Yash founded Security Brigade in 2006 and has led the firm through 6,700+ security assessments across BFSI, government, healthcare, and SaaS. The firm has been CERT-In empanelled since 2008. He is the principal architect of B-52 — the AI-powered pentesting and red-teaming platform that runs inside every Security Brigade engagement — and the founder of ShadowMap, the attack-surface intelligence platform. Yash writes regularly on India regulatory cybersecurity, AI in offensive security, and the engineering inside B-52.
Articles by Yash K
Google Play removes unregistered app packages on 30 September 2026
Google removes unregistered Play packages on 30 September 2026, and the sentence that does it carries no country limit. What automatic registration turns on, why the four-country announcement beside it binds someone else, and what to check in Play Console this week.
September 20, 2026
PCI SSC revised FAQ 1331: who now agrees SAQ-based scoping
PCI SSC revised FAQ 1331 in August 2026. SAQ-based scoping in a ROC now needs the compliance accepting entity's agreement.
September 14, 2026
CERT-In's OEM guidelines: five deliverables, and a named right to test your supplier
Five deliverables CERT-In advises OEMs to maintain, indicative patch timelines for IT and OT, and a named right for buyers to test.
September 14, 2026
CERT-In's space framework: an annual empanelled audit, five testing phases
An internal audit every six months, an external audit through a CERT-In empanelled organisation every year, and five testing phases across the mission lifecycle.
September 14, 2026
SEBI's MII subsidiary proposal: three tests, one narrow exemption
Three tests decide whether an MII's IT and cyber framework reaches a subsidiary. SEBI's proposal, and the one narrow exemption.
September 14, 2026
The Significant Data Fiduciary's Four Duties Under Rule 13
Rule 13's four duties for a Significant Data Fiduciary: a twelve-month DPIA and audit, a Board report, algorithmic due diligence, an India-only restriction.
DPDP Rule 7: Three Breach Intimations, One Extendable Clock
One breach starts three intimations under DPDP Rule 7. Two are owed without delay; the seventy-two-hour Board filing is extendable on written request.
DPDP Rule 6: the seven security safeguards, and the runway to May 2027
Rule 6's seven minimum safeguards commence 13 or 14 May 2027. What each limb must produce, and the two that need a budget.
SEBI CSCRF for Custodians: AUC Tiers & CCI Obligations
Custodians under SEBI CSCRF: Assets Under Custody drives three-tier classification (₹1L Cr, ₹10L Cr thresholds), CCI self-assessment at QRE, and what custodians of every size must do.
May 6, 2026
SEBI CSCRF for KRAs & QRTAs: The April 2025 Demotion & What It Means
KYC Registration Agencies were reclassified from MII to Qualified RE in April 2025. QRTAs (≥2 Cr folios) remain at MII tier. What changed, what stayed, and what KRAs and QRTAs must do now.
May 6, 2026
SEBI CSCRF for AIFs & VCFs: Manager-Level Corpus Rule
CSCRF for Alternative Investment Funds and Venture Capital Funds: the April 2025 manager-level classification, corpus thresholds, sub-100-client exemptions, and what AIF/VCF managers must do.
May 6, 2026
SEBI CSCRF for AMCs & Mutual Funds: AUM-Tiered Classification & Qualified RE Obligations
Asset Management Companies under SEBI CSCRF: AUM-tiered classification (₹10k Cr, ₹1L Cr thresholds), Qualified RE obligations, ISO 27001 voluntary status, and what AMCs of every size must do.
May 6, 2026
SEBI CSCRF for Stock Brokers: The Two-Parameter Rule, Thresholds & QSB → QRE Link
SEBI's April 2025 CSCRF amendment rewrote stock-broker classification: clients OR trading volume determines your tier, and the higher of the two wins. How the two-parameter rule works, what each tier requires, and the QSB auto-classification.
May 6, 2026
The Principle of Exclusivity and Equivalence Under SEBI CSCRF: A Guide for Multi-Regulator Entities
SEBI's August 2025 clarifications introduced two principles for entities regulated by multiple bodies: Exclusivity (CSCRF covers only SEBI-regulated activities) and Equivalence (duplicate audits not required if the other regulator's framework matches). Here's how they work.
May 6, 2026
SEBI CSCRF Data Localisation in Abeyance: What Regulated Entities Should Know
SEBI's Data Localisation mandate (PR.DS.S2) has been in regulatory abeyance since December 2024. What this means for compliance planning, what stays binding, and what to do instead of building a localisation programme that may never activate.
May 6, 2026
August 2025 SEBI CSCRF Technical Clarifications: ISO 27001, PM Revision & More
SEBI's August 2025 technical clarifications made ISO 27001 voluntary for QREs, downgraded Mobile App Security and BAS/CART to recommendatory, narrowed critical-systems scope, and introduced multi-regulator principles. Decoded.
May 6, 2026
What Changed in the April 2025 SEBI CSCRF Amendment
SEBI's April 2025 CSCRF amendment rewrote stock-broker thresholds with a two-parameter rule, reclassified KRAs from MII to QRE, clubbed AIFs+VCFs at the manager level, and introduced the HSM mandate. Here's what every regulated entity needs to know.
May 6, 2026
SEBI CSCRF in 2026: A Complete Guide for SEBI Regulated Entities
SEBI's Cybersecurity and Cyber Resilience Framework, covered in one place: the 5-tier model, 22 entity types, amendment history through Aug 2025, and what every regulated entity needs to do in FY 2026-27.
May 6, 2026
SEBI's May 2026 AI Vulnerability Detection Advisory: What Every Regulated Entity Must Do Now
SEBI has issued an advisory on AI tools like Claude Mythos that find vulnerabilities at speed and scale. What its 10 directives require, how they apply across the 19 regulated-entity categories, and a 90-day path to readiness.
May 5, 2026