Author
Santhosh K
Santhosh K is Chief Operating Officer, CyberWave GRC. He writes and reviews CyberWave GRC's articles on SOC 2, HITRUST, ISO standards, privacy regulation, risk management and IT audit.
Credentials
- CISA
- CISM
- CCISO
- CC
- HITRUST CCSFP
- HITRUST CHQP
- ISO/IEC 27001 Lead Auditor
- ISO/IEC 42001 Lead Auditor
- ISO 9001 Lead Auditor
- CSOE
- CRCMP
- GRCP
- GRCA
- CSCP
- ITIL
- PMP
- Scrum
Articles (57)
- SOC 2 When Your Product Uses AI: The Evidence Auditors Ask For in 2026 · Oct 11, 2026
- DPDP 13 November 2026: What Starts, What Doesn't, and What to Do Before May 2027 · Oct 11, 2026
- HITRUST Readiness Assessment: What It Covers and How to Prepare · Oct 11, 2026
- SOC 2 for Startups: When You Need It, What It Costs and How to Start · Oct 11, 2026
- SOC 2 Penetration Testing: Is It Required and What Auditors Expect · Oct 11, 2026
- SOC 2 Type 2 Audit: Process, Timeline and Cost · Oct 11, 2026
- What Is GRC? Governance, Risk and Compliance Explained · Oct 6, 2026
- How to Build a GRC Program in 2026: A Step-by-Step Guide · Oct 6, 2026
- Best HITRUST Consultants and Assessors in 2026: How to Choose · Oct 6, 2026
- Best HIPAA Compliance Consultants in 2026: Firms Compared · Oct 6, 2026
- Best SOC 2 Consultants in India (2026): Top Firms Compared · Oct 6, 2026
- Best ISO 27001 Consultants in India (2026): Top Firms Compared · Oct 6, 2026
- SOC 2 Audit Cost in 2026: What You'll Actually Pay and Why · Oct 6, 2026
- HITRUST Certification Cost: e1 vs i1 vs r2 Pricing Explained · Oct 6, 2026
- ISO 27001 Certification Cost in India: A Complete Breakdown · Oct 6, 2026
- SOC 2 vs ISO 27001 vs HIPAA vs HITRUST: Which One Does Your Business Need First? · Oct 3, 2026
- How to Choose the Best SOC 2 Consulting Service: A Buyer's Guide for US and India · Oct 2, 2026
- Top ISO 27001 Certification Consulting Firms: How the Leading Options Compare (US & India) · Oct 2, 2026
- ISO 9001:2026 vs ISO 9001:2015: What Changed and How to Transition · Oct 1, 2026
- ISO 27701:2025 vs ISO 27701:2019: Key Changes and What They Mean for Your PIMS · Oct 1, 2026
- SOC 2 Readiness Assessment: What It Covers, Cost, Timeline and Deliverables · Sep 28, 2026
- HITRUST e1 vs i1 vs r2: Which Assessment Is Right for Your Organization? · Sep 28, 2026
- Cyber Resilience Beyond Control: Lessons from NCSC CEO Richard Horne · Sep 26, 2026
- AI in Internal Audit: Five Assurance Priorities from IIA CEO Anthony Pugliese · Sep 26, 2026
- Who Owns AI Risk? Accountability Lessons from Walter Haydock · Sep 26, 2026
- DPDP Rules 2025: Operational Lessons from Privacy Leader Tanin Chakraborty · Sep 26, 2026
- ISO 27001 Audit Evidence: Lessons from Joseph Kirkpatrick · Sep 26, 2026
- ISO 27001 Implementation Without Checklist Theatre: Lessons from Robin Long · Sep 26, 2026
- ISO 42001 and AI Regulation: Build One Governance System, Not Two · Sep 26, 2026
- DPDP Compliance in Practice: Lessons from MeitY Secretary S. Krishnan · Sep 26, 2026
- ISO 22301 BCMS Implementation Roadmap: 13 Steps to Certification · Sep 19, 2026
- The CIA Triad Explained: Confidentiality, Integrity and Availability · Sep 19, 2026
- Cybersecurity vs GRC: What Is the Difference and Why You Need Both · Sep 19, 2026
- The PDCA Cycle Explained: Plan-Do-Check-Act for Continuous Improvement · Sep 19, 2026
- NIST CSF 2.0 Explained: The Six Functions and How to Use Them · Sep 19, 2026
- Risk Owner vs Control Owner: Roles, Responsibilities and Examples · Sep 19, 2026
- SOC 2 Compliance Checklist: Every Control, Evidence Item and Audit Step · Sep 19, 2026
- ISO 27001 Audit Checklist: Clause-by-Clause and Annex A Control Evidence · Sep 19, 2026
- ISO 42001 Certification: Requirements, Cost, Timeline and Step-by-Step Process · Sep 18, 2026
- Data Fiduciary Under India's DPDP Act: Duties, Liabilities and Compliance Checklist · Sep 12, 2026
- DPDP Rules: How the Draft Rules Change Day-to-Day Compliance · Sep 5, 2026
- Audit Working Papers: Standards, Structure and Review Best Practices · Aug 28, 2026
- Data Protection Officer: Role, Responsibilities and When You Must Appoint One · Aug 20, 2026
- SOC 1 Reports Explained: Type 1 vs Type 2, Scope and Readiness · Aug 12, 2026
- SOC 2 vs ISO 27001 – Complete Guide to Choosing the Right Framework · Mar 18, 2026
- How to Get HITRUST Certification: A Step-by-Step Roadmap · Mar 10, 2026
- Zero Trust Architecture: Moving Beyond the Perimeter · Mar 5, 2026
- GRC Checklist for Startups: Building Compliance from Day One · Mar 5, 2026
- Navigating India's DPDP Act: What Organizations Need to Know · Feb 28, 2026
- The Rise of AI-Powered Threat Detection in SOC Operations · Feb 18, 2026
- Building a Resilient GRC Program: From Framework to Execution · Feb 10, 2026
- ISO 27001:2022 Transition — Key Changes and Implementation Guide · Jan 20, 2026
- HITRUST CSF v11: What's New and How to Prepare · Jan 12, 2026
- Third-Party Risk Management: A Strategic Imperative for 2026 · Jan 5, 2026
- Ransomware in 2026: Evolving Tactics and Defense Strategies · Dec 20, 2025
- The Role of Internal Audit in Strengthening Cyber Resilience · Nov 28, 2025
- ITGC Controls: A Comprehensive Guide for IT Auditors · Nov 10, 2025
