Do you help with RBI Cyber Security Framework and CSITE inspections?
Yes. We map controls to the RBI Cyber Security Framework, prepare the evidence pack that CSITE inspectors ask for, and sit with your CISO through the mock inspection. We have seen the exact objections inspectors raise on change management, privileged access review, log retention, and vendor risk. We produce the artefacts that stand up to that scrutiny rather than a generic ISO checklist.
Who signs the VAPT report and is it acceptable to auditors?
Reports are signed by a named lead tester with a public CV, CVSS 3.1 scoring on every finding, proof-of-concept screenshots, and a remediation retest included. Format matches what RBI CSITE, SEBI and NPCI empanelled auditors expect. If your board asks for CERT-In empanelled tester sign-off on the covering letter, we arrange that through a partner CERT-In firm at no markup.
How do you protect UPI, IMPS and card payment endpoints from DDoS?
Layered defence. Cloudflare Magic Transit or AWS Shield Advanced at the network edge for volumetric traffic. WAF rules tuned for the specific request shape of your payment API (Cloudflare, AWS WAF, or Imperva). Rate limits per client IP, per device fingerprint, per BIN range. Bot rules that separate legitimate merchant traffic from scripted enumeration. Runbook for L7 attacks so the on-call team knows exactly what knob to turn at 2am on a settlement day.
Is DPDP Act 2023 relevant for banks that already follow RBI rules?
Yes, and the two overlap but do not replace each other. RBI rules cover confidentiality and integrity of customer data. DPDP adds specific obligations around consent capture, purpose limitation, breach notification within 72 hours, and the right of erasure for non-KYC data. We do a DPDP gap review against your existing RBI-aligned controls and fill only the delta so you are not re-doing work.
What is your scope on PCI-DSS for a payment aggregator or bank?
Full readiness up to the QSA audit. Scope reduction through tokenisation and network segmentation is usually where we save the most cost. We work with your acquiring bank or QSA of choice for the certifying audit, produce the required policies, do the internal vulnerability scans, help configure the PCI SSC-approved scanning vendor, and run the annual penetration test PCI requires.
Can you integrate with our existing SOC / SIEM / core banking?
Yes. If you already run Splunk, Wazuh, ArcSight, Sentinel, or Qradar we work inside it. Core banking integrations (Finacle, Flexcube, TCS BaNCS) are read-only unless a specific control needs a change. We do not force a stack swap. The stack you run is agreed in writing at scoping so there is no surprise licence cost during rollout.
How much does BFSI security engagement cost?
Channel VAPT (web + mobile + API): typically Rs. 1.5 to 6 lakh depending on surface size. RBI CSITE / IS Audit readiness sprint: Rs. 4 to 8 lakh. Payment infra DDoS + WAF setup: Rs. 2 to 4 lakh plus vendor licence. Monthly managed SOC + incident response retainer: Rs. 80,000 to 2.5 lakh depending on log volume and coverage window. Fixed-price scoping in 48 hours after a short call.