Home / Services

// Capability map

Fourteen domains. One accountable partner.

This is our full capability map — the complete practice we are building toward. Phase 01 domains are live and staffed today; the rest are sequenced behind them. We'll always tell you plainly which is which.

// Phase 01 — 0 to 6 months

Live and delivering today

Three services, delivered by senior engineers. These are where our team's depth is strongest and where Indian businesses have the most urgent, unmet need.

VAPT — Network, Web & API

Manual, exploit-led testing that proves business impact instead of listing scanner output.

What is VAPT?

Cloud Security & DevSecOps

Cloud configuration and identity review, plus security built into your delivery pipeline.

See scope

DPDP Readiness & Gap Assessment

Know what personal data you hold, where it flows, and which gaps carry penalty exposure.

What is DPDP?

// The full catalogue

All 14 practice domains

Filter by the market each domain serves. Tags mark commercial fit, government fit, newly emerging demand, and the credential-building work that opens doors to regulated sectors.

COMMGOVCREDPhase 01

Offensive Security & VAPT

01

Adversary-simulation testing across every layer of your estate — the practice everything else at Cybergil is built on.

  • Network penetration testing (external & internal)
  • Web, mobile and API application testing
  • Red teaming & adversary simulation
  • Wireless and physical security assessment
  • Social engineering & phishing simulation
  • Configuration and secure code review
COMMGOV

Governance, Risk & Compliance

02

The frameworks auditors, boards and enterprise customers ask for — implemented so they hold up under scrutiny.

  • ISO 27001 implementation & audit readiness
  • SOC 2 readiness assessment
  • PCI DSS gap analysis and advisory
  • RBI / SEBI / IRDAI cybersecurity framework alignment
  • Risk assessment & treatment planning
  • Third-party and vendor risk management
COMMGOVNEWPhase 01

Data Privacy & DPDP

03

India's data protection regime is now operational. We turn the statute into a concrete engineering and process programme.

  • DPDP readiness & gap assessment
  • Personal data discovery and flow mapping
  • Consent architecture & notice design
  • Data principal rights fulfilment workflows
  • Data Protection Impact Assessments
  • Virtual DPO advisory & cross-border transfer review
COMMGOVNEW

Managed Security Services

04

Continuous defence for teams without a 24×7 security function of their own.

  • SOC as a Service — monitoring & triage
  • Managed detection & response (MDR)
  • Continuous vulnerability management
  • Attack surface monitoring
  • SIEM deployment, tuning & use-case engineering
  • Virtual CISO retainer
COMMNEWPhase 01

Cloud Security

05

Our core technical edge. Most breaches today are misconfigurations, not exotic exploits — we find them.

  • AWS / Azure / GCP configuration review
  • Cloud IAM and privilege-escalation path analysis
  • Kubernetes & container security hardening
  • Infrastructure-as-Code (Terraform) security scanning
  • CSPM implementation & posture baselining
  • Cloud incident readiness and logging design
COMMNEWPhase 01

Application & Product Security

06

Security that moves at the speed of your release cycle, embedded where developers already work.

  • DevSecOps pipeline design & integration
  • SAST, DAST and SCA tooling implementation
  • Secure code review & threat modelling
  • Secrets management and supply-chain security
  • Secure SDLC programme design
  • Developer security enablement
COMMGOV

Identity & Access Management

07

Identity is the new perimeter. We make sure the right people — and only the right people — get in.

  • IAM strategy, architecture & roadmap
  • Single sign-on and MFA rollout
  • Privileged access management (PAM)
  • Access review, recertification & role mining
  • Zero Trust architecture design
  • Directory hardening (Active Directory / Entra ID)
COMMGOV

Incident Response & Forensics

08

When something has already gone wrong, the first six hours decide the outcome — legally and technically.

  • Incident response retainer & emergency support
  • Digital forensics and root-cause analysis
  • Ransomware containment & recovery support
  • CERT-In incident reporting assistance
  • Threat intelligence & dark web monitoring
  • Compromise assessment & threat hunting
COMMGOVNEW

OT / ICS / IoT Security

09

Manufacturing, energy and utilities run on systems that were never designed to be online. Now they are.

  • OT/ICS network assessment & segmentation review
  • SCADA and PLC security testing
  • IoT device and firmware security testing
  • IEC 62443 alignment advisory
  • OT asset discovery & passive monitoring
  • IT/OT convergence architecture review
COMMGOV

Network & Infrastructure Security

10

The fundamentals, done properly. Unglamorous work that stops the majority of real attacks.

  • Firewall rule review & network segmentation
  • Endpoint protection & EDR deployment
  • Email and web gateway security
  • Server, OS and database hardening (CIS benchmarks)
  • Secure remote access & VPN architecture
  • Backup, resilience and recovery review
COMMGOV

Training, Awareness & Talent

11

Your people are tested by attackers every day. We make sure they're prepared for it.

  • Security awareness programmes for employees
  • Simulated phishing campaigns & reporting
  • Secure coding training for developers
  • Executive and board-level cyber briefings
  • Incident response tabletop exercises
  • Hands-on technical upskilling & hiring support
NEW

Emerging & New-Age Services

12

Where the threat landscape is heading. We invest here so our clients aren't caught flat-footed.

  • AI/LLM application security & prompt-injection testing
  • AI governance and model risk advisory
  • Software supply chain security & SBOM
  • Post-quantum cryptography readiness
  • Blockchain and smart contract auditing
  • Continuous security validation & BAS
COMMGOV

Strategic Advisory

13

Senior counsel for the decisions that shape your security programme for years.

  • Cybersecurity strategy & multi-year roadmap
  • Security maturity assessment (NIST CSF / C2M2)
  • Security budgeting & investment prioritisation
  • M&A cyber due diligence
  • Cyber insurance readiness assessment
  • Board reporting & security metrics design
GOVCRED

Government-Specific Offerings

14

Public sector security carries its own standards, procurement rules and reporting duties.

  • Security audit for government web applications
  • Compliance with national cybersecurity guidelines
  • Smart city and public infrastructure security review
  • e-Governance platform security assessment
  • Capacity building for government IT teams
  • Tender and RFP technical support

Straight answer on capacity: domains outside Phase 01 are on our roadmap and we scope them case by case. If we don't yet have the depth to deliver something to our own standard, we'll say so and point you somewhere better rather than learning on your budget.

// Engagement models

Work with us the way that fits

/ Model 01

Project-based

A defined assessment with a fixed scope, timeline and price. Best for a specific audit, a compliance deadline, or a customer security questionnaire you need to clear.

/ Model 02

Retainer

An agreed block of security hours each month — testing, advisory and on-call support. Best for teams shipping continuously who need security to keep pace.

/ Model 03

Embedded / vCISO

We act as your security function: strategy, vendor management, audits and board reporting. Best for companies too small for a full in-house team but too exposed to go without.

// Next step

Not sure which domain you need?

Most clients aren't, at first. Tell us what you're running and what's worrying you — we'll map it to the right service and be honest about priority order.