These five are being written now, in this order. Nothing publishes here until it is worth your time, which is also why there are five and not thirty.
- In the works
SOC 2 for founders: the operating manual.
The piece we wish existed when we ran our first SOC 2. What controls auditors actually open on Day 1, which evidence packets matter, what enterprise customers ask for in the procurement cycle after the report lands.
- In the works
The auditor opens seven documents on Day 1.
The order matters. Get the first three right and the audit hums; get them wrong and every subsequent control gets re-asked. The seven, ranked, with what each is actually being read for.
- In the works
How to lose a board on cybersecurity in one meeting.
Four failure patterns we have watched up close. The CRQ-in-dollars-without-context deck. The NIST-IDs-on-screen deck. The two slides that quietly land instead.
- In the works
DPDP Right Answers: what to actually do.
₹250 crore penalty exposure. Forty-seven pages of rules. Six pages of useful interpretation, the consent-pattern table we run with clients, and the three cross-border clauses that come up in every contract negotiation.
- In the works
The SEBI CSCRF reading list.
Board cyber maturity attestation, audit-committee briefing, CRQ in rupees. The reference document we hand to every SEBI-regulated CISO we work with, annotated with the three questions a SEBI inspector opens with.