The practice in detail
What this covers
- Security programme ownership
- Board and audit committee reporting
- Policy and governance framework
- Vendor and contract security review
- Budget and roadmap planning
What we do
What the regulator asks for
Start here
Six practices, one lifecycle: advise, assess, comply, protect, monitor, respond. Most engagements begin with an assessment and stay for the monitoring.
Prime can sign the audit report your regulator will accept.
Scope an engagementAudit & testing
Certification & privacy
Arrived with a deadline rather than a question? Every page above states the scope, the evidence produced and the typical duration.
All requirementsRegulated
Operational
Data-intensive
Each industry page names the specific obligations that apply — SEBI CSCRF for market infrastructure, CEA guidelines for utilities, DPDP for everyone holding personal data.
All industriesThirty minutes with a practitioner rather than a salesperson. If the requirement somebody has handed you does not match what you actually need, that is a more useful thing to find out now than in week nine.
Or reach the incident line directly on +91 9147712576, monitored 24×7 from Kolkata.