Chetan Seripally
Managing Partner, Hyderabad
Counsels boards and CISOs through cyber incidents, DPDPA implementation and AI governance; founded SIRI's integrated legal–security practice
LL.B · CISSP · CIPP/E
Bar Council of Telangana & A.P.
SIRI Law LLP is India’s integrated cyber law and cybersecurity firm — the only practice where your attorney and penetration tester share a building, your legal advice carries technical authority, and your incident response activates within the hour.
You have 6 hours to notify
CERT-In. Every minute
of delay costs more.
Our integrated legal and forensics team delivers immediate incident response, evidence preservation, regulatory notification drafting, and litigation risk containment — all before your board meeting.
India’s first law practice
purpose-built
for the AI era.
EU AI Act compliance, NIST AI RMF alignment, LLM vendor contracts, algorithmic liability, and generative AI governance. We practise AI law the same way we do cybersecurity law: with deep technical fluency.
Legal + Security + Compliance.
One monthly retainer.
From ₹30,000/month.
Stop paying surprise legal invoices. SIRI Shield gives you a dedicated attorney, quarterly penetration testing, DPDPA compliance, and a 2-hour incident response SLA — all in a fixed monthly retainer.
ISO 27001, SOC 2, DPDPA
& SEBI CSCRF — compliance
backed by legal authority.
GRC from a consulting firm has no legal teeth. SIRI delivers it with legal enforceability, regulatory liaison, and attorney-client privilege protecting your compliance workpapers from discovery.
Legal infrastructure for
companies building on technology
— from seed to M&A.
From startup incorporation and SaaS contracts to VC funding rounds, IP protection, and M&A due diligence — SIRI is the legal infrastructure partner for India’s technology sector.
Our People
Advocates, security engineers and forensic examiners who have advised through live breaches, regulatory investigations and cross-border transactions. Every engagement carries a named lead who answers for the outcome.
Managing Partner, Hyderabad
Counsels boards and CISOs through cyber incidents, DPDPA implementation and AI governance; founded SIRI's integrated legal–security practice
LL.B · CISSP · CIPP/E
Bar Council of Telangana & A.P.
Senior Partner, Hyderabad
Leads the Data Protection practice across DPDPA, GDPR and HIPAA; advises multinationals on cross-border transfer architecture
LL.M · CIPP/E · CIPM
Bar Council of Telangana & A.P.
Partner, New Delhi
Heads Litigation and Disputes; appears before the Delhi High Court, NCLT and the Cyber Appellate Tribunal in technology-led matters
LL.B · Delhi HC · NCLT
Bar Council of Delhi
Partner, Bengaluru
Leads AI and Emerging Technology Law; advises on EU AI Act classification, model governance and algorithmic accountability
LL.M (NLSIU) · EU AI Act · NIST AI RMF
Bar Council of Karnataka
Partner, Hyderabad
Leads Corporate and Commercial; structures technology M&A, venture rounds and cross-border investment under FEMA and SEBI
LL.B (NUJS) · FEMA · SEBI
Bar Council of Telangana & A.P.
Associate Partner, Hyderabad
Heads GRC and Compliance; delivers ISO 27001, SOC 2 and SEBI CSCRF programmes for regulated and listed entities
CISA · ISO 27001 LA · CISM
Certified Information Systems Auditor
Head of Cybersecurity, Hyderabad
Directs offensive security and incident response; leads red team engagements and CERT-In breach containment for enterprise clients
OSCP · CREST · CEH
Offensive Security Certified Professional
Digital Forensics Lead, Hyderabad
Leads digital forensics and evidence handling; prepares court-admissible forensic reports and testifies as an expert witness
CHFI · CCFP · CCSP
Computer Hacking Forensic Investigator
Senior Associate, Hyderabad
Advises startups from incorporation through Series C; structures ESOP pools, term sheets and founder arrangements
LL.B (NLSIU) · SEBI · FEMA
Bar Council of West Bengal
Senior Associate, Mumbai
Advises banks, NBFCs and payment aggregators on RBI licensing, SEBI CSCRF and financial-sector cyber resilience
LL.M · RBI · SEBI CSCRF
Bar Council of Maharashtra
AI & LLM Security Lead, Bengaluru
Runs adversarial testing of LLM and RAG deployments; assesses prompt injection, data poisoning and model supply-chain risk
OSCP · AWS Security · NIST AI
Offensive Security Certified Professional
Associate, New Delhi
Advises hospitals and healthtech platforms on ABDM, HIPAA alignment and health-data obligations under the DPDP Act
LL.B · ABDM · HIPAA
Bar Council of Delhi
When a breach hits at 2 AM you call one team — not two firms hoping to coordinate. SIRI integrates legal counsel and cybersecurity into a single engagement so every decision is made once, by people who own the consequences.
Our mission is to create a safer digital world where enterprises flourish and customers are empowered with confidence in their data security. With SIRI, you gain a trusted partner committed to your growth and resilience in a rapidly evolving regulatory ecosystem.
Achieve seamless organisational privacy compliance with respect to DPDPA, GDPR, HIPAA and global regulations.
Strengthen your information security posture with compliance to ISO 27001, SOC 2 and universally recognised standards.
Ensure compliance with every sectoral regulation governing your industry — RBI, SEBI, IRDAI, CERT-In and more.
At the heart of our practice is a multidisciplinary team of advocates, information security engineers and data protection specialists, united by a shared mission: empowering organisations to thrive in an increasingly regulated digital landscape.
CERT-In Directions, 2022 — s.70B(6) IT Act, 2000
CERT-In’s 2022 Directions require breach notification within 6 hours of discovery. Every minute of delay increases your regulatory and litigation exposure. Our integrated legal-forensics team mobilises immediately.
Calculate Your Notification Deadline
Deadline = discovery time + 6 hours, per CERT-In’s 2022 Directions. This is a planning estimate, not legal advice on your specific obligations.
Response Velocity vs. Exposure
Illustrative model, not measured data from a specific matter — shown to explain why response speed matters, not as a performance guarantee.
Legal, cybersecurity, AI governance, digital forensics, privacy, compliance and investigations — connected through one operating model, not sold as isolated services.
Every engagement, policy, incident, contract, audit finding and regulatory obligation sits in one connected model — so legal advice, technical evidence and board reporting draw on the same record rather than three disconnected ones.
Select any node to see the capability, the instruments that govern it, and where it sits in the platform.
Turn regulatory complexity into decisions a board can act on. Contracts, privacy, disputes and corporate counsel, with the technical record attached.
Explore →Prevent, investigate, respond and recover. Penetration testing, forensics and CERT-In incident response instructed under a single legal engagement.
Explore →Build organisations that are secure, compliant and investment-ready. ISO 27001, SOC 2, DPDPA programmes and AI governance frameworks.
Explore →Not your traditional law firm.
SIRI Law LLP is designed around how modern businesses actually operate. As your long-term counsel, we act as catalysts for growth — not gatekeepers to it.
Purpose-built for how modern technology businesses actually operate — from pre-revenue startups to listed enterprises with multi-jurisdictional obligations.
Advocates and security engineers under one roof. No translation layer, no coordination gap between legal advice and technical reality.
Compliance aligned with product design, user flows, software architecture and business operations — not bolted on after the fact.
We balance legal risk against business growth. Our advice is legally sound, commercially practical and operationally implementable.
We see ourselves as long-term legal partners, not transactional service providers. Our retainer models are startup-friendly and growth-aligned.
Your first consultation is always free. Come with your situation — we will listen carefully and give you an honest view of how we can help.
Legal counsel, offensive security, compliance and litigation — delivered by one accountable team. 58 services across four practice areas.
58 services across 4 practice areas
Cyber, privacy, AI, commercial & corporate counsel.
Penetration testing, red teaming & AI/LLM security.
ISO 27001, SOC 2, DPDPA & global frameworks.
Courtroom advocacy across commercial & IP matters.
Four specialist areas ahead of where Indian regulation currently sits — built now, so you are covered when the rules catch up.
The first practice to combine AI Act legal compliance with AI red teaming and LLM security assessment under one engagement.
Attorney-designed privacy architectures that are legally enforceable and technically sound — not just policy compliant.
Legal and security advisory for national infrastructure, defence contractors, and government technology programmes.
Smart contract audits, token structuring, exchange compliance, and digital asset dispute resolution under Indian law.
Five distinct client journeys. One firm that handles all of them.
Enterprise / CISO
Penetration testing, GRC readiness, and a legal team that defends your posture before regulators and boards — running simultaneously, not sequentially.
Enterprise Security →Startup / Scale-up
Founder agreements, VC due diligence readiness, DPDPA compliance, and IP protection — the full legal stack for technology companies growing fast.
Startup Services →In-House Legal / GC
Specialist cyber law and security expertise to augment your in-house team on DPDPA, incident response, and technology transactions your generalists can’t handle.
Enquire →Healthcare / FinTech
HIPAA alignment, RBI compliance, SEBI CSCRF, and sector-specific regulatory counsel for India’s most heavily regulated technology industries.
Enquire →Individual / SME
Cybercrime, data breaches, online fraud, or legal disputes with a technology dimension? We handle the legal and technical sides together.
Enquire Now →Three purpose-built tools that give SIRI clients a structural advantage in compliance, response, and intelligence.
Real-time regulatory intelligence platform delivering CERT-In updates, DPDPA developments, and emerging threat advisories directly to your legal and security teams.
Regulatory IntelWhy choosing separately costs more and delivers less when a breach hits.
| Capability | SIRI Law LLP | Traditional Law Firm | Security Firm Only |
|---|---|---|---|
| Legal representation before CERT-In | Yes | Yes | No |
| Penetration testing & red teaming | Yes | No | Yes |
| Attorney-client privilege on pentest reports | Yes | No | No |
| DPDPA compliance (legal + technical) | Both | Legal only | Technical only |
| Incident response < 2 hours | Yes — 24/7 | Legal only | Technical only |
| Regulatory filings (CERT-In, SEBI, RBI) | Attorney-drafted | Yes | No |
| AI/LLM security testing + AI law | Combined | Law only | Security only |
| Fixed monthly retainer | From ₹30,000 | Hourly only | Project-based |
| Court representation | Yes | Yes | No |
| Technical fluency of legal advisors | Deep technical | Limited | N/A |
We map your full legal and technical exposure across cyber, privacy, AI, and compliance domains — identifying the precise risks that require legal authority to resolve versus technical controls alone.
A single engagement brief covering legal obligations, technical gaps, and compliance priorities. No separate legal memo and security report. One integrated document, one chain of privilege.
Legal counsel, penetration testers, and GRC specialists execute simultaneously — not sequentially. Your DPDPA compliance review and your penetration test run in parallel, not series.
SIRI Shield retainer clients receive monthly legal updates, quarterly security testing, continuous compliance monitoring, and 24/7 incident response — all in one fixed monthly subscription.
We don’t hand over a report and walk away. We stay until the problem is closed — legally, technically, and commercially.
Case Studies
Every matter below closed the way it’s described here — no rounding up, no composite clients. If a deadline was 72 hours, it was 72 hours.
The moment a listed fintech’s systems were hit by ransomware, attorneys and forensics moved together. CERT-In notification and containment closed within 72 hours — no regulatory penalty issued.
Read outcomeAn enterprise deal was on hold for one line item: SOC 2 Type II. Legal drafting and technical audit ran in parallel, and certification was delivered in 14 weeks.
Read outcomeA Series B healthtech had investor due diligence eight weeks away and an unaudited DPDPA posture. The compliance review closed with zero critical findings, on schedule.
Read outcomeA government technology contractor faced an ISO 27001 deadline with no margin left. Gap assessment and remediation roadmap were delivered in 14 days.
Read outcomeLegal and security due diligence for a SaaS acquisition ran as one workstream instead of two. Material risks surfaced early and were priced into the final deal terms.
Read outcomeA single breach triggered notification duties in three legal regimes at once. India, EU, and US frameworks were managed in parallel — no enforcement action followed in any jurisdiction.
Read outcome“When ransomware hit at 2am, SIRI had a legal response and a technical containment team active within two hours. That dual capability is irreplaceable — no other firm we spoke with could offer both.”
Rajesh S.
CISO, Listed BFSI Enterprise
“SIRI got us DPDPA-compliant in 8 weeks. Their legal team drafted policies while the security team ran the technical audit simultaneously. Genuinely integrated — not two firms pretending to collaborate.”
Priya K.
VP Legal & Compliance, HealthTech SaaS
“The SIRI Shield retainer means our dedicated attorney knows our business inside-out. When EU AI Act questions came up at board level, SIRI had a comprehensive briefing ready within 24 hours.”
Arjun M.
Founder & CEO, AI/SaaS Scale-up
Frequently Asked
SIRI Shield — Retainer Plans
Three plans for every stage of growth. No surprise invoices. Switch or scale as your business evolves.
| Feature | Foundation ₹30K/mo |
Growth ₹75K/mo |
Enterprise Custom |
|---|---|---|---|
| Dedicated advocate hours/month | 10 hrs | 25 hrs | Unlimited |
| DPDPA compliance | ✓ Gap + Monitor | ✓ Full Implementation | ✓ Full + vDPO |
| GDPR advisory | — | ✓ Advisory | ✓ Full Implementation |
| HIPAA compliance | — | Advisory only | ✓ Full Implementation |
| UAE / Singapore / Canada privacy | — | Advisory | ✓ Full Coverage |
| Virtual DPO (vDPO) | — | Partial coverage | ✓ Named officer |
| Penetration testing | Annual (1 scope) | Quarterly (2 scopes) | Full red team + unlimited |
| ISO 27001 / SOC 2 readiness | — | ✓ Included | ✓ + PCI-DSS + NIST |
| Incident response SLA | 4 hours | 2 hours | 1 hour (24/7) |
| CERT-In notification support | ✓ | ✓ | ✓ + Regulator liaison |
| Technology contract reviews/month | 1 | 3 | Unlimited |
| Trademark & IP advisory | — | ✓ Watch + advisory | ✓ Full portfolio mgmt |
| Fundraising documentation | — | ✓ Included | ✓ + M&A diligence |
| Board-level reporting | — | ✓ Monthly | ✓ + Audit committee |
| AI governance advisory | — | Advisory | ✓ Full EU AI Act framework |
| Website & app policies | ✓ Initial draft | ✓ Annual refresh | ✓ Ongoing maintenance |
All plans include a free onboarding consultation. Pricing is exclusive of applicable taxes. Plans can be upgraded or paused with 30 days’ notice. This is a general description; specific terms, scope, and deliverables are set out in the engagement agreement.
Regulation in cyber, privacy, and AI law moves faster than most firms can track. We write about the parts that will actually change what your organisation has to do next.
Data Privacy
A practical checklist for data fiduciaries as enforcement shifts from guidance to penalty.
May 2026
Read ArticleAI Law
Why a European regulation can reach a company that has never opened an EU office.
April 2026
Read ArticleIncident Response
What has to happen inside those six hours — and where most incident plans break down.
March 2026
Read ArticleSix questions on DPDPA, CERT-In readiness, vendor contracts and incident response. Get an instant baseline score and see where your gaps are — no email required.
This assessment is general regulatory information, not legal advice on your specific situation. Your answers are processed entirely in your browser and are never transmitted or stored.
Come with your situation — legal, technical, or somewhere in between. We will listen carefully and give you an honest view of how we can help.
From growth-stage startups to multinational corporations, we work with organisations of every scale across industries and jurisdictions — advising where law, technology and regulatory risk converge.
From early-stage startups to established enterprises — across India and globally.
Our scalable, outcome-driven approach has served organisations across industries and jurisdictions — from first incorporation through cross-border expansion and regulatory scrutiny.
All trade marks, service marks, trade names, logos and other proprietary designations mentioned on this website are the property of their respective owners. The use of these marks does not imply endorsement, affiliation or sponsorship. All rights are reserved by the respective trade mark holders.
SIRI had a legal response and technical containment team coordinated within the hour of ransomware hitting at 2 AM. The CERT-In notification was filed on time without us having to think about it.
SIRI got us fully DPDPA-compliant in eight weeks — consent architecture, vendor DPAs, privacy notice — ahead of our Series B diligence. Zero critical findings. They understand both the law and how a product actually works.
We needed ISO 27001 certification in fourteen days for a government contract renewal. The team delivered a complete remediation roadmap, documentation and internal audit support. The audit passed. The contract was retained.
Their AI governance framework gave our board the assurance it needed before we shipped an LLM feature into a regulated workflow. Clear, practical, and grounded in the actual regulation rather than hypotheticals.
Client names withheld and details anonymised by sector and role at client request. Testimonials published with permission. Outcomes described are specific to those matters and are not a guarantee of results in any other situation.
Talk To Us Today
Breach response, DPDPA compliance, or an ongoing retainer — the gap between your legal exposure and your security posture closes with one call. Not next quarter. Today.
Emergency line: +91 7981912046 · contact@sirilawllp.com
Offices in Hyderabad, New Delhi and Texas — with a fully remote engagement process available to clients anywhere in the world.
HITEC City, Hyderabad, Telangana, India — 500081
Contact this office →Connaught Place, New Delhi, India — 110001
Contact this office →Austin, Texas, United States of America
Contact this office →Every service available fully remote. No travel required.
We believe sustainable growth is built through long-term strategic partnerships founded on trust, shared values, and mutual success. Get in touch to explore a partnership.
All trade marks, service marks, trade names, logos and other proprietary designations mentioned on this website are the property of their respective owners. The use of these marks does not imply endorsement or sponsorship. All rights are reserved by the respective trade mark holders.
A monthly note on DPDPA enforcement, CERT-In directions, AI regulation and sectoral cyber rules — written for General Counsel and CISOs, not for search engines.
The next briefing lands at the start of the month. Nothing else in between.
Free 30-minute consultation — discuss your cyber law or security challenge with a SIRI attorney.
SIRI Law LLP uses cookies to improve your experience and analyse site usage. By using this site you agree to our Privacy Policy and DPDPA-compliant data practices.