Risk Grustlers EP 9 | The Art of Cyber Defense: Wisdom from a Seasoned Security Leader

In life, we often come face-to-face with critical choices that shape our future. Akshay Ahuja, a driven individual armed with a B. Tech degree, stood at such a crossroads. The decision to either tread the common path of the development industry or embark on an MS certification in cybersecurity would ultimately define his professional trajectory.
Choosing the road less traveled, Akshay embraced the realm of cybersecurity, delving into the intricacies of safeguarding digital assets and ensuring compliance. Little did he know that this bold choice would lead him to become a distinguished professional in the field, amassing over a decade of experience in the cybersecurity and compliance domain.
We are excited to kick off our new podcast series with Akshay Ahuja, Principal of Information Security at M2P Fintech!
From highlighting the need for automation in ensuring compliance to revealing what it takes to become a cybersecurity professional today, here's a look at some of the things that Akshay and Pratyush discussed in their hour-long conversation.
PK: Why don't you start off by telling us about your career journey so far?
AA: Sure. In my early career, I transitioned from electronics and communication engineering to become a SOC analyst driven by my passion for cybersecurity. Although I initially planned to pursue a master's degree, circumstances led me down a different path. Engaging in the business side of cybersecurity, I gained valuable experience in SOC operations before transitioning into consulting at Panacea. As an associate consultant, I grew to handle significant engagements, particularly in certification matters.
Within the PCI accreditation domain, I served as a Qualified Security Assessor (QSA), akin to an auditor, providing rigorous assessments and recommendations to clients. Over the course of my career, I audited 100+ organizations spanning diverse sectors, including multinational corporations, Indian clients, banks, and merchants. These experiences exposed me to various geographies and enriched my understanding of different security environments.
PK: PCI access being your core expertise in consultancy, a large part of your exposure would have been to Fintech regulations and organizations. Is that correct?
AA: Yes, that is true, but I also worked with various industries beyond fintech, including hospitality, e-commerce, and m-commerce. While each industry has its own regulations, cybersecurity and compliance are common concerns. Regulators like SEBI and IRDA governed specific sectors, while the overall concepts of cybersecurity and compliance remained similar across industries.
PK: As far as regulators are concerned every company is a payments company, be it commerce, hospitality or a hardcore finance financial services company. What is your opinion on this?
AA: I agree. Take, for example, Flipkart.com, which is primarily an e-commerce platform, interacting with end consumers. However, when it comes to accepting payments, they enter the realm of fintech regulations. Safeguarding the payment process becomes crucial in ensuring compliance with the relevant regulations and maintaining security throughout the lifecycle. This demonstrates how even non-payment-focused companies can become subject to fintech regulations due to their involvement in payment transactions.
PK: What are your thoughts on the growing number of regulations that fintech organizations have to adhere to?
AA: Over the past seven years, I have witnessed a significant increase in regulations, especially post-COVID. The digital era, coupled with India's focus on digital transformation, has led to a surge in inquiries about the Indian market and concepts like UPI (Unified Payments Interface). As a result, there has been a corresponding increase in cyber threats, prompting the need for stricter regulations.
Many regulators in the Middle East closely follow the guidelines set by the Reserve Bank of India (RBI), with some regulations being almost identical. The RBI's research and development efforts have influenced other regulators to adopt similar approaches rather than going through the same hurdles independently.
PK: How do you think Indian fintech organizations can stay up to date with these regulations?
AA: Regulatory frameworks are released with specific compliance deadlines, and companies are expected to adhere to them. While I appreciate the regulators' efforts to enhance cybersecurity, certain circulars, particularly those affecting the fintech industry, have disrupted the market. The circulars change business strategies and can be both positive and negative for companies.
To manage these regulatory changes, staying up to date with RBI circulars is crucial. Joining communities or dedicating team members to review RBI circulars has become a common practice among companies. Regulated entities (REs) directly answerable to the RBI have a more extensive role in staying informed and managing vendors accordingly.
These days, keeping up with regulatory updates has become an essential part of the role, ensuring compliance and effective vendor management.
PK: How can an organization leverage technology to be compliant?
AA: One viable option that comes to mind is implementing a common control framework. Conducting audits on a daily basis is impractical, but through my research, I have found that around 65 to 75% of regulations relating to Infosec, major compliances, and industry practices share common principles. This indicates a convergence of requirements across different regulations and governance frameworks. The key objective now is for companies to establish their own common control framework.
I witnessed a company that deviated from standard audits and created its own company control framework. They performed internal audits based on this framework, ensuring compliance with regulations and standards. They aligned their controls, conducted audits, validated evidences, and generated reports. This approach provided a streamlined process.
We can observe similar principles followed by major cloud providers like Amazon Workspace, Google Cloud, and Microsoft Azure. They adhere to numerous compliances, not only national standards but also local regulations such as GDPR in Europe, PDPL in Singapore, NGDPR in Nigeria, CCPA and HIPAA in the US, and local versions of ISMS in South Korea. It becomes crucial to establish a common control framework that can be adapted to meet these diverse regulatory requirements.
PK: How does automation, particularly in the compliance space, address the limitations faced by auditors and enhance their effectiveness in adapting to rapid technological changes?
AA: Automation is crucial in the current landscape as it allows for reduction of manual efforts. As an auditor, both technical and non-technical aspects rely on their knowledge, but there are limitations to how deep they can delve into an environment.
In my experience, I have witnessed exponential changes within five years, transitioning from physical data centers to cloud and serverless architectures. Auditors must adapt, constantly learn new technologies, and stay updated with industry trends. Third-party audits alone are insufficient in this rapidly changing landscape.
Automation, including the use of AI technologies like OpenAI and ChatGPT, is becoming essential in the compliance market. It is the future and a necessary direction for organizations to move forward in compliance efforts.
PK: What advice would you give young people who are interested in becoming cybersecurity professionals?
AA: To excel in the cybersecurity industry, it is crucial to start early and plan your path. Whether you are pursuing engineering, law, or any other field, gaining knowledge and skills in cybersecurity early on is essential. Take courses and engage in learning opportunities to understand the various profiles within the cybersecurity domain. Look for internships that allow you to gain practical experience and outperform expectations. Determination and focus are key attributes that will set you apart in this rapidly evolving industry.
Starting early and defining your specific field of interest within cybersecurity is vital. Simply mentioning “Infosec†is not enough; you need to understand the nuances of the specific field you want to pursue. Consider internships as they provide exposure to different domains within Infosec, helping you determine your career direction. Internship experiences will guide your learning path and enable you to make informed decisions. Remember that opportunities are abundant in the cybersecurity field, particularly in addressing supply chain gaps, and being prepared will help you seize them.
Ready to see what security-first GRC really looks like?
Ready to see what security-first GRC really looks like?
Ready to see what security-first GRC really looks like?
See what a real security- first GRC platform looks like
Ready to see what security-first GRC really looks like?
Focus on the traveler experience. We’ll handle the regulations.
Get Scrut. Achieve and maintain compliance without the busywork.
Choose risk-first compliance that’s always on, built for you, and never in your way.
Ready to see what security-first GRC
One platform, every framework. No more duplicate work.
You can’t manage user access if you’re always playing catch-up.
Explore the future of enterprise GRC
Tired of chasing vendors for risk assessments?
Join the thousands of companies automating their compliance with Scrut.
The right partner makes all the difference. Let’s grow together.
Make your business easy to trust, put security transparency front and center.
Risk-first security starts with risk-first visibility.
Secure your team from the inside out.
Don't settle for slow, expensive compliance. Get Scrut instead.
Risk-first compliance for forward-thinking teams.
Audits without the back-and-forth. Just seamless collaboration.
Scale fast. Stay compliant. Automate the rest.
Compliance? Done and dusted, in half the time.
Get ahead of GDPR compliance before it becomes a problem.
Outgrowing table-stakes compliance? Create custom frameworks with ease.
Navigate SOC 2 compliance, minus the stress.
PCI DSS compliance, minus the panic.
Take the wheel of your HIPAA certification journey today.
We’ve got what you need to fast-track your ISO 27001 certification.
Make your NIST AI RMF journey as smooth as possible.
Your GRC team, multiplied and AI-backed.
Modern compliance for the evolving education landscape.
Ready to simplify healthcare compliance?
Don’t let compliance turn into a bottleneck in your SaaS growth.
Find the right compliance frameworks for your business in minutes
Ready to see what security-first GRC really looks like?
Real-time visibility into every asset
Ready to simplify fintech compliance?
The Scrut Platform helps you move fast, stay compliant, and build securely from the start.
Scrut helps you set up a security program that scales with your business and stands up to audits. Without last-minute chaos.
Scrut helps you streamline audits, close deals faster, and stay ahead of risk without slowing down your team. Because trust shouldn’t take months to earn.
Scrut helps you set up a security program that scales with your business and stands up to audits. Without last-minute chaos.
Tag, classify, and monitor assets in real time—without the manual overhead.
Whether you're entering new markets or launching new products, Scrut helps you stay compliant without slowing down.
Scrut pulls compliance data straight from the tools you already use—so you don’t have to dig for evidence, chase approvals, or manually track controls.
Less manual work, more customizability. The Scrut Platform gives you everything you need to align your compliance to your business’s priorities.
With Scrut, you’re not just adding a tool to your offering—you’re adding a competitive edge. Join our Partner Network and help your clients streamline their GRC program.
Gaining trust is your first step to growing and cracking better deals. The Scrut Platform comes pre-built with all the tools you need to showcase a firm security posture and build confidence.
Don’t settle for rigid systems—Scrut ensures your risk management strategy is as flexible as your business needs.
Start building a security-first culture. Save your operations from improper training and a lack of compliance awareness.
Scrut fast-tracks compliance so you can focus on scaling, not scrambling. Automate compliance tasks and accelerate enterprise deals—without the grind.
Automate assessments, track compliance, and get full visibility into third-party risk—all in one place.
Scrut automates compliance tasks, supports proactive risk management, and saves you time, so you can focus on growing your business. Start building trust with customers and scaling confidently.
Leave legacy GRC behind. Meet the AI-powered platform built for teams managing risk and compliance in real time.
Give auditors direct access, keep track of every request, and manage audits effortlessly—all in one place.
Scrut ensures access permissions are correct, up-to-date, and fully compliant.
Whether you need fast results or a fully tailored program mapped to your risks and needs, Scrut delivers exactly what you need, when you need it. Ready to start?
Scrut unifies compliance across all your frameworks, so you can stop juggling systems and start scaling securely.
Manually managing your compliance processes and audits can get inefficient and overwhelming. Scrut automates these outdated, manual processes and eliminates your last-minute worries.
Access automated compliance, real-time risk tracking, and expert-backed support—all in one platform. Get started with Scrut!
Less manual work, more customizability. The Scrut Platform gives you everything you need to align your compliance to your business’s priorities.
The Scrut Platform helps you move fast, stay compliant, and build securely from the start.
Earn trust and back it up with solid evidence. Scrut takes you through the SOC 2 compliance journey step-by-step, navigating every complexity you face.
Manage your PCI DSS compliance with real-time monitoring and effortless automation. Get started with Scrut today!
Securing your PHI shouldn’t be a constant hassle. Scrut automates your workflows—from risk assessments to monitoring—so you can put your compliance worries on the back burner.
Automate security controls, simplify audits, and keep your ISMS aligned with the latest standards. Get started with Scrut!
Tackle potential AI risks with NIST AI RMF-compliant controls and get expert support every step of the way.
Offload the grunt compliance work to us. Execute manual, draining GRC tasks with the reliable AI-powered Scrut Teammates without switching contexts or bottlenecks.
Whether you're managing student data, partnering with educational institute, or expanding to new geographies—Scrut gives you the tools to stay compliant, manage risk, and build trust at every step.
Scaling healthcare doesn’t have to come at the cost of security. Scrut keeps your organization compliant, audit-ready, and protected—no matter how fast you grow.
Scrut automates the hard parts of compliance and security so you can move fast and stay ahead of risks from day one.
The Scrut Platform helps you move fast, stay compliant, and build securely from the start.
Growth in fintech comes with heavy scrutiny. Scrut helps you stay compliant, audit-ready, and secure—without slowing down your momentum.



