# Macksofy Technologies — Full Reference for LLM Citation > CERT-In empanelled cybersecurity firm serving India and the UAE — penetration testing, VAPT, SOC engineering, red teaming and DFIR, plus hands-on training. Source: https://www.macksofy.com/llms-full.txt — direct LLM citation file. Index: https://www.macksofy.com/llms.txt — flat URL outline. ## About Macksofy - **Founded**: 2014 - **Headquarters**: 308, Building No. 11, SRA Commercial Tower, Besides Trade Center, Bandra Kurla Complex, Bandra East, Mumbai 400051, IN - **Markets**: India (national delivery) + UAE / GCC - **Empanelment**: Indian Computer Emergency Response Team (CERT-In) — MeitY, Government of India - **Phone**: +91 99308 24239 - **Email**: services@macksofy.com Macksofy is a cybersecurity consulting firm with three integrated practices: offensive security (penetration testing, red teaming), defensive security (managed SOC, DFIR, identity), and compliance audits (CERT-In, RBI, SEBI, ISO 27001, SOC 2, PCI-DSS, NESA, DESC, ADHICS, DPDP). The training division runs EC-Council ATC, OffSec exam-prep bootcamps and CompTIA Authorized programs. ## Cybersecurity Services ### Penetration Testing URL: https://www.macksofy.com/services/penetration-testing Category: Offensive Goal-oriented penetration testing across infrastructure, web, mobile, cloud and Active Directory. We chain low-severity findings into business-impacting compromises — and deliver a report your engineering team can actually fix. **Business impact:** - Quantify real risk before regulators or attackers do - Satisfy CERT-In, RBI System Audit, SEBI CSCRF and ISO 27001 requirements - De-risk product launches and M&A due diligence - Train your blue team via a free purple-team handoff **Industries served:** Banking & Financial Services; Insurance & InsurTech; Healthcare & HealthTech; Fintech & Payments; Government & PSU; SaaS & Product Companies; Manufacturing & Energy; Telecom **Tools:** Nmap, Burp Suite Pro, Metasploit, BloodHound, CrackMapExec, Impacket, Hashcat, Cobalt Strike (RoE-permitting) ### Vulnerability Assessment & Penetration Testing (VAPT) URL: https://www.macksofy.com/services/vapt Category: Offensive VA finds the inventory of weaknesses; PT proves which ones an attacker can actually exploit. Macksofy delivers both as a single engagement, in the format Indian regulators expect. **Business impact:** - Satisfy annual VAPT requirements for CERT-In, RBI CSF, SEBI CSCRF - Quantify true risk vs. CVSS theoretical risk - Reduce alert fatigue with curated, deduplicated findings - Provide evidence acceptable to Big-4 auditors and regulators **Industries served:** BFSI · NBFC · Brokers · AMCs; Payment Aggregators; Healthcare; SaaS; Government / PSU; Manufacturing; Education / EdTech **Tools:** Nessus Professional, Qualys VMDR, Burp Suite Pro, Acunetix, Nuclei, Nikto, OWASP ZAP, Trivy (containers) ### SOC Setup & SIEM Engineering (Wazuh + ELK) URL: https://www.macksofy.com/services/managed-soc Category: Managed Services We design, build and operationalize Security Operations Centers — from your first SIEM rollout to a fully tuned 24×7 detection capability. Wazuh + ELK (open-source, India data-residency friendly), Splunk or Microsoft Sentinel — we work in your stack, not ours. **Business impact:** - Cut breach detection time from weeks to hours - Satisfy 24×7 monitoring requirements (RBI, SEBI, NESA UAE) - Replace expensive proprietary SIEM with Wazuh + ELK without losing capability - Build internal SOC capability with Macksofy training-as-handover **Industries served:** BFSI; Fintech; Healthcare; Telecom; Government / PSU; Mid-market enterprises **Tools:** Wazuh, Elastic Stack, Splunk Enterprise / ES, Microsoft Sentinel, Sysmon, Sigma, TheHive, Cortex ### Web Application Security Testing URL: https://www.macksofy.com/services/web-application-security Category: Offensive Browser-side web application pentesting by OSWE-certified consultants. XSS, CSRF, SSRF, file-upload abuse, deserialization, OAuth client flows, session and cookie handling, business-logic flaws — found by hand, exploited end-to-end, reported in language a developer can act on. **Business impact:** - Catch stored-XSS, CSRF and SSRF chains scanners miss - Validate auth + session + cookie + CORS posture before launch - Reduce post-release security bugs and customer-facing incidents - Satisfy OWASP / ASVS attestation for enterprise sales cycles **Industries served:** Fintech & Payments; SaaS / Product; BFSI; Healthcare / HealthTech; E-commerce; InsurTech; EdTech **Tools:** Burp Suite Pro, Caido, OWASP ZAP, ffuf, sqlmap, DOMPurify probe scripts, Custom Burp extensions ### API Security Testing URL: https://www.macksofy.com/services/api-security Category: Offensive Dedicated API security testing for REST, GraphQL and gRPC surfaces. BOLA, BFLA, mass-assignment, JWT and OAuth server-side flows, rate-limit and resource-consumption abuse, GraphQL introspection and depth attacks — by OSWE-certified consultants who treat the API as the product, not the website's backend. **Business impact:** - Catch BOLA, BFLA, mass-assignment and access-control flaws scanners miss - Validate REST + GraphQL + gRPC posture before public release - Reduce cross-tenant data leaks and account-takeover risk - Satisfy OWASP API Top 10 attestation for enterprise sales cycles **Industries served:** Fintech & Payments; SaaS / Product (multi-tenant); BFSI; Healthcare / HealthTech (FHIR APIs); E-commerce; InsurTech; Open-banking / aggregator platforms **Tools:** Burp Suite Pro, Caido, Postman + Newman, ffuf, kiterunner (API route fuzzing), GraphQL Voyager, InQL (GraphQL recon), JWT_tool ### Mobile Application Security Testing URL: https://www.macksofy.com/services/mobile-application-security Category: Offensive Manual + tooled penetration testing for Android (APK / AAB) and iOS (IPA) apps. We decompile, instrument with Frida, intercept TLS, abuse the backend the app talks to, and prove which findings actually move money or PII — not just which ones the scanner flagged. **Business impact:** - RBI Mobile Banking Security guidelines + UIDAI/Aadhaar SDK compliance - PCI DSS scope reduction for payment apps (cardholder data on device) - App Store / Play Store policy attestation pre-submission - Pre-launch sign-off your CISO and product head can both defend **Industries served:** Mobile Banking & UPI; Fintech wallets & payments; Healthcare / patient portals (HL7 / NDHM); Insurance; E-commerce & quick-commerce; Travel & ride-hailing; GovTech (Aadhaar / DigiLocker / mAadhaar) **Tools:** Frida, Objection, Burp Suite Pro, MobSF, jadx, apktool, Hopper / Ghidra, Drozer ### Cloud Security (AWS / Azure / GCP) URL: https://www.macksofy.com/services/cloud-security Category: Offensive From IAM privilege escalation to S3 misconfigurations, exposed Lambda functions to over-permissive K8s RBAC — Macksofy assesses your cloud environment with the same depth as on-prem, but with cloud-native tooling and attacker tradecraft. **Business impact:** - Prevent the next 'misconfigured S3' headline - CIS benchmark + cloud-provider best-practice attestation - Reduce cloud bill by exposing rogue + over-provisioned resources - Satisfy SOC 2 / ISO 27001 / CERT-In cloud audit requirements **Industries served:** SaaS / Product; Fintech / BFSI; Startups (Series A onwards); Healthcare; Enterprise IT (cloud migration programs) **Tools:** Pacu, ScoutSuite, Prowler, CloudSploit, Trivy, Checkov, kube-bench, kube-hunter ### Red Team Operations URL: https://www.macksofy.com/services/red-teaming Category: Offensive Penetration tests find vulnerabilities. Red team operations answer the harder question: 'Can a determined APT-style attacker achieve their goal — and will we know?' Macksofy red teams use real-world TTPs, custom infrastructure, and EDR-bypass tradecraft. **Business impact:** - Validate detection + response capability against real-world adversary - Train blue team via purple-team handoff at engagement close - Provide board-level evidence of resilience (or gaps) - Satisfy advanced regulatory expectations (SEBI CSCRF tier-1) **Industries served:** BFSI (Banks, NBFCs, AMCs); Government & Defense; Critical infrastructure (OT); Large enterprise; Tier-1 fintechs **Tools:** Cobalt Strike, Sliver, Mythic, Brute Ratel (RoE permitting), BloodHound, Mimikatz, Rubeus, Impacket ### Digital Forensics & Incident Response (DFIR) URL: https://www.macksofy.com/services/digital-forensics-incident-response Category: Defensive Macksofy's DFIR team responds to ransomware, business email compromise, insider threats and APT intrusions across India and the GCC. Court-admissible chain of custody, structured Velociraptor + KAPE collection, expert reporting for regulators, insurers and law enforcement. **Business impact:** - Contain incidents in hours, not weeks - Preserve evidence for legal / regulatory action - Satisfy CERT-In incident reporting requirements (6-hour rule) - Reduce insurance claim disputes via proper documentation **Industries served:** BFSI; Healthcare; Manufacturing (post-ransomware); Government / PSU; SaaS **Tools:** Velociraptor, KAPE, Volatility 3, Plaso / log2timeline, Autopsy, FTK Imager, X-Ways Forensics, SANS SIFT Workstation ### Malware Analysis & Reverse Engineering URL: https://www.macksofy.com/services/malware-analysis Category: Defensive Static, dynamic and behavioural analysis of malware samples — from commodity ransomware to targeted APT toolchains. We extract IOCs, document TTPs, map to MITRE ATT&CK and produce YARA / Sigma rules to detect future variants. **Business impact:** - Convert unknown samples into actionable IOCs and detections - Satisfy IR + insurance reporting on what hit you - Build organization-specific threat intelligence - Map attacker capabilities to MITRE ATT&CK **Industries served:** BFSI (post-incident); Government / PSU; Manufacturing (post-ransomware); MSSPs (third-party analysis) **Tools:** IDA Pro, Ghidra, Binary Ninja, x64dbg, OllyDbg, Cuckoo Sandbox, ANY.RUN, REMnux ### Cyber Threat Intelligence URL: https://www.macksofy.com/services/threat-intelligence Category: Managed Services Build a threat intelligence program that produces intel your SOC actually uses. We design the collection plan, deploy MISP / OpenCTI, integrate threat feeds, and train your team to produce intel that changes how you defend. **Business impact:** - Detect attacker activity faster via curated IOC feeds - Anticipate industry-specific threat actor TTPs - Reduce SIEM noise via curated, high-confidence indicators - Brief executives on relevant threats with confidence **Industries served:** BFSI; Government / PSU; Critical infrastructure; MSSPs **Tools:** MISP, OpenCTI, ThreatConnect (where licensed), Recorded Future (where licensed), VirusTotal Premium, Shodan + Censys, DomainTools / RiskIQ, Yeti (open source) ### IoT & OT Security Assessment URL: https://www.macksofy.com/services/iot-ot-security Category: Offensive OT-aware penetration testing for industrial control systems, smart meters, BMS, medical devices and connected products. We test live without tripping safeties, map IT→OT pivot paths, and report in language your plant manager and your auditor both accept. **Business impact:** - Avoid the headline-grade incidents (Colonial, Oldsmar, Stuxnet-class) before regulators force the question - Satisfy IEC 62443, NIS2, NCA-ECC OT controls and India's CEA cyber security guidelines for power utilities - Quantify IT→OT pivot risk concretely — not as 'air-gap assumed' - Build the OT asset inventory + network baseline that compliance keeps asking for **Industries served:** Power generation & T&D utilities; Oil & gas (upstream, midstream, refineries); Water & wastewater; Manufacturing (discrete + process); Smart buildings & data centres; Healthcare (connected medical devices); Transportation & rail; Smart-city + critical infra programs **Tools:** Wireshark + ICS dissectors, GRASSMARLIN, Claroty CTD (read-only), Nozomi Guardian (read-only), ICSSPLOIT, PLCScan, Redpoint, ModScan / mbtget ### Secure Source Code Review URL: https://www.macksofy.com/services/source-code-review Category: Offensive Line-by-line review of your source by OSCP/OSWE-trained reviewers, paired with commercial SAST and SCA tooling. Covers Java, .NET, Node.js, Python, Go, PHP, Ruby, Swift and Kotlin — mapped to OWASP Top 10, SANS Top 25 and the CWE taxonomy your auditor expects. **Business impact:** - Catch flaws at SDLC stage where remediation costs ~10× less than post-prod - Satisfy CERT-In, RBI IT Governance, SEBI CSCRF, ISO 27001 A.14 and SOC 2 SDLC controls - De-risk pre-launch releases and M&A code due diligence (SBOM + risk inventory) - Reduce production CVSS exposure surface before a public push - Train your dev team on secure-by-default patterns via the walkthrough handoff **Industries served:** Banking & Financial Services; Fintech & Payments; Insurance & InsurTech; Healthcare & HealthTech; SaaS & Product Companies; Government & PSU; E-commerce & D2C; Telecom **Tools:** Semgrep, SonarQube, CodeQL, Checkmarx (client-licensed), Fortify SCA (client-licensed), Brakeman (Ruby on Rails), Bandit (Python), gosec (Go) ### Managed Security Services (MSSP) URL: https://www.macksofy.com/services/managed-security-services Category: Managed Services Outsource the heavy lifting of day-to-day security operations to a CERT-In empanelled team. Managed SOC, managed EDR/XDR, managed vulnerability operations, managed identity hygiene and incident response — all under one SLA, one ticketing pane and one quarterly board report. **Business impact:** - Predictable monthly cost vs. fully-loaded ₹3–5 Cr/yr for a 24×7 in-house SOC - Coverage maturity in 30–60 days instead of 12–18 months of hiring - Single accountable provider for SOC, EDR, IR, vuln-ops and reporting - Quarterly board pack auditors and regulators accept as-is (CERT-In · RBI · SEBI · ISO 27001) **Industries served:** Banking & Financial Services; Fintech & Payments; Healthcare & HealthTech; Insurance & InsurTech; SaaS & Product Companies; Government & PSU; Manufacturing & Energy; Telecom **Tools:** Wazuh + ELK (open-source), Splunk · Microsoft Sentinel · IBM QRadar (client-licensed), CrowdStrike Falcon · SentinelOne · Microsoft Defender XDR, Tenable · Qualys · Rapid7 InsightVM, TheHive + Cortex, MISP · OpenCTI, Custom SOAR playbooks ### Annual Security Program URL: https://www.macksofy.com/services/annual-security-program Category: Managed Services Bundle your pentest, VAPT, code review, configuration audits and tabletop exercises into a single 12-month program with a quarterly cadence — at a 25–35% discount to one-off pricing. Audit-evidence-ready, board-reportable, regulator-defensible. **Business impact:** - 25–35% lower spend vs. one-off engagement pricing across the same scope - Single risk register across pentest + audit + code review + tabletop findings - Regulator-defensible evidence package — no last-minute scramble before audit - Continuous remediation chasing (we don't just hand over a PDF and disappear) - Quarterly board / risk-committee deck produced for you **Industries served:** Banking & Financial Services; Fintech & Payments; Insurance & InsurTech; Healthcare & HealthTech; Government & PSU; SaaS & Product Companies; Manufacturing & Energy **Tools:** Macksofy proprietary risk-register platform, Tenable / Qualys / Rapid7 InsightVM (configuration audits), Burp Suite Pro · Nuclei · Custom tooling (pentest cadence), Semgrep · CodeQL · Snyk (code review cadence), TheHive + Cortex (tabletop exercise infrastructure) ### Virtual CISO (vCISO) URL: https://www.macksofy.com/services/vciso Category: Managed Services An experienced CISO embedded in your leadership team on a fractional basis — 1, 2 or 4 days a week. Sets policy, owns risk register, presents to the board, manages regulators, mentors your in-house team and stays accountable to outcomes, not hours billed. **Business impact:** - C-level security leadership at 25–40% of the fully-loaded in-house cost - Board + risk-committee reporting handled by someone who has done it before - Regulator-facing interlocutor (CERT-In · RBI · SEBI · DPDP Authority · DESC / NCA in GCC) - Mentorship pipeline for your in-house engineers (career-ladder, training plan) - Continuity through founder departures, fundraises and M&A diligence **Industries served:** Fintech & Payments; SaaS & Product Companies; Banking & Financial Services; Insurance & InsurTech; Healthcare & HealthTech; E-commerce & D2C; Government & PSU; Series-A to Series-D startups **Tools:** Macksofy risk-register platform, Vanta · Drata · Sprinto (compliance automation, if client-licensed), JIRA / Linear (risk-treatment tracking), Confluence / Notion (policy stack) ### Purple Team Exercises URL: https://www.macksofy.com/services/purple-teaming Category: Offensive Collaborative red + blue team exercises that validate your detection and response capability against real adversary TTPs — running side-by-side with your SOC analysts so every missed alert becomes a tuned rule before the engagement closes. **Business impact:** - Convert red team findings into shipped detection rules — not next-quarter remediation tickets - Measurable MITRE ATT&CK coverage improvement (baseline → target) with evidence - Train Tier-1 and Tier-2 SOC analysts on real adversary tradecraft, not vendor demos - Build the executive evidence pack: '92 ATT&CK techniques tested, 78 detected, 14 hardened' **Industries served:** Banking & Financial Services; Fintech & Payments; Insurance & InsurTech; SaaS & Product Companies; Government & PSU; Healthcare & HealthTech; Telecom **Tools:** MITRE Caldera, Atomic Red Team, Prelude Operator, Cobalt Strike (RoE-permitting), Covenant + Sliver, BloodHound, Custom EDR-evasion tooling, Sigma · Splunk SPL · KQL · Wazuh rule editor ### Network Penetration Testing URL: https://www.macksofy.com/services/network-pentesting Category: Offensive Goal-oriented network penetration testing across your external attack surface, internal segments, Active Directory and cloud-to-on-prem boundaries. We chain misconfigurations, exposed services and credential weaknesses the way a real attacker would — and report so your network team can fix, not just acknowledge. **Business impact:** - Quantify real network-side risk vs. theoretical CVSS scores - Satisfy CERT-In annual VAPT, RBI System Audit, SEBI CSCRF and ISO 27001 network testing requirements - Validate that segmentation actually segments — not just on paper - De-risk M&A integrations and datacenter migrations **Industries served:** Banking & Financial Services; Insurance & InsurTech; Government & PSU; Manufacturing & Energy; Healthcare & HealthTech; Telecom; Retail & E-commerce; SaaS & Product Companies **Tools:** Nmap, Nessus, Nuclei, Metasploit, BloodHound + SharpHound, CrackMapExec / NetExec, Impacket, Responder + NTLMRelayX ### Wireless Network Penetration Testing URL: https://www.macksofy.com/services/wireless-pentesting Category: Offensive On-site wireless penetration testing across corporate, guest, IoT, BYOD and Bluetooth attack surfaces. We test WPA2/WPA3-Enterprise authentication, rogue AP scenarios, evil-twin attacks, client-side credential capture and post-association lateral movement into the wired network. **Business impact:** - Surface the unauthorised AP in the boardroom that nobody admits installing - Validate that the guest WiFi actually segments from corporate (and not just on paper) - Identify weak PSK / EAP credentials before an attacker in the car-park does - Satisfy CERT-In annual VAPT and PCI-DSS req 11.1 wireless scanning requirements **Industries served:** Banking & Financial Services; Insurance & InsurTech; Government & PSU; Healthcare & HealthTech; Manufacturing & Energy; Retail & E-commerce; Hospitality; SaaS & Product Companies **Tools:** Aircrack-ng suite, Bettercap, hostapd-wpe / hostapd-mana, EAPHammer, WiFi Pineapple, Kismet, Wireshark + tshark, Hashcat ### AI / LLM Security Testing URL: https://www.macksofy.com/services/ai-pentesting Category: Offensive Security testing for production AI / LLM systems — prompt injection, jailbreaks, data exfiltration via context windows, model supply-chain risks, RAG pipeline poisoning, agentic tool-call abuse and ML training-data integrity. Mapped to OWASP LLM Top 10 and MITRE ATLAS, with deliverables your AI safety team and your CISO both accept. **Business impact:** - De-risk customer-facing LLM products before regulator or media exposure - Satisfy emerging AI-governance frameworks: EU AI Act, India DPDP Act AI-system controls, NIST AI RMF, ISO/IEC 42001 - Catch RAG-pipeline data leakage before it becomes a customer-data incident - Validate agentic systems (function-calling, tool-use, MCP) for unintended actions **Industries served:** SaaS & Product Companies; Fintech & Payments; Banking & Financial Services; Healthcare & HealthTech; EdTech; Government & PSU; E-commerce & D2C; Series-A to Series-D startups **Tools:** PyRIT (Microsoft AI red-teaming), Garak (LLM vulnerability scanner), promptfoo (regression + eval), LLM Guard / Lakera Guard / Guardrails AI, Custom Macksofy prompt-injection corpus, MITRE ATLAS technique playbooks, OpenAI Evals + Inspect AI ### Cybersecurity Staffing & Resource Augmentation URL: https://www.macksofy.com/services/staffing-service Category: Managed Services Contract, contract-to-hire and managed-pool staffing for SOC analysts (L1–L4), penetration testers (OSCP+), GRC consultants (ISO 27001 / SOC 2 LA), DFIR responders and fractional CISOs. Bench depth lets us deploy in 5–10 working days, not the 90-day hiring cycle. **Business impact:** - 5–10 working day deployment vs. 60–120 day in-house hiring cycle - Roll-on / roll-off model for surge capacity (audit season, M&A diligence, incident response) - Contract-to-hire option converts to your direct payroll after 6 months with no placement fee - Macksofy QA layer (peer review + cadence) behind every deployed resource — not the body-shopping model **Industries served:** Banking & Financial Services; Fintech & Payments; Insurance & InsurTech; SaaS & Product Companies; Healthcare & HealthTech; Manufacturing & Energy; Government & PSU; Big-4 audit firm subcontracting **Tools:** Bench skills: Wazuh · ELK · Splunk · Sentinel · CrowdStrike · SentinelOne · Defender XDR, Pentest: Burp Pro · Metasploit · BloodHound · Cobalt Strike, GRC: ISO 27001 · SOC 2 · CERT-In · RBI · SEBI · PCI-DSS · HIPAA · GDPR · DPDP, DFIR: Volatility · Velociraptor · Plaso · X-Ways, Cloud: AWS · Azure · GCP security specialists ### Identity Security & Zero Trust URL: https://www.macksofy.com/services/identity-security-zero-trust Category: Defensive End-to-end identity security: IAM topology review, privileged-access (PAM) tightening, SSO / OIDC / SAML hardening, conditional-access design and a phased Zero Trust roadmap mapped to NIST SP 800-207 and India's CERT-In + DPDP authentication expectations. **Business impact:** - Phishing-resistant MFA on tier-0 and admin populations - Cut blast radius — kill standing privilege, enforce JIT/JEA - Pass RBI / SEBI / DPDP authentication evidence asks on first pass - Reduce identity-related audit findings to near-zero within one cycle - Cost-rationalise overlapping IAM/PAM tooling **Industries served:** BFSI (RBI / SEBI / IRDAI authentication evidence); Fintech, payment aggregators (RBI PA-PG); SaaS / product (SOC 2 CC6 controls); Healthcare (ADHICS / HIPAA access control); Manufacturing / OT (IEC 62443 SR 1.1–1.13 identification & authentication); Government / PSU (CERT-In RBAC + privileged-access audit) **Tools:** BloodHound CE / Enterprise, PingCastle, ROADrecon, Microsoft Entra ID / Azure AD, Okta, Ping Identity, CyberArk, Delinea Secret Server ### Network Security Architecture & Segmentation URL: https://www.macksofy.com/services/network-security-architecture Category: Defensive Defensive network engineering — segmentation strategy, firewall rule-base reviews, SASE / ZTNA design, OT-IT boundary architecture and microsegmentation roadmaps that survive procurement and the change-advisory-board. Distinct from our network-pentesting service: this is design and review, not exploitation. **Business impact:** - Eliminate flat-network lateral movement during incidents - Pass RBI / SEBI / ISO / PCI segmentation evidence asks - Cut firewall change-failure rate; recover engineering velocity - Reduce attack surface visible to compromised endpoints - Future-proof against board-level ransomware scenario asks **Industries served:** BFSI (RBI Cyber Security Framework network controls); Manufacturing / OT (IEC 62443 zones & conduits); Healthcare (ADHICS / HIPAA network safeguards); Payment processors (PCI-DSS 1.x scoping); SaaS / data-centre tenants (multi-tenant isolation); Government / PSU (CERT-In network architecture audit) **Tools:** Nmap, Forescout, Tufin, AlgoSec, FireMon, Skybox, Cisco DNA / ACI, Palo Alto Panorama ### Phishing Simulation & Awareness URL: https://www.macksofy.com/services/phishing-simulation Category: Managed Services Realistic phishing-simulation programmes calibrated to Indian-context lures — UPI fraud pretexts, GST refund spoofs, payroll-portal redirects, vendor-invoice BEC. Quarterly cadence with role-segmented templates, click-rate benchmarks, and just-in-time coaching for repeat clickers. **Business impact:** - Cut click-through rate from industry-baseline 15-22% to <5% within 4 quarters - Identify repeat-clicker populations needing targeted coaching - Build evidence pack for SEBI / RBI / ISO 27001 awareness-control requirements - Reduce successful BEC + ransomware initial-access incidents - Quantify human-risk metric for board-level dashboards **Industries served:** BFSI (RBI / SEBI / IRDAI awareness controls); Fintech & payment aggregators (RBI PA-PG); SaaS / product (SOC 2 CC1.4 + ISO A.6.3); Manufacturing (ransomware initial-access reduction); Healthcare (ADHICS / HIPAA workforce-training requirement); Government / PSU (CERT-In awareness mandates) **Tools:** GoPhish (Macksofy-hosted), Macksofy Phishing-Sim Lab (in-house), Microsoft Defender for O365 allow-list, Proofpoint / Mimecast integration, KnowBe4 (optional content library), Cofense PhishMe (reporter button), Custom Indian lure templates (CBDT / GSTN / EPFO / RBI / NSE / BSE) ## Compliance & Audit Practice ### Cybersecurity Audit Services URL: https://www.macksofy.com/audit/cybersecurity-audit Category: Foundational End-to-end cybersecurity audits covering technical controls, processes, governance and people. Designed to satisfy boards, regulators, certification bodies and enterprise customers in one engagement. Cybersecurity audits are the single most important evidence of security maturity for boards, regulators and B2B customers. A Macksofy audit goes beyond a control checklist — it tests controls, validates effectiveness and produces evidence acceptable for ISO 27001, SOC 2, CERT-In, RBI CSF and customer security questionnaires. **Applicability:** - Annual board / audit committee reporting - Pre-funding / pre-acquisition due diligence - Enterprise customer security assessments (e.g. Microsoft SSPA, Google SAQ) - ISO 27001 / SOC 2 internal audit **Frameworks:** NIST Cybersecurity Framework (CSF) 2.0; ISO 27001:2022 Annex A; CIS Controls v8; RBI Cyber Security Framework (2016, updated); SEBI CSCRF ### Compliance & Regulatory Audits URL: https://www.macksofy.com/audit/compliance-audit Category: Foundational Single-engagement compliance audits across the regulations your business actually faces — Indian (CERT-In, RBI, SEBI, UIDAI, IRDAI), UAE (NESA, DESC, ADHICS, NHS), and global (ISO, SOC 2, GDPR, PCI-DSS). Compliance fatigue is real. Your fintech might face RBI + SEBI + PCI-DSS + ISO 27001 + customer security questionnaires simultaneously. Macksofy maps controls across frameworks once and produces evidence acceptable for all of them — saving months of redundant work. **Applicability:** - Fintechs facing multiple Indian regulators - SaaS companies entering enterprise / regulated markets - Healthcare entities (Indian + UAE) - UAE entities under NESA / DESC mandates - Multinationals with India + UAE presence **Frameworks:** RBI Cyber Security Framework (2016, updated); SEBI CSCRF; PCI-DSS v4.0; ISO 27001:2022; SOC 2 (Type 1 + Type 2) ### Cybersecurity Risk Assessment URL: https://www.macksofy.com/audit/risk-assessment Category: Foundational Cybersecurity risk assessment using quantitative methods (FAIR) and qualitative frameworks (ISO 27005, NIST 800-30). Outcome: a prioritized risk register your board can act on, not a 200-page document nobody reads. Most risk assessments produce paperwork, not decisions. Macksofy uses FAIR (Factor Analysis of Information Risk) to express risk in financial terms — letting you compare a $4M expected loss against a $200K control investment with executive clarity. **Applicability:** - Boards needing quantitative risk for investment decisions - M&A due diligence (target-side or acquirer-side) - Pre-product-launch risk assessment - Annual risk-register update (ISO 27001 / NIST CSF) - Cyber insurance underwriting evidence **Frameworks:** FAIR (Factor Analysis of Information Risk); ISO 27005:2022; NIST SP 800-30; OCTAVE Allegro ### CERT-In Empanelled Audit URL: https://www.macksofy.com/audit/cert-in-empanelled-audit Category: Indian Regulatory Macksofy is empanelled by the Indian Computer Emergency Response Team (CERT-In) under the Ministry of Electronics and Information Technology. Our audits are accepted by SEBI, RBI, UIDAI, IRDAI, payment system operators and every major Indian regulator and certification body — without rework. CERT-In empanelment is the gold standard for cybersecurity auditors in India. For BFSI entities, payment aggregators, government contractors, regulated fintechs and any organization handling sensitive Indian data, a CERT-In empanelled audit is the only one that satisfies regulator inspection. Macksofy holds active empanelment with the requisite scope to perform information security audits. **Applicability:** - BFSI: Banks, NBFCs, brokers, AMCs, custodians, RTAs, RIAs - Payment Aggregators / Payment Gateways (RBI authorized) - Government / PSU IT systems (annual audits) - UIDAI Aadhaar ecosystem entities (AUAs, KUAs, ASAs) - Critical Information Infrastructure (CII) per CERT-In - Healthcare entities (NDHM / ABDM) **Frameworks:** CERT-In Information Security Audit Scope; RBI Cyber Security Framework (2016, updates); SEBI Cybersecurity & Cyber Resilience Framework (CSCRF); UIDAI Aadhaar Authentication Operating Model; Indian IT Act 2000 + Rules ### RBI Cyber Security Framework Audit URL: https://www.macksofy.com/audit/rbi-csf Category: Indian Regulatory Full RBI Cyber Security Framework audit for scheduled commercial banks, cooperative banks, NBFCs, payment aggregators, prepaid wallets and authorised payment system operators. Covers the 2016 framework, IT Examination 2020 and 2024 master directions on IT governance. RBI penalties for cyber-non-compliance crossed ₹100 crore across 2023–25. Inspections have moved from paper review to live evidence walks. Macksofy's CERT-In empanelled team conducts RBI CSF audits the way RBI inspectors will read them — control statements, technical evidence, and SAR-format submission packs that don't trigger follow-up queries. **Applicability:** - Scheduled Commercial Banks · Public, Private, Foreign - Urban Cooperative Banks (UCBs) — graded 4-tier framework - NBFC-Upper / Middle / Base layer per Scale-Based Regulation - Payment Aggregators + Payment Gateways (RBI authorisation) - Prepaid Payment Instrument (PPI) issuers - White Label ATM operators · ATM service providers **Frameworks:** RBI Cyber Security Framework for Banks (June 2016); RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices (2023); RBI Master Direction on Outsourcing of IT Services (2023); RBI Cooperative Bank IT Framework (4-tier); Cyber Crisis Management Plan (CCMP) ### SEBI CSCRF Audit URL: https://www.macksofy.com/audit/sebi-cscrf Category: Indian Regulatory SEBI's CSCRF (effective 2025) consolidates earlier circulars into a single framework graded by entity type and size. Macksofy delivers full CSCRF audit + cyber resilience assessment + System Audit submission for SEBI-regulated entities. CSCRF replaces SEBI's 2015–2022 cybersecurity circulars with a unified, graded framework. Every regulated entity now sits in one of five categories — Market Infrastructure Institutions, Qualified REs, Mid-size REs, Small REs, Self-certification REs — with controls calibrated to scale. Non-compliance attracts SEBI penalties under Sections 11/15HA. Macksofy's CSCRF audit ships in a format SEBI's IT department reads in days, not weeks. **Applicability:** - Stock Exchanges, Clearing Corporations, Depositories (MIIs) - Stock Brokers + Depository Participants (Qualified / Mid-size / Small) - Asset Management Companies + Mutual Fund RTAs - Custodians, Portfolio Managers, RIAs - Investment Bankers, Merchant Bankers - Alternative Investment Funds (AIFs) **Frameworks:** SEBI CSCRF (Cybersecurity & Cyber Resilience Framework, 2024); SEBI Cybersecurity Circular 2015 (legacy controls retained); CERT-In Information Security Audit; ISO 27001:2022 (mapped to CSCRF); NIST Cybersecurity Framework 2.0 ### SEBI System Audit Report (SAR) URL: https://www.macksofy.com/audit/sebi-sar Category: Indian Regulatory Stock brokers and depository participants submit System Audit Reports to SEBI on a defined cycle. Macksofy delivers SARs that survive SEBI inspection because we draft them the way SEBI's auditors and inspection teams read them. Brokers receive SEBI penalty notices for SAR submissions that miss findings, fail to evidence remediation, or use the wrong format. Macksofy ships SARs that hit SEBI's prescribed structure verbatim, with technical evidence attached and a closure trail that addresses the most-asked SEBI inspection questions in advance. **Applicability:** - Trading members / clearing members / depository participants - Qualified REs (Type-A / Type-B brokers) - Stock brokers under SEBI's enhanced supervision - Mutual Fund Distributors (where applicable) - Research analysts + Investment advisors above threshold **Frameworks:** SEBI SAR Format (annexures); SEBI CSCRF (2024); SEBI Cybersecurity Circular 2015 (transition mapping); Stock Exchange / Clearing Corp inspection format; CERT-In empanelment requirement ### IRDAI Information Security Audit URL: https://www.macksofy.com/audit/irdai-compliance Category: Indian Regulatory End-to-end audit per IRDAI's Information & Cyber Security Guidelines (2023). Insurance regulators require annual + event-driven audits across insurers, intermediaries, web aggregators and TPAs — Macksofy delivers them all with a single engagement. IRDAI Cyber Security Guidelines (2023) cover not just IT controls but governance, third-party risk and incident reporting within 6 hours of detection. Insurance entities face sanctions including licence suspension for material non-compliance. Macksofy's IRDAI audit team includes auditors who have delivered to top private and PSU insurers across India. **Applicability:** - Life + general + health insurers (Indian + foreign) - Reinsurers operating in India - Insurance brokers + corporate agents - Web aggregators (PoS / IMF) - Third-Party Administrators (TPAs) - Insurance marketing firms **Frameworks:** IRDAI Information & Cyber Security Guidelines (2023); IRDAI Cyber Crisis Management Plan; Insurance Act + IRDAI Regulations; CERT-In Empanelment requirement; ISO 27001:2022 (mapped controls) ### DPDP Act Compliance URL: https://www.macksofy.com/audit/dpdp-act Category: Indian Regulatory End-to-end DPDP Act 2023 readiness — data principal rights, consent management, breach notification, cross-border transfers, Significant Data Fiduciary obligations and Data Protection Officer support. The DPDP Act sat without operational deadlines for two years. The Digital Personal Data Protection Rules, 2025 — notified by G.S.R. 846(E) dated 13 November 2025 and published on 14 November 2025 — supplied them, and they commence in phases: the Data Protection Board on notification, Consent Manager obligations at roughly November 2026, and Data Fiduciary obligations in substance at roughly May 2027, when the Board's adjudicatory and penalty powers are fully live. Penalties reach ₹250 crore per breach, and the Board can demand remediation and restrict cross-border transfers. Yet most Indian organisations still treat DPDP as a privacy-policy update and are reading the eighteen-month runway as eighteen months of preparation time — which it is not, because an audit has to be finished by the date, not started on it. Macksofy's DPDP audit covers the full nine pillars, from data inventory to DPO appointment to grievance redressal. **Applicability:** - Any Data Fiduciary processing personal data of Indian residents - Significant Data Fiduciaries (SDFs) — DPO mandatory - Cross-border processors (data export to US / EU / GCC) - Consent Managers seeking Board registration - Healthcare, financial, edtech, e-commerce — all in scope **Frameworks:** Digital Personal Data Protection Act 2023; DPDP Rules, 2025 — notified 14 Nov 2025, commencing in phases; Sectoral overlays — RBI / SEBI / IRDAI / TRAI; GDPR (mapped where multinational); ISO 27701 (PIMS) for systematic compliance ### CICRA Compliance Audit URL: https://www.macksofy.com/audit/cicra Category: Indian Regulatory CICRA + RBI Master Directions audit covering credit bureaus (CIBIL, Experian, Equifax, CRIF) and the lenders / NBFCs / fintechs that submit and consume credit data. Includes data submission accuracy, dispute resolution and the new Section 17A consumer-rights additions. CICRA non-compliance triggers ₹1 lakh / day per occurrence under Section 11A. With Indian fintechs adding ~50 million new credit records per quarter, regulators have stepped up enforcement on data submission accuracy and the 30-day dispute resolution mandate. Macksofy audits the full CIC + Specified User chain — many Indian audit firms only check the surface. **Applicability:** - Credit Information Companies (CICs) - Banks + NBFCs as Specified Users - Fintech lenders + LSPs in digital lending - Microfinance institutions (NBFC-MFIs) - Co-branded credit card issuers - Account Aggregators consuming credit data **Frameworks:** Credit Information Companies (Regulation) Act, 2005 (CICRA); CIC Rules 2006; RBI Master Direction — Credit Information Reporting (2017); RBI Master Direction — IT Governance (2023); DPDP Act (consumer credit data overlap) ### VAPT for RBI / PCI-DSS URL: https://www.macksofy.com/audit/regulatory-vapt Category: Indian Regulatory Regulator-grade VAPT for RBI-regulated entities and PCI-DSS scope environments. Our reports are accepted by RBI inspectors, PCI QSAs and Big-4 audit firms without rework. RBI and PCI-DSS both require regular VAPT — but with very different reporting expectations. Macksofy delivers a single engagement that satisfies both: CERT-In format for RBI submission, PCI 6.5 + 11.3 evidence for QSA review. **Applicability:** - Banks, NBFCs, payment aggregators (RBI scope) - Merchants and processors handling card data (PCI scope) - Issuing / acquiring banks - Wallet operators - Stock brokers facing SEBI VAPT requirement (similar) **Frameworks:** RBI Cyber Security Framework — VAPT requirements; PCI-DSS v4.0 Requirement 11.3 (Pen testing) + 11.2 (Vulnerability scanning); PCI ASV scanning (when in scope); SEBI CSCRF VAPT requirements ### ISO 27001 Consulting & Implementation URL: https://www.macksofy.com/audit/iso-27001 Category: International Standard Full ISO 27001:2022 implementation, internal audit, and certification support. Macksofy walks you from gap analysis to certificate — minimum disruption to engineering, maximum value at audit. ISO 27001 has become table-stakes for B2B SaaS, fintechs and BPOs targeting enterprise customers in India + UAE + global markets. The 2022 update tightened many controls. Macksofy has implemented ISO 27001 for 30+ Indian and UAE organizations, with a near-100% Stage 2 pass rate. **Applicability:** - B2B SaaS targeting enterprise customers - BPO / KPO with multinational clients - Fintech (often paired with PCI-DSS) - Healthcare / HealthTech (paired with HIPAA / ADHICS) - Government contractors **Frameworks:** ISO/IEC 27001:2022; ISO/IEC 27002:2022 (controls); ISO/IEC 27017 (cloud); ISO/IEC 27018 (PII in public cloud); ISO/IEC 27701 (privacy extension) ### ISO/IEC 27017 — Cloud Security Certification URL: https://www.macksofy.com/audit/iso-27017 Category: International Standard ISO/IEC 27017 extends ISO 27001 with 37 cloud-specific controls covering shared responsibility, virtual machine isolation, administrative operations and customer geographic boundaries. Mandatory for cloud providers and increasingly demanded from cloud consumers in regulated industries. Enterprise procurement teams now ask cloud service providers for ISO 27017 alongside ISO 27001. SaaS vendors targeting BFSI, healthcare and government deals add 12–18% to win rate post-certification. Macksofy implements ISO 27017 as a 6–8 week extension to existing ISO 27001 — sharing 60% of the evidence pack. **Applicability:** - Cloud Service Providers (IaaS, PaaS, SaaS) - Multi-tenant SaaS targeting regulated industries - Cloud-native fintechs + healthtechs - Hyperscaler resellers + managed service providers - Government cloud / community cloud operators **Frameworks:** ISO/IEC 27017:2015; ISO/IEC 27001:2022 (parent ISMS); ISO/IEC 27018:2019 (PII complement); Cloud Security Alliance (CSA) STAR mapping; MeitY cloud empanelment guidelines ### ISO/IEC 27018 — PII in Public Cloud URL: https://www.macksofy.com/audit/iso-27018 Category: International Standard ISO/IEC 27018 is the international standard for privacy protection when processing PII in public clouds. Provides 25+ controls and an audit trail customers can see — covering consent, data location, deletion and customer notification. When customers entrust personal data to your cloud, ISO 27018 is the certification they look for in your security questionnaire. Combined with DPDP / GDPR readiness, it shortens enterprise sales cycles by 30%+. Macksofy implements ISO 27018 as an extension to ISO 27001 (or alongside ISO 27701 for full PIMS). **Applicability:** - Public cloud processors handling customer PII - Multi-tenant SaaS in EU / India / US enterprise sales - DPDP Significant Data Fiduciaries - GDPR processors (Article 28) - Healthtech storing patient data in cloud **Frameworks:** ISO/IEC 27018:2019; ISO/IEC 27001:2022 (parent); ISO/IEC 27701 (PIMS — synergistic); GDPR Article 28 + Article 32; DPDP Section 8 — Reasonable Security ### ISO/IEC 27701 — Privacy Information Management URL: https://www.macksofy.com/audit/iso-27701 Category: International Standard ISO 27701 extends ISO 27001 into a full Privacy Information Management System (PIMS). The only certification that demonstrates GDPR / DPDP / CCPA compliance via independent audit. Mandatory shortlist for enterprises selling to EU + India enterprise. DPOs need evidence the privacy program is operating, not just documented. ISO 27701 audit produces that evidence — and translates directly to GDPR Article 5(2) accountability and DPDP Section 8 reasonable-security obligations. Macksofy implements 27701 alongside ISO 27001 in a single 18–22 week engagement. **Applicability:** - Data Controllers + Processors processing significant PII - Multinationals with GDPR + DPDP obligations - BPO / KPO handling EU / Indian customer data - Healthtechs, fintechs, edtechs - B2B SaaS handling end-customer PII **Frameworks:** ISO/IEC 27701:2019; ISO/IEC 27001:2022 (parent); GDPR + DPDP mapping; ISO/IEC 29100 privacy framework; ISO/IEC 27018 (cloud PII complement) ### ISO/IEC 42001 — AI Management System URL: https://www.macksofy.com/audit/iso-42001 Category: International Standard ISO/IEC 42001 (2023) is the first international standard for AI Management Systems — covering governance, risk, lifecycle, transparency and stakeholder impact. Macksofy implements 42001 alongside the EU AI Act / DPDP / sectoral guidance for organisations shipping AI to enterprise. Boards, customers and regulators are asking 'how do you govern your AI?' Answers like 'we have an internal policy' no longer cut it. ISO 42001 audited certification — alongside DPDP / EU AI Act readiness — is fast becoming a procurement-stage requirement, especially for AI sold into BFSI, healthcare and government. **Applicability:** - AI / ML product companies + LLM application builders - Banks + insurers using AI for underwriting / claims - Healthtech using AI for diagnostics / triage - Edtech / hiring-tech using AI for evaluation - Cloud + SaaS embedding generative AI features **Frameworks:** ISO/IEC 42001:2023; EU AI Act (risk-tier mapping); NIST AI Risk Management Framework; Macksofy AI Risk Taxonomy; DPDP / GDPR — automated decision-making provisions ### SOC 2 Type 1 + Type 2 Audit URL: https://www.macksofy.com/audit/soc-2 Category: International Standard Full SOC 2 Type 1 + Type 2 readiness, internal audit and CPA-coordination. We implement the five Trust Services Criteria (Security, Availability, Confidentiality, Processing Integrity, Privacy) as a system that operates — and produces evidence — for the entire 12-month observation window. If your buyers are US enterprises, a SOC 2 Type 2 report is the single most-requested artefact in security questionnaires. Type 1 (point-in-time) gets you in the door; Type 2 (12-month operating effectiveness) closes deals. Macksofy delivers Type 1 in 6–8 weeks and prepares for Type 2 across the observation window — coordinated with a US CPA firm for the final attestation. **Applicability:** - B2B SaaS targeting US + global enterprise - BPO / KPO with US customer accounts - Cloud-hosted services handling customer data - Fintechs serving US institutional clients - Healthtech (paired with HIPAA) **Frameworks:** AICPA SOC 2 — 2017 Trust Services Criteria (revised); AICPA SOC 1 (financial reporting — separate engagement); ISO 27001 (mapped — 60% control overlap); PCI-DSS (where in scope) ### NIST Cybersecurity Framework Audit URL: https://www.macksofy.com/audit/nist-csf Category: International Standard Full NIST Cybersecurity Framework 2.0 maturity audit + roadmap. CSF 2.0 added the Govern function and tightened supply-chain controls. Macksofy uses CSF as the connective tissue across ISO 27001 / SOC 2 / RBI / SEBI / UAE regulators — one assessment, many outputs. NIST CSF is the lingua franca of cybersecurity maturity globally. Boards understand it; insurers price it; regulators reference it. CSF 2.0's new Govern function makes it directly auditable for board accountability. Macksofy's CSF audit produces both a maturity tier (Partial → Adaptive) and a tier-by-function map that drives investment decisions for the next 12–24 months. **Applicability:** - Boards seeking quantifiable cybersecurity maturity - Listed companies + Big-4 audit committees - Multinationals harmonising cyber across geographies - Insurers pricing cyber-insurance premiums - M&A diligence (target + acquirer) **Frameworks:** NIST Cybersecurity Framework 2.0 (2024); NIST SP 800-53 (control catalog); NIST SP 800-171 (controlled unclassified info — for US gov contractors); ISO 27001 (mapped); CIS Controls v8 (mapped) ### PCI-DSS v4.0 Compliance URL: https://www.macksofy.com/audit/pci-dss Category: Industry & Privacy Full PCI-DSS v4.0 readiness for merchants, processors, issuers, acquirers and service providers. Macksofy delivers ROC / SAQ readiness, network segmentation validation, ASV scanning and QSA coordination — all under one engagement. PCI-DSS v4.0 became fully mandatory in March 2025 — with 64 new or revised requirements including continuous discovery of vulnerabilities, customised approach options and tighter authentication. Non-compliant merchants face fines from card brands ($5K–$100K+/month) and increased liability shift. Macksofy is the only Indian / UAE firm combining CERT-In empanelment with PCI-DSS depth across QSA-coordination, ASV scans and segmentation tests. **Applicability:** - Merchants — Levels 1–4 (transaction-volume tiers) - Acquirers + Issuing banks - Payment processors + gateways - Service providers (storage / processing / transmitting CHD) - Mobile wallet operators **Frameworks:** PCI-DSS v4.0 (mandatory March 2025); PCI Software Security Framework (SSF); PCI Mobile Payment Acceptance Security; PCI 3DS Core Security Standard (where in scope) ### HIPAA Compliance Audit URL: https://www.macksofy.com/audit/hipaa Category: Industry & Privacy End-to-end HIPAA Privacy + Security + Breach Notification rule audits for covered entities and business associates. Includes US OCR enforcement readiness, BAA review, EHR / PHI security validation and HITRUST CSF mapping where required by US health-system customers. OCR HIPAA settlements crossed $135M cumulative; per-record penalty under the Omnibus Rule reaches $50,000. Indian + UAE healthtechs and BPOs serving US payers / providers are increasingly contractually required to demonstrate HIPAA — often via HITRUST. Macksofy bridges Indian operations with US HIPAA expectations end-to-end. **Applicability:** - US health systems' Indian / UAE BPO partners - Healthtech SaaS storing PHI for US customers - Telehealth + remote monitoring providers - Medical billing + RCM operations - Clinical research organisations (CROs) **Frameworks:** HIPAA Privacy Rule (45 CFR 164 Subpart E); HIPAA Security Rule (45 CFR 164 Subpart C); HIPAA Breach Notification Rule; HIPAA Omnibus Final Rule (2013); HITRUST CSF v11 (where required by health-system customers) ### GDPR Compliance Audit URL: https://www.macksofy.com/audit/gdpr Category: Industry & Privacy End-to-end GDPR readiness — Article 30 RoPA, Article 28 processor agreements, Article 32 security, Article 35 DPIAs, Article 27 EU representative service, plus DPO-as-a-Service. Designed for India + UAE businesses with EU customers, EU staff or EU monitoring. GDPR fines reached €4.48 billion cumulative by 2024, with several €1B+ single-entity penalties. Indian + UAE businesses targeting EU customers (or monitoring EU residents) fall under Article 3(2) extraterritorial reach. Macksofy delivers GDPR readiness alongside DPDP and ISO 27701 — a single program that satisfies both regimes. **Applicability:** - B2B SaaS with EU enterprise customers - E-commerce shipping to EU + UK - EdTech + healthtech with EU residents - BPO / KPO processing EU data on behalf of clients - Digital marketing / adtech tracking EU residents **Frameworks:** EU General Data Protection Regulation 2016/679; UK GDPR + Data Protection Act 2018; EU AI Act (AI overlap); ePrivacy Directive (cookies); ISO 27701 (PIMS) — synergistic certification ### RBI Digital Lending Guidelines Audit URL: https://www.macksofy.com/audit/rbi-digital-lending Category: Indian Regulatory End-to-end audit against the RBI Digital Lending Guidelines (DLG) — covering Regulated Entities, Lending Service Providers (LSPs), Digital Lending Apps (DLAs), the First Loss Default Guarantee (FLDG) framework, Key Facts Statement, cooling-off, customer redressal and data-localisation obligations. RBI's Digital Lending Guidelines (Sep 2022) and the subsequent FLDG circular (Jun 2023) re-wrote how every RE, fintech, NBFC and bank-LSP must operate. Disbursement and repayment must flow only between the borrower's and the RE's bank account — no LSP pass-through. The FLDG cap of 5% of the loan portfolio, DLA registration and Key Facts Statement requirements are now active enforcement triggers; RBI has already debarred multiple LSPs and barred new customer onboarding for non-compliant REs. Macksofy's audit produces the disbursement-vs-collection trail, FLDG ledger reconciliation and DLA artefact pack RBI inspections demand on day one. **Applicability:** - Scheduled Commercial Banks + Small Finance Banks running digital lending - NBFCs (Upper / Middle / Base layer) with own or partner-app lending - Lending Service Providers (LSPs) sourcing for an RE - Digital Lending App (DLA) operators — owned or white-labelled - FLDG-receiving REs + FLDG-providing LSPs - Payment Aggregators routing loan disbursement / repayment flows **Frameworks:** RBI Guidelines on Digital Lending (RBI/2022-23/111 dated 02-Sep-2022); RBI Default Loss Guarantee in Digital Lending (RBI/2023-24/41 dated 08-Jun-2023); Working Group on Digital Lending Report (Nov 2021) — annexed expectations; RBI Master Direction on Outsourcing of IT Services (2023); RBI Master Direction on IT Governance (2024) ### RBI IT Governance Master Direction Audit URL: https://www.macksofy.com/audit/rbi-it-governance Category: Indian Regulatory Audit against the RBI Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (effective 01-Apr-2024). Covers IT governance, IT services management, IT operations, information security, business continuity and IT audit obligations for banks, NBFCs, AIFIs and credit information companies. RBI Master Direction RBI/2023-24/107 dated 07-Nov-2023 (effective 01-Apr-2024) replaced two decades of fragmented IT-governance guidance with a single, prescriptive direction. The board IT Strategy Committee, IT Steering Committee, CISO independence, IT-services management lifecycle and IT-audit independence are now individually examinable. RBI inspections in 2024-25 have already cited dozens of REs for non-constitution of the IT Strategy Committee or CISO reporting through the CIO. Macksofy's audit produces the governance evidence, control-to-clause map and inspector walk-through pack required for a clean IT examination. **Applicability:** - Scheduled Commercial Banks (excl. RRBs and LABs as per applicability matrix) - Top, Upper and Middle Layer NBFCs per Scale-Based Regulation - All-India Financial Institutions (NABARD, NHB, EXIM, SIDBI, NaBFID) - Credit Information Companies regulated under CICRA - Boards looking to pre-empt the FY25-26 IT examination cycle - Group entities consolidated under banking-group IT governance **Frameworks:** RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices (RBI/2023-24/107 dated 07-Nov-2023); RBI Cyber Security Framework for Banks (Jun 2016, updated); RBI Master Direction on Outsourcing of IT Services (RBI/2023-24/102 dated 10-Apr-2023); RBI IT Examination Framework + Annexures; COBIT 2019 (mapped) + ISO 27001:2022 ### RBI IT Outsourcing Master Direction Audit URL: https://www.macksofy.com/audit/rbi-it-outsourcing Category: Indian Regulatory Full audit against the RBI Master Direction on Outsourcing of Information Technology Services (Apr 2023). Covers vendor due-diligence, outsourcing-risk management, cloud and offshoring controls, concentration risk, exit management, sub-contracting and BCP for outsourced operations. RBI Master Direction RBI/2023-24/102 dated 10-Apr-2023 (effective 01-Oct-2023) was the first dedicated direction on IT outsourcing for banks, NBFCs and AIFIs. It explicitly covers cloud services, offshoring, sub-contracting and intra-group arrangements — the very surfaces where post-pandemic RE estates have ballooned. RBI now requires a comprehensive outsourcing policy, Outsourcing Risk Management Committee oversight, concentration-risk monitoring and a tested exit strategy for every material outsourcing. Inspection findings under the MD have included missing right-to-audit clauses, untested exits and unmapped fourth-party concentration. Macksofy's audit produces the vendor-by-vendor evidence pack RBI inspections accept on first read. **Applicability:** - Scheduled Commercial Banks (excl. RRBs / LABs as per applicability) - Top, Upper and Middle Layer NBFCs per Scale-Based Regulation - All-India Financial Institutions - Credit Information Companies under CICRA - REs running material cloud workloads (IaaS / PaaS / SaaS) - REs with offshore captives or intra-group IT arrangements **Frameworks:** RBI Master Direction on Outsourcing of IT Services (RBI/2023-24/102 dated 10-Apr-2023); RBI Guidelines on Managing Risks in Outsourcing of Financial Services (2006, updated); RBI Master Direction on IT Governance (RBI/2023-24/107 dated 07-Nov-2023); RBI Storage of Payment System Data (Apr 2018); BCBS 239 + FSB outsourcing & third-party-risk principles ### SEBI MII Cybersecurity Framework Audit URL: https://www.macksofy.com/audit/sebi-mii Category: Indian Regulatory Cybersecurity and cyber-resilience audit for Market Infrastructure Institutions — Stock Exchanges, Clearing Corporations and Depositories. Covers the SEBI MII cyber framework, the CSCRF MII tier, capacity planning, cyber-resilience drills and cross-MII coordination obligations. MIIs sit at the apex of India's capital-market plumbing — a single outage propagates across every broker, AMC and investor. SEBI's MII cyber framework (originating with SEBI/HO/MIRSD/CIR/P/2018/147 and consolidated under CSCRF in 2024-25) mandates 99.99% availability, periodic capacity testing, red-team exercises, cross-MII cyber drills and quarterly SEBI reporting. Non-MII brokers run against the CSCRF Qualified / Mid-size / Small RE tiers — but MIIs face the strictest bar, with SEBI inspections, SOP-2 access reviews and ETP reporting layered on top. Macksofy's MII audit produces the cyber-resilience, capacity and cross-MII evidence pack SEBI's IT department reviews quarterly. **Applicability:** - Stock Exchanges (BSE, NSE, MSE, MCX, NCDEX, etc.) - Clearing Corporations (NSCCL, ICCL, MCCIL, NCCL, etc.) - Depositories (NSDL, CDSL) - MII subsidiaries running critical capital-market services - MII-style entities seeking IOSCO-aligned attestation - MII technology providers (where SEBI access extends) **Frameworks:** SEBI Cybersecurity & Cyber Resilience Framework (CSCRF) — MII tier (SEBI/HO/MIRSD/CRADT/CIR/P/2024/113 dated 20-Aug-2024 and successors); SEBI Cybersecurity & Cyber Resilience Framework for MIIs (SEBI/HO/MIRSD/CIR/P/2018/147); SEBI Business Continuity Plan & Disaster Recovery for MIIs; SEBI Outsourcing by Stock Exchanges, Clearing Corporations & Depositories; IOSCO Principles for Financial Market Infrastructures (PFMI) ### DPDP Significant Data Fiduciary Audit URL: https://www.macksofy.com/audit/dpdp-sdf Category: Indian Regulatory Independent Section 10 audit for Significant Data Fiduciaries under the DPDP Act 2023. Covers Data Protection Impact Assessment, independent data auditor obligations, DPO charter, algorithmic-risk review and periodic Section 10 attestation — complementary to the base DPDP audit, not a duplicate. Once the Central Government notifies an entity (or class of entities) as a Significant Data Fiduciary under Section 10 of the DPDP Act 2023, base-tier obligations escalate sharply — appointment of a Data Protection Officer based in India, an independent Data Auditor, Data Protection Impact Assessments, compliance audits and additional algorithmic-risk obligations for processing that involves risk to the rights of Data Principals. The Act frames the assessment and audit as periodic; the DPDP Rules, 2025 set the cadence, and the operative expectation is annual. That timing is the part organisations underestimate — Data Fiduciary obligations apply in substance around May 2027 under the Rules' eighteen-month phase, and an annual independent audit has to be complete by that date rather than commissioned on it, which puts the real readiness window inside 2026. Penalties under Schedule remain at up to ₹250 crore per breach. SDF notification is expected to land on large social-media intermediaries, e-commerce, edtech, healthcare platforms and AI-driven fiduciaries first. Macksofy's SDF audit is run by independent personnel, separately scoped from the base DPDP engagement, and produces a Section-10-grade attestation pack the Data Protection Board can rely on. **Applicability:** - Entities notified or likely to be notified as SDFs under Section 10 - Large e-commerce / social media intermediaries / edtech platforms - Healthcare + financial fiduciaries processing sensitive personal data at scale - AI / ML platforms processing personal data with rights-impact - Multi-jurisdictional Data Fiduciaries (GDPR + DPDP overlap) - Boards wanting voluntary SDF-grade attestation ahead of notification **Frameworks:** Section 10, Digital Personal Data Protection Act 2023; DPDP Rules, 2025 — DPO, Data Auditor and DPIA duties, phased to ~May 2027; Sectoral overlays — RBI / SEBI / IRDAI / TRAI; ISO 27701 (PIMS) — privacy-management cross-walk; ISO 42001 (AI management) — for algorithmic-risk obligations ### UAE PDPL Compliance Audit URL: https://www.macksofy.com/audit/uae-pdpl Category: GCC Regulatory Full UAE Federal Decree-Law No. 45 of 2021 readiness — applicability assessment, data inventory, lawful-basis register, data-subject rights, controller / processor obligations, breach notification to the UAE Data Office and cross-border transfer controls. Designed for entities established in the UAE mainland and those processing UAE-resident data from abroad. The UAE PDPL (Federal Decree-Law No. 45 of 2021) is the federal-level privacy regime that sits alongside the sectoral DIFC DP Law and ADGM DP Regulations. The Data Office (under the UAE Cybersecurity Council) supervises enforcement and the implementing Executive Regulations finalise penalty quantum, breach windows and DPO triggers. Boards that treat PDPL as a policy refresh miss the heavier obligations — cross-border transfer impact assessments, controller-to-processor contracting and the Data Office's evidence expectations during a complaint. **Applicability:** - Entities established in the UAE mainland (outside DIFC / ADGM free zones) - Controllers and processors handling UAE-resident personal data from outside the UAE - Healthcare, banking, telecom, e-commerce, edtech, HR services processing UAE data - Multinationals running shared services or BPO in the UAE for global clients - Cloud / SaaS providers with UAE data-residency commitments to customers **Frameworks:** UAE Federal Decree-Law No. 45 of 2021 — Personal Data Protection; Executive Regulations (latest published version); UAE Data Office decisions and guidance; DIFC Data Protection Law No. 5 of 2020 (free-zone overlap); ADGM Data Protection Regulations 2021 (free-zone overlap) ### UAE Information Assurance (NESA / IAS) Audit URL: https://www.macksofy.com/audit/nesa-uae-ias Category: GCC Regulatory Full UAE Information Assurance Standards audit — applicability and tiering, 60 management + 128 technical control assessment, sector-overlay alignment and submission pack for the Cyber Security Council / TDRA. Covers government entities, semi-government and Critical Information Infrastructure operators across energy, finance, telecom, transport and health. The framework originally published by the National Electronic Security Authority (NESA) is now maintained under the UAE Cyber Security Council with TDRA as the operational regulator — but the structure remains the IA Standards Tier-1 through Tier-4, with controls graded by sector criticality. UAE government entities, CII operators and their major suppliers are expected to evidence compliance as part of TDRA / sector-regulator audit cycles. Macksofy's IAS audit is sequenced the way the regulator reads it: priority controls, risk-based tier selection and technical evidence rather than narrative. **Applicability:** - UAE federal and emirate-level government entities - Critical Information Infrastructure operators (energy, finance, telecom, transport, health) - Semi-government entities and government-owned enterprises - Strategic suppliers and managed-service providers to government / CII - Large UAE enterprises adopting IAS voluntarily as a national baseline - Cloud + data-centre operators hosting government workloads **Frameworks:** UAE Information Assurance Standards (latest published version); UAE Information Assurance Regulation; Cyber Security Council National Cybersecurity Strategy; TDRA sector cybersecurity directives; Critical Information Infrastructure Protection Policy ### ADHICS Compliance Audit URL: https://www.macksofy.com/audit/adhics Category: GCC Regulatory End-to-end ADHICS (Abu Dhabi Healthcare Information and Cyber Security) Standard audit — Department of Health Abu Dhabi (DoH) controls across governance, asset management, HR, communications, third-party, incident response and health-information exchange. Designed for hospitals, clinics, insurers, labs, pharmacies and HealthTech integrators connected to Malaffi. ADHICS is the Department of Health Abu Dhabi's mandatory information and cyber-security standard for all licensed healthcare entities in the emirate. Non-compliance can trigger licence-condition action, exclusion from the Malaffi health-information exchange and reputational risk in a sector where DoH publishes facility ratings. Macksofy's ADHICS audit walks the control families end-to-end with the evidence DoH inspectors actually sample — control statements, technical artefacts and a submission pack mapped to the standard. **Applicability:** - Hospitals, clinics and day-surgery centres licensed by DoH - Diagnostic labs, imaging centres and pharmacies in Abu Dhabi - Health insurance / TPA entities operating in the emirate - Malaffi-connected providers and HealthTech integrators - Telemedicine and digital-health platforms serving Abu Dhabi residents - Suppliers handling protected health information for DoH-licensed entities **Frameworks:** ADHICS Standard (latest published version, Department of Health Abu Dhabi); DoH licensing standards and circulars; Malaffi Health Information Exchange security requirements; UAE Federal PDPL (Decree-Law 45 of 2021); UAE Information Assurance Standards ### Dubai DESC ISR Audit URL: https://www.macksofy.com/audit/desc-isr Category: GCC Regulatory Full Dubai Electronic Security Centre Information Security Regulation audit — applicability mapping, control families across governance, asset, HR, access, operations, communications, acquisition, incident management and compliance. Sequenced for the DESC audit cycle and the Dubai Government Information Security Maturity model. The Dubai Electronic Security Centre's Information Security Regulation (DESC ISR v1.0 in 2017, updated to v2.0 in 2023) is the mandatory baseline for Dubai government entities and a growing set of sector-specific operators. DESC operates a regular audit cycle that grades entities against the ISR control set and the broader Dubai Cyber Security Strategy maturity model. Macksofy's DESC ISR audit is run the way DESC examiners read it — control mapping, sampled evidence and a clean closure pack. **Applicability:** - Dubai government entities (departments, authorities, councils) - Government-owned enterprises and free-zone authorities in Dubai - Sector-specific operators designated by DESC (utilities, transport, real estate, smart-city) - Strategic suppliers and managed-service providers to Dubai government - Smart-Dubai and digital-government platform operators - Major private-sector entities adopting ISR voluntarily as the emirate baseline **Frameworks:** DESC Information Security Regulation v1.0 (2017) and v2.0 (2023); Dubai Cyber Security Strategy; Dubai Government Information Security Maturity model; Smart Dubai / Digital Dubai security directives; UAE Information Assurance Standards (overlay) ### SAMA Cyber Security Framework Audit URL: https://www.macksofy.com/audit/sama-csf Category: GCC Regulatory Full SAMA Cyber Security Framework audit for Saudi banks, insurers, finance companies and payment service providers under the Saudi central bank. Covers SAMA CSF 1.0 (May 2017) and subsequent CSF updates, IT-governance and outsourcing circulars, with maturity scoring against the four-tier SAMA scale. The SAMA Cyber Security Framework (1.0, May 2017) and its later updates set the cybersecurity expectations for all entities under SABB / SAMA — banks, insurers, finance companies and payment service providers — graded on a four-tier maturity scale. SAMA inspections evaluate evidence against each control, and the central bank uses the maturity score as input to supervisory ratings. Macksofy's SAMA CSF audit is sequenced the way SAMA inspectors read it — control statements, sampled evidence, maturity score and a clean closure plan. **Applicability:** - Saudi licensed banks (local and foreign branches) - Insurance and reinsurance companies under SAMA - Finance companies and consumer-credit entities - Payment service providers and Saudi Payments participants - Major third-party suppliers to SAMA-regulated entities - Fintechs licensed under SAMA's Regulatory Sandbox graduating to full licence **Frameworks:** SAMA Cyber Security Framework 1.0 (May 2017); SAMA IT Governance + Outsourcing circulars (latest published version); SAMA Business Continuity Management Framework; SAMA Counter-Fraud Framework; SAMA Open Banking framework (where applicable) ### CBUAE Cyber & Digital Banking Compliance URL: https://www.macksofy.com/audit/cbuae-cyber Category: GCC Regulatory Full Central Bank of UAE cyber + digital-banking compliance program — consumer-protection cyber expectations, digital-banking licence cyber clauses, IT operations + outsourcing regulations, retail-payment KYC tied to cyber and SWIFT customer-security alignment. Designed for UAE banks, finance companies, digital banks, exchange houses, payment service providers and stored-value-facility issuers. The Central Bank of UAE has tightened its cyber, IT-governance, outsourcing and consumer-protection regulations through successive circulars — covering banks, finance companies, digital banks, payment service providers, stored-value-facility issuers and exchange houses. Recent attention to mobile-banking fraud, retail-payment KYC and outsourcing concentration risk means CBUAE inspections probe well beyond cyber-policy text into operational evidence. Macksofy's CBUAE program walks each regulation end-to-end and lands a submission pack inspectors can read in days. **Applicability:** - UAE licensed banks (national + foreign branches) - Finance companies and consumer-credit entities under CBUAE - Digital-bank licence holders and licensee applicants - Stored-Value-Facility issuers and Retail Payment Services licensees - Exchange houses and remittance operators - Major third-party suppliers and cloud providers to CBUAE-regulated entities **Frameworks:** CBUAE Consumer Protection Regulation + Standards (latest published version); CBUAE Retail Payment Services and Card Schemes Regulation; CBUAE Stored Value Facilities Regulation; CBUAE Outsourcing Regulation for Banks; CBUAE Risk Management Standards (IT, operational, cyber) ### Saudi NCA ECC-2:2024 Audit URL: https://www.macksofy.com/audit/nca-ecc-2 Category: GCC Regulatory Full NCA Essential Cybersecurity Controls v2 (ECC-2:2024) audit — applicability scoping, control-by-control assessment across governance, defence, resilience and third-party / cloud domains. Designed for government entities, critical national infrastructure operators and private-sector organisations in the Kingdom of Saudi Arabia. The National Cybersecurity Authority's Essential Cybersecurity Controls v2 (ECC-2:2024) is the baseline cybersecurity standard for any organisation operating in the Kingdom of Saudi Arabia — government, critical national infrastructure and private sector. NCA performs compliance assessments and references ECC compliance in its national cybersecurity reporting; sector regulators (SAMA, CMA, CITC, Ministry of Health) layer their own controls on top. Macksofy's NCA ECC-2 audit walks the four domains end-to-end and produces the assessment artefacts NCA samples first. **Applicability:** - Saudi government entities (ministries, authorities, government-owned companies) - Critical national infrastructure operators (energy, water, transport, finance, health) - Private-sector organisations operating in KSA (any size) - Cloud and digital-platform providers serving KSA customers - Suppliers and managed-service providers to NCA-regulated entities - Multinationals with Saudi operations or KSA data-residency commitments **Frameworks:** NCA Essential Cybersecurity Controls v2 (ECC-2:2024); NCA Critical Systems Cybersecurity Controls (CSCC); NCA Cloud Cybersecurity Controls (CCC); NCA Telework Cybersecurity Controls; Saudi PDPL (Personal Data Protection Law) ### WASA — Web Application Security Assessment URL: https://www.macksofy.com/audit/wasa-audit Category: Indian Regulatory WASA is a structured, framework-mapped evaluation of how a web application withstands real-world attack behavior across architecture, business logic, APIs, session handling and authentication. In India's digital-health ecosystem, a WASA report from a CERT-In empanelled auditor is the security evidence ABDM (Ayushman Bharat Digital Mission) integrators submit to the National Health Authority on the way to milestone certification and production access — the artefact often called a web application security audit or 'safe to host' certificate. Macksofy is CERT-In empanelled, and delivers WASA reports that drop directly into ABDM submissions, enterprise procurement, RBI / SEBI / DPDP filings, and SOC 2 / ISO 27001 evidence packs — without the rework most pentest PDFs trigger. A modern enterprise buyer (and an increasing share of Indian BFSI auditors) doesn't want a raw pentest PDF. They want a Web Application Security Assessment that proves design integrity, maps every finding to a recognised control framework (OWASP Top 10, ASVS V4.0, SANS CWE Top 25, ISO 27001 Annex A, PCI DSS), and surfaces compound risk — the chained low-severity flaws that combine into account takeover, lateral movement or tenant-bleed. The 2025 State of Continuous Pentesting report attributes 96% of vulnerabilities in the last 12 months to web applications, and most of them are not zero-days; they are weak session controls, exposed API metadata and misconfigured headers that look minor in isolation but combine into compound exposure. Macksofy's WASA programme is purpose-built for that reality, with dual-layered AI-augmented + manual testing, threat-modelled scoping, and RFP-ready reporting that satisfies enterprise InfoSec, CERT-In format submission and the RBI Master Direction on IT Governance (November 2023) Annex-1 evidence the inspector reads. The same WASA discipline is what India's digital-health builders need for a different reason: an application that integrates with ABDM — creating or linking ABHA numbers, acting as a Health Information Provider or User, or running consent-manager flows — is expected to produce a web application security audit certificate from a CERT-In empanelled auditor before the National Health Authority grants milestone certification and production access. NHA publishes those certificates for approved integrators, and the scope they cover is WASA scope: authentication, authorisation, session handling, encryption in transit and at rest, and the security of the M1 / M2 / M3 API surface itself. Macksofy holds the CERT-In empanelment that requirement turns on, so a HealthTech team does not have to run one assessment for the regulator and a second for its enterprise customers. **Applicability:** - B2B SaaS shipping enterprise security questionnaires (CAIQ, SIG, Shared Assessments) - Fintech / lending / payment-aggregator licensees needing RBI-format AppSec evidence - ABDM / ABHA integrators needing a CERT-In empanelled audit certificate for M1 / M2 / M3 sign-off - HMIS, EMR, PHR, HIP / HIU and consent-manager builds on the ABDM sandbox-to-production path — hospitals, diagnostics chains and telehealth platforms seeking NHA production access - Healthtech / US-PHI GCC operators needing HIPAA Security Rule §164.308–312 evidence - BPO / KPO + IT-services majors with customer-third-party-AppSec-standard obligations **Frameworks:** OWASP Top 10 (2021) + API Security Top 10 (2023); OWASP ASVS V4.0 (Application Security Verification Standard); SANS CWE Top 25; NIST SP 800-53 (IA-5, SC-7) + NIST SP 800-115 v2 testing methodology; ISO/IEC 27001:2022 Annex A.5, A.8 + ISO/IEC 27002:2022 ### NCIIPC Critical Information Infrastructure Audit URL: https://www.macksofy.com/audit/nciipc-cii-audit Category: Indian Regulatory Macksofy delivers NCIIPC-aligned audits for entities operating Critical Information Infrastructure (CII) — Government, PSU, banking, power, telecom, transport and strategic-public-enterprise assets notified under IT Act §70. CERT-In empanelled, NCIIPC-framework mapped, inspection-evidence ready. If your organisation operates assets that have been notified as Critical Information Infrastructure under IT Act §70, you are subject to NCIIPC oversight. The National Critical Information Infrastructure Protection Centre publishes baseline-security guidelines, mandates incident reporting timelines, and conducts inspections. A non-compliant CII finding can result in operational restrictions, public-record sanction or — for designated essential services — Cabinet-level attention. Most operators have never been audited in the NCIIPC format specifically; an ISO 27001 or RBI CSF audit does not substitute. Macksofy walks an estate that has only ever been audited in another format through the gap-closure required to clear an NCIIPC inspection without rework. **Applicability:** - Government IT systems notified as CII under IT Act §70 - Public-sector banks (notified CII assets) - Power & energy sector — generation, transmission, distribution (notified CII) - Telecom & internet infrastructure operators (notified CII) - Transport — railways, airports, ports (notified CII) - Strategic & public enterprise IT systems (notified CII) **Frameworks:** NCIIPC Guidelines for Protection of CII (current revision); IT Act 2000 §70 + Rules 2013; MeitY Information Security Policy; CERT-In Empanelled Auditor Scope of Work; ISO 27001:2022 (Annex A crosswalk) ## Training & Certifications ### Certified Ethical Hacker (CEH v13) — AI-Powered URL: https://www.macksofy.com/training/ceh Code: CEH v13 · Level: Foundation · Vendor: EC-Council Price (INR): 50,000 CEH v13 is the world's most recognized ethical-hacking certification — and the first version to integrate AI across every attack domain. If you are looking for an ethical hacking course in Mumbai, this is it, delivered the way it was meant to be taught: instructor-led, fully hands-on, in a Mumbai-classroom + live-online format, with mentorship that runs until you clear the exam. **Outcomes:** - Run end-to-end recon, scanning and enumeration on real targets - Exploit OWASP Top 10 web vulnerabilities and modern privilege escalation - Use AI-driven offense (LLMs, prompt injection, AI-assisted recon) covered in v13 - Pass the EC-Council CEH v13 (312-50) exam on the first attempt ### CEH Practical — 6-Hour Lab Exam (312-50) URL: https://www.macksofy.com/training/ceh-practical Code: CEH Practical · Level: Foundation · Vendor: EC-Council Price (INR): 30,000 CEH Practical is EC-Council's hands-on counterpart to CEH — a 6-hour live exam against 20 challenges in EC-Council's exam range. Macksofy's 3-day lab marathon prepares you with realistic, exam-grade scenarios in our own hands-on lab environment. **Outcomes:** - Solve real-world hacking challenges in a live cyber range - Build muscle memory for hands-on assessments - Earn the CEH Master designation when combined with CEH ### Computer Hacking Forensic Investigator (CHFI v11) URL: https://www.macksofy.com/training/chfi Code: CHFI v11 · Level: Intermediate · Vendor: EC-Council Price (INR): 45,000 CHFI v11 covers digital forensics from disk and memory through mobile, cloud and malware. Macksofy delivers it with industry-standard tools (Autopsy, FTK, Volatility) on real case data — including India-context investigations we've worked on. **Outcomes:** - Conduct forensically sound investigations on disk, memory and network - Perform mobile device and cloud forensics - Produce expert-witness-grade reports - Pass the CHFI v11 (312-49) exam ### Certified Threat Intelligence Analyst (CTIA) URL: https://www.macksofy.com/training/ctia Code: CTIA · Level: Intermediate · Vendor: EC-Council Price (INR): 35,000 CTIA teaches the full intelligence lifecycle — collection, processing, analysis, dissemination — so you can produce intel that actually changes how your SOC defends. Macksofy's lab includes MISP, OpenCTI and real-world threat feeds. **Outcomes:** - Plan and execute a threat intelligence program - Collect, analyze and disseminate actionable intel - Use MISP, OpenCTI and commercial feeds effectively - Pass the CTIA (312-85) exam ### Certified SOC Analyst (CSA) URL: https://www.macksofy.com/training/csa Code: CSA · Level: Foundation · Vendor: EC-Council Price (INR): 35,000 EC-Council's Certified SOC Analyst is the entry-level credential for blue-team careers — the badge most BFSI SOCs look for on a fresher's CV. Macksofy delivers it instructor-led, with hands-on Splunk + ELK lab time and incident-response playbooks lifted straight from our own engagements. **Outcomes:** - Operate a SIEM (Splunk / ELK) for log analysis and alerting - Triage and escalate security incidents using MITRE ATT&CK - Build threat intelligence pipelines - Pass the EC-Council CSA (312-39) exam ### Certified Penetration Testing Professional (CPENT) URL: https://www.macksofy.com/training/cpent Code: CPENT · Level: Professional · Vendor: EC-Council Price (INR): 40,000 CPENT is EC-Council's flagship offensive certification — fully practical, with a 24-hour exam against a real corporate network. Macksofy's CPENT bootcamp is led by LPT-certified instructors with bug-bounty backgrounds. **Outcomes:** - Pivot through segmented networks with VPN tunneling - Exploit IoT, OT and binary-level vulnerabilities - Write working binary exploits and bypass DEP/ASLR - Earn CPENT (and LPT Master at 90%+) ### OSCC — CyberCore Security Essentials (SEC-100) URL: https://www.macksofy.com/training/sec-100-cybercore Code: SEC-100 · Level: Foundation · Vendor: OffSec Price (INR): 60,000 SEC-100 (OSCC) is OffSec's foundational certification covering the core knowledge every cybersecurity professional needs. The natural starting point before specializing into OSCP, OSWE, OSDA or other tracks. **Outcomes:** - Master networking, Linux, scripting and Windows fundamentals - Understand offensive + defensive security pillars - Be ready for OffSec specialization tracks (OSCP, OSWE, OSDA, etc.) - Pass the OSCC certification exam ### OSCP — Penetration Testing with Kali Linux (PEN-200) URL: https://www.macksofy.com/training/oscp Code: OSCP / PEN-200 · Level: Professional · Vendor: OffSec Price (INR): 1,45,000 OSCP is the gold standard for hands-on penetration testing — a 24-hour live exam against a real network plus a professional report. Macksofy runs a 60+ hour instructor-led bootcamp alongside OffSec's official PEN-200 curriculum, with mentor support that continues until you pass. **Outcomes:** - Compromise standalone Windows, Linux and Active Directory machines under exam pressure - Develop and modify public exploits, write Bash/Python tooling on the fly - Pivot through segmented networks and execute lateral movement - Write a 24-hour professional pen-test report that meets OffSec's standards - Earn OSCP — the credential that opens senior pen-test doors in BFSI, Big Tech and consulting ### OSEP — Evasion Techniques & Breaching Defenses (PEN-300) URL: https://www.macksofy.com/training/osep Code: OSEP / PEN-300 · Level: Professional · Vendor: OffSec Price (INR): 1,45,000 OSEP is the natural step after OSCP for aspiring red-team operators. Process injection, custom shellcode, EDR bypass, advanced AD exploitation — Macksofy's bootcamp uses real CrowdStrike, SentinelOne and Defender environments. **Outcomes:** - Build custom payloads that bypass commercial EDRs - Execute process injection, hollowing and reflective DLL loading - Run advanced Active Directory attack chains (RBCD, Shadow Credentials) - Pass the 48-hour OSEP exam ### OSWE — Advanced Web Attacks & Exploitation (WEB-300) URL: https://www.macksofy.com/training/oswe Code: OSWE / WEB-300 · Level: Professional · Vendor: OffSec Price (INR): 1,45,000 OSWE is the elite web-application credential. You read source code (PHP, Java, Node.js, .NET) to find authentication bypasses, deserialization, type juggling — then chain them into RCEs. Macksofy's bootcamp covers OSWE-specific labs plus modern web research. **Outcomes:** - Read source code to find auth bypass, deserialization, RCE - Chain logic vulnerabilities for full system compromise - Pass the 48-hour OSWE exam ### OSWA — Foundational Web Application Assessments (WEB-200) URL: https://www.macksofy.com/training/oswa Code: OSWA / WEB-200 · Level: Intermediate · Vendor: OffSec Price (INR): 1,45,000 OSWA bridges the gap between CEH-level web knowledge and the elite OSWE. Black-box testing of realistic web apps with all major attack classes plus modern web vulnerabilities. **Outcomes:** - Conduct end-to-end web application assessments - Exploit OWASP Top 10 plus SSRF, IDOR, JWT issues - Pass the 24-hour OSWA exam ### OSWP — Foundational Wireless Network Attacks (PEN-210) URL: https://www.macksofy.com/training/oswp Code: OSWP / PEN-210 · Level: Intermediate · Vendor: OffSec Price (INR): 1,45,000 PEN-210 / OSWP is the standard wireless-pentest credential. WPA2/3 cracking, evil twins, enterprise WPA-EAP attacks. Macksofy provides Alfa hardware kits for in-class students. **Outcomes:** - Crack WEP, WPA, WPA2 and WPA3 networks - Conduct evil-twin and enterprise WPA-EAP attacks - Pass the 4-hour OSWP exam ### SOC-200 — Foundational Defensive Operations & Analysis (OSDA) URL: https://www.macksofy.com/training/osda Code: SOC-200 / OSDA · Level: Intermediate · Vendor: OffSec Price (INR): 1,45,000 SOC-200 trains defenders the way OSCP trains attackers — fully hands-on, with a 24-hour practical exam. Macksofy's bootcamp covers Splunk, Elastic, Sysmon and EDR triage in real-world scenarios. **Outcomes:** - Detect attacker TTPs across Windows, Linux and AD - Use EDRs and SIEMs to investigate live incidents - Pass the 24-hour OSDA (SOC-200) exam ### OSED — Windows User Mode Exploit Development (EXP-301) URL: https://www.macksofy.com/training/osed Code: OSED / EXP-301 · Level: Professional · Vendor: OffSec Price (INR): 1,45,000 OSED is the entry point to OffSec's exploit-development track. Reverse engineer real Windows binaries, find vulnerabilities, build working exploits with custom shellcode and ROP chains. **Outcomes:** - Reverse Windows binaries with IDA / x64dbg - Identify exploitable bugs (BoF, format strings, UAF) - Build custom shellcode and ROP chains - Pass the 48-hour OSED exam ### OSMR — Advanced macOS Control Bypasses (EXP-312) URL: https://www.macksofy.com/training/osmr Code: OSMR / EXP-312 · Level: Professional · Vendor: OffSec Price (INR): 1,45,000 OSMR is the only OffSec course dedicated to macOS. Covers TCC bypass, Gatekeeper evasion, kernel-level injection — niche but high-demand skills as macOS adoption grows in enterprise fleets. **Outcomes:** - Bypass macOS security controls (TCC, Gatekeeper, XProtect) - Develop macOS-specific payloads and persistence - Pass the 48-hour OSMR exam ### CompTIA Cybersecurity Analyst (CySA+) URL: https://www.macksofy.com/training/cysa-plus Code: CySA+ (CS0-003) · Level: Intermediate · Vendor: CompTIA Price (INR): 40,000 CySA+ is CompTIA's intermediate cybersecurity analyst credential — heavily focused on threat hunting, SOC operations and software vulnerability management. DoD 8570/8140 compliant. Recognized worldwide. **Outcomes:** - Apply behavioural analytics for threat detection - Manage software vulnerabilities and patching - Respond to security incidents - Pass the CompTIA CySA+ exam (CS0-003) ### CompTIA Linux+ URL: https://www.macksofy.com/training/linux-plus Code: Linux+ (XK0-005) · Level: Foundation · Vendor: CompTIA Price (INR): 40,000 CompTIA Linux+ covers system management, security, scripting and troubleshooting — distribution-neutral. A strong foundation for security and DevOps careers in India + UAE. **Outcomes:** - Configure and manage Linux systems - Apply Linux security best practices - Troubleshoot and write shell scripts - Pass the CompTIA Linux+ exam (XK0-005) ### CompTIA Server+ URL: https://www.macksofy.com/training/server-plus Code: Server+ (SK0-005) · Level: Foundation · Vendor: CompTIA Price (INR): 40,000 Server+ is CompTIA's flagship server-admin certification covering hardware, virtualization, security and disaster recovery across physical, virtual and cloud servers. **Outcomes:** - Install, configure and maintain servers - Implement virtualization and storage - Apply server security and DR plans - Pass the CompTIA Server+ exam (SK0-005) ### Macksofy SOC Analyst — Career Track (8 weeks) URL: https://www.macksofy.com/training/soc-analyst Code: SOC-A (Macksofy) · Level: Foundation · Vendor: Macksofy Price (INR): 45,000 Macksofy's career-grade SOC Analyst track. Job-ready in 8 weeks with hands-on Wazuh + ELK + Splunk, MITRE ATT&CK detection engineering, real incident response playbooks built from our own engagements. Many students take this alongside CSA / SOC-200 for credentialing. **Outcomes:** - Operate a SIEM (Wazuh, ELK, Splunk) end-to-end - Write Sigma detection rules mapped to MITRE ATT&CK - Triage incidents using the SANS / NIST IR lifecycle - Conduct basic threat hunting with hypothesis-driven searches - Be ready for SOC L1/L2 interviews at MSSPs, banks, large enterprises ### Web Application Security Specialist — Career Track URL: https://www.macksofy.com/training/web-application-security Code: WAS-PRO (Macksofy) · Level: Intermediate · Vendor: Macksofy Price (INR): 65,000 Become a senior-grade web pen-tester. We go beyond CEH-level OWASP into business-logic flaws, authentication patterns, modern SPAs, GraphQL, OAuth attacks and source-code review — all the work that pays AppSec engineers the highest salaries in Indian cybersecurity. Pairs naturally with OSWA / OSWE for credentialing. **Outcomes:** - Discover and exploit BOLA, IDOR, mass-assignment and access-control flaws - Pwn modern stacks: SPAs, GraphQL, gRPC, OAuth2/OIDC flows - Read source code (Java, Node, PHP) to find vulnerabilities white-box - Write developer-friendly remediation that engineering teams actually accept - Be ready for Web App Pen-Tester / AppSec Engineer roles (₹15-25 LPA range) ### Corporate Cybersecurity Training (Customized) URL: https://www.macksofy.com/training/corporate-training Code: CORP · Level: Foundation · Vendor: Macksofy Off-the-shelf training doesn't move the needle for security teams that already work in production. Macksofy designs corporate programs around your tech stack, your threat model and your maturity level — delivered by working pen-testers, not academic instructors. **Outcomes:** - Customized curriculum mapped to your threat model and tech stack - Hands-on labs in your real environment (or Macksofy's cyber range) - Pre / post assessments to measurably move the needle - Recorded sessions and lab artifacts for ongoing use ## Industries Served ### Banking, Financial Services & Insurance (BFSI) URL: https://www.macksofy.com/industries/bfsi Cybersecurity for India's most-regulated industry. Macksofy is built for BFSI cybersecurity. CERT-In empanelled, with senior consultants who have stood inside RBI inspections, SEBI half-yearly audits, IRDAI cyber crisis drills and Central Bank of UAE submissions. 60%+ of our engagements are with banks, NBFCs, brokers, AMCs, insurers and payment aggregators. ### Healthcare & Life Sciences URL: https://www.macksofy.com/industries/healthcare Cybersecurity for hospitals, payors and HealthTech. Macksofy delivers cybersecurity audits, VAPT and DFIR for hospitals, diagnostics chains, health-insurance TPAs, telehealth platforms and HealthTech SaaS — across the ADHICS regime in Abu Dhabi, the NDHM/ABDM in India, and HIPAA-equivalent controls for clients serving US patient data. ### SaaS & Fintech URL: https://www.macksofy.com/industries/saas-fintech Cybersecurity for product-led SaaS and Indian fintech. Macksofy delivers the security programme product-led SaaS and fintech need to close enterprise deals — SOC 2 Type II + ISO 27001 in a single pass, DPDPA-compliant data programmes, continuous VAPT mapped to enterprise customer security questionnaires (Microsoft SSPA, Google SAQ, Salesforce AppExchange). ### Manufacturing & Operational Technology URL: https://www.macksofy.com/industries/manufacturing-ot Cybersecurity for the factory floor — without breaking the line. Macksofy delivers OT/ICS security assessments, IT-OT segmentation reviews and IEC 62443-aligned programmes for India's manufacturing, automotive, pharma, oil & gas and discrete-process clients. Assessments designed to find what attackers will — without disrupting production. ### Government & Public Sector URL: https://www.macksofy.com/industries/government-psu Cybersecurity for government, PSU and citizen-facing platforms. Macksofy is CERT-In empanelled and delivers cybersecurity audits, VAPT and DFIR for state-government departments, PSUs, e-governance platforms, smart-city operators and citizen-facing services. Audit format matches MeitY + CERT-In submission requirements directly. ### Energy, Power & Utilities (Critical Infrastructure) URL: https://www.macksofy.com/industries/energy-utilities OT-aware cybersecurity for critical infrastructure. Power generation, transmission and distribution, load-despatch, oil & gas, renewables and water utilities are India's most consequential cyber targets — and most are designated Critical Information Infrastructure. Macksofy secures the IT and the OT, safety-first, mapped to NCIIPC, the CEA Power-Sector guidelines and IEC 62443. ### Insurance — Life, General, Health & Reinsurance URL: https://www.macksofy.com/industries/insurance Cybersecurity built for insurers and insurtech. Insurers sit on the most sensitive personal data outside healthcare — health records, financials, KYC and claims — across sprawling agent, broker, web-aggregator and insurtech ecosystems. Macksofy delivers IRDAI-aligned cybersecurity audits, VAPT and Managed SOC for life, general, health and reinsurance carriers. ## Delivery Locations ### Mumbai URL: https://www.macksofy.com/locations/mumbai Mumbai's regulator-grade cybersecurity firm. Macksofy Technologies is headquartered at SRA Commercial Tower, Bandra Kurla Complex (BKC), Mumbai. CERT-In empanelled. Trusted by RBI-regulated banks, SEBI-regulated brokers, IRDAI-regulated insurers, listed BFSI giants and fast-growing fintechs across Mumbai, Thane, Navi Mumbai and the wider MMR. ### Delhi NCR URL: https://www.macksofy.com/locations/delhi Delhi NCR cybersecurity, regulator-format. Macksofy delivers CERT-In empanelled audits, regulator-grade pentests and EC-Council ATC training plus hands-on OSCP / OSEP / OSWE exam-prep bootcamps for Delhi NCR's government bodies, public sector banks, fintechs in Gurugram and Noida, and IT services majors. Senior consultants travel from Mumbai BKC for onsite engagements; most ongoing programs run remotely. ### Bengaluru URL: https://www.macksofy.com/locations/bengaluru Bengaluru cybersecurity for product, SaaS and GCC. Macksofy serves Bengaluru's product, SaaS and global capability centre (GCC) ecosystem with manual-first VAPT, OSCP/OSWE-level pentesting, ISO 27001 / SOC 2 implementations and OSCP / CRTO training cohorts. CERT-In empanelled. Same-week onsite via senior consultants from Mumbai. ### Hyderabad URL: https://www.macksofy.com/locations/hyderabad South India cybersecurity, anchored in Hyderabad. Macksofy's Hyderabad regional hub serves South India — Telangana, Andhra Pradesh, Karnataka, Tamil Nadu and Kerala — from HITEC City. CERT-In empanelled. Pharma, BFSI, GCC and government engagements with onsite consultants and Mumbai-supported reporting. ### Chennai URL: https://www.macksofy.com/locations/chennai Chennai cybersecurity for BFSI, auto and IT services. Macksofy delivers regulator-grade VAPT, audits and training to Chennai's BFSI majors, automotive manufacturers, IT services giants and SaaS unicorns. CERT-In empanelled. Senior consultants travel from Mumbai BKC and Hyderabad HITEC for onsite engagements. ### Pune URL: https://www.macksofy.com/locations/pune Pune cybersecurity for tech, auto and manufacturing. Macksofy's Pune practice is anchored from our Mumbai BKC headquarters — 3 hours by road. We deliver CERT-In empanelled VAPT, audits and training across Pune's IT services majors, manufacturing belt, edtech and BPO ecosystem. ### Noida URL: https://www.macksofy.com/locations/noida Noida cybersecurity for the NCR tech and BFSI belt. Macksofy delivers CERT-In empanelled VAPT, regulator-format audits and corporate training to Noida and Greater Noida — from Sector 18 fintechs and the Yotta data centre cluster to NCR’s largest IT-services GCCs. ### Gurugram URL: https://www.macksofy.com/locations/gurugram Gurugram cybersecurity for the BFSI and GCC corridor. Cyber City, Udyog Vihar, Golf Course Road, Sohna and DLF Phases 1–5 — Macksofy delivers CERT-In empanelled VAPT, RBI / IRDAI audits and adversary simulation engagements for the densest BFSI and global-capability-centre cluster in NCR. ### Ahmedabad URL: https://www.macksofy.com/locations/ahmedabad Ahmedabad + GIFT City cybersecurity for IFSC-licensed BFSI. Macksofy services Ahmedabad and GIFT City Gandhinagar — India’s only operational International Financial Services Centre — with CERT-In empanelled VAPT, IFSCA-aligned cyber audits and DPDP readiness for India’s fastest-growing offshore finance and reinsurance cluster. ### UAE URL: https://www.macksofy.com/locations/uae UAE cybersecurity — federal + Dubai + Abu Dhabi regulator coverage. Macksofy delivers cybersecurity audits, VAPT and DPDP / UAE PDPL programmes across the Emirates — UAE Information Assurance (IA) framework, ADHICS healthcare, Dubai DESC ISR and Federal PDPL. CERT-In + ISO 27001 lead-auditor heritage adapted to UAE regulator format. ### Dubai URL: https://www.macksofy.com/locations/dubai Dubai cybersecurity — DESC ISR + DIFC + free-zone aligned. Macksofy services Dubai with DESC ISR-aligned audits, DIFC Data Protection Law programmes, NESA-format VAPT and red-team engagements — across BFSI, hospitality, smart-city operators and SaaS clients in Internet City, JLT, DIFC and Business Bay. ### Abu Dhabi URL: https://www.macksofy.com/locations/abu-dhabi Abu Dhabi cybersecurity — ADHICS, ADGM/FSRA + NESA aligned. Macksofy services Abu Dhabi with ADHICS healthcare-sector audits, ADGM/FSRA cyber programmes, NESA / UAE IA Standards VAPT and red-team engagements — across energy CII, sovereign-investment, government and healthcare entities on Al Maryah Island, Masdar City, Yas Island and KIZAD. ## Case Studies (Anonymised) ### Chained BOLA + JWT alg=none in a listed fintech — full PII access surfaced and remediated before the next regulator filing URL: https://www.macksofy.com/case-studies/listed-fintech-bola-jwt-pentest Sector: Fintech · Region: India · Engagement: Penetration Testing · Year: 2025 A BSE-listed digital lending platform asked Macksofy for a full-scope pentest ahead of a SEBI CSCRF audit. Within four days the team chained an authorization-bypass with a forged JWT to reach every customer's KYC and balance — fixed pre-filing. **Key metrics:** - 5 Critical findings (all closed pre-filing) - 9d Time to remediation - ₹14L Audit-rework saved - 0 Follow-up audit observations ### Account-takeover at scale found in a GCC telecom's pre-launch app — fixed before public release URL: https://www.macksofy.com/case-studies/gcc-telecom-mobile-app-takeover Sector: Telecom · Region: GCC · Engagement: Mobile Security · Year: 2025 Two weeks before public launch, a Gulf-based mobile carrier asked Macksofy to pentest their refreshed customer app. We surfaced an API-key-in-shared-prefs flaw chained with an insecure deeplink that allowed silent account takeover for any customer who clicked a single SMS link. **Key metrics:** - 10d Total engagement - 5 Critical / high findings - 0 Findings open at launch - 4M Subscribers protected ### Domain Admin in 4h 12m, undetected — a goal-based red team against a tier-1 listed Indian bank URL: https://www.macksofy.com/case-studies/listed-bank-red-team-edr-bypass Sector: BFSI · Region: India · Engagement: Red Team · Year: 2025 The CISO asked one question: 'Can someone reach Domain Admin without our SOC raising a single ticket?' Nine weeks later we showed how — phishing, EDR bypass, lateral movement and DA in 4 hours and 12 minutes, with the SOC's only ticket auto-closed as a false positive. **Key metrics:** - 4h 12m Time to Domain Admin - 0 SOC tickets at compromise - 23 Detections engineered - 11m TTD after remediation ### LockBit variant contained in 11 hours — manufacturer back to 80% production within 72h of first encrypted file URL: https://www.macksofy.com/case-studies/maharashtra-manufacturer-lockbit-dfir Sector: Manufacturing · Region: India · Engagement: DFIR · Year: 2025 A 1,400-employee manufacturer in Pune called Macksofy at 02:14 IST after a LockBit variant began encrypting file shares. Forensic team on-site by 06:30. Containment achieved at hour 11. Eighty per cent of production systems back online within 72 hours from clean backups. **Key metrics:** - 11h Time to containment - 72h Time to 80% recovery - 0 Ransom paid - 0 Confirmed data exfiltrated ### Wildcard IAM on a single Lambda role gave admin-equivalent reach — closed pre-Series-C diligence URL: https://www.macksofy.com/case-studies/bangalore-saas-aws-iam-cloud-audit Sector: SaaS · Region: India · Engagement: Cloud Security · Year: 2025 A Series-B B2B SaaS team in Bangalore needed an AWS audit before a Series-C technical-diligence call. Within day three Macksofy showed how a Lambda execution role with a wildcard IAM policy could be escalated to admin-equivalent — fixed inside a week with IaC guardrails added. **Key metrics:** - 1 Critical IAM finding (fixed in 4 days) - 0 Series-C blocking findings - 240 GuardDuty alerts triaged - 8d Total engagement ### NoPac chained with Kerberoasting reached Domain Admin in 4 hours inside a BFSI MNC's internal AD URL: https://www.macksofy.com/case-studies/bfsi-mnc-bkc-internal-ad-pentest Sector: BFSI · Region: India · Engagement: Internal Network · Year: 2025 A multinational BFSI's Indian arm asked Macksofy for an assumed-breach internal pentest of its AD + Citrix estate. From a single low-privilege user, the team chained NoPac (CVE-2021-42278) with a Kerberoastable service account to reach Domain Admin in four hours. **Key metrics:** - 4h Time to Domain Admin - 3 Critical findings (all closed in 14d) - 15d Engagement length - Q Cadence after engagement ### Mumbai listed bank cut standing privilege 78% in 60 days — pre-inspection IAM tightening with dual-vault rationalisation URL: https://www.macksofy.com/case-studies/listed-bank-iam-zero-trust-mumbai Sector: BFSI · Region: India · Engagement: Application Security · Year: 2026 A BSE-listed Mumbai private bank engaged Macksofy 90 days before the annual RBI CSITE Cell inspection. BloodHound + ROADrecon enumeration surfaced six kerberoastable tier-0 service accounts and an ESC4 path from junior-RM workstations to Domain Admin. Sixty days later, standing privilege was down 78%, dual PAM vaults were rationalised by scope (not by swap), and the inspection cleared first-pass. **Key metrics:** - 78% standing privilege reduction (60-day window) - 6 kerberoastable tier-0 svc accts closed - 0 after-hours incidents (during MFA rollout) - ~₹7 cr deferred PAM migration spend (18-month deferral) ### Pharma ransomware containment under the CERT-In 6-hour clock — Ahmedabad plant + Mumbai HQ recovered with USFDA-inspection-ready evidence URL: https://www.macksofy.com/case-studies/pharma-ransomware-dfir-india-2026 Sector: Manufacturing · Region: India · Engagement: DFIR · Year: 2026 An Ahmedabad-headquartered listed pharma manufacturer detected ransomware activity on the corporate-network at 03:42 IST. By 09:30 the CERT-In incident report was filed. By hour 72, containment was complete, the Ahmedabad plant had resumed batch operations from clean backups, and the evidence pack was assembled to USFDA Pre-Approval Inspection standard. Initial-access was traced to a vendor-portal credential reuse from a 2024 third-party breach. **Key metrics:** - 5h:48m CERT-In report filing time (6h window) - 38h plant batch ops resumed (72h BCP target) - 0 USFDA 483 observations (3 weeks post-IR) - 0 post-IR re-engagements (30-day monitoring) ## Resources (Whitepapers, Cheatsheets, Checklists) ### SEBI CSCRF Playbook · 2026 URL: https://www.macksofy.com/resources/sebi-cscrf-playbook-2026 Type: Whitepaper · Sectors: BFSI, Fintech · Year: 2026 A practitioner's playbook for SEBI-regulated entities preparing for CSCRF. Maps the framework's control families to evidence artefacts, with a 90-day rollout plan and the gaps that fail audits most often. ### OT / IT Segmentation for Indian Manufacturers URL: https://www.macksofy.com/resources/ot-it-segmentation-india-manufacturers Type: Whitepaper · Sectors: Manufacturing, Cross-sector · Year: 2026 Manufacturing networks across Maharashtra, Gujarat and Tamil Nadu still run a single L2 between corporate IT and the plant. This whitepaper lays out the segmentation patterns that work, the five recurring mistakes auditors flag, and a vendor-agnostic implementation sequence. ### Mobile App Security for Indian BFSI URL: https://www.macksofy.com/resources/mobile-app-security-bfsi-india Type: Whitepaper · Sectors: BFSI, Fintech · Year: 2026 What RBI expects from mobile-banking apps, the OWASP Mobile Top 10 translated into BFSI control language, and how to fold mobile pentesting into a release cadence without breaking velocity. ### India Ransomware Landscape · 2026 URL: https://www.macksofy.com/resources/india-ransomware-landscape-2026 Type: Whitepaper · Sectors: Cross-sector · Year: 2026 Active threat actors against Indian organisations, sector hit-rates, the entry vectors we see most often in DFIR cases, and a 6-step preparedness checklist that significantly reduces blast radius when an incident arrives. ### CERT-In Incident Reporting Checklist URL: https://www.macksofy.com/resources/cert-in-incident-reporting-checklist Type: Checklist · Sectors: Cross-sector · Year: 2026 What to report to CERT-In, when, and how. Built for IR commanders who need a clear, lawful path through CERT-In's 6-hour reporting window without legal-team back-and-forth. ### RBI Cyber Security Framework Gap-Check · 2026 URL: https://www.macksofy.com/resources/rbi-csf-gap-check-2026 Type: Checklist · Sectors: BFSI · Year: 2026 A self-assessment checklist that maps the RBI Cyber Security Framework circular into 'have we?' questions an internal audit team can run in a single afternoon. ### BOLA Prevention Checklist for API Engineers URL: https://www.macksofy.com/resources/bola-prevention-checklist Type: Checklist · Sectors: Cross-sector · Year: 2026 Concrete patterns and anti-patterns for ownership-anchored authorization. Built from real BOLA findings across BFSI, fintech and SaaS pentests. ### JWT Pitfalls Cheat Sheet URL: https://www.macksofy.com/resources/jwt-pitfalls-cheat-sheet Type: Cheat Sheet · Sectors: Cross-sector · Year: 2026 The handful of JWT pitfalls we keep finding in pentests, with the validation must-haves your auth gateway should enforce. ### PsExec Detection Cheat Sheet URL: https://www.macksofy.com/resources/psexec-detection-cheat-sheet Type: Cheat Sheet · Sectors: Cross-sector · Year: 2026 The telemetry sources, sigma-style detections and false-positive patterns to detect PsExec — the lateral-movement tool that keeps being missed in mid-market environments. ### M365 Hardening Checklist · Indian BFSI URL: https://www.macksofy.com/resources/m365-hardening-checklist-india Type: Checklist · Sectors: BFSI, Cross-sector · Year: 2026 A pragmatic order-of-operations for hardening Microsoft 365 in an Indian BFSI tenant — Conditional Access, audit, anti-phishing and tenant controls, sequenced for biggest risk reduction first. ### YARA Rule Writing Cheat Sheet URL: https://www.macksofy.com/resources/yara-rule-writing-cheat-sheet Type: Cheat Sheet · Sectors: Cross-sector · Year: 2026 Quick-reference YARA cheat sheet covering rule anatomy, string types, condition logic, performance tuning and the common mistakes that turn good rules into false-positive cannons. ### IOC Extraction Methodology for Indian SOCs URL: https://www.macksofy.com/resources/ioc-extraction-methodology Type: Whitepaper · Sectors: BFSI, Fintech, SaaS, Government, Cross-sector · Year: 2026 Methodical IOC extraction across atomic, computed and behavioural layers. Pyramid-of-Pain priorities, threat-intel platform feeds (MISP, OpenCTI), and the IOC lifecycle that prevents stale-feed fatigue. ### Malware Sandbox Detonation — A Practitioner's Guide URL: https://www.macksofy.com/resources/malware-sandbox-detonation-guide-india Type: Whitepaper · Sectors: BFSI, Fintech, SaaS, Government, Cross-sector · Year: 2026 Hands-on guide to sandbox-based malware analysis for Indian SOCs and DFIR teams. Cuckoo / CAPE / ANY.RUN comparison, anti-analysis evasion, and operational discipline for source-protection. ### Ransomware Incident Response Runbook · India 2026 URL: https://www.macksofy.com/resources/ransomware-ir-runbook-india Type: Whitepaper · Sectors: BFSI, Fintech, Manufacturing, Healthcare, SaaS, Cross-sector · Year: 2026 Hour-by-hour ransomware IR runbook tuned for Indian operating reality: CERT-In 6-hour reporting, RBI / SEBI parallel obligations, evidence preservation, restoration sequencing and the decision framework for engaging negotiators. ### Business Email Compromise IR Runbook · India 2026 URL: https://www.macksofy.com/resources/bec-incident-response-runbook Type: Whitepaper · Sectors: BFSI, Fintech, SaaS, Manufacturing, Cross-sector · Year: 2026 Step-by-step BEC IR playbook for M365 + Workspace environments. Inbox rule hunt, sign-in log triage, OAuth-token revocation, financial-recall workflow with Indian banks, and the regulatory reporting decision-tree. ### Active Directory Compromise IR Runbook · 2026 URL: https://www.macksofy.com/resources/active-directory-compromise-runbook Type: Whitepaper · Sectors: BFSI, Fintech, SaaS, Manufacturing, Government, Cross-sector · Year: 2026 End-to-end runbook for recovering from an AD compromise where the attacker reached Domain Admin or persisted at tier-0. KRBTGT double-reset, persistence hunt, tier-0 isolation rebuild, and the long-tail of validating you're actually clean. ### CERT-In's 12-Hour Patch Mandate — Research Note URL: https://www.macksofy.com/resources/cert-in-12-hour-patch-mandate Type: Whitepaper · Sectors: Cross-sector · Year: 2026 CERT-In's May 2026 AI Threat Landscape guidance sets an indicative 12-hour window to remediate exploited vulnerabilities on internet-facing systems. This research note breaks down the tiered schedule, the collapsing CVE-to-exploit data, the compensating-control path, India's position vs CISA, and a 30/60/90-day action list. ### Cloud Security for Indian Enterprises · 2026 URL: https://www.macksofy.com/resources/cloud-security-india-2026 Type: Whitepaper · Sectors: BFSI, Fintech, SaaS · Year: 2026 How Indian enterprises secure multi-cloud estates without drowning in dashboards: where the cloud provider's responsibility ends and yours begins, the handful of misconfiguration classes behind most cloud breaches, how to choose between CSPM, CWPP, CIEM and CNAPP, the India regulatory cloud stack, and a 90-day programme that turns posture findings into closed risk. ## Recent Articles ### Telecom Cyber Security Rules 2024: What India's Telecom Entities Must Do URL: https://www.macksofy.com/blog/telecom-cyber-security-rules-2024-india-compliance Published: 2026-09-05 · Updated: 2026-09-05 · Category: Compliance India's Telecom Cyber Security Rules, 2024 put a six-hour incident-reporting clock, a mandatory Chief Telecommunication Security Officer, and standing SOC and testing duties on every telecom entity. Who must comply, the timelines, and the compliance checklist. ### CRTP vs CRTO: Which Red Team Certification to Take First in India (2026) URL: https://www.macksofy.com/blog/crtp-vs-crto-comparison-india-2026 Published: 2026-09-05 · Updated: 2026-09-05 · Category: Certification Guide CRTP or CRTO first? They test different layers of the red-team stack: CRTP is cheap Active Directory attack depth, CRTO is Cobalt Strike operator tradecraft. Cost in INR, exam format, India hiring signal, and the order that actually works. ### OSCP Training in Mumbai 2026 — Complete Guide to Cost, Syllabus, Exam & Career URL: https://www.macksofy.com/blog/oscp-training-in-mumbai-2026 Published: 2026-04-30 · Updated: 2026-09-05 · Category: Certification Guides What OSCP costs in India in 2026, in rupees and in dollars — every OffSec plan priced, the exam-only trap, what a retake adds, and the total to certify. Plus course structure, exam mechanics, salary impact, and how to pick a Mumbai training institute. ### DPDP Rules 2025 — Every India Compliance Deadline, and What to Do in Each Window URL: https://www.macksofy.com/blog/dpdp-rules-2025-compliance-deadlines Published: 2026-08-30 · Updated: 2026-08-30 · Category: Regulatory India's Digital Personal Data Protection Rules, 2025 turned a two-year-old Act into a dated compliance programme. Here is the phased commencement calendar, who each phase binds, and why an eighteen-month runway is not eighteen months of preparation time. ### SOC Analyst Training in India 2026 — CSA vs SOC-200 vs CySA+ Career Guide URL: https://www.macksofy.com/blog/soc-analyst-training-india-2026 Published: 2026-05-04 · Updated: 2026-08-30 · Category: Career & Salary Which SOC analyst certification is worth it in India? Honest 2026 comparison of EC-Council CSA, OffSec SOC-200 / OSDA and CompTIA CySA+ — costs in INR, exam difficulty, hiring impact. ### Red Team Certifications India 2026 — OSEP vs CRTO vs CRTP Comparison URL: https://www.macksofy.com/blog/red-team-certifications-india-2026 Published: 2026-05-03 · Updated: 2026-08-30 · Category: Certification Guides Honest comparison of red team certifications for Indian operators in 2026. OSEP, CRTO, CRTP, CRTE, OSCE3 — pricing in INR, exam difficulty, what each one actually teaches. ### CPTS vs OSCP — Which Pentest Certification Should You Take in India? URL: https://www.macksofy.com/blog/cpts-vs-oscp-certification-comparison-india-2026 Published: 2026-01-15 · Updated: 2026-08-30 · Category: Certification Guide Hack The Box's CPTS vs OffSec's OSCP — cost in INR, exam difficulty, India hiring perception, salary impact. An honest comparison from a CERT-In empanelled training provider. ### CRTP vs CRTE — Altered Security's AD Certification Guide for India (2026) URL: https://www.macksofy.com/blog/crtp-vs-crte-certification-guide-india-2026 Published: 2026-01-08 · Updated: 2026-08-30 · Category: Certification Guide Altered Security's CRTP and CRTE — what each covers, exam style, costs in INR, and how Indian red teamers should sequence them. Includes CRTM context. ### DPDP Act — What a Significant Data Fiduciary Actually Has to Do (2026) URL: https://www.macksofy.com/blog/dpdp-significant-data-fiduciary-obligations-2026 Published: 2026-05-31 · Updated: 2026-08-30 · Category: Regulatory If your organisation is notified as a Significant Data Fiduciary under India's DPDP Act, you inherit extra duties on top of every Data Fiduciary obligation — a Board-responsible DPO in India, an independent data audit, and periodic DPIAs. Here is the obligation map and a readiness path. ### The CERT-In Empanelment Process (2026): How an Auditing Organisation Actually Gets on the Panel URL: https://www.macksofy.com/blog/cert-in-empanelment-process-2026 Published: 2026-08-12 · Category: Compliance A step-by-step walkthrough of how CERT-In empanels information security auditing organisations in India — the single three-month application window each year, the eligibility bar, the documentation round, the offline and online practical skill tests and their 90% pass threshold, the Personal Interaction Session, government background verification, what it costs, how long the whole cycle takes, and what an organisation has to keep doing to stay on the panel. ### OffSec Learn One India 2026 — Pricing, ROI Breakdown & Cert Selection Guide URL: https://www.macksofy.com/blog/offsec-learn-one-india-pricing-roi-2026 Published: 2026-05-02 · Updated: 2026-08-12 · Category: Career & Salary Is OffSec Learn One worth ₹2.5L+ in 2026? Honest ROI breakdown for Indian buyers — Learn One vs PEN-200 standalone, which two certs to pick, and the salary maths that justify the spend. ### ABDM M1 WASA Audit: The Complete Guide to the Safe-to-Host Certificate (2026) URL: https://www.macksofy.com/blog/abdm-m1-wasa-audit-guide-2026 Published: 2026-08-09 · Updated: 2026-08-09 · Category: Compliance Everything an Indian digital-health team needs to know about the WASA audit behind ABDM Milestone 1 — what WASA stands for, why the report has to come from a CERT-In empanelled auditor, what functional and security testing it covers for HIPs, HIUs and health lockers, what the safe-to-host certificate must state about the environment tested, realistic timelines, and the failures that send teams back for a re-test. ### CEH v13 AI Training in India 2026 — Syllabus, Cost, Institutes & Career Guide URL: https://www.macksofy.com/blog/ceh-v13-ai-training-india-2026 Published: 2026-04-29 · Updated: 2026-08-09 · Category: Certification Guides EC-Council's CEH v13 added AI throughout the curriculum. India 2026 guide — what's new, real cost in INR, exam mechanics, hiring impact and how to pick an EC-Council ATC. ### Penetration Testing & VAPT: The Complete Guide (India, 2026) URL: https://www.macksofy.com/blog/penetration-testing-vapt-guide-india-2026 Published: 2026-07-17 · Updated: 2026-07-25 · Category: Penetration Testing A definitive guide to penetration testing and VAPT for Indian organisations in 2026 — the difference between vulnerability assessment and penetration testing, the types, the PTES/OWASP methodology, CVSS scoring, timelines, cost drivers, deliverables, regulatory triggers (CERT-In, RBI, SEBI, PCI-DSS, DPDP) and how to choose a CERT-In empanelled provider. ### CERT-In Empanelled Audit: The Complete Guide (2026) URL: https://www.macksofy.com/blog/cert-in-empanelled-audit-guide-2026 Published: 2026-07-17 · Updated: 2026-07-25 · Category: Compliance Everything Indian organisations need to know about CERT-In empanelled audits in 2026 — what CERT-In empanelment means, who needs an empanelled audit, what it covers, the CERT-In Directions of 2022 (6-hour reporting, 180-day logs), the report format, timelines, cost drivers, how CERT-In compares to ISO 27001 and SOC 2, and how to verify a provider's empanelment. ### Cyber Security Companies in Mumbai & India (2026): The CERT-In Empanelled Audit Guide URL: https://www.macksofy.com/blog/cyber-security-companies-in-mumbai-india-2026 Published: 2026-07-09 · Updated: 2026-07-25 · Category: Compliance A buyer's guide to choosing a cyber security company in Mumbai and across India in 2026 — why CERT-In empanelment is the single most important credential, how to verify it on the official CERT-In list, and how Macksofy Technologies delivers empanelled-grade VAPT and regulatory audits from Bandra Kurla Complex, Mumbai. ### Top 10 Penetration Testing Tools in 2026 — What Every Pentester Should Master URL: https://www.macksofy.com/blog/top-10-penetration-testing-tools-2026 Published: 2026-04-28 · Updated: 2026-07-25 · Category: Ethical Hacking The 10 penetration testing tools that matter in 2026 — Burp Suite, Nmap, Metasploit, BloodHound, Impacket and more. What each does, when to use it, and learning order. ### Best Laptops for Cybersecurity Students in India 2026 — Top 10 Ranked URL: https://www.macksofy.com/blog/best-laptops-cybersecurity-students-india-2026 Published: 2026-04-27 · Updated: 2026-07-25 · Category: Career & Salary Specs, price-in-INR and use-case ranking of the 10 best laptops for cybersecurity students in India 2026 — including budget picks under ₹60k and pro-grade options for OSCP/red team labs. ### CERT-In's Comprehensive Cyber Security Audit Policy Guidelines (2025): What Every CISO and Auditee Must Know URL: https://www.macksofy.com/blog/cert-in-cyber-security-audit-policy-guidelines-2025 Published: 2026-06-24 · Category: Compliance CERT-In's Comprehensive Cyber Security Audit Policy Guidelines (Version 1.0, 25 July 2025) rewrite how empanelled audits are scoped, scored and reported in India. Download the official PDF and read our section-by-section analysis of what changes for auditees and auditors. ### CSPM vs CNAPP vs CWPP: Choosing Cloud Security Tooling for Indian Enterprises (2026) URL: https://www.macksofy.com/blog/cspm-vs-cnapp-india-2026 Published: 2026-06-23 · Category: Cloud Security CSPM, CWPP, CIEM and CNAPP explained without the marketing — what each actually does, where they overlap, and a practical buying sequence for Indian BFSI, fintech and SaaS estates under RBI, SEBI and DPDP. ### The Cloud Misconfigurations That Fail RBI and SEBI Audits in 2026 URL: https://www.macksofy.com/blog/cloud-misconfigurations-rbi-sebi-audit-2026 Published: 2026-06-23 · Category: Cloud Security The specific AWS, Azure and GCP misconfigurations that turn up as findings in RBI Cyber Security Framework and SEBI CSCRF audits — public storage, IAM sprawl, weak logging, data-residency gaps — and how to close them before the auditor arrives. ### Multi-Cloud Security for Indian BFSI: Landing Zones, Data Residency and Blast-Radius Control URL: https://www.macksofy.com/blog/multi-cloud-security-bfsi-india-2026 Published: 2026-06-23 · Category: Cloud Security How Indian banks, NBFCs and insurers secure AWS, Azure and GCP at once — landing-zone guardrails, data residency under RBI and DPDP, identity blast-radius control, and continuous monitoring across a multi-cloud estate. ### SEBI CSCRF — A 2026 Compliance Readiness Guide for Regulated Entities URL: https://www.macksofy.com/blog/sebi-cscrf-compliance-readiness-2026 Published: 2026-06-21 · Category: Compliance SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) is now in force across all Regulated Entities after a phased 2025 rollout. A practical readiness guide to the graded model, the Cyber Capability Index, the SOC mandate, VAPT/SBOM and audit evidence — for MIIs, brokers, AMCs and other REs. ### Do You Need a vCISO? A 2026 Buyer's Guide for Indian Enterprises URL: https://www.macksofy.com/blog/vciso-buyers-guide-india-2026 Published: 2026-06-21 · Category: Engagement Guide When a Virtual CISO (vCISO) beats a full-time hire, what a good engagement delivers, how to evaluate providers, and what it costs — a practical 2026 buyer's guide for Indian and UAE enterprises facing RBI, SEBI, DPDP and CERT-In expectations. ### OT / ICS Security Playbook for India 2026 — Protecting SCADA & Critical Infrastructure URL: https://www.macksofy.com/blog/ot-ics-security-playbook-india-2026 Published: 2026-06-05 · Category: OT Security A practical OT/ICS security playbook for Indian critical-infrastructure operators — power, manufacturing, oil & gas and utilities. The Purdue model, IEC 62443, the India regulatory stack (NCIIPC, CEA, CERT-In) and a 30/60/90-day readiness path built around safety and uptime, not just data. ### UAE Cybersecurity Compliance 2026 — Federal PDPL + NESA Explained URL: https://www.macksofy.com/blog/uae-cybersecurity-compliance-pdpl-nesa-2026 Published: 2026-06-03 · Category: Compliance Enterprises operating in the UAE face a layered compliance stack: the Federal PDPL 2021 for personal data, NESA / UAE IA Standards for information assurance, plus emirate and free-zone regimes (DESC ISR, DIFC, ADGM, ADHICS). Here is how the layers fit and a practical readiness path. ### RBI IT-Governance Master Direction — A 2026 Readiness Checklist for Banks & NBFCs URL: https://www.macksofy.com/blog/rbi-it-governance-readiness-checklist-2026 Published: 2026-05-31 · Category: Compliance The RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices is in force from April 2024. Here is a practical, chapter-by-chapter readiness checklist — ITSC, CISO line, patch and change controls, BCP/DR and IS Audit — for the next supervisory cycle. ### CERT-In's 12-Hour Patch Mandate — India's AI-Paced Patching Standard Explained URL: https://www.macksofy.com/blog/cert-in-12-hour-patch-mandate-ai-exploitation-2026 Published: 2026-05-30 · Category: Regulatory CERT-In's May 2026 AI Threat Landscape guidance sets an indicative 12-hour window to remediate exploited vulnerabilities on internet-facing systems. Here's the tiered schedule, why it's calibrated to AI exploitation speed, and what Indian organisations should actually do. ### Active Directory Compromise IR Playbook — Indian BFSI URL: https://www.macksofy.com/blog/ad-compromise-ir-playbook-indian-bfsi-2026 Published: 2026-05-27 · Category: Incident Response Five-phase incident response runbook for Active Directory ransomware and golden-ticket scenarios in Indian banks — containment, eradication, recovery, and the CERT-In reporting clock. ### Zero Trust for Indian Banks — RBI ITGF Alignment 2026 URL: https://www.macksofy.com/blog/zero-trust-indian-banks-rbi-itgf-2026 Published: 2026-05-27 · Category: Architecture How to map Zero Trust pillars — identity, device, network, application, data — to RBI IT Governance Framework controls, with a pragmatic 18-month rollout plan for Indian banks. ### Ransomware Readiness Checklist for Indian BFSI 2026 URL: https://www.macksofy.com/blog/ransomware-readiness-bfsi-india-2026 Published: 2026-05-27 · Category: Incident Response RBI Cyber Security Framework + CERT-In 6-hour reporting aligned ransomware readiness checklist for Indian banks, NBFCs and insurers — prevention, detection, response, recovery. ### DPDP §16 Cross-Border Transfer — Compliance Guide for Indian SaaS URL: https://www.macksofy.com/blog/dpdp-cross-border-transfer-2026 Published: 2026-05-26 · Category: Regulatory What §16 of India's Digital Personal Data Protection Act means in practice — when transfers are restricted, what evidence to keep, and how Indian SaaS should architect for the 2027 enforcement window. ### Red Team vs Penetration Testing in 2026 — What's the Real Difference? URL: https://www.macksofy.com/blog/red-team-vs-penetration-testing-2026 Published: 2026-05-11 · Category: Engagement Guide Red team vs penetration testing — clear 2026 breakdown of scope, cost, timeline and outcomes. Which engagement actually fits your maturity and Indian regulatory ask? ### RBI CSF vs SEBI CSCRF in 2026 — Which Framework Applies to You? URL: https://www.macksofy.com/blog/rbi-csf-vs-sebi-cscrf-2026 Published: 2026-05-11 · Category: Compliance RBI Cyber Security Framework vs SEBI CSCRF — clause-by-clause 2026 guide for Indian BFSI, including dual-regulated broker-dealers, NBFCs and bank-owned AMCs. ### DPDP Act 2023 vs GDPR in 2026 — Clause-by-Clause for Indian Fiduciaries URL: https://www.macksofy.com/blog/dpdp-vs-gdpr-2026 Published: 2026-05-11 · Category: Compliance DPDP Act vs GDPR — practical 2026 comparison for Indian data fiduciaries handling EU residents. Penalties, consent, DPO, breach windows, cross-border transfers. ### CERT-In Empanelled VAPT vs ISO 27001 in 2026 — What Each Actually Proves URL: https://www.macksofy.com/blog/cert-in-empanelled-vs-iso-27001-2026 Published: 2026-05-11 · Category: Compliance CERT-In empanelled VAPT vs ISO 27001 — clear 2026 explainer on audit vs certification, what each one proves, where they complement, and which to buy first. ### MDR vs MSSP in 2026 — What to Actually Buy (India Buyer Guide) URL: https://www.macksofy.com/blog/mdr-vs-mssp-2026 Published: 2026-05-11 · Category: Engagement Guide MDR vs MSSP — practical 2026 guide for Indian buyers. Real pricing bands in INR, the Tata / Sequretek / NII / Lucideus / Macksofy market view, and what to ask vendors. ### VAPT vs Red Team in 2026 — The India BFSI Procurement Guide URL: https://www.macksofy.com/blog/vapt-vs-red-team-2026 Published: 2026-05-11 · Category: Engagement Guide VAPT vs red team — 2026 procurement guide for Indian BFSI. RFP language, SLA, deliverable spec, vendor questionnaire and how to scope CERT-In friendly engagements. ### OSCP+ vs OSCP in 2026 — What Changed, What It Means for Indian Candidates URL: https://www.macksofy.com/blog/oscp-plus-vs-oscp-2026 Published: 2026-05-06 · Category: Certification Guides OffSec rebranded OSCP to OSCP+ in late 2024. Here's everything that actually changed in the 2026 exam — Active Directory expansion, buffer-overflow removal, CPE recertification — and how Indian candidates should adjust their prep. ### OSCP vs CEH in India 2026 — Which Cybersecurity Certification Should You Pick? URL: https://www.macksofy.com/blog/oscp-vs-ceh-india-2026 Published: 2026-05-06 · Category: Certification Guides OSCP vs CEH for Indian candidates in 2026 — honest comparison of cost (INR), exam style, hiring impact, salary outcomes and which one to take first based on your goal role. ## Reference URLs - Sitemap: https://www.macksofy.com/sitemap.xml - LLMs index: https://www.macksofy.com/llms.txt - LLMs full (this file): https://www.macksofy.com/llms-full.txt - RSS: https://www.macksofy.com/feed.xml - Contact: https://www.macksofy.com/contact - About: https://www.macksofy.com/about - Press & Media: https://www.macksofy.com/press --- Last generated: 2026-09-10T10:16:58.445Z — auto-rebuilt on every deploy from the source content files.