Niranjan Patil
Twenty-five years securing how organisations build, run and defend their systems. Founder and Director of OPSEC Labs, advising founders and leadership on risk, compliance and resilience across India and international markets.
Security leadership that scales with the business
Most growing businesses reach a point where security can no longer be someone's side responsibility, but a full-time CISO is not yet justified. That gap is where I work. As a virtual CISO and strategic advisor, I partner with founders and leadership teams on security strategy, board-level risk communication, and programmes that hold up under regulatory and customer scrutiny.
I lead OPSEC Labs, a Bengaluru-based cybersecurity and data privacy consulting firm I founded in 2014 and grew from an independent practice into a specialist team. We serve clients across SaaS, fintech, IT services, hospitality and clean technology, in India and internationally, helping them achieve ISO 27001, PCI DSS and SOC 2 certifications and navigate DPDPA, GDPR and regional PDPL compliance.
My background spans both sides of the problem: running information security inside large enterprises and testing it from the outside as an assessor and auditor. I hold the CISSP, am an ISO/IEC 27001 Lead Auditor and an IEEE Senior Member. I have also served as an empanelled auditor with NPCI and a cybersecurity instructor with DSCI.
Areas of work
vCISO & Strategic Advisory
Security leadership on demand: strategy, board reporting, programme design and roadmap ownership without a full-time hire.
Governance, Risk & Compliance
ISMS design and ISO/IEC 27001:2022 audits, risk assessments, policy frameworks and certification readiness for regulated and growth-stage firms.
Data Privacy & Regulation
DPDPA, GDPR and regional PDPL programmes, data mapping, consent and DPA reviews, and privacy-by-design for products and vendor contracts.
VAPT & Security Testing
Vulnerability assessment and penetration testing across web, network, cloud and application layers, with remediation teams can act on.
Cloud & Infrastructure Security
Security architecture and hardening on AWS and Azure, perimeter and network controls, SIEM and monitoring design.
Training & Capacity Building
Hands-on training in OSINT, DFIR and security operations for teams and law-enforcement, plus awareness programmes that change behaviour.
Career & firm history
Built OPSEC Labs from an independent practice into a specialist cybersecurity and data privacy consulting firm serving 100+ client engagements. Lead vCISO advisory, GRC, privacy, VAPT and ISO/IEC 27001 auditing. Incorporated in Bengaluru in 2021 (CIN U72900KA2021PTC155591).
OSINT, dark web, cryptocurrency, forensics and cybercrime investigation training with the Centre for Cybercrime Investigation Training & Research (CCITR). Trained officers of the Narcotics Control Bureau and Karnataka State Police (CEN).
Member of the NPCI vendor auditor panel.
Auditor, consultant and advisor across information security, privacy and technology. OPSEC.IN operated as the information security unit of VSR Tech.
Co-founded a pure-play information security services firm. Led data privacy, risk management, enterprise compliance, VAPT, ISO 27001 and PCI DSS readiness, cybercrime investigation and security education.
Implemented and monitored the organisation's information security policies, internal audits and risk assessments; managed external compliance audits.
ISMS auditing and compliance, IT risk management, business continuity and disaster recovery, across Bangalore and Amsterdam. Earlier a Systems Engineer supporting network, server and desktop infrastructure.
Led support for Symantec's SOHO range of antivirus, firewall and intrusion-detection products.
Bachelor's degree.
What the work has delivered
- 10+ ISO/IEC 27001 certifications achieved for clients, and 25+ external audits successfully cleared.
- Multi-jurisdiction compliance programmes for growth-stage companies expanding into enterprise and international markets.
- Security governance frameworks built from scratch across SaaS, fintech, IT services, hospitality and clean technology.
- 90%+ reduction in critical vulnerabilities across assessed environments through structured VAPT and remediation.
- Law-enforcement training on OSINT, dark web and cybercrime investigation for NCB, CISF, IAF, and Karnataka State Police, via DSCI and CCITR.
Let's talk
If your business is approaching a compliance deadline, preparing for an audit, or simply needs security leadership without a full-time hire, tell me a little about your systems or the problem you are facing and I will come back to you.
Download public key (.asc)