Prime Infoserv Prime Infoserv

What the regulator asks for

Start here

Six practices, one lifecycle: advise, assess, comply, protect, monitor, respond. Most engagements begin with an assessment and stay for the monitoring.

All services

Prime can sign the audit report your regulator will accept.

Scope an engagement

Audit & testing

Certification & privacy

Arrived with a deadline rather than a question? Every page above states the scope, the evidence produced and the typical duration.

All requirements

Data-intensive

Each industry page names the specific obligations that apply — SEBI CSCRF for market infrastructure, CEA guidelines for utilities, DPDP for everyone holding personal data.

All industries

A state distribution utility, ahead of a CEA audit

The corporate network and the operational estate had been described as separate for years. The assessment found four routable paths between them, three of them undocumented. Prime mapped the boundary, sequenced the closures against the utility's maintenance windows, and produced the evidence pack the audit asked for.

Sector
Energy & Utilities
Driver
CEA cyber security audit
Duration
11 weeks
Planned outages required
None

The engagement

The situation

A state distribution utility with a CEA audit approaching. The internal position, documented and repeated for several years, was that the corporate IT network and the operational technology estate were air-gapped. The audit would test that claim.

What we found

Four routable paths between the two estates. One was documented and managed. Three were not: a vendor support link left in place after a commissioning project, a shared management VLAN introduced during a switch replacement, and a dual-homed engineering workstation.

None was malicious and none was recent. All three were the ordinary residue of operational work done under time pressure, which is where this class of finding almost always comes from.

What we did

Mapped the boundary properly, then sequenced closure against the utility's maintenance windows rather than against our own reporting timetable. Two paths closed inside existing windows; the third needed a vendor change that was scheduled rather than forced.

The evidence pack was built as the work proceeded, so the audit submission was a by-product of the remediation rather than a separate exercise afterwards.

What changed

The utility went into the audit with a documented boundary, a closure record and a monitoring rule that alerts if a new path appears. The last part matters most: the finding was not a one-off condition but a recurring consequence of how operational work happens.

4

undocumented IT/OT paths found

0

planned outages required

11

weeks from scoping to submission

Tell us the deadline, not the acronym.

Thirty minutes with a practitioner rather than a salesperson. If the requirement somebody has handed you does not match what you actually need, that is a more useful thing to find out now than in week nine.

Talk to an expert

Or reach the incident line directly on +91 9147712576, monitored 24×7 from Kolkata.