Notes from the work

Writing on how systems get specified, built and defended. Research published through IGRS, the director’s open investigation resource, alongside notes from our own engagements.

06
Featured Practice 04 Aug 2026 9 min

Specification as a security control

Most breaches trace back to a decision nobody wrote down. The specification is where security is decided, or quietly deferred.

Read the article
Practice

Specification as a security control

Most breaches trace back to a decision nobody wrote down. How to write a control into a specification so it survives the build and the audit.

Read
RegulationIGRS

DPDP Act 2023 and Rules 2025: compliance and investigation

What the Act actually requires of a data fiduciary, what the 2025 Rules changed, and how an investigation runs under them.

Read
IncidentIGRS

Star Health: 31 million records, and what the DPDP Act says about it

A breach of this size read against the Act clause by clause, with the investigation methodology it calls for.

Read
Threat intelIGRS

WazirX: how Lazarus breached India’s largest crypto exchange

The intrusion path, the laundering trail, and what a defender should take from a state-sponsored operation at this scale.

Read
ForensicsIGRS

Deepfake fraud: detection tools and Indian legal grounds

Which detection methods hold up as evidence, and the sections of Indian law a case is actually built on.

Read
ForensicsIGRS

SIM swap fraud: the telecom process behind an investigation

TRAI MNP records, the nodal officer route, and how the trail is reconstructed end to end.

Read