29 security controls for Indian IT & SaaS firms, and what answers each

What the obligations make you do, the breaches each one would have stopped, what a client’s security review asks to see — and what answers it.

  • 29controls, in four groups
  • 25answered by software we shortlist
  • 4no software answers
  • 7where our catalogue is thin — said plainly
For
Answer

Showing 29 of 29

Shared by both halves

12

Every firm in the industry needs these, whichever half it is in.

Detect and respond inside six hours

Both

Endpoint detection and response, or a managed service that watches it 24×7.

4 obligations require it2 breach patterns it stops2 guides

What it is

Endpoint detection and response, or a managed service that watches it 24×7.

Why it matters here

Every Indian clock on this page starts at detection — CERT-In’s, and a bank client’s. You cannot report in six hours what you find in six days. CircleCI’s 2022 breach began with malware that antivirus missed on one engineer’s laptop.

What a client or auditor asks to see

Coverage across every endpoint and server, 24×7 monitoring (in-house or MDR), and a dated record of detection-to-report times from your last incidents or drills.

Logs kept, and producible

Both

Central log management or SIEM with retention set to the longest clock you owe.

8 obligations require it1 guide

What it is

Central log management or SIEM with retention set to the longest clock you owe.

Why it matters here

CERT-In wants 180 days of logs from every ICT system; the DPDP Rules want at least a year for personal-data processing — including processing you do as someone else’s processor. Voice BPOs owe a year of call records under the OSP rules.

What a client or auditor asks to see

Retention settings per log source, NTP synchronisation to an NIC/NPL-traceable source, and a test retrieval of a six-month-old log.

Phishing-resistant sign-in

Both

Single sign-on everywhere, with FIDO2 or passkey MFA that a phone call cannot reset.

4 obligations require it2 breach patterns it stops1 guide

What it is

Single sign-on everywhere, with FIDO2 or passkey MFA that a phone call cannot reset.

Why it matters here

Help-desk impersonation and stolen sessions are how firms in this industry get breached. The Snowflake intrusions of 2024 succeeded on accounts with no MFA at all; CISA’s guidance on the help-desk attackers is phishing-resistant MFA.

What a client or auditor asks to see

MFA coverage across workforce and admin accounts, which methods are allowed, and how a lost authenticator is replaced.

Access that ends when the job does

Both

Identity governance: automated joiner-mover-leaver, contractors included, with access reviews.

1 obligation require it1 breach pattern it stops1 guide

What it is

Identity governance: automated joiner-mover-leaver, contractors included, with access reviews.

Why it matters here

Attrition runs at 13–15% at the largest firms, and contract staff are a large share of delivery. KiranaPro’s servers and code were wiped in 2025 through a former employee’s access that was never revoked.

What a client or auditor asks to see

Time from exit to access removal, quarterly access reviews signed off by owners, and how contractor accounts expire.

Managed devices only

Both

Unified endpoint management, so work happens only on devices you can see, patch and wipe.

1 obligation require it2 breach patterns it stops1 guide

What it is

Unified endpoint management, so work happens only on devices you can see, patch and wipe.

Why it matters here

Mandiant traced the Snowflake intrusions to infostealers on contractor laptops also used for gaming and pirated software. SEZ units must provide the equipment for work from home.

What a client or auditor asks to see

Device inventory against headcount, encryption and patch compliance, and the policy for personal devices.

Email security and phishing training

Both

A secure email gateway or API-based protection, with awareness training that tests people.

0 obligations require it1 breach pattern it stops1 guide + 4 products

What it is

A secure email gateway or API-based protection, with awareness training that tests people.

Why it matters here

Phishing — including voice and SMS — is the most common way in for Indian breaches (IBM, 2026). Wipro’s 2019 intrusion began with a phished employee.

What a client or auditor asks to see

Phishing simulation results over time, DMARC enforcement, and training completion.

Backups the attacker cannot reach

Both

Immutable or air-gapped backup, including Microsoft 365 and Google Workspace, with tested restores.

4 obligations require it3 guides

What it is

Immutable or air-gapped backup, including Microsoft 365 and Google Workspace, with tested restores.

Why it matters here

Ransomware is the incident that stops delivery. Your books of account must be backed up daily in India, and DPDP lists backups among the required safeguards.

What a client or auditor asks to see

Immutability settings, an India copy for books of account, and the date and duration of the last full restore test.

Vulnerability management and VAPT

BothThin coverage

Continuous scanning and exposure management, plus annual penetration testing.

5 obligations require it2 breach patterns it stops1 guide

What it is

Continuous scanning and exposure management, plus annual penetration testing.

Why it matters here

Kaseya, MOVEit and SimpleHelp were all internet-facing tools exploited at scale. Regulated clients increasingly ask for an annual audit by a CERT-In-empanelled auditor.

What a client or auditor asks to see

Scan coverage, time to fix critical findings, and the last VAPT report with closure evidence.

What answers it

The two VAPT services in our catalogue are not CERT-In-empanelled. If a client needs an empanelled auditor, that is a separate engagement.

Shortlist this with us →

Audit evidence: ISO 27001, SOC 2

BothThin coverage

A GRC or compliance-automation platform that collects evidence continuously instead of before the audit.

6 obligations require it5 products in our catalogue

What it is

A GRC or compliance-automation platform that collects evidence continuously instead of before the audit.

Why it matters here

ISO 27001 is the first line of nearly every RFP, and SOC 2 is the gate to US enterprise customers. Every 2013-edition certificate lapsed on 31 October 2025.

What a client or auditor asks to see

A current certificate or report, the scope statement, and how evidence is collected between audits.

What answers it

In our catalogue:

Only three of these automate SOC 2 / ISO 27001 evidence collection; the others are enterprise GRC platforms.

Shortlist this with us →

Privacy operations for DPDP

Both

Consent, notices, data-principal requests and a record of processing.

2 obligations require it5 products in our catalogue

What it is

Consent, notices, data-principal requests and a record of processing.

Why it matters here

From May 2027 every firm here is a Data Fiduciary at least for its own employees, and SaaS firms for their users. Grievances must be resolved within 90 days.

What a client or auditor asks to see

A data map, the consent and notice flows, and request-handling times.

Required by

Your own suppliers, managed

BothThin coverage

Third-party risk management: who your subcontractors are, what they can reach, and what they have promised.

8 obligations require it2 products in our catalogue

What it is

Third-party risk management: who your subcontractors are, what they can reach, and what they have promised.

Why it matters here

The RBI can now inspect your subcontractors, DORA and NIS2 push supply-chain clauses down to you, and the 2024 C-Edge outage reportedly began at a partner’s misconfigured build server.

What a client or auditor asks to see

A register of subcontractors and SaaS tools with their access, back-to-back contract clauses, and periodic reviews.

What answers it

In our catalogue:

Thin: two products in our catalogue. Most firms this size run supplier risk in their GRC platform.

Shortlist this with us →

Client and customer data, encrypted and found

Both

Data discovery and posture management, encryption with keys you control, tokenisation where it fits.

6 obligations require it1 breach pattern it stops2 guides

What it is

Data discovery and posture management, encryption with keys you control, tokenisation where it fits.

Why it matters here

DPDP names encryption, masking and tokenisation; SEBI wants keys managed in India; GDPR transfers to India rely on safeguards because there is no adequacy decision.

What a client or auditor asks to see

Where sensitive data lives, how it is encrypted, who holds the keys, and where.

Services firms

6

For firms that work inside their clients’ environments.

Privileged access into client environments

Services

Privileged access management with vaulted credentials, just-in-time access and session recording.

1 obligation require it2 breach patterns it stops1 guide

What it is

Privileged access management with vaulted credentials, just-in-time access and session recording.

Why it matters here

Your engineers hold the keys to someone else’s estate. Cloud Hopper went through service providers’ jump servers into their clients; the RBI requires that only people the bank authorises can reach its data.

What a client or auditor asks to see

Who can reach which client, through what, with recordings of privileged sessions and per-client separation.

Zero-trust access for distributed delivery

Services

ZTNA or SASE in place of the flat VPN, so a home laptop reaches one client’s apps and nothing else.

1 obligation require it1 breach pattern it stops2 guides

What it is

ZTNA or SASE in place of the flat VPN, so a home laptop reaches one client’s apps and nothing else.

Why it matters here

Hybrid delivery is the norm and SEZ units must provide “secured connectivity” for work from home. A VPN that drops a laptop onto the whole network is how one infection becomes a client incident.

What a client or auditor asks to see

Per-application access policies, device-posture checks, and the absence of standing network-level access.

Leakage and insider risk on delivery floors

Services

Data-loss prevention and insider-risk monitoring sized for support and operations teams.

1 obligation require it1 breach pattern it stops1 guide

What it is

Data-loss prevention and insider-risk monitoring sized for support and operations teams.

Why it matters here

In 2025 Coinbase disclosed that overseas support agents were bribed to pull customer data; Reuters reported an Indore BPO employee photographing her screen. Coinbase put its costs at $180–400 million.

What a client or auditor asks to see

Masking of customer data in support tools, DLP policies by role, and how anomalous access is investigated.

Required by

Would have stopped

Isolated client workspaces

ServicesThin coverage

Virtual desktops or a secure enterprise browser, so client data and code never land on the laptop.

1 obligation require it2 breach patterns it stops5 products in our catalogue

What it is

Virtual desktops or a secure enterprise browser, so client data and code never land on the laptop.

Why it matters here

HCLTech’s 2023 ransomware incident stayed inside one project’s isolated cloud environment. Isolation per client is what keeps one engagement’s incident from becoming every client’s.

What a client or auditor asks to see

How each client’s environment is separated, and whether data can be copied out of it.

Your remote-management tools, locked down

Services

RMM, PSA and remote support — kept off the open internet, patched, and behind MFA.

1 obligation require it1 breach pattern it stops2 guides

What it is

RMM, PSA and remote support — kept off the open internet, patched, and behind MFA.

Why it matters here

Kaseya VSA reached about 1,500 downstream businesses through fewer than 60 MSPs in 2021; CISA warned in 2025 of attackers using an unpatched RMM to reach a provider’s customers. Your tools are their tools.

What a client or auditor asks to see

An inventory of every remote-access tool in use, how consoles are exposed, and MFA on technician accounts.

Contact-centre and BPO operations

ServicesThin coverage

The contact-centre, workforce-management and quality stack — with call records kept and card details masked.

2 obligations require it6 products in our catalogue

What it is

The contact-centre, workforce-management and quality stack — with call records kept and card details masked.

Why it matters here

Voice BPOs owe a year of call records under the OSP rules, and any centre taking card payments must keep card numbers out of recordings under PCI DSS.

What a client or auditor asks to see

Call-record retention, how card details are captured, and agent access to customer data.

Required by

What answers it

In our catalogue:

Thin: our contact-centre coverage is Zendesk and Zoom, and nothing we list does DTMF masking for card payments.

Shortlist this with us →

Product firms

7

For firms that ship software other people run.

Source code and the build pipeline

Product

A hardened Git platform and CI/CD: SSO on every account, protected branches, isolated runners, nothing internet-facing that need not be.

1 obligation require it3 breach patterns it stops1 guide

What it is

A hardened Git platform and CI/CD: SSO on every account, protected branches, isolated runners, nothing internet-facing that need not be.

Why it matters here

Codecov’s tampered uploader sent customers’ CI secrets to an attacker; the 2024 C-Edge outage that hit about 300 small banks reportedly began at a partner’s misconfigured Jenkins server; the 2025 Salesloft Drift token theft started in Salesloft’s GitHub account.

What a client or auditor asks to see

Branch protection, who can approve and deploy, how runners are isolated, and SSO and MFA on the code platform.

Dependencies you can account for

Product

Software composition analysis, an SBOM per release, and a repository firewall in front of npm and PyPI.

4 obligations require it1 breach pattern it stops1 guide + 4 products

What it is

Software composition analysis, an SBOM per release, and a repository firewall in front of npm and PyPI.

Why it matters here

The xz-utils backdoor (2024) and the Shai-Hulud npm worm (2025) came in through dependencies, and a ManageEngine flaw exploited in the wild came from an outdated third-party library. The EU CRA, SEBI’s buyers and US agencies now ask for the SBOM.

What a client or auditor asks to see

An SBOM per release, the policy for new and vulnerable dependencies, and time to patch a disclosed vulnerability.

Secrets and signing keys out of the code

ProductThin coverage

A secrets vault with short-lived credentials, secret scanning in commits, and protected code-signing keys.

1 obligation require it2 breach patterns it stops1 guide + 4 products

What it is

A secrets vault with short-lived credentials, secret scanning in commits, and protected code-signing keys.

Why it matters here

29 million new hardcoded secrets reached public GitHub in 2025 (GitGuardian). CircleCI told every customer to rotate every secret after one stolen session.

What a client or auditor asks to see

Where secrets are stored, how long they live, scanning results, and who can sign a release.

What answers it

Also in our catalogue:

Code signing is thin: one dedicated product, plus PKI from Entrust and eMudhra.

Shortlist this with us →

Cloud posture and workloads

Product

Cloud-native application protection: misconfiguration, identities and entitlements, and runtime threats.

1 obligation require it1 guide

What it is

Cloud-native application protection: misconfiguration, identities and entitlements, and runtime threats.

Why it matters here

Your product runs in the cloud and a customer’s security review will ask how you know it is configured safely. KiranaPro’s attacker replaced MFA on the AWS root account.

What a client or auditor asks to see

Posture findings over time, root and admin account protection, and least-privilege cloud roles.

Required by

Application and API protection

Product

WAF and API security, bot and DDoS defence, and payment-page script monitoring.

1 obligation require it8 products in our catalogue

What it is

WAF and API security, bot and DDoS defence, and payment-page script monitoring.

Why it matters here

MOVEit was an internet-facing application exploited at 2,773 organisations. If you take card payments, PCI DSS now requires integrity monitoring of payment-page scripts.

What a client or auditor asks to see

WAF and API inventory coverage, DDoS protection, and script monitoring on payment pages.

Required by

Customer identity and account protection

ProductThin coverage

Sign-in, MFA and account-takeover defence for your own customers.

0 obligations require it1 breach pattern it stops1 guide + 3 products

What it is

Sign-in, MFA and account-takeover defence for your own customers.

Why it matters here

Credential stuffing and session theft against your users become your incident and, under DPDP, your notification.

What a client or auditor asks to see

MFA options offered to customers, account-takeover detection, and session lifetimes.

What answers it

Also in our catalogue:

Thin: three products in our catalogue.

Shortlist this with us →

AI features, secured and governed

Product

Guardrails and firewalls for the AI you ship, and governance that maps to ISO 42001 and the EU AI Act.

2 obligations require it6 products in our catalogue

What it is

Guardrails and firewalls for the AI you ship, and governance that maps to ISO 42001 and the EU AI Act.

Why it matters here

EU transparency duties apply from August 2026, high-risk duties from December 2027 — and AI used in recruitment, credit scoring or education is classed high-risk.

What a client or auditor asks to see

An inventory of models and AI features, guardrail policies, and how AI-generated content is labelled.

What no software answers

4

Procedure, hiring, a runbook and a contract — where the 2023–25 attacks got in.

Verifying the caller before a reset

BothNot a product

A help-desk procedure that proves who is asking before any password or MFA reset.

0 obligations require it1 breach pattern it stopsNo software answers it

What it is

A help-desk procedure that proves who is asking before any password or MFA reset.

Why it matters here

This is the attack of 2023–25. Clorox alleges in its lawsuit that Cognizant’s help desk reset credentials without verification; Co-op’s attackers called its help desk; the UK’s NCSC told firms to review reset processes.

What a client or auditor asks to see

The written reset procedure, call-back or manager-approval records, and alerts on resets of privileged accounts.

Why software does not answer this

A procedure and a culture: call back on a number already on record, require manager approval for privileged accounts, and use phishing-resistant MFA so a reset alone is not enough. We list no product that verifies callers.

Knowing who you hired

BothNot a product

Identity and background verification at offer and onboarding, with in-person or verified-video steps for privileged roles.

1 obligation require it1 breach pattern it stopsNo software answers it

What it is

Identity and background verification at offer and onboarding, with in-person or verified-video steps for privileged roles.

Why it matters here

AuthBridge found discrepancies in 9.46% of IT/ITES candidates it checked (2024–25). The US Justice Department found North Korean IT workers inside more than 100 US companies in 2025.

What a client or auditor asks to see

Verification at offer, liveness checks for remote hires, and least-privilege access in the first weeks.

Why software does not answer this

Background-verification firms and a hiring process. We list no employee-verification product — the KYC tools in our catalogue verify customers, not candidates.

The six-hour runbook

BothNot a product

Who calls CERT-In, who calls each client, in what order, with what.

2 obligations require itNo software answers it

What it is

Who calls CERT-In, who calls each client, in what order, with what.

Why it matters here

One incident can start several clocks to several recipients — and filing one does not discharge another.

What a client or auditor asks to see

A runbook naming owners and recipients per client, and the date of the last drill.

Required by

Why software does not answer this

A document, a contact list and a rehearsal. Software can collect the evidence; it cannot make the calls.

The clauses you sign

BothNot a product

Audit rights, data location, subcontractor flow-down and incident terms — in your client contracts and your customers’ DPAs.

3 obligations require itNo software answers it

What it is

Audit rights, data location, subcontractor flow-down and incident terms — in your client contracts and your customers’ DPAs.

Why it matters here

Most of what binds a services firm arrives in a client’s contract; most of what binds a SaaS firm arrives in a customer’s data-processing agreement.

What a client or auditor asks to see

A clause register across client contracts, mapped to what you can actually deliver.

Why software does not answer this

Legal and commercial work. Contract tools can store the clauses; only you can negotiate them.

Guides do the vendor-neutral shortlisting with India pricing. Where no guide exists we name the products in our catalogue that answer the control, and say where that list is thin. General information, not legal advice.

Questions people ask

IT & ITES controls, answered

Short answers, each backed by the sources on this page.

Which security controls should an Indian IT company start with?

Those every obligation leans on, whichever half you are in: Detect and respond inside six hours; Logs kept, and producible; Phishing-resistant sign-in; Access that ends when the job does; Managed devices only; Email security and phishing training; Backups the attacker cannot reach; Vulnerability management and VAPT; Audit evidence: ISO 27001, SOC 2; Privacy operations for DPDP; Your own suppliers, managed; Client and customer data, encrypted and found.

What security controls do IT services firms need that product firms don't?

The ones for working inside clients' environments: Privileged access into client environments; Zero-trust access for distributed delivery; Leakage and insider risk on delivery floors; Isolated client workspaces; Your remote-management tools, locked down; Contact-centre and BPO operations.

What security controls do SaaS and software-product companies need?

Beyond the shared baseline, the ones for shipping software other people run: Source code and the build pipeline; Dependencies you can account for; Secrets and signing keys out of the code; Cloud posture and workloads; Application and API protection; Customer identity and account protection; AI features, secured and governed.

Which security controls can't be bought as software?

Verifying the caller before a reset; Knowing who you hired; The six-hour runbook; The clauses you sign. Each is a procedure, a hiring check, a runbook or a contract: the places the 2023 to 2025 attacks on IT firms got in.