A Comprehensive Guide to Establishing an Effective GRC Framework

In today’s dynamic business landscape, organizations face an ever-increasing array of challenges, from regulatory compliance and cybersecurity threats to operational risks and data privacy concerns. To navigate these treacherous waters, companies must implement a holistic approach to governance, risk management, and compliance (GRC). This journey toward achieving effective GRC can be likened to setting sail […]
Conducting a Risk Assessment: A Practical Guide for Organizations

Information security is a critical concern for organizations in the digital age, as the proliferation of data and technology brings new vulnerabilities and threats. To safeguard sensitive information, organizations must conduct information security risk assessments. This comprehensive guide will walk you through the key steps and best practices involved in conducting an effective information security […]
Ensuring Compliance and Security: A Comprehensive Guide to Achieving ISO 27001 Certification

1. Purchasing ISO 27001 document – Your organization must purchase the ISO 27001 document and understand how to implement a structured ISMS for your organization. This will help your organization to understand why the controls are necessary and how they can be implemented to mitigate risks. 2. Gap Analysis – Before ISO 27001 certification, a gap analysis, is […]
Guidelines for Secure Application Design, Development, Implementation, and Operations

One of the key reasons for vulnerabilities in the applications are lack of secure design, development, implementation, and operations. Insecure application development is a primary cause of cyberinfrastructure vulnerabilities. Relying solely on post-development audits for security is insufficient. Security should be an integral part of the application’s design and development process, with built-in measures to […]
Draft Master Directions on Cyber Resilience and Digital Payment Security Controls for Payment System Operators

India’s digital payment ecosystem has witnessed exponential growth in recent years, providing convenience and accessibility to millions of users. However, as the digital landscape expands, so does the need for robust cybersecurity measures. To address this critical aspect, the Reserve Bank of India (RBI) has introduced a draft master direction that covers various domains of […]
Will passkeys be the future and can we forget passwords?

What is a Passkey? Passkeys are a promising new technology that has the potential to make online security much stronger and user experience simpler. Benefits of Passkey: Passkeys are a significant improvement over passwords. They are faster, more secure, and more convenient. Many brands will follow in supporting passkeys. I expect passkeys to become the […]
Common Cybersecurity Threats, their prevention, and possible Mitigation

It is imperative to understand the distinction between a cyber-attack and a cybersecurity threat. A cyberattack is any offensive maneuver that targets computer information systems, computer networks, infrastructures, or personal computer devices. Whereas a Cybersecurity threat is a potential negative action or event facilitated by a vulnerability that results in an undesirable impact on a computer system or application. There […]
Guidelines on Digital Lending by Reserve Bank of India

The banking sector has been at the heart of the Indian economy contributing to more than 40% of the GDP and lending or credit is what fuels the Indian economy contributing more than 60% of the GDP. Digital lending is the new buzzword in banking, where people mean different things. So let us understand what […]
What’s Buy Now Pay Later (BNPL)? Why is it in the news?

On June 20th, RBI issued a direction disallowing non-banking Prepaid Payment Instruments (PPI) from loading credit lines on the PPI. This bans PPI wallets from being loaded with credit lines/credit cards. What is BNPL? BNPL is short-term financing for consumers who can buy products and get short-term credit and pay later for the credit taken. […]
Why Security Architecture Review is important for Cyber Security?

The cyber security threat landscape is rapidly evolving. Increasingly sophisticated attacks, multiple threat actors, strict regulations on security and privacy, and new-age trends on BYOD, remote working and growing adoption of cloud, and digital transformation initiatives are just some of the varied challenges that Information Security teams face. And the lack of adequate skilled resources […]




