29 security controls for Indian IT & SaaS firms, and what answers each
What the obligations make you do, the breaches each one would have stopped, what a client’s security review asks to see — and what answers it.
- 29controls, in four groups
- 25answered by software we shortlist
- 4no software answers
- 7where our catalogue is thin — said plainly
Which controls are whose
Services-only on the left, product-only on the right, the ones both halves share in the middle. Dashed red: no software answers it. Tap a tile to open its card.
- Detect and respond inside six hours
- Logs kept, and producible
- Phishing-resistant sign-in
- Access that ends when the job does
- Managed devices only
- Email security and phishing training
- Backups the attacker cannot reach
- Vulnerability management and VAPT
- Audit evidence: ISO 27001, SOC 2
- Privacy operations for DPDP
- Your own suppliers, managed
- Client and customer data, encrypted and found
- Verifying the caller before a reset
- Knowing who you hired
- The six-hour runbook
- The clauses you sign
Showing 29 of 29
Services firms
6For firms that work inside their clients’ environments.
Privileged access into client environments
ServicesPrivileged access management with vaulted credentials, just-in-time access and session recording.
1 obligation require it2 breach patterns it stops1 guide
Privileged access into client environments
ServicesPrivileged access management with vaulted credentials, just-in-time access and session recording.
What it is
Why it matters here
What a client or auditor asks to see
Required by
Zero-trust access for distributed delivery
ServicesZTNA or SASE in place of the flat VPN, so a home laptop reaches one client’s apps and nothing else.
1 obligation require it1 breach pattern it stops2 guides
Zero-trust access for distributed delivery
ServicesZTNA or SASE in place of the flat VPN, so a home laptop reaches one client’s apps and nothing else.
What it is
Why it matters here
What a client or auditor asks to see
Required by
Would have stopped
Leakage and insider risk on delivery floors
ServicesData-loss prevention and insider-risk monitoring sized for support and operations teams.
1 obligation require it1 breach pattern it stops1 guide
Leakage and insider risk on delivery floors
ServicesData-loss prevention and insider-risk monitoring sized for support and operations teams.
What it is
Why it matters here
What a client or auditor asks to see
Required by
Would have stopped
Isolated client workspaces
ServicesThin coverageVirtual desktops or a secure enterprise browser, so client data and code never land on the laptop.
1 obligation require it2 breach patterns it stops5 products in our catalogue
Isolated client workspaces
ServicesThin coverageVirtual desktops or a secure enterprise browser, so client data and code never land on the laptop.
What it is
Why it matters here
What a client or auditor asks to see
Required by
Would have stopped
What answers it
In our catalogue:
Virtual desktops in our catalogue are Citrix only.
Shortlist this with us →Your remote-management tools, locked down
ServicesRMM, PSA and remote support — kept off the open internet, patched, and behind MFA.
1 obligation require it1 breach pattern it stops2 guides
Your remote-management tools, locked down
ServicesRMM, PSA and remote support — kept off the open internet, patched, and behind MFA.
What it is
Why it matters here
What a client or auditor asks to see
Required by
Would have stopped
Contact-centre and BPO operations
ServicesThin coverageThe contact-centre, workforce-management and quality stack — with call records kept and card details masked.
2 obligations require it6 products in our catalogue
Contact-centre and BPO operations
ServicesThin coverageThe contact-centre, workforce-management and quality stack — with call records kept and card details masked.
What it is
Why it matters here
What a client or auditor asks to see
What answers it
In our catalogue:
Thin: our contact-centre coverage is Zendesk and Zoom, and nothing we list does DTMF masking for card payments.
Shortlist this with us →Product firms
7For firms that ship software other people run.
Source code and the build pipeline
ProductA hardened Git platform and CI/CD: SSO on every account, protected branches, isolated runners, nothing internet-facing that need not be.
1 obligation require it3 breach patterns it stops1 guide
Source code and the build pipeline
ProductA hardened Git platform and CI/CD: SSO on every account, protected branches, isolated runners, nothing internet-facing that need not be.
What it is
Why it matters here
What a client or auditor asks to see
Required by
Dependencies you can account for
ProductSoftware composition analysis, an SBOM per release, and a repository firewall in front of npm and PyPI.
4 obligations require it1 breach pattern it stops1 guide + 4 products
Dependencies you can account for
ProductSoftware composition analysis, an SBOM per release, and a repository firewall in front of npm and PyPI.
What it is
Why it matters here
What a client or auditor asks to see
Required by
Would have stopped
Secrets and signing keys out of the code
ProductThin coverageA secrets vault with short-lived credentials, secret scanning in commits, and protected code-signing keys.
1 obligation require it2 breach patterns it stops1 guide + 4 products
Secrets and signing keys out of the code
ProductThin coverageA secrets vault with short-lived credentials, secret scanning in commits, and protected code-signing keys.
What it is
Why it matters here
What a client or auditor asks to see
Required by
Would have stopped
What answers it
Also in our catalogue:
Code signing is thin: one dedicated product, plus PKI from Entrust and eMudhra.
Shortlist this with us →Cloud posture and workloads
ProductCloud-native application protection: misconfiguration, identities and entitlements, and runtime threats.
1 obligation require it1 guide
Cloud posture and workloads
ProductCloud-native application protection: misconfiguration, identities and entitlements, and runtime threats.
What it is
Why it matters here
What a client or auditor asks to see
Required by
Application and API protection
ProductWAF and API security, bot and DDoS defence, and payment-page script monitoring.
1 obligation require it8 products in our catalogue
Application and API protection
ProductWAF and API security, bot and DDoS defence, and payment-page script monitoring.
What it is
Why it matters here
What a client or auditor asks to see
Required by
Customer identity and account protection
ProductThin coverageSign-in, MFA and account-takeover defence for your own customers.
0 obligations require it1 breach pattern it stops1 guide + 3 products
Customer identity and account protection
ProductThin coverageSign-in, MFA and account-takeover defence for your own customers.
What it is
Why it matters here
What a client or auditor asks to see
Would have stopped
AI features, secured and governed
ProductGuardrails and firewalls for the AI you ship, and governance that maps to ISO 42001 and the EU AI Act.
2 obligations require it6 products in our catalogue
AI features, secured and governed
ProductGuardrails and firewalls for the AI you ship, and governance that maps to ISO 42001 and the EU AI Act.
What it is
Why it matters here
What a client or auditor asks to see
What no software answers
4Procedure, hiring, a runbook and a contract — where the 2023–25 attacks got in.
Verifying the caller before a reset
BothNot a productA help-desk procedure that proves who is asking before any password or MFA reset.
0 obligations require it1 breach pattern it stopsNo software answers it
Verifying the caller before a reset
BothNot a productA help-desk procedure that proves who is asking before any password or MFA reset.
What it is
Why it matters here
What a client or auditor asks to see
Would have stopped
Why software does not answer this
A procedure and a culture: call back on a number already on record, require manager approval for privileged accounts, and use phishing-resistant MFA so a reset alone is not enough. We list no product that verifies callers.
Knowing who you hired
BothNot a productIdentity and background verification at offer and onboarding, with in-person or verified-video steps for privileged roles.
1 obligation require it1 breach pattern it stopsNo software answers it
Knowing who you hired
BothNot a productIdentity and background verification at offer and onboarding, with in-person or verified-video steps for privileged roles.
What it is
Why it matters here
What a client or auditor asks to see
Required by
Would have stopped
Why software does not answer this
Background-verification firms and a hiring process. We list no employee-verification product — the KYC tools in our catalogue verify customers, not candidates.
The six-hour runbook
BothNot a productWho calls CERT-In, who calls each client, in what order, with what.
2 obligations require itNo software answers it
The six-hour runbook
BothNot a productWho calls CERT-In, who calls each client, in what order, with what.
What it is
Why it matters here
What a client or auditor asks to see
Why software does not answer this
A document, a contact list and a rehearsal. Software can collect the evidence; it cannot make the calls.
The clauses you sign
BothNot a productAudit rights, data location, subcontractor flow-down and incident terms — in your client contracts and your customers’ DPAs.
3 obligations require itNo software answers it
The clauses you sign
BothNot a productAudit rights, data location, subcontractor flow-down and incident terms — in your client contracts and your customers’ DPAs.
What it is
Why it matters here
What a client or auditor asks to see
Required by
Why software does not answer this
Legal and commercial work. Contract tools can store the clauses; only you can negotiate them.
Guides do the vendor-neutral shortlisting with India pricing. Where no guide exists we name the products in our catalogue that answer the control, and say where that list is thin. General information, not legal advice.
IT & ITES controls, answered
Short answers, each backed by the sources on this page.
Which security controls should an Indian IT company start with?
Those every obligation leans on, whichever half you are in: Detect and respond inside six hours; Logs kept, and producible; Phishing-resistant sign-in; Access that ends when the job does; Managed devices only; Email security and phishing training; Backups the attacker cannot reach; Vulnerability management and VAPT; Audit evidence: ISO 27001, SOC 2; Privacy operations for DPDP; Your own suppliers, managed; Client and customer data, encrypted and found.
What security controls do IT services firms need that product firms don't?
The ones for working inside clients' environments: Privileged access into client environments; Zero-trust access for distributed delivery; Leakage and insider risk on delivery floors; Isolated client workspaces; Your remote-management tools, locked down; Contact-centre and BPO operations.
What security controls do SaaS and software-product companies need?
Beyond the shared baseline, the ones for shipping software other people run: Source code and the build pipeline; Dependencies you can account for; Secrets and signing keys out of the code; Cloud posture and workloads; Application and API protection; Customer identity and account protection; AI features, secured and governed.
Which security controls can't be bought as software?
Verifying the caller before a reset; Knowing who you hired; The six-hour runbook; The clauses you sign. Each is a procedure, a hiring check, a runbook or a contract: the places the 2023 to 2025 attacks on IT firms got in.