Home All services
Start a project → Call Now

Security architecture consulting in India

Choose your security architecture — and write down why.

When you adopt new technology or overhaul existing systems, the Reserve Bank of India (RBI) says to follow a standard enterprise architecture planning methodology or framework, but names none. The Securities and Exchange Board of India (SEBI) leaves similar choices to your IT Committee. We help you decide, and record why and who approved it.

  • A decision record, not a score
  • Advisory work, not an audit
  • Delivered remotely from India
  • RBI 2026 Directions, paragraph 30
  • SEBI CSCRF as clarified 28 August 2025
  • NIST SP 800-160 Vol. 1 Rev. 1
  • NIST SP 800-207 and CSWP 20
  • CIS Controls v8 and v8.1
Illustration: an architecture drafting table with a translucent blueprint of a system, a set square, a compass and a small ribbon shield placed where the key decision is made

In brief

What it is
Help choosing a security architecture method or design, with the alternatives you weighed and why.
Why it matters
Regulators leave the choice to you, and your committee must approve it. Nobody can approve a decision nobody wrote down.
What you get
Findings against agreed criteria, and a record of each key decision, its reasons and its approver. No score.

What we do

Six questions we help you settle, in writing.

Which method to follow

The method that answers RBI's paragraph 30, the ones you set aside, and why.

What already binds you

Reference designs you are already tied to, including any that came with a platform.

Whether each control holds

Four tests from the US National Institute of Standards and Technology (NIST), asked as plain questions.

What zero trust means for you

Nobody is trusted by default. SEBI states it three ways; we reconcile them.

What has to exist first

The survey of your assets, accounts, data flows and workflows that NIST puts before zero trust.

Where to start

Which of the three Center for Internet Security (CIS) Implementation Groups, sorted by risk and resources, fits you, so a gap becomes a next step.

The clause that names no framework

Your regulators hand the decision back to you.

Paragraph 30 of RBI's 2026 Directions for commercial banks reads: "The bank shall adopt a standard enterprise architecture planning methodology or framework while adopting new or emerging technologies, tools, or while revamping the existing technology stack."

SEBI reached the same place from the other side. Its Cybersecurity and Cyber Resilience Framework (CSCRF) prescribed four things, zero trust among them. A circular of 28 August 2025 turned them into decisions for your IT Committee. Either way, the decision record is yours.

What only you can bring

  • A named signer. NIST's task AR-4.1 is "Obtain agreement on the security aspects of the architecture". No signer, no decision.
  • Your trade-offs, in writing. RBI's paragraph 33 asks a bank to "document in writing any risk-cost or potential cost trade-off decisions".
  • Your goals and limits. Objectives, requirements, success measures, and the cost, schedule, performance and contract limits that decide the answer.
The RBI and SEBI texts behind this
  • RBI. Directions for commercial banks on Cybersecurity, Technology: Risk, Resilience and Assurance Framework, DoS.CO.CSITEG.4/31.01.015/2026-27, dated 31 July 2026 and in effect on issue. Paragraph 19(9): the Board-level IT Strategy Committee approves need-based access standards (access "only where a valid business need exists", paragraph 104). Paragraph 22(3): the IT Steering Committee ensures a compliant IT architecture, which the IT Strategy Committee reviews at least annually (paragraph 33). Paragraph 110 bases two-factor or multi-factor authentication (MFA) on the bank's own risk assessment and makes MFA mandatory for privileged users of "(i) critical information systems and (ii) critical activities".
  • SEBI. CSCRF Version 1.0, circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 of 20 August 2024, modified by the Technical Clarifications circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119. Paragraph 6.2 makes zero trust one of the "suggested strategies/ methodologies", "approved by IT committee for REs" (regulated entities). DE.CM.S3, GV.SC.S2 and RC.RP.S2 (detection, supply chain risk, recovery planning) moved to consultation with the IT Committee, with immediate effect (paragraph 11).
Before zero trust: the survey NIST leaves with you

NIST SP 800-207, section 7.3, makes "a survey of assets, subjects, data flows, and workflows" the enterprise's own first step. That includes administrator and developer accounts that in legacy architectures "may have blanket permission to access all enterprise resources", and unknown "shadow IT". SEBI's ID.AM (asset management) guidelines ("All REs (Mandatory)") already require that inventory, updated "within 3 working days" of a change, and an entity-wide network architecture diagram "including wired and wireless networks", read subject to the Principle of Exclusivity added on 28 August 2025, which limits the framework's scope to what is used exclusively for SEBI regulated activities.

NIST suggests starting with "a low-risk business process", with first policies run in reporting-only mode.

Five questions to ask anyone selling you zero trust

From SP 800-207, section 7.3.5:

  • Does the solution require that components be installed on the client asset? NIST notes this "may limit business processes where nonenterprise-owned assets are used or desired, such as BYOD or cross-agency collaborations".
  • Does it work where the business process resources exist entirely on enterprise premises?
  • Does it provide a means to log interactions for analysis?
  • Does it provide broad support for different applications, services, and protocols?
  • Does it require changes to subject behavior?

We answer none of them on any vendor's behalf.

DPDP Rules, 2025: safeguards that are design decisions

Rule 6(1) of the Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E), November 2025) sets a Data Fiduciary's minimum safeguards: encryption, obfuscation, masking or virtual tokens; access control; log visibility; backups; keeping logs and data "for a period of one year" unless another law says otherwise; Data Processor contract clauses; and other measures. Each describes how a system is built. Rule 1(4) starts Rule 6 "eighteen months after the date of publication of this Gazette". See which DPDP clauses have commenced.

Criteria that need no tooling

Four questions to put to any control in your design.

NIST SP 800-160 Vol. 1 Rev. 1 sets four tests that any protection mechanism must pass.

Source: SP 800-160, Table 3, derived from the generalized reference monitor concept. The questions are ours.
CriterionNIST's wordsQuestion for your design
Non-bypassable"The mechanism must not be circumventable"Which paths go around it? Check break-glass accounts, admin consoles, direct database access and old scheduled jobs.
EvaluatableSmall and simple enough "to be assessed to produce adequate confidence"Can anyone name the control objective it enforces and check it does so correctly? If not, it fails.
Always invoked"The protection provided by a mechanism or feature that is not always invoked is not continuous."Which environments, tenants or failure modes skip it? A rule checked in the user interface but not the API behind it is the classic case.
Tamper-proof"cannot be modified in an unauthorized manner"Who can change it or its policy, and who sees that change afterwards?
NIST's design order of precedence

Appendix D.3 of SP 800-160 (November 2022) lists five design alternatives "in order of decreasing effectiveness": design selection that eliminates the potential for loss; design alteration that reduces it; engineered features or devices; visibility and feedback; and signage, procedures, training and equipment, which NIST says should be avoided as the only means of reducing loss.

A boxed note on page 76 quotes a 2015 RAND Corporation report: "Poor systems security engineering is very difficult to mitigate by overlaying security controls, whereas security controls overlaid on a sound, secure design can be quite effective."

CIS Implementation Groups: what comes first

CIS Controls v8 and v8.1 hold 153 Safeguards in three Implementation Groups (IGs), and CIS says "Every enterprise should start with IG1", its "essential cyber hygiene". On the CIS Controls Navigator (10 September 2026), three of the eighteen Controls have no IG1 Safeguards, including Network Monitoring and Defense (0 of 11) and Application Software Security (0 of 14).

Safeguards 12.2, 3.7, 12.4 and 3.8 (secure network architecture, data classification, architecture diagrams, data flows) are IG2 and above, though SEBI's ID.AM asks every regulated entity for a network diagram and data flows. Safeguard 16.14, Conduct Threat Modeling, is IG3 only, so threat modeling is its own engagement.

How we work

Four steps from agreed criteria to a signed decision.

Appendix H.4.3 of NIST SP 800-160 sets out four activities. None is running a tool.

  1. Prepare

    We agree strategy, objectives and judging criteria, and list the reference architectures that already apply (AR-1, AR-1.2).

  2. Create the candidates

    We draw up more than one option and say what each connects to outside your systems (AR-2). No alternative, no real review.

  3. Evaluate

    We weigh each option against the criteria and share findings and recommendations with your team (AR-3.3, AR-3.4).

  4. Record and agree

    We record each key decision and its reasons, get your approver's agreement, link each control to the requirement it answers so it can be traced, and support your architecture governance (AR-4).

Scope and limits

What this engagement does not do.

Not an audit

No audit under section 70B of the Information Technology Act, 2000, and no certificate or attestation. SecWiz is not a CERT-In empanelled auditing organization.

No conformance score

NIST rules out judging conformance against its thirty design principles, so you get findings, not a percentage.

No security operations center

SecWiz does not operate a security operations center (SOC). RBI's 2026 Directions place a commercial bank's required SOC in its own chief information security officer's (CISO) office, whoever staffs it.

A bounded engagement. Advisory work runs in business hours. Monitoring set-up, incident response and retainers are separate: see managed security services.

Related: threat modeling, security posture assessment, threat detection and SOC readiness, vCISO services, GRC and compliance and all defensive cybersecurity services.

FAQ

What an IT committee wants settled before it signs.

NIST names them in SP 800-160 Vol. 1 Rev. 1, Appendix H.4.3: findings and recommendations (AR-3.3), agreement on the security aspects of the architecture (AR-4.1), a record of key decisions and the rationale (AR-4.2), traceability (AR-4.3), showing which requirement each control answers, and baseline artifacts (AR-4.4). No score, maturity level or percentage is on the list.

Some of it, eventually: NIST's zero trust planning guide, CSWP 20 of 6 May 2022, says some changes "may involve the purchase and deployment of new infrastructure". But the first work is produced, not bought: the survey NIST SP 800-207 leaves with you, the inventory and network diagram SEBI already requires, the trade-offs RBI wants written down, and the 56 of 153 CIS Safeguards in IG1. Your own people can start all four.

Three SEBI texts bear on it, and they differ. PR.AA (identity and access) Standard 4 of the CSCRF says "follow Zero Trust Model", with no definition. A PR.AA guideline, applicability "MIIs and Qualified REs (Mandatory)" (market infrastructure institutions and qualified regulated entities), denies access to critical systems by default. SEBI's 28 August 2025 circular replaced it with suggested strategies approved by the IT Committee. The framework's 205 pages never cite NIST SP 800-207, so you reconcile from SEBI's own words. NIST calls its own seven tenets "the ideal goal", adding that not all may be fully implemented.

No, and the refusal is NIST's. SP 800-160 Vol. 1 Rev. 1 says Appendix E's thirty principles should not be "used as a basis for making judgments on conformance", and that they may conflict. NIST's criteria are the four in Table 3, which give findings, not a rating.

RBI names none; choosing and recording is the work. As checked on 10 September 2026, access differs: NIST SP 800-160, SP 800-207 and CSWP 20 are direct PDF downloads from nvlpubs.nist.gov; the TOGAF Standard (an enterprise architecture framework) redirects to an Open Group login; the white papers index of SABSA (a security architecture method) is "restricted to members only", though ten named documents are free on request. Internal use of SABSA is "Free to use with brief copyright citation", but training on it needs the SABSA Institute's "prior written consent".

RBI has issued separate sets since 31 July 2026; check paragraph 3 of yours. The commercial banks set covers banking companies, corresponding new banks and the State Bank of India as the Banking Regulation Act, 1949 defines them, but not local area banks. Small finance banks, payments banks, Credit Information Companies, the five All India Financial Institutions and non-banking financial companies (NBFCs) have their own sets; the NBFC set puts the architecture duty in Chapter V, which covers only the Top, Upper and Middle Layers, not Core Investment Companies. Foreign banks in branch mode take paragraph 4's comply-or-explain route, where a deviation is "subject to examination and acceptance by RBI of a reasonably justifiable explanation". RBI's circular DoS.CO.PPG.66/11.01.005/2026-27 of the same date lists the 2016 Cyber Security Framework in Banks and the 2023 IT Governance Directions among the circulars it repealed.

No on both counts. This is advisory work: no audit under section 70B of the Information Technology Act, no certificate or attestation, and SecWiz is not a CERT-In empanelled auditing organization. Where a regulator requires one, the work goes to a firm that holds the empanelment. You get evidence and a decision record for your own named body to approve; the obligation stays with you.

Not in this engagement: it is bounded advisory work in business hours, with no monitoring. SecWiz does not operate a security operations center. Where a managed security retainer includes security monitoring, its coverage hours and escalation path are agreed in writing; see managed security services. The duty stays with you: RBI's paragraph 143 says a bank "shall set up a CSOC to ensure continuous surveillance", paragraph 28(4) places the SOC in the bank's own CISO office, and Rule 6(1)(c) of the DPDP Rules, 2025 puts log visibility on the Data Fiduciary.

Let's talk

Bring the clause and the constraint.

Send the rule that binds you, the decision it forces and the limits that will settle it, and we scope against those. We reply within one working day.