Data Privacy | Tricona
TECHNOLOGY ASSURANCE & DATA PRIVACY

KNOW YOUR RISK.
PROVE YOUR CONTROLS.
STRENGTHEN WHAT MATTERS.

Independent, evidence-led assessment of systems, cloud environments, security controls and data-protection practices.

WHAT WE ASSESS

Technology risk, examined where it actually lives.

We assess how systems are designed, configured, operated and governed—not only what policies say should happen.

01

System & Technology Audits

Architecture, IAM and access controls, SDLC, security testing governance, monitoring, resilience and technology controls.

02

AWS & Cloud Security

IAM, CIS benchmarking, network exposure, encryption, vulnerability management, logging, backup and resilience.

03

DPDP Act, 2023 Readiness

Personal-data mapping, notices and consent, Data Principal rights, retention, safeguards, processors and governance.

04

Third-Party Technology Risk

Vendor access, processor relationships, security obligations, data sharing and critical technology dependencies.

OUR APPROACH

Evidence before assumptions.

Documentation review is only the beginning. We combine technical evidence, walkthroughs, architecture and configuration review, and control testing.

01DiscoverScope · Systems · Data
02AssessArchitecture · Controls
03EvidenceRecords · Configurations
04TestWalkthroughs · Validation
05Identify GapsRisk · Priority · Impact
06RemediateActions · Closure
SYSTEM & TECHNOLOGY AUDITS

Understand how the environment really operates.

We examine architecture, access models, application delivery practices, monitoring, resilience and governance against defined control expectations and the realities of your operating environment.

Architecture IAM & Access SDLC VAPT Governance Logging & Monitoring BCP / DR
SYSTEM ASSURANCECONTROL VIEW
ARCHITECTUREBoundaries
Dependencies
Exposure
ACCESSIAM
Privilege
Segregation
DELIVERYSDLC
Testing
Change
RESILIENCEBackup
Recovery
Monitoring
AWS & CLOUD SECURITY

Cloud controls that can be evidenced, not assumed.

We assess identity, configuration, exposure, encryption, vulnerability management, observability, backup and resilience across cloud environments.

IAM CIS Benchmarking Network Exposure Encryption Vulnerability Management Backup & Resilience
CLOUD CONTROL REVIEWAWS
IDENTITYUsers
Roles
Privileges
NETWORKIngress
Exposure
Segmentation
DATAEncryption
Storage
Backup
OPERATIONSLogging
Monitoring
Resilience
DIGITAL PERSONAL DATA PROTECTION ACT, 2023

From policy intent to operational readiness.

DPDP readiness requires more than drafting notices. We examine how personal data actually enters, moves through, is used by and leaves the organisation.

Our readiness and gap assessments connect privacy obligations to operational reality across technology, processes and third parties.

Personal-Data Mapping Notices & Consent Data Principal Rights Retention & Erasure Security Safeguards Processors & Vendors Breach Readiness Governance

Readiness assessment, gap identification and remediation support.

01PERSONAL DATA
02PURPOSE & CONSENT
03PROCESSING
04PROCESSORS
05RETENTION
06RIGHTS & ERASURE
THIRD-PARTY TECHNOLOGY RISK

Your control environment extends beyond your organisation.

We assess the technology and data dependencies created by vendors, processors and external platforms—including access, obligations, data sharing and concentration risk.

Vendor Access Processors Security Obligations Data Sharing Technology Dependencies
THIRD-PARTY VIEWDEPENDENCIES
ACCESSWho
What
Why
DATAShared
Processed
Stored
CONTROLObligations
Evidence
Assurance
DEPENDENCYCriticality
Continuity
Exit
REMEDIATION & CONTINUOUS ASSURANCE

Assessment should lead to action.

We translate findings into practical remediation priorities and can support closure reviews, periodic assessments and ongoing assurance.

TECHNOLOGY ASSURANCE

Know where the risk is. Strengthen what matters.

assurance@tricona.com

Request an Assessment →