NBFC with INR 6,000+ Cr AUM
Scaled the security program from 250 to 1,600 employees in 4 years. Today the team passes 8–10 audits a year including ITGC, PCI-DSS, ISO 27001:2022 and RBI.
We turn cyber risk into a clear, budgeted roadmap — one partner for vCISO, GRC, privacy, breach response, and security architecture.
Trusted across FinTech, aviation, retail, energy and SaaS.


































We start with your risk appetite — not a product catalog. Bespoke, measurable, framework-aligned.
From strategy through deployment to ongoing monitoring — under one accountable program, with one budget.
Map a single program to NIST CSF, CIS Controls, ISO 27001:2022, C2M2 and sector regs — no duplicate work.
Recovery, not just prevention — you keep running when something gets through.
Minimal cost and disruption — security staff actually adopt, without the friction.
Engage one capability — or run all seven as a single accountable program.
The same methodology across FinTech, retail, aviation, and smart-grid.
Governance, identity, infra & SDLC
Board-ready NIST · CIS · ISO scores
Priorities set by risk appetite
Controls deployed & integrated
KPIs & KRIs, continuously
With optional ongoing advisory
Vendor-agnostic — the platforms and tools we most often run in client environments.















Outcomes from a few of our recent engagements. Names withheld under NDA — happy to share references on request.
Scaled the security program from 250 to 1,600 employees in 4 years. Today the team passes 8–10 audits a year including ITGC, PCI-DSS, ISO 27001:2022 and RBI.
Project-managed security across 18+ malls and 16 commercial/residential properties to meet ISO 27001:2022 compliance, with central visibility for group CxOs.
Coordinated across four teams in France and India to deliver holistic readiness for CERT-In April 2022 guidelines, including external audit support.
Hardened the security profile of a salad-vending robot company to industry standards — contributing to a successful acquisition by a US retail giant.
Locked down PII-heavy environments deploying smart meters across multiple Indian states. Introduced dark-web monitoring against external attacks.
INR 30,000 Cr revenue firm prepared for ISO 27001:2022. Deployed and configured 24 security platforms, then empowered the internal IT team for run-state.
You're hiring decades of in-the-trenches CISO experience — the people you talk to in the proposal are the people in the program.
Three decades in cybersecurity. Founder of multiple security ventures; published author and frequent industry speaker. Leads strategy, business and security engagements at KAS.
Field CISO with deep experience running GRC, audit and incident programs for regulated enterprises. Leads vCISO engagements and security control deployments.
Runs operations across KAS — engagements, scheduling, finance and client success. Keeps the practice moving smoothly so the team stays focused on the work that matters to clients.
We work across timezones so your program runs continuously — not just in business hours.

2033 Sixth Ave, Suite 600
Seattle, WA 98121

Hovslagaregatan 17, LGH 1101
461 62 Trollhättan

504, Water's Square, Pimple Nilakh
Pune 411027
A short, structured conversation with our founders to gauge where you are, what's at stake, and the shortest path to a meaningful posture upgrade.