Serving Indian Enterprises, Startups & Boards

India's Trusted
AI Governance
& Cyber Risk Advisory

Helping Indian organizations navigate the DPDP Act, CERT-In mandates, ISO 42001, and global AI regulations — with expert governance advisory, Enterprise Architecture guidance, and Technology Strategy that turns compliance into competitive advantage.

🔴 DPDP Act — Act Now ✅ CERT-In ISO 42001 ISO 27001 GDPR SEBI CSCRF
DPDP Act Rules Notified
Data Fiduciaries must appoint DPO & implement consent frameworks
CERT-In Cyber Directions
Mandatory 6-hour incident reporting & 180-day log retention
SEBI CSCRF 2024
Cybersecurity framework mandatory for all SEBI-regulated entities
EU AI Act — India Impact
Indian SaaS & tech companies serving EU must comply

About Cybercalm

India-Focused AI Governance
& Cyber Risk Advisory

Maya MS — AI Governance, Cybersecurity & Privacy Advisor
Maya MS
Enterprise Architect & Governance Advisor
Founder, Cybercalm · India
20+ Yrs AI Governance Advisor DPDP & GDPR Advisor ISO 42001 ISO 27001 vCTO vCISO vCDPO

Cybercalm is India's independent advisory platform focused on helping organizations manage risks from AI systems, cybersecurity threats, and data privacy obligations under Indian and global regulatory frameworks.

Led by Maya MS — an Enterprise Architect and Governance Advisor with over 20+ years of experience — Cybercalm brings deep technical expertise and practical governance leadership to Indian enterprises, startups, fintechs, and boards.

We specialize in India's DPDP Act, 2023, CERT-In cyber directions, SEBI CSCRF, and RBI cybersecurity frameworks — alongside international standards ISO 42001, ISO 27001, GDPR, and the EU AI Act.

Our approach is methodical, jargon-free, and designed for Indian business realities — delivering governance programs that regulators, boards, and investors rely on.

India Regulatory & Global Frameworks
DPDP Act 2023 🔴 CERT-In Directions 🔴 SEBI CSCRF ✅ RBI Cyber Framework ISO 42001 ISO 27001 GDPR EU AI Act NIST AI RMF MeitY AI Policy
⚠️ CERT-In Compliance — Are You Covered?

India's CERT-In directions mandate 6-hour incident reporting, virtual asset obligations, and log retention for minimum 180 days. Non-compliance attracts penalties.

Cybercalm conducts CERT-In readiness assessments →

India's Data Protection Law

Digital Personal Data
Protection (DPDP) Act, 2023

India's landmark data protection legislation is now in force. The DPDP Act introduces binding obligations for every organization that collects, processes, or stores the personal data of Indian citizens.

Whether you are a startup, enterprise, healthcare platform, or fintech — DPDP compliance is now a board-level priority. Penalties can reach ₹250 crore.

Cybercalm provides end-to-end DPDP readiness advisory — from gap assessment and policy drafting to DPO appointment support and ongoing compliance management.

Act Now — Rules Are Notified.

Non-compliance with DPDP Act obligations carries penalties up to ₹250 crore per violation.

  • Data Fiduciary Obligations AssessmentIdentify personal data you collect and your legal basis under the DPDP Act.
  • Consent Framework DesignImplement lawful, specific, and withdrawable consent mechanisms.
  • Data Protection Officer (DPO) Supportvirtual CDPO services or advisory for compliant DPO appointment.
  • Data Principal Rights MechanismBuild processes to handle access, correction, and erasure requests.
  • Cross-border Data Transfer ComplianceAdvisory on permitted countries and contractual safeguards.
  • DPIA & Privacy-by-Design IntegrationEmbed privacy risk assessments into product and vendor processes.

Advisory Services

How Cybercalm Helps
Indian Organizations

Request a Service Briefing
01

AI Governance Advisory

Responsible AI governance frameworks aligned with ISO 42001, EU AI Act, and MeitY's emerging AI policy.

  • ISO 42001 Readiness
  • AI risk assessments & frameworks
  • EU AI Act readiness
  • MeitY AI policy alignment
  • Responsible AI lifecycle governance
02

Cybersecurity Governance

Meeting CERT-In, SEBI CSCRF, and RBI mandates with security governance programs built for Indian regulations.

  • ISO 27001 advisory
  • CERT-In Compliance Assessment
  • SEBI CSCRF Implementation
  • RBI Cybersecurity Framework
  • Information Security Program Management
03

Data Privacy Advisory

End-to-end DPDP Act compliance advisory — India's most urgent regulatory priority — plus GDPR for EU-facing businesses.

  • DPDP Act Compliance — Full Suit
  • Data Protection Impact Assessments (DPIA)
  • Records of Processing Activities (RoPA)
  • Privacy-by-Design & Privacy-by-Default
  • Data Subject Rights & Consent Management
04

Fractional Leadership

Senior governance leadership on demand — ideal for Indian startups and scaleups that need a CISO or CDPO without full-time cost.

  • Virtual CTO (vCTO)
  • Virtual CDPO (vCDPO)
  • Virtual CISO (vCISO)
  • Investor & board briefings
  • DPDP DPO statutory advisory

Who We Serve

Built for Indian Organizations
at Every Stage

AI Startups & SaaS Companies

Build AI governance from day one. DPDP Act compliance, ISO 42001 readiness, and EU AI Act advisory for Indian AI-native companies scaling globally.

Fintech & BFSI Companies

Navigate RBI Cybersecurity Framework, SEBI CSCRF 2024, and DPDP Act — advisory tailored for India's banking, financial services, and insurance sector.

Enterprise Boards & CXOs

Board-ready cyber risk briefings, AI governance dashboards, and DPDP compliance status reporting for enterprise leadership and audit committees.

Healthcare & EdTech Platforms

Sensitive personal data under DPDP Act carries heightened obligations. Sector-specific privacy governance for India's healthcare and education platforms.

Indian Companies with Global Operations

Dual-compliance advisory for Indian companies subject to DPDP Act domestically and GDPR, EU AI Act, or other international frameworks.

CERT-In Regulated Entities

Mandatory CERT-In direction compliance — 6-hour incident reporting, VPN/cloud usage reporting, and log retention for critical sector organizations.

  • Independent — No Vendor Bias
  • 20+ Years Enterprise Experience
  • DPDP · CERT-In · ISO 42001 · ISO 27001
  • Practical · Jargon-free · India-focused

India Regulatory Landscape

Key Regulations Your
Organization Must Address

Urgent — Act Now

Digital Personal Data Protection Act, 2023

Binding Data Fiduciary obligations, consent requirements, data principal rights, and cross-border transfer rules. Penalties up to ₹250 crore.

Authority: MeitY · Data Protection Board of India
Get DPDP Advisory →
In Force

CERT-In Cyber Security Directions, 2022

Mandatory 6-hour incident reporting, 180-day log retention, VPN and cloud usage reporting for all Indian organizations.

Authority: CERT-In · MeitY
Get CERT-In Assessment →
Effective 2024

SEBI Cybersecurity & Cyber Resilience Framework (CSCRF)

Mandatory cybersecurity framework for stock brokers, depositories, mutual funds, and all SEBI-regulated entities.

Authority: SEBI
Get SEBI CSCRF Advisory →
Ongoing

RBI Master Directions on Cyber Security

Cybersecurity and IT risk management requirements for banks, NBFCs, and payment system operators.

Authority: Reserve Bank of India
Get RBI Cyber Advisory →
International

EU AI Act — India Impact

Indian SaaS platforms and AI developers serving EU markets must comply with the EU AI Act — including conformity assessments for high-risk AI systems.

Authority: European AI Office
Get EU AI Act Advisory →
Global Standard

ISO 42001 — AI Management System

The international standard for AI governance. Enterprise clients and global partners are now requiring ISO 42001 compliance in vendor agreements.

Authority: ISO · Bureau of Indian Standards
Get ISO 42001 Readiness →

AI Governance in Practice

Responsible AI Advisory
for Indian Organizations

India is witnessing rapid AI adoption across banking, healthcare, e-commerce, HR, and government. Yet most organizations lack governance structures to manage AI risks — creating significant regulatory, reputational, and operational exposure.

MeitY's AI policy framework is evolving. The EU AI Act already applies to Indian companies serving European markets. ISO 42001 is now appearing in enterprise vendor agreements as a mandatory requirement.

Cybercalm helps Indian organizations design, implement, and maintain AI governance programs that satisfy regulators, investors, and customers — with practical frameworks built for Indian business realities.

ISO 42001 EU AI Act MeitY AI Policy NIST AI RMF Responsible AI

AI Risk Assessment

Identifying bias, explainability failures, data quality risks, and regulatory gaps in AI systems.

AI Governance Framework Design

Policies, controls, roles, and oversight structures for responsible AI across the product lifecycle.

ISO 42001 Readiness & Implementation

Gap assessments and implementation roadmap for the international AI management system standard.

EU AI Act for Indian Exporters

Conformity assessment support for Indian AI companies serving EU clients and markets.

Board & Investor AI Briefings

Translating AI governance risk into clear narratives for boards, audit committees, and investors.

Get in Touch

Start Your Governance
Advisory Engagement

Let's Work Together
Whether you need DPDP Act compliance, a Virtual CISO, ISO 42001 readiness, or board-level AI governance — Cybercalm delivers practical guidance tailored for Indian organizations.
🇮🇳 India-focused. We understand MeitY, CERT-In, SEBI, RBI, and IRDAI — and design governance programs that work within Indian business and legal realities.

Send an Enquiry