DPDP Act 2023 Readiness
A gap assessment against the DPDP Act — consent, data inventory, retention, breach notification, grievance handling — with a prioritized remediation report your board can act on.
I help NBFCs, fintechs, and SMEs across Gujarat become audit-ready for the DPDP Act 2023 and RBI directions — with enterprise-grade security governance, on terms that fit their size.
Each engagement produces something concrete — a report, a control set, a closure log — not an open-ended invoice. Start small, scale into ongoing oversight when it earns its place.
A gap assessment against the DPDP Act — consent, data inventory, retention, breach notification, grievance handling — with a prioritized remediation report your board can act on.
Ongoing security leadership: policy, governance, audit support, vendor risk, and incident readiness — the role of a CISO without the full-time cost.
Policy framework, control implementation guidance, and audit preparation mapped to ISO 27001 Annex A and the applicable RBI master directions for your entity type.
Coordinated vulnerability assessment and penetration testing of your applications and network, delivered as a closure-tracked report with remediation guidance.
About
I’m Pranay Modi, Group CISO at MAS Financial Services Ltd and its subsidiaries. Across 10+ years of total experience, I’ve built and run security programs inside regulated financial institutions — SOC operations, data loss prevention, governance and compliance against RBI, NHB, SEBI, and ISO 27001, and, most recently, DPDP Act readiness.
Smaller firms face the same regulatory expectations as large ones, but rarely have the budget for a full-time security chief. I close that gap — the same rigor, sized to your organization.
A selection of security, compliance, and productivity tools I’ve designed and developed in-house.
A comprehensive, self-hosted governance, risk & compliance platform I designed and built end to end. Twenty-four modules span risk and asset management, policy and audit management, vulnerability and VAPT tracking, incident and CAPA workflows, vendor risk, access reviews, SIEM (Wazuh) integration, security-awareness training and phishing simulation, and a full DPDP Act 2023 compliance suite — mapped to six regulatory frameworks, with AI features running entirely on-premise so no data leaves the organisation.
A custom endpoint data-loss-prevention system: a Windows agent that blocks exfiltration via USB, clipboard, print, screenshots, and uploads — with PAN/Aadhaar detection, run from a central console.
View detailsA self-hosted document platform: 13 PDF tools plus a full electronic-signature workflow with audit trails, document verification, and enterprise AD/SSO login.
View detailsA phone-based multi-factor / passwordless login system for Windows: a native credential provider, an Android authenticator (QR enrollment + TOTP + push), and an Active-Directory-integrated proxy.
View detailsA sequence, not a one-off audit. Readiness should hold between assessments — not spike only when one is due.
Understand your data, systems, and obligations. Surface the gaps that actually carry risk.
A remediation plan ranked by risk and regulatory exposure — signal, not noise.
Policies, controls, and tooling put in place with your team, at a pace they can absorb.
Ongoing oversight so your posture holds steady through the next audit and beyond.
I speak at colleges, universities, and industry forums — bringing security from inside regulated finance to students and teams entering the field. Available for guest lectures, workshops, and panels.
The first 30-minute conversation is free — a straight read on your DPDP and RBI exposure, no obligation.