Adv. Kavya Reddy
Senior Partner, Hyderabad
Leads the Data Protection practice across DPDPA, GDPR and HIPAA; advises multinationals on cross-border transfer architecture
LL.M · CIPP/E · CIPM
Bar Council of Telangana & A.P.
SIRI Law LLP is India’s integrated cyber law and cybersecurity firm — the only practice where your attorney and penetration tester share a building, your legal advice carries technical authority, and your incident response activates within the hour.
You have 6 hours to notify
CERT-In. Every minute
of delay costs more.
Our integrated legal and forensics team delivers immediate incident response, evidence preservation, regulatory notification drafting, and litigation risk containment — all before your board meeting.
India’s first law practice
purpose-built
for the AI era.
EU AI Act compliance, NIST AI RMF alignment, LLM vendor contracts, algorithmic liability, and generative AI governance. We practise AI law the same way we do cybersecurity law: with deep technical fluency.
Legal + Security + Compliance.
One monthly retainer.
From ₹30,000/month.
Stop paying surprise legal invoices. SIRI Shield gives you a dedicated attorney, quarterly penetration testing, DPDPA compliance, and a 2-hour incident response SLA — all in a fixed monthly retainer.
ISO 27001, SOC 2, DPDPA
& SEBI CSCRF — compliance
backed by legal authority.
GRC from a consulting firm has no legal teeth. SIRI delivers it with legal enforceability, regulatory liaison, and attorney-client privilege protecting your compliance workpapers from discovery.
Legal infrastructure for
companies building on technology
— from seed to M&A.
From startup incorporation and SaaS contracts to VC funding rounds, IP protection, and M&A due diligence — SIRI is the legal infrastructure partner for India’s technology sector.
DPDPA implementation, cross-border transfer architecture and cyber law advisory — drafted and defended by the same team that runs the technical audit, so legal advice and evidence never disagree.
Learn MoreEnd-to-end implementation for ISO/IEC 27001, SOC 2, PCI DSS and HIPAA — gap assessment, control design, evidence collection and certification-audit support.
Learn MorePenetration testing, red teaming and attack-surface assessment — we test systems the way they can actually be attacked, across web, API, cloud and network.
Learn MoreRansomware response, breach investigation and court-admissible digital forensics — activated the moment an incident is confirmed, with CERT-In’s 6-hour notification clock already running.
Learn MoreOne accountable team across offensive security, AI security, incident response, digital forensics and cyber resilience — connected to SIRI Law LLP for the legal and regulatory side of the same problem.
Offensive security, AI security, incident response, digital forensics and cyber resilience delivered by one accountable team across 45 services — not handed between vendors.
LLMs, AI agents, autonomous systems and connected infrastructure are core to how SIRI is built, not bolted on to a traditional security practice afterward.
SIRI Law LLP and SIRI Security operate as one ecosystem — connecting legal and regulatory capability directly to technical response, not referred out to a separate firm.
CERT-In’s 2022 Directions require breach notification within 6 hours of discovery. SIRI Response investigates, contains and recovers on that timeline, every time.
Our People
Advocates, security engineers and forensic examiners who have advised through live breaches, regulatory investigations and cross-border transactions. Every engagement carries a named lead who answers for the outcome.
Founder & Managing Partner
Managing Partner, Hyderabad · 14+ yrs in practice
Counsels boards and CISOs through cyber incidents, DPDPA implementation and AI governance; founded SIRI's integrated legal–security practice
Supreme Court of India · Bar Council of Uttar Pradesh & Telangana
The Practice Team
Senior Partner, Hyderabad
Leads the Data Protection practice across DPDPA, GDPR and HIPAA; advises multinationals on cross-border transfer architecture
LL.M · CIPP/E · CIPM
Bar Council of Telangana & A.P.
Partner, New Delhi
Heads Litigation and Disputes; appears before the Delhi High Court, NCLT and the Cyber Appellate Tribunal in technology-led matters
LL.B · Delhi HC · NCLT
Bar Council of Delhi
Partner, Bengaluru
Leads AI and Emerging Technology Law; advises on EU AI Act classification, model governance and algorithmic accountability
LL.M (NLSIU) · EU AI Act · NIST AI RMF
Bar Council of Karnataka
Partner, Hyderabad
Leads Corporate and Commercial; structures technology M&A, venture rounds and cross-border investment under FEMA and SEBI
LL.B (NUJS) · FEMA · SEBI
Bar Council of Telangana & A.P.
Associate Partner, Hyderabad
Heads GRC and Compliance; delivers ISO 27001, SOC 2 and SEBI CSCRF programmes for regulated and listed entities
CISA · ISO 27001 LA · CISM
Certified Information Systems Auditor
Head of Cybersecurity, Hyderabad
Directs offensive security and incident response; leads red team engagements and CERT-In breach containment for enterprise clients
OSCP · CREST · CEH
Offensive Security Certified Professional
Digital Forensics Lead, Hyderabad
Leads digital forensics and evidence handling; prepares court-admissible forensic reports and testifies as an expert witness
CHFI · CCFP · CCSP
Computer Hacking Forensic Investigator
Senior Associate, Hyderabad
Advises startups from incorporation through Series C; structures ESOP pools, term sheets and founder arrangements
LL.B (NLSIU) · SEBI · FEMA
Bar Council of West Bengal
Senior Associate, Mumbai
Advises banks, NBFCs and payment aggregators on RBI licensing, SEBI CSCRF and financial-sector cyber resilience
LL.M · RBI · SEBI CSCRF
Bar Council of Maharashtra
AI & LLM Security Lead, Bengaluru
Runs adversarial testing of LLM and RAG deployments; assesses prompt injection, data poisoning and model supply-chain risk
OSCP · AWS Security · NIST AI
Offensive Security Certified Professional
Associate, New Delhi
Advises hospitals and healthtech platforms on ABDM, HIPAA alignment and health-data obligations under the DPDP Act
LL.B · ABDM · HIPAA
Bar Council of Delhi
When a breach hits at 2 AM you call one team — not two firms hoping to coordinate. SIRI integrates legal counsel and cybersecurity into a single engagement so every decision is made once, by people who own the consequences.
Our mission is to create a safer digital world where enterprises flourish and customers are empowered with confidence in their data security. With SIRI, you gain a trusted partner committed to your growth and resilience in a rapidly evolving regulatory ecosystem.
Achieve seamless organisational privacy compliance with respect to DPDPA, GDPR, HIPAA and global regulations.
Strengthen your information security posture with compliance to ISO 27001, SOC 2 and universally recognised standards.
Ensure compliance with every sectoral regulation governing your industry — RBI, SEBI, IRDAI, CERT-In and more.
At the heart of our practice is a multidisciplinary team of advocates, information security engineers and data protection specialists, united by a shared mission: empowering organisations to thrive in an increasingly regulated digital landscape.
CERT-In Directions, 2022 — s.70B(6) IT Act, 2000
CERT-In’s 2022 Directions require breach notification within 6 hours of discovery. Every minute of delay increases your regulatory and litigation exposure. Our integrated legal-forensics team mobilises immediately.
Calculate Your Notification Deadline
Deadline = discovery time + 6 hours, per CERT-In’s 2022 Directions. This is a planning estimate, not legal advice on your specific obligations.
Response Velocity vs. Exposure
Illustrative model, not measured data from a specific matter — shown to explain why response speed matters, not as a performance guarantee.
Legal, cybersecurity, AI governance, digital forensics, privacy, compliance and investigations — connected through one operating model, not sold as isolated services.
Every engagement, policy, incident, contract, audit finding and regulatory obligation sits in one connected model — so legal advice, technical evidence and board reporting draw on the same record rather than three disconnected ones.
Select any node to see the capability, the instruments that govern it, and where it sits in the platform.
Under the Digital Personal Data Protection Act, accountability does not stop at collection. It travels with the data — through processing, through every third party it is shared with, through storage, and back to the principal who can ask what you did with it. Mapping that path is where compliance actually begins.
Legal counsel, offensive security, compliance and litigation — delivered by one accountable team across 49 services and six practice groups.
No services match that search.
Three interconnected layers that work together to reduce your organisation’s cyber risk holistically — not sold as isolated services.
Proactive testing to find and fix vulnerabilities before attackers do. We simulate real-world attack scenarios across web, cloud, network and AI systems.
Continuous security operations and monitoring through SIRI MDR — the operation that never stops, backed by threat hunting and incident response.
Navigate complex regulatory landscapes with confidence — technical implementation for ISO 27001, SOC 2, DPDPA and sector-specific frameworks.
All 45 services — offensive security, managed detection, governance and AI security — plus the SIRI Intel, Exposure, Response and Labs technology modules live at sirisecurity.com, built and supported by the same team behind SIRI Law LLP.
Four specialist areas ahead of where Indian regulation currently sits — built now, so you are covered when the rules catch up.
The first practice to combine AI Act legal compliance with AI red teaming and LLM security assessment under one engagement.
Attorney-designed privacy architectures that are legally enforceable and technically sound — not just policy compliant.
Legal and security advisory for national infrastructure, defence contractors, and government technology programmes.
Smart contract audits, token structuring, exchange compliance, and digital asset dispute resolution under Indian law.
Five distinct client journeys — Indian enterprises, startups and cross-border clients in the United States and Canada. One firm that handles all of them.
Enterprise / CISO
Penetration testing, GRC readiness, and a legal team that defends your posture before regulators and boards — running simultaneously, not sequentially.
Enterprise Security →Startup / Scale-up
Founder agreements, VC due diligence readiness, DPDPA compliance, and IP protection — the full legal stack for technology companies growing fast.
Startup Services →In-House Legal / GC
Specialist cyber law and security expertise to augment your in-house team on DPDPA, incident response, and technology transactions your generalists can’t handle.
Enquire →Healthcare / FinTech
HIPAA alignment, RBI compliance, SEBI CSCRF, and sector-specific regulatory counsel for India’s most heavily regulated technology industries.
Enquire →Individual / SME
Cybercrime, data breaches, online fraud, or legal disputes with a technology dimension? We handle the legal and technical sides together.
Enquire Now →Three purpose-built tools that give SIRI clients a structural advantage in compliance, response, and intelligence.
Real-time regulatory intelligence platform delivering CERT-In updates, DPDPA developments, and emerging threat advisories directly to your legal and security teams.
Regulatory IntelWhy choosing separately costs more and delivers less when a breach hits.
| Capability | SIRI Law LLP | Traditional Law Firm | Security Firm Only |
|---|---|---|---|
| Legal representation before CERT-In | Yes | Yes | No |
| Penetration testing & red teaming | Yes | No | Yes |
| Attorney-client privilege on pentest reports | Yes | No | No |
| DPDPA compliance (legal + technical) | Both | Legal only | Technical only |
| Incident response < 2 hours | Yes — 24/7 | Legal only | Technical only |
| Regulatory filings (CERT-In, SEBI, RBI) | Attorney-drafted | Yes | No |
| AI/LLM security testing + AI law | Combined | Law only | Security only |
| Fixed monthly retainer | From ₹30,000 | Hourly only | Project-based |
| Court representation | Yes | Yes | No |
| Technical fluency of legal advisors | Deep technical | Limited | N/A |
We map your full legal and technical exposure across cyber, privacy, AI, and compliance domains — identifying the precise risks that require legal authority to resolve versus technical controls alone.
A single engagement brief covering legal obligations, technical gaps, and compliance priorities. No separate legal memo and security report. One integrated document, one chain of privilege.
Legal counsel, penetration testers, and GRC specialists execute simultaneously — not sequentially. Your DPDPA compliance review and your penetration test run in parallel, not series.
SIRI Shield retainer clients receive monthly legal updates, quarterly security testing, continuous compliance monitoring, and 24/7 incident response — all in one fixed monthly subscription.
We don’t hand over a report and walk away. We stay until the problem is closed — legally, technically, and commercially.
Case Studies
Every matter below closed the way it’s described here — no rounding up, no composite clients. If a deadline was 72 hours, it was 72 hours.
The moment a listed fintech’s systems were hit by ransomware, attorneys and forensics moved together. CERT-In notification and containment closed within 72 hours — no regulatory penalty issued.
Read outcomeAn enterprise deal was on hold for one line item: SOC 2 Type II. Legal drafting and technical audit ran in parallel, and certification was delivered in 14 weeks.
Read outcomeA Series B healthtech had investor due diligence eight weeks away and an unaudited DPDPA posture. The compliance review closed with zero critical findings, on schedule.
Read outcomeA government technology contractor faced an ISO 27001 deadline with no margin left. Gap assessment and remediation roadmap were delivered in 14 days.
Read outcomeLegal and security due diligence for a SaaS acquisition ran as one workstream instead of two. Material risks surfaced early and were priced into the final deal terms.
Read outcomeA single breach triggered notification duties in three legal regimes at once. India, EU, and US frameworks were managed in parallel — no enforcement action followed in any jurisdiction.
Read outcome“When ransomware hit at 2am, SIRI had a legal response and a technical containment team active within two hours. That dual capability is irreplaceable — no other firm we spoke with could offer both.”
Rajesh S.
CISO, Listed BFSI Enterprise
“SIRI got us DPDPA-compliant in 8 weeks. Their legal team drafted policies while the security team ran the technical audit simultaneously. Genuinely integrated — not two firms pretending to collaborate.”
Priya K.
VP Legal & Compliance, HealthTech SaaS
“The SIRI Shield retainer means our dedicated attorney knows our business inside-out. When EU AI Act questions came up at board level, SIRI had a comprehensive briefing ready within 24 hours.”
Arjun M.
Founder & CEO, AI/SaaS Scale-up
Frequently Asked
SIRI Shield — Retainer Plans
Three plans for every stage of growth. No surprise invoices. Switch or scale as your business evolves.
| Feature | Foundation ₹30K/mo |
Growth ₹75K/mo |
Enterprise Custom |
|---|---|---|---|
| Dedicated advocate hours/month | 10 hrs | 25 hrs | Unlimited |
| DPDPA compliance | ✓ Gap + Monitor | ✓ Full Implementation | ✓ Full + vDPO |
| GDPR advisory | — | ✓ Advisory | ✓ Full Implementation |
| HIPAA compliance | — | Advisory only | ✓ Full Implementation |
| UAE / Singapore / Canada privacy | — | Advisory | ✓ Full Coverage |
| Virtual DPO (vDPO) | — | Partial coverage | ✓ Named officer |
| Penetration testing | Annual (1 scope) | Quarterly (2 scopes) | Full red team + unlimited |
| ISO 27001 / SOC 2 readiness | — | ✓ Included | ✓ + PCI-DSS + NIST |
| Incident response SLA | 4 hours | 2 hours | 1 hour (24/7) |
| CERT-In notification support | ✓ | ✓ | ✓ + Regulator liaison |
| Technology contract reviews/month | 1 | 3 | Unlimited |
| Trademark & IP advisory | — | ✓ Watch + advisory | ✓ Full portfolio mgmt |
| Fundraising documentation | — | ✓ Included | ✓ + M&A diligence |
| Board-level reporting | — | ✓ Monthly | ✓ + Audit committee |
| AI governance advisory | — | Advisory | ✓ Full EU AI Act framework |
| Website & app policies | ✓ Initial draft | ✓ Annual refresh | ✓ Ongoing maintenance |
All plans include a free onboarding consultation. Pricing is exclusive of applicable taxes. Plans can be upgraded or paused with 30 days’ notice. This is a general description; specific terms, scope, and deliverables are set out in the engagement agreement.
Regulation in cyber, privacy, and AI law moves faster than most firms can track. We write about the parts that will actually change what your organisation has to do next.
Data Privacy
A practical checklist for data fiduciaries as enforcement shifts from guidance to penalty.
May 2026
Read ArticleAI Law
Why a European regulation can reach a company that has never opened an EU office.
April 2026
Read ArticleIncident Response
What has to happen inside those six hours — and where most incident plans break down.
March 2026
Read ArticleSix questions on DPDPA, CERT-In readiness, vendor contracts and incident response. Get an instant baseline score and see where your gaps are — no email required.
This assessment is general regulatory information, not legal advice on your specific situation. Your answers are processed entirely in your browser and are never transmitted or stored.
Come with your situation — legal, technical, or somewhere in between. We will listen carefully and give you an honest view of how we can help.
SIRI Law LLP is an India-based multidisciplinary practice. Where jurisdiction-specific legal representation is required in the United States or Canada, SIRI coordinates with appropriately qualified local counsel.
Free 30-minute consultation — discuss your cyber law or security challenge with a SIRI attorney.
SIRI Law LLP uses cookies to improve your experience and analyse site usage. By using this site you agree to our Privacy Policy and DPDPA-compliant data practices.