure by design across AWS, Azure and Google Cloud

Most breaches in the cloud are not exotic zero-days — they are misconfigured buckets, over-permissioned IAM roles, unmonitored keys and stale service accounts. Our cloud security practice is built to close those gaps systematically.

We deliver secure landing-zone design, CSPM tuning, workload protection, container and Kubernetes security, and continuous compliance mapping against ISO 27001, SOC 2, PCI DSS and Indian regulatory expectations.

Still have questions?

The best way to understand what we do is a 30-minute call with a senior consultant. No sales pitch — just a direct conversation about your risk posture, regulatory obligations and next steps.