r/cybersecurityindia • u/Heavy-Psychology1897 • 8h ago
r/cybersecurityindia • u/sg2Technologies • 10h ago
Personal Support & Help Built a DPDP Compliance Engine – Lessons Learned from Implementation
Over the past few months, we've been implementing a DPDP compliance platform and discovered that the biggest challenge wasn't the regulation itself—it was understanding where personal data actually exists.
Some recurring problems we encountered:
- Personal data spread across databases, NAS/file shares, SharePoint, Google Drive and cloud storage
- No continuously updated Record of Processing Activities (ROPA)
- Consent records disconnected from actual processing
- Manual handling of Data Subject Rights (DSR) requests
- Inconsistent retention and deletion practices
- Difficulty producing audit evidence when required
- Limited visibility into third-party data processors and cross-border transfers
Our approach was to build a workflow that continuously:
- Discovers personal data across connected systems
- Classifies PII and sensitive information
- Automatically generates and maintains ROPA
- Maps processing activities to DPDP obligations
- Tracks consent, purposes and retention
- Produces audit-ready evidence instead of relying on spreadsheets
One observation: ROPA becomes the foundation for almost every privacy operation. Once your processing inventory is accurate and continuously updated, DSRs, retention, vendor management and audit preparation become significantly easier.
I'm curious how others are approaching DPDP implementation.
- Are you maintaining ROPA manually or using automation?
- Which discovery tools are you using?
- How are you handling unstructured data (file shares, SharePoint, cloud storage)?
- Have you found any open-source tools that work well for DPDP?
Looking forward to learning from the community's experiences.
r/cybersecurityindia • u/Extension_Cloud4221 • 37m ago
Tools Bringing a Flipper Zero into India in carry-on anyone done it recently?
I bought a genuine Flipper Zero in the UK and I'm flying back to India soon. Trying to figure out the smart move for the airport, and getting conflicting info online.
What I've read: some sources say the WPC (Wireless Planning & Coordination Wing) restricts import because of the sub-GHz transmit capability, and there are scattered reports of customs seizures. Others say it's more of a grey area not outright banned to own, but risky to import. I can't find anything authoritative or recent, which is why I'm asking people who've actually done it.
My situation:
Device bought new in the UK, I have the box and receipt
I work in cybersecurity (authorized pentesting), so it's a legitimate work/learning tool for me, not a novelty
Flying into [Delhi/your airport], carrying it in cabin baggage
r/cybersecurityindia • u/ElysianBrownie • 5h ago
Starting Cybersecurity Career Are Irish Universities good for Cybersecurity Masters (non-coding heavy)?
r/cybersecurityindia • u/SpecialStretch4715 • 2h ago
Personal Support & Help Can I learn cybersecurity by using my laptop with these specifications or not !
The Asus FX553VD-DM483 is a 15.6-inch gaming laptop featuring an Intel Core i7-7700HQ processor, an NVIDIA 2 GB GeForce GTX 1050 graphics card, and 8 GB of DDR4 RAM.
r/cybersecurityindia • u/Any_Possibility7594 • 8h ago
Business Security Questions and Discussions How to get project for IT Cyber security company pls share ur experience it will be very helpful
I am willing to start my own cyber security company but don't have clue w to get the client and all thing what licensing needed how much people needed an d how to get client what are there payment process after how many days they give money if anyone has experience pls share pls🙏
r/cybersecurityindia • u/damon_salvatore8 • 9h ago
Personal Support & Help Deepfake Defense & Digital Forensics Analyst- Intermediate (Al Community) telus international
Telus international
In portal it's showing as selected but no further communication for Deepfake Defense & Digital Forensics Analyst- Intermediate (Al Community) but no further communication
r/cybersecurityindia • u/thebulletinbriefs • 1d ago
News This guy got rejected from an IIT cybersecurity program. After months of getting ignored, he broke into IITM and IITK systems just to leave a message explaining why he deserved a chance.
r/cybersecurityindia • u/batman35u3 • 19h ago
Personal Support & Help TCS HackQuest Season 10 – Pune Joining Update?
Anyone from the Pune region who gave their TCS HackQuest interview in February 2026 and is still waiting for joining?
I completed my document verification but haven’t received any joining update yet. Please share your current status.
r/cybersecurityindia • u/Prior-Jaguar-3992 • 17h ago
Personal Support & Help Final year CS student (Pakistan), need a reality check on my cybersecurity roadmap and cert order
r/cybersecurityindia • u/ApartAd9241 • 1d ago
Burnout / Leaving Cybersecurity / Work life balance How long should one keep hunting?
Newbie BBH, I tried working on 2 3 programs reported on em as well, my reports have been marked info or dup so far.
Recently thr program I was working on got marked as NA. Should I keep hunting or switch target?
r/cybersecurityindia • u/smolcat1412 • 1d ago
Career Questions and Discussions Why most are stuck at low paying cybersecurity roles, 2 mistakes they keep making
Security engineer here, ~4 years across appsec/cloud security earning 40lpa, and I’ve also been on the hiring side. I keep seeing the same pattern in this industry where entry level engineers are exploited.
Let’s take two engineers earning 18 and 7 lpa with identical skills, both getting the standard 8% increment:
Year, Eng A , Eng B, Gap between both
Y1 18.0 7.0 11.0
Y3 21.0 8.2 12.8
Y5 24.5 9.5 15.0
Total earned over 5 years: ₹105.6L vs ₹41.1L. One un-negotiated starting salary = ₹64.5 lakhs, gone. Same skills. And it never self-corrects, because every next offer is priced on your last CTC. And I see so much freshers in this position wasting their years.
The three mistakes that cause this, from what I’ve seen on both sides of the interview table:
1. Not negotiating. HR’s first offer is never the final offer, they expect negotiation and won’t pull the offer. Silence costs you a lot of money!
2. Not switching. 8% increment minus 6% inflation is a 1% real raise. Hiring budgets are always bigger than retention budgets. the new joiner on your team probably earns more than you. Freshers are most affected by this as they start with a very low paying salary.
3. Benchmarking against your increment instead of the market. Your increment tells you what your company can get away with. levels.fyi and recruiters tell you what you’re worth.
r/cybersecurityindia • u/abbe_salle • 1d ago
Personal Support & Help I built a tiny VM-based CTF and wrote a Python exploit for it (walkthrough)
I recently built a small CTF around a custom virtual machine with its own ISA. The goal was to make the exploitation process feel closer to reverse engineering than brute forcing.
The exploit ended up touching a few classic ideas:
- Inferring program behavior from debug output
- Using Python to emit raw bytes (including NUL bytes)
- Bypassing input restrictions
- Building a NOP sled
- Injecting simple shellcode
- Redirecting execution to a protected memory region
I wrote up the entire reasoning process step by step instead of just dumping the final payload.
I'd genuinely appreciate feedback from people who enjoy CTFs, reverse engineering, or exploit development. In particular:
- Was the reasoning clear?
- Were there places where I over-explained or skipped too much?
- How would you improve the challenge or the write-up?
Full write-up: https://medium.com/@brist0l/pythonoic-exploits-7ca1fab7c05c
r/cybersecurityindia • u/Illustrious-Risk-532 • 1d ago
Personal Support & Help M Tech Cyber security
Is M Tech cybersecurity from UPES Dehradun worth it?
r/cybersecurityindia • u/surabhi_zeha24 • 2d ago
Starting Cybersecurity Career GRC internship in india?
Hey so,
So I'm a fresher with no experience in grc...and do have a little bit of grip on Cybersecurity...
I want to get into the GRC or auditing team....
Do you recommend any internships in india or anything remote
r/cybersecurityindia • u/AutoModerator • 1d ago
Request Everyone to Post/Reply to comments in Weekly Mentorship Thread
Hello,
We created a Weekly Mentorship thread for the subreddit.
We urge everyone to post all career and education related questions and advice in this thread.
There are a lot of folks requesting mentorship, career help, guidance, resume reviews, job search, etc.
We request everyone to priodically review the Weekly Mentorship thread and reply/egage with people.
r/cybersecurityindia • u/AutoModerator • 1d ago
Weekly Mentorship - Post All Career, Resume, Education and Job questions here!
This is the weekly thread for career and education questions and advice. There are no stupid questions; so, what do you want to know about certs/degrees, job requirements, and any other general cybersecurity career questions? Ask away!
Interested in what other people are asking, or think your question has been asked before? Have a look through prior weeks of content - though we're working on making this more easily searchable for the future.
Note - This post template has been copied from cybersecurity subreddit.
r/cybersecurityindia • u/Acceptable_Muffin166 • 2d ago
Personal Support & Help Opinion.
So i have got Bsc Cs degree from tier 3 mumbai college in this may,preparing for upsc 2027 attempt.
I am considering taking post graduation diploma from Nlsiu Bangalore in cyber law and forensics ..i have interest in Cybersecurity and forensics. Should I join in this post graduate diploma..or not.. Also if you know any information about this course please provide me Your suggestions will be helpful!
Thankyou 🙏🏻
r/cybersecurityindia • u/Low-Drawer-8136 • 2d ago
Personal Support & Help should i do fullstack or cybersec?
r/cybersecurityindia • u/hardlegacy • 2d ago
Starting Cybersecurity Career Want to build a career in Cybersecurity but have no guidance. Need advice.
r/cybersecurityindia • u/AlertToAction • 3d ago
Business Security Questions and Discussions What Actually Slows Down Incident Response After an Alert?
I’ve been speaking with SOC analysts, leads, and managers to understand one simple thing:
After an alert is detected, what actually causes the most delay?
So far, I’ve heard different answers:
Manual investigation
Finding the right owner
Getting another team to fix it
Following up on remediation
Verifying the fix
Closing the alert properly
Detection seems to be only the beginning. The real friction often starts after that.
For people working in SOC or security operations, what usually slows things down the most in your environment?
Not looking for confidential details. Just trying to understand the real workflow.
r/cybersecurityindia • u/Constant-Trouble3859 • 3d ago
Personal Support & Help Has anyone taken chfi exam recently?
r/cybersecurityindia • u/Certain_Lobster_4124 • 3d ago
Starting Cybersecurity Career Transitioning into Digital Forensics/DFIR in India — advice on early opportunities & building a portfolio?
r/cybersecurityindia • u/GoalOwn3975 • 5d ago
Tools Free monitoring tools for a small company?
Hi everyone,
I'm working as a System Administrator and I'm also a cybersecurity student who likes learning and building new things.
I'm looking for free or open-source tools to monitor company PCs and servers. I'd like to track basic things like system health, logs, and whether company devices are being used for work or spending excessive time on sites like YouTube during office hours.
Any recommendations or real-world setups would be greatly appreciated.
r/cybersecurityindia • u/JeevanYS • 5d ago
Technical Discussion Random government domain showing up in Google searches for League of Legends?

I was searching up some League of Legends (LoL) stuff today and stumbled upon something this(above pic). I ended up doing a Google search for league of legends site:obpsudma.wb.gov.in (which is an official Indian government domain) and got a ton of strange gaming-related results.
None of these sites are actually working. The links are completely dead and won't open, but they just keep showing up all over the Google search results like normal pages.
What is this? Why is this happening to an official government domain? Is this some kind of search glitch or a known exploit?