We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Cybersecurity blog

Choosing a Cybersecurity Company in Delhi NCR

PCI SSC Qualified Security Assessor — CYBERSIGMA CONSULTING SERVICES LLP

QSA Authorised
CEMEA · Asia Pacific · USA

Choosing a Cybersecurity Company in Delhi NCR

A CISO in Gurugram called me on a Sunday. His board had approved a cybersecurity vendor the previous Friday, chosen because the quote was the lowest of five and the sales deck had the most logos. By Sunday, a ransomware note was sitting on his file server, and the vendor's incident number rang out to a voicemail box that was full. That is the real cost of choosing wrong, and it is almost never on the invoice.

Delhi NCR has more cybersecurity companies per square kilometre than almost anywhere in India. Cyber Hub in Gurugram, the tech parks in Noida and Greater Noida, the consulting firms in Nehru Place and Connaught Place. Everyone has a website that says end-to-end security and zero-trust and AI-powered. Very few of them can sit across from a CERT-In auditor, or an RBI examiner, or a PCI QSA, and hold their ground. This is how you tell the two apart before you sign.

Start with one question: are they CERT-In empanelled?

CERT-In is the Indian Computer Emergency Response Team, the national nodal agency for cybersecurity under the Ministry of Electronics and Information Technology. It maintains a published list of empanelled information security auditing organisations. If a vendor cannot give you their empanelment reference and tell you which cycle it belongs to, most of your regulatory conversations are already over.

This matters because a growing number of Indian obligations do not accept just any audit. They accept an audit by a CERT-In empanelled auditor. RBI's guidelines for banks, NBFCs and payment operators expect it. SEBI's Cyber Security and Cyber Resilience Framework (CSCRF) for regulated entities expects it. The 2022 CERT-In directions on incident reporting expect regulated bodies to work with empanelled auditors. If your partner is not on the list, you will pay them, and then pay someone else to do the audit that actually counts.

Ask three follow-up questions. First, is the empanelment current, not lapsed between cycles. Second, will the named auditors on your engagement be their own staff or subcontractors flown in for the signature. Third, can they show you a redacted audit report they have actually issued, so you can judge whether it reads like evidence or like a template with your logo dropped in.

The four things a Delhi NCR enterprise actually needs

Most buyers conflate cybersecurity into one line item. In practice, an enterprise here needs four distinct capabilities, and very few firms are genuinely strong at all four. Map your vendor against these before the demo dazzles you.

CapabilityWhat it really meansWho signs off on the outcome
VAPTVulnerability Assessment and Penetration Testing of your applications, networks and cloud, with proof-of-exploit not just scanner outputA CERT-In empanelled auditor issues the certificate your regulator or client asks for
Compliance auditIndependent assessment against a named standard: ISO 27001, PCI DSS v4.0, SOC 2, RBI, SEBI CSCRF, DPDPA QSA for PCI, a lead auditor for ISO, an empanelled auditor for CERT-In-referenced work
Incident readinessRetainer, playbooks, forensics capability, and a phone that a human answers at 2amAn incident commander who has run a real breach, not a helpdesk ticket
Ongoing monitoringManaged detection, log retention, and someone watching when your team is asleepA SOC analyst backed by an escalation path to a decision-maker

A firm that only does VAPT will hand you a PDF and disappear. A firm that only does compliance paperwork will pass your audit and leave you genuinely insecure. You want a partner who understands how the four connect, because a regulator will ask you to demonstrate all four in the same breath.

What VAPT should look like, and what usually gets sold instead

VAPT is the most commoditised and the most faked service in this market. A ₹40,000 VAPT and a ₹4,00,000 VAPT can both call themselves the same thing. The difference is what actually happened during the engagement.

Here is the tell. Ask to see a sample report. If every finding is a CVE number lifted straight from an automated scanner, with a generic remediation paragraph and a CVSS score, you bought an automated scan with a human invoice stapled to it. Real penetration testing chains findings. It shows that a low-severity information disclosure plus a misconfigured storage bucket plus a weak session token became full account takeover. That chain is the thing an attacker uses and a scanner never finds.

Scanner report dressed as VAPTGenuine VAPT
Raw list of CVEs, sorted by CVSSFindings ranked by real business impact and exploitability
No proof the issue is reachable or exploitableProof-of-concept, request/response evidence, screenshots of exploitation
Generic remediation text copied per findingSpecific fix mapped to your stack and config
No retest includedRetest after you fix, then a clean certificate
Delivered in 2 days for any size scopeScoped by asset count and complexity, typically 1-3 weeks

Indicative pricing in Delhi NCR, so you can sanity-check quotes. A focused web application VAPT runs roughly ₹60,000 to ₹2,50,000 depending on scope and authentication complexity. An external network VAPT for a mid-sized estate is often ₹1,00,000 to ₹3,00,000. A full-scope enterprise engagement with internal, external, cloud and application testing can run ₹5,00,000 upward. If a quote is far below the floor, someone is running a scanner and printing a certificate.

Compliance is where the amateurs get exposed

Compliance audits are unforgiving because the standards are specific and the assessor either knows the clauses or does not. This is where you separate a consultant from a content marketer.

For payments, PCI DSS v4.0 became mandatory over the 2024-25 transition, and it introduced future-dated requirements that many merchants in NCR have quietly ignored. Requirement 6.4.3 and 11.6.1 on payment page scripts and change-detection. Requirement 8.3.6 on minimum password length moving to twelve characters. Requirement 12.3.1 on targeted risk analyses. A serious QSA will ask which of these you have operationalised, not just documented. If your vendor cannot name a single v4.0 change off the top of their head, they are reading the standard for the first time on your project.

For data protection, the Digital Personal Data Protection Act 2023 (DPDP) is the one every Delhi NCR board is now asking about. The Act is passed; the Rules are being finalised. A competent partner will not sell you DPDP compliance as a certificate, because there is no certification scheme. They will help you build the consent architecture, the data principal rights workflow, the breach notification process, and the data fiduciary obligations, so that when the Data Protection Board comes calling, you can show intent and evidence.

StandardWho needs it in NCRWhat the auditor actually checks
ISO/IEC 27001:2022Any firm selling to enterprises or exporting services93 Annex A controls, risk treatment plan, real evidence over 3+ months
PCI DSS v4.0Anyone storing, processing or transmitting card dataScope of the CDE, segmentation, v4.0 future-dated requirements
SOC 2 Type IISaaS firms selling to US and global clientsTrust services criteria evidenced across a 6-12 month window
RBI directionsBanks, NBFCs, payment aggregators, fintechsIS audit, VAPT by empanelled auditor, incident reporting to RBI
SEBI CSCRFStockbrokers, AMCs, RIAs, market infrastructureCyber resilience controls, VAPT, SOC, empanelled-auditor sign-off
DPDP 2023Almost every business handling personal dataConsent, data principal rights, breach process, fiduciary duties

The 2am test: incident readiness

Every vendor sells prevention. Almost none can handle the day prevention fails. And under the CERT-In directions of April 2022, when it fails you have six hours to report certain incident types to CERT-In. Six hours. That clock starts the moment you notice, not the moment your vendor picks up.

Picture the scene. It is 1:40am on a Saturday. Your finance team's shared drive is encrypted. Your monitoring vendor's dashboard is red but nobody is watching it. You call the number in the SLA. It goes to voicemail. This is the single most common failure I see, and it is entirely avoidable at the procurement stage.

Interrogate the incident retainer before you need it. Ask these, and listen for hesitation:

  • What is the guaranteed response time, and is it contractual or aspirational — get the number in writing
  • Who is my incident commander by name, and have they personally run a ransomware or data-breach response
  • Do you have in-house digital forensics, or will you subcontract it and lose 48 hours finding a partner
  • Will you draft and file the CERT-In six-hour report on my behalf, or just advise from the sidelines
  • Have you handled a breach involving DPDP-scoped personal data, and do you know the notification path
  • Can you produce chain-of-custody evidence that would survive scrutiny if this ends up in litigation

How to run the selection without being sold to

The demo is theatre. The real signal is in the boring questions the sales team hoped you would not ask. Here is the process I recommend to boards in NCR.

Verify the empanelment yourself

Do not take the logo on the slide as proof. Get the empanelment reference and check it against the published CERT-In list. Confirm the auditors on your engagement are named individuals, not a floating pool of contractors who share one certificate.

Ask for a redacted deliverable

Any firm that has done real work has a report they can redact and show you. The quality of that document — how it evidences findings, how it maps to controls, how it reads to a regulator — tells you more than any reference call.

Test their regulatory fluency

Ask a specific question about the framework that governs you. If you are a fintech, ask how they would handle RBI's expectation for an annual IS audit plus VAPT. If you take cards, ask what changed for you between PCI DSS v3.2.1 and v4.0. A practitioner answers instantly. A reseller reaches for Google.

Insist on retest and a clean certificate

A VAPT that ends at the findings report is half a job. The value is in the retest: you fix, they verify, and only then does the certificate say clean. Regulators and enterprise clients want the closed-loop version, not the open-findings one.

Local presence still matters — but not the way you think

A Delhi NCR address is not the point. Remote testing is normal and effective. What local presence buys you is the ability to put people in your building when it counts: an internal network test that needs physical access, a live incident that needs boots on the ground in Noida or Gurugram at 3am, an executive briefing where the auditor sits with your board rather than dialling in from another timezone. Weigh that against the reality that the best specialist for your exact standard may sit two cities away. Capability beats postcode, but for incident response and internal testing, proximity earns its keep.

The procurement checklist to keep on your desk

Before you sign anything, walk this list. If a vendor fails three or more, keep looking.

  • CERT-In empanelment reference verified against the published list, current cycle
  • Named auditors on your engagement, in-house, with relevant certifications (OSCP, CISSP, ISO 27001 LA, PCI QSA)
  • A redacted sample report reviewed and judged on evidence quality, not layout
  • Scope of every engagement written down in assets and hours, so the price maps to real work
  • Retest and a clean certificate included, not sold as an extra later
  • Incident retainer with a contractual response time and a named human commander
  • Demonstrated fluency in your specific framework — RBI, SEBI CSCRF, PCI v4.0, DPDP, ISO 27001
  • Clarity on the CERT-In six-hour incident-reporting duty and who files it
  • Data handling and NDA terms that survive your own client and regulator scrutiny
  • References from firms in your sector and roughly your size, not just marquee logos

The quiet part

The CISO from that Sunday call recovered, eventually. It cost him three weeks of downtime, a forensic bill larger than five years of the cheaper vendor's fees, and a very uncomfortable board meeting. His mistake was not technical. He bought cybersecurity the way you buy stationery — lowest quote, most logos, sign here. Cybersecurity is not stationery. It is the partner you will call on your worst day, and you find out who they really are only when it is already too late to change your mind.

Choose as if the breach has already happened and you are looking back at the decision. If that framing changes who you would pick, you have your answer. At CyberSigma we are CERT-In empanelled auditors and PCI QSAs who do this work hands-on — the audits, the pen tests, the 2am calls. If you want a second pair of senior eyes on a shortlist or a scope, that is a conversation we are glad to have.

FAQs

Is CERT-In empanelment legally mandatory for my cybersecurity vendor?

It depends on your obligations. For many regulated entities — banks, NBFCs, payment operators under RBI, and market participants under SEBI's CSCRF — audits and VAPT are expected to be performed by CERT-In empanelled auditors. If you are unregulated, it is not strictly mandatory, but the empanelment is still the clearest external signal that a firm has passed CERT-In's own scrutiny. There is little downside to insisting on it.

How much should a VAPT cost in Delhi NCR?

As a rough guide, a focused web application VAPT runs ₹60,000 to ₹2,50,000, an external network VAPT ₹1,00,000 to ₹3,00,000, and a full enterprise engagement covering internal, external, cloud and application testing ₹5,00,000 and upward. Price should track scope in assets and hours. A quote well below these floors usually means an automated scan sold as a penetration test.

What is the difference between a vulnerability assessment and a penetration test?

A vulnerability assessment identifies and lists weaknesses, largely with automated tooling. A penetration test goes further — a human attacker attempts to exploit those weaknesses, chain them together, and demonstrate real impact such as account takeover or data exfiltration. VAPT combines both. The exploitation and chaining is where the genuine value sits, and where cheap providers cut corners.

Do I need a local Delhi NCR firm, or can testing be remote?

Most application, external network and cloud testing is performed remotely and is equally effective. Local presence earns its keep for internal network tests that need physical access, live incident response that needs people on site quickly, and in-person board briefings. Prioritise capability and framework fluency first; treat proximity as a tie-breaker that matters most for incident response.

How does the DPDP Act change what I should ask a vendor?

The Digital Personal Data Protection Act 2023 introduces obligations around consent, data principal rights, breach notification and data fiduciary duties. There is no DPDP certificate to buy, so be wary of anyone selling one. A good partner helps you build and evidence the underlying processes so you can demonstrate compliance to the Data Protection Board once the Rules are enforced.

What should I check before signing an incident response retainer?

Get the response time in writing as a contractual commitment, not an aspiration. Confirm your incident commander is a named individual who has run a real breach. Verify they have in-house forensics rather than a subcontracting scramble. Confirm they will help you meet the CERT-In six-hour reporting duty. And confirm they can produce chain-of-custody evidence that would survive legal scrutiny if the incident leads to litigation.

Naveen Kumar

Naveen Kumar

CyberSigma is a CERT-In empanelled cybersecurity firm helping Indian businesses with VAPT, ISO 27001, PCI DSS, SOC 2 and DPDP compliance — delivered by senior auditors, not juniors.

Free 1-minute check
Free Security Assessment
Get a complimentary, no-obligation assessment from CERT-In empanelled senior auditors.
Try it free →

Leave A Comment

Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne see all locations & addresses →