Notes on cyber maturity
Practical thinking on measuring risk, prioritising spend, and running security like a CISO is in the room, for teams at every stage.
TPRM for BFSI, Episode 6: Exit & Resilience
You must be able to leave any vendor and keep running. Exit strategy, tested continuity, step in rights, and the breach runbook nobody rehearses.
DPDP Rules 2025 series
TPRM for BFSI, Episode 6: Exit, Resilience and When a Vendor Fails (The Test Everyone Skips)
The mandated exit strategy, substitutability, tested continuity, step in rights, and the vendor breach runbook everyone documents and nobody rehearses. Series finale.
TPRM for BFSI, Episode 5: Continuous Monitoring and Concentration Risk (Beyond the Annual Questionnaire)
Why the annual questionnaire fails, what continuous monitoring watches, event triggered reassessment, and the cloud concentration hiding under your diversified vendor list.
TPRM for BFSI, Episode 4: The Contract Is the Control (The Clauses That Survive an RBI Inspection)
The RBI 2025 shall-include clauses, incident flowdown, subcontracting approval, offshore safeguards, and the DPDP data processing agreement your MSA is missing.
TPRM for BFSI, Episode 3: Due Diligence That Is Not Theatre (Why a Filed Certificate Is Not Verification)
Collecting a SOC 2 and filing it is not due diligence. RBI's ongoing factors, certificate carve outs, bridge letters, and why real assessment is continuous.
TPRM for BFSI, Episode 2: Building the Vendor Inventory (Material vs Non-Material, and the Fourth Party Problem)
You cannot govern a vendor you have not listed. Material versus non material, the Appendix III trap, fourth parties, SBOM, and concentration risk under the RBI 2025 Directions.
TPRM for BFSI, Episode 1: Why Your Vendors Are Now Your Liability (RBI, SEBI & DPDP in One Frame)
Outsourcing never dilutes your liability. RBI's IT Outsourcing Direction, the 2025 NBFC and AIFI Directions, SEBI CSCRF and DPDP, mapped in one frame, with the deadline that already passed.
DPDP Rules 2025 Episode 5: SDF Readiness, DPO, DPIA, Independent Audit & Algorithmic Accountability
The finale. India-based DPO, annual DPIA, independent audit, and algorithmic due diligence on every credit and fraud model. Rule 13 mapped to FREE-AI and SEBI Regulation 16C.
DPDP Rules 2025 Episode 4: Breach Readiness & the Four-Clock Incident Runbook
One breach triggers up to four filings on four clocks. CERT-In at 6h. RBI/SEBI at 2 to 6. DPB without delay, and again at 72h. The hour-by-hour runbook and eight failure modes.
DPDP Rules 2025 Episode 3: Data Retention & Deletion for BFSI
The Third Schedule does not bind your NBFC. Rule 8(3) is an erasure clock. The field-level retention register, deletion engineering, and evidence auditors ask for.
DPDP Rules 2025 Episode 2: Continuous Data Governance for BFSI
RBI already mandates continuous auditing. SEBI already mandates a maturity score. DPDP made privacy part of the same programme. How to run them as one.
DPDP Rules 2025 for Fintech, BFSI & NBFCs: The Dual Compliance Playbook
Interactive guide: how DPDP stacks on RBI, SEBI, PMLA and CERT-In. Timelines, breach clocks, dual compliance map, and a trackable readiness checklist.