Practitioner-grade cybersecurity content
Technical playbooks, war stories, and how-to-think guides — written by practitioners, anchored to the Indian context.
Want structured, step-by-step learning instead? Explore the Academy (guided courses) or the AI security hub.
Latest articles
Most recent practitioner playbooks across every track. Filter by topic in the sidebar, or use search.
VAPT in CI/CD: Shifting Penetration Testing Left in 2026
You deploy daily; annual VAPT tests a snapshot that no longer exists. Here is how to shift testing into the pipeline.
Cloud SecurityAWS IAM Privilege Escalation: Real Attack Paths and How to Find Them
In AWS, identity is the perimeter — and IAM privesc is how attackers take the account. The paths to hunt for.
Cloud SecurityCloud Misconfigurations: The 60% Problem (IAM, Storage, Keys, Gateways)
Most cloud breaches are not exotic — they are misconfigurations. The 60% problem, and the checks to fix it.
VAPTAPI Penetration Testing 2026: BOLA, Broken Auth, and the Bugs Scanners Miss
APIs are the new front door. BOLA, broken auth, and mass assignment are where real API pentests pay off.
Cloud SecurityKubernetes Penetration Testing: An Attacker’s Methodology for 2026
Modern attackers know RBAC, tokens, and admission control. Here is the Kubernetes pentest methodology, with commands.
ComplianceDPDP for Startups: A Practical Data Fiduciary Checklist You Can Action This Week
You do not need an enterprise GRC team to get DPDP-ready. A practical startup checklist you can start this week.
ComplianceSEBI CSCRF in 2026: Annual VAPT, Bi-Annual for MIIs, and What It Means for You
SEBI's CSCRF makes VAPT mandatory — annual for most, bi-annual for MIIs. A plain-English compliance guide.
ComplianceRBI Cybersecurity Framework 2026: What Banks and NBFCs Must Actually Do
RBI raised the bar in 2026: independent vendor assessments and evidence, not self-attestation. Here is what is actually required.
ComplianceThe 6-Hour Rule: Building One Breach Playbook for CERT-In, DPDP, and RBI
CERT-In: 6 hours. DPDP: 72. RBI/SEBI/IRDAI: their own. One incident, five clocks — here is how to run them as one playbook.
ComplianceDPDP Enforcement Has Begun: ₹250 Crore Penalties and the Data Protection Board
The DPDP grace period is over. The Board is live, and the penalty for a breach reaches ₹250 crore.