Resources for enterprise security leaders
Blogs, research, white papers, advisories, and case studies from the Open Security Alliance research desk. Updated regularly for CISOs, boards, and security teams across regulated industries.
Critical Advisory: VPN Gateway Zero-Day Exploited In-The-Wild
Active exploitation of an unauthenticated RCE in a widely deployed enterprise VPN appliance. Immediate mitigation steps and detection guidance.
Ransomware Resilience Playbook for Indian Enterprises 2026
A pragmatic 2026 ransomware readiness playbook covering backup immutability, network segmentation, EDR tuning, tabletop exercises, and CERT-In reporting workflows.
AI Security & Model Risk Framework for Regulated Enterprises
A first-of-its-kind framework for securing enterprise AI adoption — covering model supply chain, prompt-injection defence, data leakage, and governance.
RBI CSITE 2026 Update — What Changes for Banks
Summary of the 2026 RBI CSITE circular refresh: new baseline controls, revised audit expectations, and reporting cadence for scheduled commercial banks.
DPDP Act 2023 — Enterprise Implementation Guide
A comprehensive white paper mapping DPDP obligations to enterprise data governance, consent architecture, DPIA methodology, and DPB reporting workflows.
CERT-In Directions: Four Years On — Enterprise Impact
Analysis of how the 2022 CERT-In directions have reshaped incident reporting, log retention, and third-party governance across Indian enterprises.
Indian Threat Landscape Report — Q1 2026
Quarterly threat intelligence report analysing 4,200+ incidents across BFSI, healthcare, government, and critical infrastructure sectors in India.
Case Study: SIEM Modernisation for a Tier-1 Indian Bank
How OSA replatformed a legacy SIEM to a cloud-native detection stack, cutting MTTD by 71% and false positives by 63% while achieving RBI CSITE readiness.
Zero-Trust Architecture: A Practical Primer for Enterprise CISOs
A pragmatic technical article on rolling out zero-trust for identity, device, network, application, and data pillars — without a rip-and-replace project.
ISO/IEC 27001:2022 Transition Guide
Field-tested transition guide covering the 93 revised Annex A controls, gap-analysis templates, and evidence packs for certification bodies.
Weekly cyber advisories & regulatory updates
Curated advisories, compliance updates and research — delivered every Monday.