For the CISO

For the CISO who owns the blast radius.

You're the person who has to answer for what happens next. When the incident report goes to the regulator, when the auditor asks for evidence, when the board asks "could this have been prevented" - you're on the stand. We build the posture that lets you answer "yes, and here's how." Zero trust, DPDP-ready, CERT-In-compliant, evidence-first.

Get a Posture Review

60 min · Free

Zero trust, DPDP, and the evidence to prove it.

Zero trust for the estate you actually have.

Zero trust is easy on a whiteboard. Hard on a fifteen-year-old estate. We work with what you have - legacy Windows fleets, on-prem apps that were meant to be temporary in 2011, a Wi-Fi network that predates BYOD as a policy - and build zero-trust the way it can actually be lived. Identity-aware. Segmented. Least-privileged. Continuously verified. And auditable at every point.

DPDP Act 2023 + CERT-In. Mapped to controls.

The Digital Personal Data Protection Act 2023 doesn't come with an implementation manual. The CERT-In Directions of April 2022 didn't either. We've built the controls-mapping table for both - showing which requirement each control satisfies, which technology delivers each control, and which of your existing tools already partly get you there.

Our SOC. Your escalation.

Our 24/7 SOC runs from Bengaluru with follow-the-sun coverage from a partner NOC in Manila. Analysts are Cisco XDR- and Splunk-certified. Detection rules are tuned quarterly. MDR customers get a Tier-3 incident responder on the phone within twelve minutes of a high-severity trigger. Not a chatbot. Not an SDR. A real human whose name you'll know.

Audit-ready evidence packs.

Every control we implement comes with evidence - logs, screenshots, configuration exports, attestation letters - packaged in a format your internal audit team and external assessor can consume without a second request. We keep the evidence pack current between audits, so when the auditor arrives, so does the pack.

On the record

"Our MTTD on critical incidents dropped from 14 days to under 8 hours within the first quarter of Proactive's SOC engagement."

CISO, National life insurance company

CISO questions.

What's your DPDP timeline for a mid-size enterprise?
Ninety days for the controls that matter, six months for full evidence packs, twelve months for automated attestation. We publish the 90-day checklist openly - see the DPDP topic hub.
How do you handle the CERT-In six-hour reporting rule?
Our SOC runs a pre-drafted CERT-In notification template that starts filling itself the moment a high-severity incident is confirmed. We help you get to filed-in-time on every occasion the rule applies.
Do you run incident-response tabletops?
Quarterly for MDR customers. Twice a year for others. Ransomware, insider threat, regulator-notification scenarios, and DR failure are the four we cover on rotation.
What's your MDR pricing model?
Per-endpoint per-month, plus a per-log-source flat fee for SIEM ingestion. No surprise overages. Volume tiers kick in at three hundred endpoints and again at three thousand.
How do you handle compliance audits?
We staff a compliance lead per named customer who owns audit-cycle evidence, coordinates auditor requests, and handles remediation planning. You aren't running the audit alone.
What if we already have an MDR incumbent?
We work alongside them. Many CISOs run MDR on endpoints with one provider and SIEM/SOC with another. We're comfortable operating in that arrangement - or replacing an incumbent when the time is right.

Share a few details to get started.

We'll get back to you shortly.