Zero Trust + DPDPA

A security baseline that actually fits an Indian SMB.

You don't need a 200-page policy binder. You need MFA on every account, encrypted laptops, backed-up files, monitored endpoints and an email gateway that catches phishing. We deliver that, properly, in 4-6 weeks.

Free security audit WhatsApp our team
Sound familiar?

Most owners don’t lose sleep over “cybersecurity.” They lose sleep over specific things.

If any of these are quietly running through your head, you’re thinking about it for the right reasons.

  • “If one staff member clicks the wrong link, are we finished?”
  • “I don’t actually know if MFA is on for everyone.”
  • “Half my team uses personal laptops. I have no visibility.”
  • “We collect customer data and DPDPA scares me a little.”
  • “If ransomware hit tonight, would our backups even restore?”
  • “We got a fake-CEO email last month. It almost worked.”
Right for: 25–500 staff Healthcare / Finance Schools handling student data
4–6 week rollout. CIS-aligned. DPDPA-ready. Audit evidence included.
Five pillars we harden

Zero Trust, translated for real businesses.

We follow Microsoft's Zero Trust reference architecture, mapped to CIS Controls v8 and aligned with India's Digital Personal Data Protection Act, 2023. No jargon overload - just controls you can audit.

Identity (Entra)
Devices (Intune)
Data (Purview / DLP)
Network (NSG, VPN)
Email (Defender for O365)
Compliance (Purview)

What's included

  • Microsoft Secure Score baseline & gap report
  • Conditional Access & MFA enforcement
  • Intune enrolment + BitLocker encryption
  • Compliance & configuration profiles
  • Anti-phishing & safe-links / safe-attachments
  • DLP policies for PAN, Aadhaar, GSTIN, credit cards
  • Sensitivity labels & encryption for documents
  • Audit log retention + alerting playbook
  • Incident response runbook + IR drill

Our 6-step security uplift

Audit

2-week assessment of identity, devices, email, data and your current Microsoft Secure Score.

Prioritise

Risks ranked by likelihood, impact and effort. You get a "fix this Monday" shortlist plus a 90-day plan.

Identity hardening

MFA, Conditional Access, break-glass accounts, admin tier separation and PIM where licensed.

Endpoint hardening

Intune profiles, BitLocker, attack-surface reduction rules and patch baselines for Windows + macOS.

Data & email

DLP for sensitive data, sensitivity labels, anti-phishing and email authentication (SPF/DKIM/DMARC).

Operate

Monthly security review, Secure Score tracking and an annual tabletop incident response drill.

Indicative project pricing

Get a precise quote
Baseline

Up to 25 users

From ₹ 55,000

Excl. licences & GST
  • Secure Score audit
  • MFA & Conditional Access
  • BitLocker via Intune
  • Email anti-phishing
Request quote
Most Popular

26-100 users

From ₹ 1,45,000

Excl. licences & GST
  • Full Zero Trust baseline
  • Intune device compliance
  • Purview DLP & labels
  • IR runbook + tabletop drill
Request quote
Enterprise

100+ users

Custom

Multi-site, regulated industries
  • CIS L1/L2 alignment
  • DPDPA & ISO 27001 mapping
  • Sentinel SIEM integration
  • Quarterly security reviews
Talk to sales

FAQs

Will this make our staff hate us?
No. We pilot every change with 10 users first, write the comms in plain English (and Hindi), and exempt low-risk situations - so the day-to-day experience improves more than it disrupts.
Do we need Microsoft 365 E5 for this?
No. The baseline runs on Business Premium for SMBs (which includes Defender, Intune and Entra ID P1). E5 unlocks Sentinel, Defender for Identity and advanced Purview - useful for regulated or 100+ user organisations.
Are you DPDPA-aware?
Yes. Our DLP and labelling templates include India-specific sensitive types (PAN, Aadhaar, GSTIN, IFSC, vehicle registration). We map controls to the DPDPA principles of purpose limitation, data minimisation and breach notification.
What if we already use a different antivirus?
We can either replace it with Defender for Endpoint (recommended for full integration) or run Defender in passive mode alongside it. Either way, you keep visibility through the Microsoft 365 Defender portal.
How do you measure success?
Microsoft Secure Score uplift, % users on MFA, % devices encrypted & compliant, mean time to detect/respond, and number of phishing emails caught vs. delivered. Reported monthly.