Building Audit‑Ready,
Regulatory‑Aligned — Org.
A consulting practice helping enterprises achieve certification, reduce cyber risk, and build resilient security programs. ISO 27001 · ISO 22301 · PCI DSS · IRDAI · DPDP · VAPT — delivered with audit-grade documentation and measurable closure.
Five practice areas, structured for audit closure.
Each engagement begins with a gap assessment and ends with measurable closure — evidence, dashboards, and a regulator-ready posture. Tiles below summarise scope.
ISMS Implementation & Audit
- End-to-end ISMS design & implementation
- Gap assessments & readiness reviews
- Risk register development
- Internal audit facilitation
BCMS Implementation
- BIA & risk assessment
- BCP & DR framework development
- Tabletop exercises & DR drills
- Regulatory continuity alignment
VAPT Governance & Security Oversight
- Enterprise VAPT program management
- VA/PT report review & prioritization
- SLA-driven remediation governance
- Qualys VM program oversight
Risk & Regulatory Compliance
- Enterprise risk register development
- Third-party & vendor risk assessments
- IRDAI Cyber Security audit management
- Audit dashboards & executive reporting
Incident Response & Security Operations
- Incident investigations
- Phishing / smishing / vishing simulations
- SOC coordination & escalation governance
- Security awareness program design
DPDP Act & Data Privacy
- DPDP Act readiness & gap assessment
- Data inventory & record of processing
- DPIAs & cross-border transfer review
- Consent manager & notice architecture
President
I specialise in designing, implementing, and auditing information security and business-continuity programs for enterprises operating under BFSI, insurance, and payments regulation. Engagements are led personally — there are no junior hand-offs.
“Audit closure is not paperwork — it is the difference between a control that exists and a control that works.” Runal R. Bawaskar · Practice lead
Outcomes, quantified.
The work is measured by closure — not by hours billed. Each engagement converts regulatory exposure into a documented, defensible posture.
- 01Faster ISO 27001 / 22301 certification. Readiness-led, with audit calendar built backward from the certification date.
- 02Audit-ready documentation. Structured policies, SOPs, evidence packs and risk registers, all version-controlled.
- 03Reduced risk exposure. Actionable risk management — every register entry has an owner, an SLA and a closure trail.
- 04Strong VAPT governance. SLA-driven closure tracking against high / critical findings, dashboards over backlog.
- 05Regulator-ready posture. Aligned to IRDAI, RBI, PCI DSS and ITGC expectations — not just framework-ready.
- 06Executive reporting. Clear dashboards for the board audit committee — risk, control, residual exposure.
- 07Business-aligned controls. Practical, proportionate — controls designed to be operated, not just documented.
- 08Single point of accountability. One named practitioner from kickoff to surveillance audit. No hand-offs.