Field Notes

We publish field notes, not marketing content. If we have an opinion that is not load-bearing, we do not publish it.

01 · On the shelf

These five are being written now, in this order. Nothing publishes here until it is worth your time, which is also why there are five and not thirty.

  1. SOC 2 for founders: the operating manual.

    The piece we wish existed when we ran our first SOC 2. What controls auditors actually open on Day 1, which evidence packets matter, what enterprise customers ask for in the procurement cycle after the report lands.

    In the works
  2. The auditor opens seven documents on Day 1.

    The order matters. Get the first three right and the audit hums; get them wrong and every subsequent control gets re-asked. The seven, ranked, with what each is actually being read for.

    In the works
  3. How to lose a board on cybersecurity in one meeting.

    Four failure patterns we have watched up close. The CRQ-in-dollars-without-context deck. The NIST-IDs-on-screen deck. The two slides that quietly land instead.

    In the works
  4. DPDP Right Answers: what to actually do.

    ₹250 crore penalty exposure. Forty-seven pages of rules. Six pages of useful interpretation, the consent-pattern table we run with clients, and the three cross-border clauses that come up in every contract negotiation.

    In the works
  5. The SEBI CSCRF reading list.

    Board cyber maturity attestation, audit-committee briefing, CRQ in rupees. The reference document we hand to every SEBI-regulated CISO we work with, annotated with the three questions a SEBI inspector opens with.

    In the works