Comply Geek · InfoSec & Governance

Building Audit‑Ready,
Regulatory‑Aligned Org.

A consulting practice helping enterprises achieve certification, reduce cyber risk, and build resilient security programs. ISO 27001 · ISO 22301 · PCI DSS · IRDAI · DPDP · VAPT — delivered with audit-grade documentation and measurable closure.

0+ yrs
Practice experience
In InfoSec, governance and audit leadership across regulated enterprises.
0
Certifications held
Including CISA, ISO 27001:2022 LA, ISO 22301 LA, PCI DSS, IRDAI, CEH.
0
Practice areas
ISMS, BCMS, VAPT governance, Risk & Regulatory, Incident Response, DPDP & privacy.
0%
Closure tracked
SLA-driven remediation governance with executive dashboard reporting.
BFSI Insurance IT Services Global Operations Regulatory-driven enterprises Payment Processors Public Sector BFSI Insurance IT Services Global Operations Regulatory-driven enterprises Payment Processors Public Sector
Mr. Runal R. Bawaskar
Mr. Runal R. Bawaskar President — Info-Sec
Mr. Runal R. Bawaskar

President

I specialise in designing, implementing, and auditing information security and business-continuity programs for enterprises operating under BFSI, insurance, and payments regulation. Engagements are led personally — there are no junior hand-offs.

“Audit closure is not paperwork — it is the difference between a control that exists and a control that works.” Runal R. Bawaskar · Practice lead
What clients can expect

Outcomes, quantified.

The work is measured by closure — not by hours billed. Each engagement converts regulatory exposure into a documented, defensible posture.

  • 01
    Faster ISO 27001 / 22301 certification. Readiness-led, with audit calendar built backward from the certification date.
  • 02
    Audit-ready documentation. Structured policies, SOPs, evidence packs and risk registers, all version-controlled.
  • 03
    Reduced risk exposure. Actionable risk management — every register entry has an owner, an SLA and a closure trail.
  • 04
    Strong VAPT governance. SLA-driven closure tracking against high / critical findings, dashboards over backlog.
  • 05
    Regulator-ready posture. Aligned to IRDAI, RBI, PCI DSS and ITGC expectations — not just framework-ready.
  • 06
    Executive reporting. Clear dashboards for the board audit committee — risk, control, residual exposure.
  • 07
    Business-aligned controls. Practical, proportionate — controls designed to be operated, not just documented.
  • 08
    Single point of accountability. One named practitioner from kickoff to surveillance audit. No hand-offs.

Ready to scope an engagement?