01
ISO 27001:2022

ISMS Implementation & Audit

End-to-end information security management system design, implementation and certification audit support. From gap assessment through Stage 2, with annual surveillance retainer optional.

Deliverables
  • Scoping & ISMS gap-assessment report
  • Risk register with treatment plan
  • Policy & SOP library (Annex A 93 controls)
  • Statement of Applicability
  • Internal audit report & non-conformity log
  • Management review records
  • Certification audit walk-through support
02
ISO 22301

BCMS Implementation

Business continuity management system from BIA through certification. Tabletop and live drills are run with the client's actual response teams — paper plans don't earn certification.

Deliverables
  • Business impact analysis (BIA) & RTO/RPO matrix
  • Business continuity plan (BCP) framework
  • Disaster recovery runbooks
  • Tabletop & DR drill scripts + after-action reports
  • Regulatory continuity alignment (RBI, IRDAI)
  • Certification audit support
03
Vulnerability Management

VAPT Governance & Security Oversight

Program-level governance of vulnerability assessment and penetration testing — third-party engagement scoping, report quality review, and SLA-driven remediation tracking with executive dashboards.

Deliverables
  • VAPT program governance framework
  • Tester onboarding & SoW templates
  • Report review with risk-based prioritisation
  • Remediation SLA tracker (high/critical)
  • Qualys VM program oversight
  • Executive VM dashboard (monthly)
04
IRDAI · PCI DSS · ITGC

Risk & Regulatory Compliance

Audit-driven regulatory compliance — IRDAI Cyber Security audits, PCI DSS coordination with QSAs, ITGC audits, and enterprise / vendor risk register management.

Deliverables
  • Enterprise risk register (taxonomy + register)
  • Third-party / vendor risk assessment
  • IRDAI Cyber Security audit management
  • PCI DSS audit coordination (QSA-facing)
  • ITGC audit & remediation tracking
  • Board audit committee report pack
05
IR · Awareness · SOC

Incident Response & Security Operations

Incident investigation, security awareness programs, and SOC operating model design. Phishing / smishing / vishing simulations run quarterly with measurable click-rate and report-rate trends.

Deliverables
  • Incident response playbook (per scenario)
  • Phishing / smishing / vishing simulations
  • SOC coordination & escalation matrix
  • Security awareness curriculum
  • Post-incident report & lessons-learned log
06
DPDPA · GDPR · Sectoral privacy

DPDP Act & Data Privacy

India Digital Personal Data Protection Act (DPDPA) readiness — from data discovery through consent architecture, DPIAs and breach-notification protocols. Aligned to GDPR for cross-border operations and sectoral privacy regimes where they overlap.

Deliverables
  • DPDP Act gap assessment & readiness report
  • Data inventory & record of processing (RoPA)
  • Notice & consent architecture (consent manager)
  • Data Principal rights workflow (access / correct / erase)
  • Data Protection Impact Assessments (DPIAs)
  • Cross-border data transfer review
  • Breach-notification protocol (72-hour playbook)
  • Vendor / processor agreement uplift
Engagement model

How an engagement is shaped.

ComplyGeek runs a small number of named engagements concurrently. The model below structures every one of them.

01
Scoping

Two-meeting scoping protocol.

A diagnostic call (45 min) followed by a written scope memo with framework, phases, deliverables, dates, and indicative effort. No engagement begins until the scope is countersigned.

02
Contracting

Fixed-scope, milestone-billed.

Default contract is fixed-scope with milestone billing. Retainer and T&M are available for surveillance and ongoing governance engagements.

03
Cadence

Weekly status, monthly steering.

Weekly written status note against the scope plan; monthly steering with the client sponsor (typically CISO or Head of Audit) tracking risk, closure, and forward calendar.

04
Closure

No engagement closes without sign-off.

Closure requires a deliverables hand-off pack, an open-items register (with owners and SLAs), and a written sign-off from the client sponsor. Surveillance retainers begin at closure if scoped.

Have a framework date already on the calendar?