CYBERSECURITY
Strategy formulation, IT risk management, security architecture.
C-CISO, CISSP, CISM, CISA, CRISC — the leadership credential stack.
Cybersecurity you can prove.
Securing a better tomorrow.
Enterprise architecture, business process re-engineering — the unglamorous plumbing of banks, hospitals and government services.
The same systems, seen from the other side. Risk instead of features. What breaks instead of what ships.
Governance is the harder discipline. Anyone can claim security. An auditor has to demonstrate it — repeatedly, to a standard, in front of a regulator.
ShieldByte Infosec: CERT-In empanelled, 400+ clients, 20+ countries. Moving organisations from reactive, checkbox security to measurable cyber resilience.
Agentic AI does not wait to be asked. Auditing it required a framework that did not exist — so it had to be written.
The arc is what matters — each chapter began because the previous one stopped being enough.
Strategy formulation, IT risk management, security architecture.
C-CISO, CISSP, CISM, CISA, CRISC — the leadership credential stack.
Standards, assurance and the discipline of provable security.
ISO 27001, 27701, 22301, 42001 lead auditor. GDPR, DPDP, HIPAA, PCI DSS programmes.
Founded ShieldByte Infosec — a CERT-In empanelled security and audit firm.
400+ clients across 20+ countries. Sustained 25–30% year-over-year growth.
Governance for systems that now act on their own.
Authored a three-layer governance framework for auditing agentic AI.
Trust does not scale by hand. Each exists because a manual, subjective process needed to become a measurable one.
A CERT-In empanelled cybersecurity and audit firm helping organisations move from reactive, checkbox security to proactive, measurable cyber resilience.
An AI-powered third-party risk management platform automating vendor evaluation, due diligence and audit through a unified key-risk-indicator dashboard.
Phishing simulation and email security — because the control that fails most often is the human one, and the only way to measure it is to test it.
Regulatory regimes spanning GDPR (EU), the DPDP Act (India), HIPAA (US) and PCI DSS — advising boards across global geographies from a base in Mumbai.
Appointed by the Indian Computer Emergency Response Team, Ministry of Electronics & IT, Government of India. Co-authored the national “AI Security Auditing Guidelines” framework.
Invited by CERT-In to co-chair the Call-for-Presentation sessions at its annual national conference for empanelled cybersecurity-auditing organisations, Mahabalipuram — reviewing and curating submissions from across the sector.
Contributing to the national cybersecurity professional agenda; recognised publicly among India’s cybersecurity leaders.
Active member; honoured as Woman Achiever 2021 for exceptional contribution to cybersecurity.
Post Graduate Diploma — Data Protection Officer, University of Derby (UK) · Diploma in Cyber Law · Master’s Degree, Mumbai University · Bachelor’s Degree, Mumbai University
An original audit framework — Agent Governance, Agent Behaviour Assurance and Operational Risk Control — producing a calculable Agentic Audit Composite Score (AACS). Published in the CERT-In SAMVAAD proceedings.
Co-authored India’s national framework for secure, ethical and auditable artificial intelligence, issued under CERT-In, Government of India, and aligned to ISO/IEC 42001, ISO 23894, the NIST AI RMF and the EU AI Act.
Pioneered an AI-powered engine that automates third-party risk assessment across multiple regulatory frameworks, replacing manual, subjective due diligence with a scalable, objective model.
An advanced model correlating software bill-of-materials data with real-world vulnerabilities and compliance risk, enabling proactive third-party mitigation with far greater precision.
Natural-language automation of audit evidence review and reporting — cutting manual audit effort by over 70% while improving accuracy and compliance coverage.
Unified AI across phishing defence, compliance, vendor risk and governance into a single cyber-risk framework, adaptable across industries and regulatory geographies.
A Three-Layer Governance Framework for Autonomous Intelligence
“As AI systems evolve from assisting humans to acting autonomously, assurance must evolve from validating outputs to assuring decision pathways.”
Published in the official proceedings of CERT-In SAMVAAD, the national cybersecurity-audit conference of the Indian Computer Emergency Response Team, Ministry of Electronics & Information Technology, Government of India — held at BITS Pilani, K.K. Birla Goa Campus. Maps an agentic-AI audit regime to ISO/IEC 42001, the NIST AI RMF, the Singapore IMDA Model AI Governance Framework, and India’s DPDP Act and CERT-In directions.




Co-author. A national AI-security audit framework aligned with ISO/IEC 42001, ISO 23894, the NIST AI RMF and the EU AI Act.
On securing mainframe environments amid cloud, AI and third-party convergence.
Thought leadership on strengthening India’s digital future through cybersecurity leadership.
Invited panel speaker at the inaugural edition, by formal invitation of the ISC2 Managing Director, APAC.
Post-quantum cryptography readiness roadmap for India — panelist alongside the CISO of Mastercard.
International speaker and coach on cybersecurity, governance, risk & compliance, ICT, and women in business leadership.