D-WINGS Consulting LLP
INSIGHTS

Practical perspective on cybersecurity, GRC and regulation.

D-WINGS' working notes on the standards, regulations and technical practices our clients navigate day to day — written to be useful, not promotional.

LATEST
CYBERSECURITY ADVISORIES
Why a Clean Scan Report Doesn't Mean You're Secure
An automated vulnerability scan with no findings is reassuring — and frequently wrong about what it implies. Scanners are good at what they're built for, and blind to almost everything else that matters.
Read more →
SECURITY LEADERSHIP
Why a vCISO Retainer Outperforms a One-Time Security Audit
An annual audit tells you where you stood on the day it happened. A virtual CISO retainer is accountable for where you stand every month in between — which is where most security postures actually decay.
Read more →
BUSINESS CONTINUITY
ISO 22301 and the Difference Between a BCP Document and a Plan That Works
A business continuity plan that has never been tested is a hypothesis, not a plan. ISO 22301 exists precisely to close that gap — but only if the exercise programme behind it is taken seriously.
Read more →
GRC INSIGHTS
Building a Risk Register That Survives Contact With an Audit
Most risk registers are built once, for the certification audit, and then quietly stop being maintained. Here's what separates a risk register that's a living governance tool from one that's a compliance artefact.
Read more →
REGULATORY UPDATES
CERT-In's Reporting Directions: What They Require in Practice
CERT-In's 2022 cybersecurity directions introduced a 6-hour incident reporting window, mandatory log retention within India, and time-synchronisation requirements. Many organisations remain only partially compliant.
Read more →
DPDP UPDATES
The DPDP Act, 2023: What It Actually Requires of a Data Fiduciary
India's Digital Personal Data Protection Act, 2023 introduces consent-based processing, breach notification duties, and a tiered penalty structure. Here's what changes in practice for organisations processing personal data of individuals in India.
Read more →
ISO GUIDANCE
ISO/IEC 27001:2022: What Changed, and What It Means If You Haven't Transitioned Yet
The 2022 revision restructured Annex A from 114 controls in 14 clauses to 93 controls in 4 themes, and added 11 new controls covering areas like threat intelligence and cloud security. The formal transition window has now closed.
Read more →
VAPT GUIDANCE
VAPT vs Vulnerability Scanning: Why the Difference Matters
A vulnerability scan tells you what might be wrong. A penetration test tells you what an attacker could actually do about it. Conflating the two is one of the most common — and costly — mistakes in security procurement.
Read more →
CATEGORIES
Cybersecurity AdvisoriesISO GuidanceGRC InsightsDPDP UpdatesVAPT GuidanceBusiness ContinuityRegulatory UpdatesSecurity Leadership

New articles are added as regulation, standards and technical practice evolve.

Have a question in the meantime?

Talk to an Expert