The Bugmetrics Blog

Notes on cyber maturity

Practical thinking on measuring risk, prioritising spend, and running security like a CISO is in the room, for teams at every stage.

Compliance · Episode 6 · Finale
The test everyone skips
FeaturedCompliance · 23 min read · Interactive

TPRM for BFSI, Episode 6: Exit & Resilience

You must be able to leave any vendor and keep running. Exit strategy, tested continuity, step in rights, and the breach runbook nobody rehearses.

AS
Ankita Sharma
15 Jul 2026

DPDP Rules 2025 series

Compliance · 23 min read

TPRM for BFSI, Episode 6: Exit, Resilience and When a Vendor Fails (The Test Everyone Skips)

The mandated exit strategy, substitutability, tested continuity, step in rights, and the vendor breach runbook everyone documents and nobody rehearses. Series finale.

15 Jul 2026
Compliance · 22 min read

TPRM for BFSI, Episode 5: Continuous Monitoring and Concentration Risk (Beyond the Annual Questionnaire)

Why the annual questionnaire fails, what continuous monitoring watches, event triggered reassessment, and the cloud concentration hiding under your diversified vendor list.

5 Jun 2026
Compliance · 23 min read

TPRM for BFSI, Episode 4: The Contract Is the Control (The Clauses That Survive an RBI Inspection)

The RBI 2025 shall-include clauses, incident flowdown, subcontracting approval, offshore safeguards, and the DPDP data processing agreement your MSA is missing.

22 May 2026
Compliance · 21 min read

TPRM for BFSI, Episode 3: Due Diligence That Is Not Theatre (Why a Filed Certificate Is Not Verification)

Collecting a SOC 2 and filing it is not due diligence. RBI's ongoing factors, certificate carve outs, bridge letters, and why real assessment is continuous.

15 May 2026
Compliance · 21 min read

TPRM for BFSI, Episode 2: Building the Vendor Inventory (Material vs Non-Material, and the Fourth Party Problem)

You cannot govern a vendor you have not listed. Material versus non material, the Appendix III trap, fourth parties, SBOM, and concentration risk under the RBI 2025 Directions.

8 May 2026
Compliance · 22 min read

TPRM for BFSI, Episode 1: Why Your Vendors Are Now Your Liability (RBI, SEBI & DPDP in One Frame)

Outsourcing never dilutes your liability. RBI's IT Outsourcing Direction, the 2025 NBFC and AIFI Directions, SEBI CSCRF and DPDP, mapped in one frame, with the deadline that already passed.

30 Apr 2026
Compliance · 20 min read

DPDP Rules 2025 Episode 5: SDF Readiness, DPO, DPIA, Independent Audit & Algorithmic Accountability

The finale. India-based DPO, annual DPIA, independent audit, and algorithmic due diligence on every credit and fraud model. Rule 13 mapped to FREE-AI and SEBI Regulation 16C.

15 Apr 2025
Compliance · 18 min read

DPDP Rules 2025 Episode 4: Breach Readiness & the Four-Clock Incident Runbook

One breach triggers up to four filings on four clocks. CERT-In at 6h. RBI/SEBI at 2 to 6. DPB without delay, and again at 72h. The hour-by-hour runbook and eight failure modes.

1 Apr 2025
Compliance · 16 min read

DPDP Rules 2025 Episode 3: Data Retention & Deletion for BFSI

The Third Schedule does not bind your NBFC. Rule 8(3) is an erasure clock. The field-level retention register, deletion engineering, and evidence auditors ask for.

18 Mar 2025
Compliance · 14 min read

DPDP Rules 2025 Episode 2: Continuous Data Governance for BFSI

RBI already mandates continuous auditing. SEBI already mandates a maturity score. DPDP made privacy part of the same programme. How to run them as one.

4 Mar 2025
Compliance · 12 min read

DPDP Rules 2025 for Fintech, BFSI & NBFCs: The Dual Compliance Playbook

Interactive guide: how DPDP stacks on RBI, SEBI, PMLA and CERT-In. Timelines, breach clocks, dual compliance map, and a trackable readiness checklist.

18 Feb 2025