Buy an Instant VAPTTalk to us

Since 2015 · Mumbai

Cyber defence, engineered and operated.

Astra Cybertech builds and runs security programmes for organisations that cannot afford to find out the hard way. A CERT-In empanelled practice covering the whole cycle — the adversarial testing that finds what is exploitable, the round-the-clock operations that catch what gets through, and the governance that keeps you defensible in between.

  • CERT-In empanelled
  • ISO/IEC 27001
  • ISO 9001
  • CERT-In empanelled
  • ISO/IEC 27001
  • ISO 9001
  • OSCP
  • OSWE
  • CISSP
  • CEH
  • CPTE
  • CAPen
  • CISEH
  • ISO 27001 Lead Auditor
  • MITRE ATT&CK aligned
  • NIST CSF

What we do

Three practices, one brief

Most firms sell one of these. Running all three under one roof is what lets a finding from a red team exercise become a detection rule on Monday and an audited control by the next review.

Our esteemed clientele

Managed SOC & MDR

Somebody is watching at 3am. It should be us.

Detection engineering, 24x7 triage, and orchestrated containment on a platform that combines SIEM, SOAR and behavioural analytics — run as a service against a response clock you can hold us to.

Response targets by severity

Critical
15 minutes
High
30 minutes
Medium
60 minutes
Low
120 minutes

Targets are contractual and reported against monthly. Final figures are agreed during scoping.

Monitoring coverage
24x7x365
Critical incident response target
15 min
Searchable log retention
365 days
Threat intelligence feeds
40+

Governance, Risk & Compliance

Audit-ready is a state, not a fortnight.

ISO certification, RBI and NHB audit readiness, policy frameworks and the risk process that keeps them alive between audits.

Frameworks we implement and audit against

ISO/IEC 27001:2022

ISO 9001:2015

ISO 14001:2015

ISO 45001:2018

RBI cyber security framework

NHB directions for HFCs

CIS Benchmarks

NIST Cybersecurity Framework

How an engagement runs

Predictable from kickoff to closure.

Every engagement runs the same three phases, with the same reporting cadence, whether it is a two-week application test or a multi-year managed service.

  1. Phase 1

    Planning and initiation

    Scope, stakeholders, rules of engagement, escalation paths and the reporting format are agreed before any technical work starts. You get a named project lead and a plan with dates.

  2. Phase 2

    Execution

    The technical work runs with daily or weekly debriefs depending on the engagement. Anything critical is escalated the moment it is found, not held for the report.

  3. Phase 3

    Reporting and closure

    Technical and executive reports, a walkthrough with the teams who have to act, a prioritised remediation plan, and a retest to confirm closure.

Why Astra

Boutique by choice, not by size.

You get the people who do the work, not an account manager relaying questions to a delivery centre. Every engagement is staffed by certified practitioners, and the person who wrote your report is in the room when you discuss it.

More about the practice
  • A CERT-In empanelled information security auditor
  • ISO 27001 and ISO 9001 certified in our own operations
  • A team of 35+ security professionals based in India
  • Certifications spanning OSCP, OSWE, CISSP, CEH and ISO lead auditor
  • Deep experience with RBI and NHB regulated environments
  • Testing, operations and compliance under a single accountable practice

Start a conversation

Tell us what you're protecting.

A scoping call takes half an hour and costs nothing. You will speak to a practitioner, not a salesperson, and leave with a view of what the work would actually involve.