vCISO · DPDP & RBI Readiness

Security leadership for firms that aren’t ready to hire a CISO.

I help NBFCs, fintechs, and SMEs across Gujarat become audit-ready for the DPDP Act 2023 and RBI directions — with enterprise-grade security governance, on terms that fit their size.

Frameworks RBI NHB SEBI ISO 27001 DPDP Act 2023
Services

Fixed-scope engagements, priced to be an easy decision.

Each engagement produces something concrete — a report, a control set, a closure log — not an open-ended invoice. Start small, scale into ongoing oversight when it earns its place.

01 / Assessment

DPDP Act 2023 Readiness

A gap assessment against the DPDP Act — consent, data inventory, retention, breach notification, grievance handling — with a prioritized remediation report your board can act on.

1–2 weeks · one-time On request
02 / Retainer

Virtual CISO

Ongoing security leadership: policy, governance, audit support, vendor risk, and incident readiness — the role of a CISO without the full-time cost.

Monthly retainer On request
03 / Project

ISO 27001 & RBI Readiness

Policy framework, control implementation guidance, and audit preparation mapped to ISO 27001 Annex A and the applicable RBI master directions for your entity type.

Project · scoped On request
04 / Project

Security Audit & VAPT

Coordinated vulnerability assessment and penetration testing of your applications and network, delivered as a closure-tracked report with remediation guidance.

Project · scoped On request
Pranay Modi About

I’ve run security inside regulated finance. Now I bring it to firms that can’t yet staff it.

I’m Pranay Modi, Group CISO at MAS Financial Services Ltd and its subsidiaries. Across 10+ years of total experience, I’ve built and run security programs inside regulated financial institutions — SOC operations, data loss prevention, governance and compliance against RBI, NHB, SEBI, and ISO 27001, and, most recently, DPDP Act readiness.

Smaller firms face the same regulatory expectations as large ones, but rarely have the budget for a full-time security chief. I close that gap — the same rigor, sized to your organization.

10+
Years’ total experience
5
Regulatory frameworks
Ahmedabad
Gujarat · serving all India
Projects

I don’t only advise on controls — I build them.

A selection of security, compliance, and productivity tools I’ve designed and developed in-house.

Flagship · GRC Platform

IT GRC & InfoSec Audit Portal

A comprehensive, self-hosted governance, risk & compliance platform I designed and built end to end. Twenty-four modules span risk and asset management, policy and audit management, vulnerability and VAPT tracking, incident and CAPA workflows, vendor risk, access reviews, SIEM (Wazuh) integration, security-awareness training and phishing simulation, and a full DPDP Act 2023 compliance suite — mapped to six regulatory frameworks, with AI features running entirely on-premise so no data leaves the organisation.

RiskAuditVAPTSIEM / WazuhIncident & CAPAPolicyVendor RiskDPDP SuiteTraining & Phishing
24Modules
300+API endpoints
6Frameworks
100%On-prem AI
View details
Data Protection

AegisDLP — Endpoint DLP

A custom endpoint data-loss-prevention system: a Windows agent that blocks exfiltration via USB, clipboard, print, screenshots, and uploads — with PAN/Aadhaar detection, run from a central console.

View details
E-Signature

PDFStudio — PDF & E-Sign Suite

A self-hosted document platform: 13 PDF tools plus a full electronic-signature workflow with audit trails, document verification, and enterprise AD/SSO login.

View details
Authentication

AuthGuard — MFA for Windows Login

A phone-based multi-factor / passwordless login system for Windows: a native credential provider, an Android authenticator (QR enrollment + TOTP + push), and an Active-Directory-integrated proxy.

View details
Approach

How an engagement runs.

A sequence, not a one-off audit. Readiness should hold between assessments — not spike only when one is due.

01

Assess

Understand your data, systems, and obligations. Surface the gaps that actually carry risk.

02

Prioritize

A remediation plan ranked by risk and regulatory exposure — signal, not noise.

03

Implement

Policies, controls, and tooling put in place with your team, at a pace they can absorb.

04

Sustain

Ongoing oversight so your posture holds steady through the next audit and beyond.

Speaking

Guest lectures & talks.

I speak at colleges, universities, and industry forums — bringing security from inside regulated finance to students and teams entering the field. Available for guest lectures, workshops, and panels.

Careers in Cybersecurity The DPDP Act, Explained Inside a Real SOC Governance, Risk & Compliance Threats Facing BFSI Building a Security Mindset
Get in touch

Tell me where your firm stands today.

The first 30-minute conversation is free — a straight read on your DPDP and RBI exposure, no obligation.