Our philosophy

Risk-based. Vendor-agnostic. Business-aware.

Security exists to enable the business — not the other way around. That belief shapes every recommendation we make. We don't have a preferred vendor list. We don't take referral fees. Every product and service we recommend is recommended because it fits your risk, your budget, and your team's ability to operate it.

01

Risk-based

Decisions follow the risk register, not the vendor pipeline. Every spend ties back to a quantified risk, not a fashion.

02

Vendor-agnostic

We're free to recommend what's right — including doing nothing. No product affiliations. No referral fees. No conflicts.

03

Business-aware

Security that lifts revenue, not friction. We work with — not against — your sales, product and operations teams.

How we work

Founders in the program. Always.

You don't get a senior partner in the proposal meeting and a junior consultant after the SOW is signed. The same operators who pitched the work are the operators who deliver it.

·

Founders-led

The senior operators in the proposal are the operators in the program — not a bait-and-switch.

·

Fractional or retainer

Engage us fractionally for a vCISO program, or on retainer for advisory and on-call leadership.

·

No referral fees

We don't take vendor kickbacks. Recommendations follow your risk, not our rebate sheet.

·

Weekly & monthly reporting

Working-level updates weekly. Board-level metrics monthly. Every engagement, every time.

·

Documented run-state

You walk away with the playbook — never dependent on a single person or vendor.

·

Confidentiality first

NDAs and need-to-know boundaries are sacrosanct. References available on direct request only.

Founders

Three decades of cyber leadership

You'll work directly with our founders — on strategy, delivery and the day-to-day. We keep the team small so accountability never gets diluted.

Rohit Srivastwa

Rohit Srivastwa

Co-Founder · Managing Director

Three decades in cybersecurity. Founder of multiple security ventures and community initiatives; published author, frequent industry speaker, and active mentor. Leads strategy, business and product security at KAS.

Aalok Karnik

Aalok Karnik

Co-Founder · Field CISO

Field CISO with deep experience running GRC, audit and incident response for regulated enterprises. Leads vCISO engagements and the deployment of security controls inside client environments.

Stuti Srivastava

Stuti Srivastava

Co-Founder · Head of Operations

Runs operations across KAS — engagements, scheduling, finance and client success. Keeps the practice moving smoothly so the team stays focused on the work that matters to clients.

Global presence

Three offices, one accountable team

Distributed by design — so your program runs across timezones, not just in business hours.

United States flag

Seattle, USA

2033 Sixth Ave, Suite 600
Seattle, WA 98121

Sweden flag

Trollhättan, Sweden

Hovslagaregatan 17, LGH 1101
461 62 Trollhättan

India flag

Pune, India

504, Water's Square, Pimple Nilakh
Pune 411027

Standards & frameworks

Mapped once. Used everywhere.

Avoid duplicate audit and control mapping work. We design one program and reflect it into every framework your business needs.

NIST CSF
CIS Controls
ISO 27001:2022
C2M2
SOC 2
RBI / CERT-In
DPDP / GDPR
CSCRF
IEC 62443
EU-NIS2
EU-CRA
and many more…

Let's talk security strategy

Whether you're scoping an ISO 27001 certification, recovering from an incident, or hiring your first vCISO — we'd love to help.