01 / 07 · Practice Area
Cybersecurity & Data Protection
Counsel from inside the SOC, not from the sidelines.
We advise boards, GCs and CISOs on the DPDP Act, CERT-In obligations, breach response and regulator-facing strategy - led by a partner with 20+ years of operating-side security experience. We don't arrive at your incident asking your CISO to explain the architecture. We translate technical reality into regulatory posture, and regulatory posture back into engineering decisions, on the same day.
Who this is for
Who we built this practice for
This practice is built for the people who carry cyber and data risk on their personal docket, not the ones who read about it in a quarterly report. Boards and General Counsel managing enterprise-wide cyber exposure find a partner who can sit through a four-hour technical briefing and then translate it into a one-page risk note for the audit committee the same evening. CISOs building or maturing a security program get legal coverage that moves at the cadence of their roadmap, not the litigation calendar, with practical input on contracts, third-party risk, and DPDP obligations as they are designed in, not bolted on.
Enterprises operating under the DPDP Act, sectoral data rules, and CERT-In directions turn to us when the compliance position needs to be defensible in front of a regulator, not just credible in front of an internal review. Global Capability Centers managing cross-border data into a parent group rely on us to keep the architecture and the law aligned across jurisdictions. And when an incident is live, we are the team that picks up the call, opens privilege, and starts the clock on the same hour, without waiting for an engagement letter to be countersigned.
Scope
What this practice covers
Our work spans the full lifecycle of data and security risk, from peacetime program design to live incident response. On the compliance side, we run DPDP gap assessments that translate the statute into operational obligations a CISO and a CTO can actually plan against, then act as outsourced or co-sourced Data Protection Officer for organizations that need senior, accountable DPO coverage without building the function internally. We design and harden consent architectures, data processing agreements, vendor risk frameworks, and the cross-border transfer mechanisms (SCCs, intra-group transfer agreements, adequacy mapping) that determine whether your data flows survive scrutiny.
When something breaks, we run day-one breach response under privilege. That means CERT-In notification within the 6-hour window where the rule bites, parallel sectoral and DPDP-side filings where applicable, evidence preservation, regulator-facing chronology, and the carefully managed communication trail that prevents an early operational note from becoming a later admission. We coordinate with your in-house SOC, MSSP, or DFIR firm, and we translate their technical reality into the regulatory posture they need it to be.
Around the perimeter, we advise on cyber insurance placement and claim notification, board-level governance of cyber risk (charter design, reporting cadence, escalation protocols), tabletop and red-team exercise review, and the controls and contractual positions that determine how a future incident will be litigated, regulated, and underwritten. The throughline is the same in every engagement: the legal posture and the engineering reality are designed together, or they will fail together.
Our Process
How the work moves
Step 01
Triage
On first contact we scope the incident or the matter, open privilege, identify the regulators in play and the clocks already running, and stand up a single legal point of contact for your technical and communications teams. This first hour shapes everything that follows; getting the perimeter right early is what keeps later submissions consistent.
Step 02
Containment posture
We align the technical containment plan with the legal narrative as it is being written. Evidence is preserved in a way that holds up later, internal communications are routed through privilege, and the operational and legal stories stop drifting apart before the regulator ever sees either.
Step 03
Regulator strategy
We draft and file the CERT-In, DPDP and sectoral notifications, manage multi-round written submissions, and prepare witnesses for hearings. Every submission is built to be consistent with every other submission, across regulators and across time, so the record reads as one coherent account.
Step 04
Close-out
We negotiate closure on terms that minimize exposure, document remediation in a defensible record, and translate the lessons into the controls, contracts and governance updates that prevent a repeat. Many engagements convert into ongoing DPO or managed compliance work from this point.
What you get
Outcomes you can plan against
You get a defensible compliance posture from day one, no privilege leakage, no contradictions a regulator can later exploit, no documentation trail that surprises you eighteen months in. Regulator close-out is faster because the case has been built as the matter unfolded, not reverse-engineered after a notice arrives. On live incidents, you get same-day triage and legal guidance under privilege, which means your engineers can stabilize the stack while we manage the legal exposure in parallel.
By the numbers
Key facts
- CERT-In Rule 4(2): breach notification required within 6 hours of discovery.
- DPDP Act penalties: up to ₹250 crore for serious violations.
- Incident response with aligned counsel: 3-7 days vs. 15-45 days without.
- Cross-border data transfers require a defined legal mechanism (SCC, adequacy or contractual safeguards).
- Most enterprises still lack a documented DPDP compliance plan.
- Privilege attaches from first contact - shared facts stay protected.
Frequently Asked
Common questions
Do you handle DPDP compliance end to end?
Yes. From gap assessment and DPO advisory through breach notification and regulator engagement.
What is your role in a live cyber incident?
We read the architecture and the law in parallel on day one, under privilege. We build a regulator-facing narrative while you stabilize the stack.
What's the CERT-In 6-hour clock?
CERT-In rules require breach notification within 6 hours of discovery. We handle the legal triage, you handle the technical response.
Can we work with our existing MSSP or SOC provider?
Yes, we coordinate. We translate their technical findings into a defensible legal narrative.
How do cross-border data transfers work under DPDP?
Transfers require a legal mechanism (SCCs, BCRs, or adequacy). We assess your flows and build the compliant structure.
Is first contact privileged?
Yes. Attorney-client privilege attaches from your first communication.
How do you price incident response?
Live incidents are fixed-fee, day-one triage. Ongoing work is hourly or phased.
What happens after the breach is closed?
We help you build forward. Many clients move into ongoing compliance advisory.
Next Step
Discuss a cybersecurity or data protection matter.
A confidential conversation with our managing partner to scope the right approach.
Book a Consultation