// CONSULTANCY AS A SERVICE

Security expertise,
on your terms.

Two advisory practices — cyber security and secure development — delivered by engineers who build compliance software for a living. Project-based, retainer or workshop, priced for Indian businesses rather than global consultancy rate cards.

ISO 27001:2022DPDP Act 2023SOC 2CERT-InOWASP
// WHY BITKOSH

Advisory from a team that ships the tooling, not just the slide deck.

Most compliance advice arrives as a spreadsheet and a fixed-fee invoice. We build a 35-framework compliance platform in-house, which means our consultants work with the same control libraries, crosswalks and evidence workflows they recommend to you. India-first expertise across DPDP Act, CERT-In and RBI requirements that global firms treat as an afterthought — with published rate cards and no scope-creep surprises.

// DELIVERY STANDARD

Built for decisions, evidence and accountable execution.

Whether this is a commercial engagement or a government program, the work is structured so technical teams can act and leadership can verify progress.

01 / Discovery

Understand the business

An intake call to understand your drivers — a certification deadline, investor due diligence, an enterprise customer questionnaire or a regulatory mandate — before anyone proposes a scope.

02 / Scoping

Fixed scope, fixed price

A written statement of work with explicit inclusions and exclusions, timeline, pricing and acceptance criteria. Changes go through a documented change request, not a surprise invoice.

03 / Delivery

Evidence, then handover

Peer-reviewed deliverables with severity-rated findings, a prioritised remediation roadmap with named owners, a close-out walkthrough and 30 days of follow-up support included.

// PROJECT OUTPUTS

What your team can take into the next review.

  • Statement of work with explicit scope and exclusions
  • Severity-rated findings (CVSS v4 or ISO 27005 risk matrix)
  • Prioritised remediation roadmap with owners and timelines
  • Executive summary your board or customers can read
  • Close-out walkthrough plus 30 days of follow-up support
// BUILT FOR

Designed around the people who own the outcome.

  • Startups preparing for Series A due diligence
  • SMEs pursuing ISO 27001 or DPDP Act compliance
  • HealthTech and FinTech teams facing sector regulation
  • Engineering leaders embedding security into the SDLC
  • International SaaS companies needing offshore AppSec depth
01

ISO 27001:2022 Implementation

End-to-end ISMS setup — scope, risk assessment, Statement of Applicability, policy suite, internal audit and certification body liaison. The 2013-edition transition deadline has passed, so legacy certificates now need re-certification, not a gap plan.

02

DPDP Act 2023 Compliance

Data mapping, privacy impact assessments, consent management design, Data Protection Officer advisory and Significant Data Fiduciary obligations for India’s data protection regime.

03

Multi-Framework Crosswalk

Map overlapping controls across ISO 27001, SOC 2, HIPAA, GDPR and DPDP using our crosswalk engine — comply once, satisfy many, instead of running each framework as a separate project.

04

Risk & Vendor Assessment

ISO 27005 / NIST-aligned risk registers, third-party security reviews, and cloud posture audits against CIS Benchmarks across AWS, Azure and GCP.

05

Virtual CISO (vCISO)

Fractional security leadership on retainer — board-level governance, programme management, regulatory interaction and security budget oversight without a full-time hire.

06

CERT-In Readiness

Incident response planning for India’s mandatory 6-hour reporting window, 180-day log retention architecture, and VPN/VPS KYC procedures.

07

DevSecOps Pipeline Hardening

Integrate SAST, DAST, SCA, container scanning, IaC scanning and secrets detection into GitHub Actions, GitLab CI or Jenkins — security gates that developers actually keep.

08

Application Security Testing

Architecture threat modelling, secure code review, web and API penetration testing against OWASP methodology, plus mobile and container security assessment.

09

Secure Development Training

OWASP Top 10 workshops, language-specific secure coding for Java, Python, Node.js and Go, threat modelling sessions and hands-on lab exercises for your engineers.

Frequently Asked Questions

How do you price engagements?
Three models: fixed-fee for defined scopes like gap assessments and penetration tests; monthly retainers for vCISO and fractional AppSec leadership; and per-session pricing for workshops and training. Indian engagements are priced roughly 60–70% below Big4 rates, and DPIIT-recognised startups get a discount on their first engagement.
Do we have to buy your compliance platform to work with you?
No. The consultancy stands on its own. Clients who do adopt the platform get a discount on advisory work and vice versa, but every engagement is delivered independently of whether you license our software.
My ISO 27001 certificate is on the 2013 edition — what now?
The three-year transition window closed on 31 October 2025, so 2013-edition certificates have expired. That means re-certification against ISO 27001:2022 rather than a routine transition audit. We start with a gap assessment against the 2022 Annex A controls and build the remediation plan from there.
Can you work with international clients?
Yes — we take export engagements across the US, UK, EU and APAC, positioned as senior offshore talent at mid-market pricing. Note that zero-rated GST treatment on service exports depends on our Letter of Undertaking filing; we confirm the applicable tax treatment in writing before invoicing.
Who actually does the work?
Practising engineers, not a sales team handing off to juniors. Every deliverable goes through peer review before it reaches you, and all findings are manually verified — we do not ship raw scanner output with false positives in it.
Let's build together

Tell us what you're up against.

Book a free 30-minute consultation with our engineering team — no obligation, just a clear, practical plan.