Bing

Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Wednesday, March 4, 2026

Beyond “Military-Grade”: What Real VPN Cryptography Looks Like in 2026

 The VPN industry loves big numbers.

“Military-grade encryption.”
“Bank-level security.”
“AES-256.”

Microsoft what happened to my personal outlook email getting blocked? The same email associated with my banks, startup registrations, cloud accounts, patent etc… But I thank Microsoft for Startup Founders, Corporate Vision Magazine, Government of U.K, Perplexity, NASSCOM 10000, my parents, my elder sister.

 

I do have plans of creating a VPN product focused on security: https://vpn.alightservices.com/


But here’s the problem:
Encryption strength isn’t just about one algorithm or one number. It’s about architecture.

In 2026, serious users — founders, developers, security-minded teams — are asking better questions:

  • How often are session keys rotated?
  • How long is any single key valid?
  • What happens if a key is exposed?
  • How much damage can an attacker realistically do?

Let’s talk about what modern cryptographic hygiene actually looks like — and how it compares to the current VPN market.


The Market Standard Today

Most major commercial VPN providers generally implement:

  • Strong industry-accepted public-key cryptography
  • AES-256 or ChaCha20-Poly1305 for symmetric encryption
  • Perfect Forward Secrecy (PFS)
  • Modern protocols like OpenVPN or WireGuard

But there’s a difference between:

“Using strong encryption”

and

“Designing cryptographic systems to minimize blast radius.”

That difference is where serious security engineering begins.


Public Key Strength:

In most commercial VPN deployments, public key cryptography is configured at levels considered secure by today’s standards.

These configurations are widely trusted and computationally efficient.

However, some providers choose to operate with a significantly larger safety margin for asymmetric key strength.

Why?

Because asymmetric keys:

  • Protect session establishment
  • Authenticate servers
  • Prevent impersonation

If an attacker were ever able to break or compromise these keys, they could attempt server impersonation or session interception.

Increasing the strength margin dramatically raises the cost of theoretical cryptographic attacks — not for marketing, but for long-term resilience.

It’s about designing for a world where computational power keeps increasing.


Symmetric Encryption: The Algorithm Is Only Part of the Story

Most reputable VPNs today use:

  • AES-256 (widely hardware accelerated)
  • Or ChaCha20-Poly1305 (efficient on mobile devices)

ALightVPN also uses modern, widely trusted symmetric ciphers.

But here’s the critical point:

The algorithm matters less than how long the key lives.


The Overlooked Factor: Key Rotation Frequency

In many market implementations:

  • Symmetric session keys are derived at handshake
  • Keys may persist for extended session durations
  • Rekeying intervals vary by configuration

This is not necessarily insecure.

But it does mean that if a session key were ever compromised — via memory disclosure, side-channel attack, or endpoint compromise — the attacker may gain visibility into a meaningful time window of traffic.

Now consider a different philosophy:

  • Symmetric keys rotate aggressively
  • Keys have extremely short lifetimes
  • Validity windows are tightly bounded
  • Even within a session, cryptographic state refreshes frequently

What does this change?

It reduces the potential damage window from “session-scale” to “minute-scale.”

That’s not incremental improvement.
That’s blast-radius minimization.


Why Short-Lived Keys Matter

Imagine an attacker somehow extracts a symmetric key from memory on a compromised device.

Two possible realities:

Scenario A — Standard Rotation

The key remains valid for a long period.
Captured traffic within that window may be decrypted.

Scenario B — Aggressive Rotation

The key expires quickly.
Captured material becomes useless within minutes.

In the second case:

  • Data exposure window collapses
  • Replay usefulness drops
  • Long-term surveillance becomes impractical
  • Retrospective decryption becomes harder
  • Ingesting packets of data based on compromised keys doesn’t happen

Security isn’t about assuming compromise will never happen.

It’s about limiting how much damage is possible if it does.


Forward Secrecy: Not Just a Checkbox

Perfect Forward Secrecy (PFS) is widely supported across modern VPN protocols.

But implementation depth varies.

There is a meaningful difference between:

  • Supporting forward secrecy
  • Designing around extremely narrow validity windows

When session keys are:

  • Frequently renegotiated
  • Strictly time-bounded
  • Cryptographically independent

The system becomes far more resilient to:

  • Key compromise
  • Memory scraping attacks
  • Traffic harvesting
  • Future cryptanalysis

Market Positioning vs Security Philosophy

Many VPN providers optimize for:

  • Speed
  • Streaming compatibility
  • Server count
  • Geographic diversity
  • Marketing claims

ALightVPN takes a different stance.

It is not optimized for:

  • Streaming platforms
  • Entertainment use cases

It is engineered around:

  • Tight cryptographic windows
  • Reduced blast radius
  • Strong asymmetric margins
  • Strict key lifecycle control
  • Defense-in-depth

The goal is not convenience-first VPN usage.

The goal is reducing scope of damage even if keys are exposed (post-quantum threat).


What This Means for Founders & Small Teams

If you’re:

  • Logging into admin dashboards from public networks
  • Accessing staging servers remotely
  • Managing infrastructure from airports
  • Using SaaS tools with sensitive client data

Then the relevant question is not:

“Is the encryption strong?”

The relevant question is:

“If a key is ever exposed, how long is the damage window?”

In most consumer marketing, that question is never discussed.

In serious security architecture, it’s central.


The Bigger Picture: Cryptographic Hygiene

Strong VPN security in 2026 should include:

  • Modern symmetric ciphers
  • High-strength asymmetric authentication
  • Perfect Forward Secrecy
  • Aggressive key rotation
  • Strict key expiration
  • Fail-closed kill switch behavior
  • No third-party traffic routing

Encryption is not a feature.
It’s a system.

And systems are only as strong as their weakest lifecycle decision.


Final Thoughts

The market has matured.
Basic encryption is no longer a differentiator.

What differentiates serious infrastructure from commodity VPN services is:

  • Margin
  • Rotation discipline
  • Validity constraints
  • Architectural intent

ALightVPN is built around minimizing exposure windows — not maximizing marketing slogans.

Because real security isn’t about having strong locks.

It’s about replacing the keys before anyone has time to copy them.

 

I do have plans of creating a VPN product focused on security: https://vpn.alightservices.com/



Follow on social media to stay updated on the latest developments:

ALight Technologies USA Inc | Facebook

https://www.facebook.com/ALightTechnologyAndServicesLimited

Web Veta | Facebook

WebVeta Saas | LinkedIn

https://www.linkedin.com/company/alight-technologies-usa-inc/

https://www.linkedin.com/company/alight-technology-and-services-limited/

https://twitter.com/ALightTech

https://www.youtube.com/@alighttechnologyandservicesltd

https://blog.alightservices.com/

https://medium.com/@ALlightTechnologyAndServices

https://kantikalyan.wordpress.com/

-

Best regards,

Mr. Kanti Arumilli 


I don’t have any fake aliases, nor any virtual aliases like some of the the psycho spy R&AW traitors of India. NOT associated with the “ass”, “es”, “eka”, “ok”, “okay”, “is”, erra / yerra karan, kamalakar, diwakar, kareem, karan, erra / yerra sowmya, erra / yerra, zinnabathuni, bojja srinivas (was a friend and batchmate 1998 – 2002, not anymore – if he joined Mafia), mukesh golla (was a friend and classmate 1998 – 2002, if he joined Mafia), erra, erra, thota veera, uttam’s, bandhavi’s, bhattaru’s, thota’s, bojja’s, bhattaru’s or Arumilli srinivas or Arumilli uttam(may be they are part of a different Arumilli family – not my Arumilli family).




Saturday, August 12, 2023

Minor update for opensource LightKeysTransfer has been published

 This version has these additional features:

1) Directly paste some content such as keys from clipboard.

2) The output can be written into a file or can replace specific section of a file.


https://github.com/ALightTechnologyAndServicesLimited/LightKeysTransfer/


The previous version had the capability of securely transferring the content of some small files. This version allows securely transferring the entire content of a file or specific line.


This is a tool, I have been developing for my own purposes, because I don't want any sensitive information to be displayed on the screen. Specifically because of the toes equipment misuse.

toes - terrorist odour (I think extremist section of India's spying organization R&AW) have a very powerful swarm of invisible micro-drones capable of viewing (camera), recording audio / video, whsipering (speakers) and even mind-reading.

This tool is a small step towards cyber-security to prevent their hacking attempts! Who knows they might have even used for por*o*raphy, blackmailing etc...



If the R&AW spies misrepresented and lied under oath in whatever "eye witness testimony", why am I being harassed, framed, blamed and why are they demanding extortion?


I don’t have any fake aliases, nor any virtual aliases like the psycho spy R&AW traitors of India. NOT associated with the erra / yerra karan, kamalakar, diwakar, kareem, karan, erra / yerra sowmya, erra / yerra sowjanya, zinnabathuni sowjanya, bojja srinivas (was a friend and batchmate 1998 – 2002, not anymore), mukesh golla (was a friend and classmate 1998 – 2002, not anymore), erra sowmya, erra sowjanya, thota veera, uttam’s, bandhavi’s, bhattaru’s, thota’s, bojja’s, bhattaru’s or Arumilli srinivas / Arumilli uttam(may be they are part of a different Arumilli family – not my family). I don’t have any siblings by the name of Sowjanya or Sowmya, Srinivas, Uttam.


-

Mr. Kanti Kalyan Arumilli

B.Tech, M.B.A

https://www.facebook.com/kanti.arumilli

https://www.linkedin.com/in/kanti-kalyan-arumilli/

https://www.threads.net/@kantiarumilli

https://www.instagram.com/kantiarumilli/

https://www.youtube.com/@alighttechnologyandservicesltd

https://www.youtube.com/@kantikalyanarumilli

https://twitter.com/KantiKalyanA/

https://kantikalyan.medium.com/

https://www.facebook.com/ALightTechnologyAndServicesLimited/

https://www.linkedin.com/company/alight-technology-and-services-limited/

Founder & CEO, Lead Full-Stack .Net developer

ALight Technology And Services Limited

Phone / SMS / WhatsApp on the following 3 numbers:

+91-789-362-6688, +1-480-347-6849, +44-07718-273-964

+44-33-3303-1284 (Preferred number if calling from U.K, No WhatsApp) 

Friday, March 31, 2023

CyberSecurity - New Tool - SecureOTP

    I have mentioned in the past of implementing very high cyber security standards. Pretty much the cyber security standards have been implemented and after much analysis the following bottlenecks were identified. The analysis has been performed based on the capabilities of the anonymous targeted hackers - R&AWMAAfia's equipment capabilities:

1) Possibility of OTP theft either OTP's received on Phone or OTP's received via EMail.

The need entering a OTP received on phone on a laptop or entering a OTP received on email in a laptop into an application on mobile. The OTP should NOT be displayed on screen. Instead the application would show XXXX - Copy/Transfer button.

With this use case identified a much needed tool for bridging this security loophole is needed.

I plan to develop this tool and release in the next few months. The tool would be developed using .Net MAUI. Lot of Operating Systems would be supported - iOS, Android, Windows, Mac. 

I am considering options such as communicating over bluetooth or local wifi - eliminating the need for server component.

In June 2022, I have wrote a blog post - An Architecture for Secure communication between two clients!. In this blog post, I have discussed an architecture for securely pairing two devices over the public internet without the need for any accounts. The architecture is like pairing of bluetooth devices over bluetooth, pairing of Netflix / Youtube with television but has few more steps for secure pairing and securely transferring data.

But, I don't want to develop the server component, because in this usecase the devices i.e laptop, mobile would be close enough and might be on the same wifi network. So, bluetooth, same wifi transfer would be appropriate. But the session specific public / private keypair generation for transferring data, pairing of devices part of the above mentioned architecture would still happen.

This would be developed along with WebVeta. And this would be completed almost in-time before the production release of WebVeta. I am thinking sometime around November 2023. This way, WebVeta production would be in a very secure environment and I am pretty much doing a thorough, holistic analysis of cyber security.

Thanks to great contributions by great people from around the world, the frameworks such as NIST, free courses and paid courses, documentation etc... have helped me in improving my knowledge of cyber security and figuring out ways to thwart the R&AWMAAfia hackers - who are violating human rights by hacking, privacy invasion by using mind reading equipment of invisible drones, doing identity distortion, identity theft, intellectual property theft.




I don’t have any fake aliases, nor any virtual aliases like the psycho spy R&AW traitors of India. NOT associated with the erra / yerra karan, kamalakar, diwakar, kareem, karan, erra / yerra sowmya, erra / yerra sowjanya, zinnabathuni sowjanya, bojja srinivas (was a friend and batchmate 1998 – 2002, not anymore), mukesh golla (was a friend and classmate 1998 – 2002, not anymore), erra sowmya, erra sowjanya, thota veera, uttam’s, bandhavi’s, bhattaru’s, thota’s, bojja’s, bhattaru’s or Arumilli srinivas / Arumilli uttam(may be they are part of a different Arumilli family – not my family). I don’t have any siblings by the name of Sowjanya or Sowmya, Srinivas, Uttam.


Mr. Kanti Kalyan Arumilli

B.Tech, M.B.A

Facebook

LinkedIn

Founder & CEO, Lead Full-Stack .Net developer

ALight Technology And Services Limited

Phone / SMS / WhatsApp on the following 3 numbers:

+91-789-362-6688, +1-480-347-6849, +44-07718-273-964

+44-33-3303-1284 (Preferred number if calling from U.K, No WhatsApp)

kantikalyan@gmail.com, kantikalyan@outlook.com, admin@alightservices.com, kantikalyan.arumilli@alightservices.com, KArumilli2020@student.hult.edu and 3 more rarely used email addresses – hardly once or twice a year.  

Sunday, February 5, 2023

Roadmap for next few months!

Roadmap for next few months!


Here is the roadmap for the next 3 - 6 months for ALight Technology And Services Limited.

1) Implement NIST Cyber Security Framework

2) Alpha / Beta of a new Product - Alerts!

3) Use Alerts for all the internal alerts of ALight Technology And Services Limited.


Alerts would be done in a semi-open-sourced approach i.e anyone who wants to implement a similar solution can implement by following the technical blog. For example, if I am writing code for Slack integration, I would write a blog post and provide the code, similarly for any other integrations. I am definitely open for consulting for Architecture, AWS Cloud Architecture, .Net based development.


The concept of Alerts:

One platform to manage alerts with different sets of business rules.

For example, let's say an application was built and sends email alerts. And what if you want to use WhatsApp / Telegram / SMS alerts? The code has to be re-developed, tested, deployed. What if there was a simple API for sending alert and the targets can be configured? What if multiple targets are supported? What if based on application, time of day, escalation rules different targets can be used? This is a very small niche, but a necessity for every software company. Big companies would probably have their own internal implementations of Alerting Microservices. Smaller startups and mid-sized companies can benefit by focusing on product features rather than worrying about alerting integrations.


NOT associated with the erra / yerra karan, kamalakar, diwakar, kareem, karan, erra / yerra sowmya, erra / yerra sowjanya, zinnabathuni sowjanya, bojja srinivas (was a friend and batchmate 1998 – 2002, not anymore), mukesh golla (was a friend and classmate 1998 – 2002, not anymore), erra sowmya, erra sowjanya, thota veera, uttam’s, bandhavi’s, bhattaru’s, thota’s, bojja’s, bhattaru’s or Arumilli srinivas / Arumilli uttam(may be they are part of a different Arumilli family – not my family). I don’t have any siblings by the name of Sowjanya or Sowmya, Srinivas, Uttam.

Mr. Kanti Kalyan Arumilli

B.Tech, M.B.A

Facebook

LinkedIn

Founder & CEO, Lead Full-Stack .Net developer

ALight Technology And Services Limited

Phone / SMS / WhatsApp on the following 3 numbers:

+91-789-362-6688, +1-480-347-6849, +44-07718-273-964

kantikalyan@gmail.comkantikalyan@outlook.comadmin@alightservices.comkantikalyan.arumilli@alightservices.comKArumilli2020@student.hult.edu and 3 more rarely used email addresses – hardly once or twice a year.


Roadmap for next few months!

Friday, December 30, 2022

Live C# development session - 2 on January 2nd at 09:20 a.m India Time

Live C# development session - 2 on January 2nd at 09:20 a.m India Time 


Another 20 - 30 minute live video while developing the free, open source tool.





NOT associated with the erra / yerra karan, kamalakar, diwakar, kareem, karan, erra / yerra sowmya, erra / yerra sowjanya, zinnabathuni sowjanya, bojja srinivas (was a friend and batchmate, not anymore), mukesh golla (was a friend and classmate, not anymore), erra sowmya, erra sowjanya, thota veera, uttam’s, bandhavi’s, bhattaru’s, thota’s, bojja’s, bhattaru’s.

Mr. Kanti Kalyan Arumilli

B.Tech, M.B.A

Facebook

LinkedIn

Founder & CEO, Lead Full-Stack .Net developer

ALight Technology And Services Limited

+91-789-362-6688, +1-480-347-6849, +44-07718-273-964

Live C# development session - 2 on January 2nd at 09:20 a.m India Time

Live C# development session - 1

Live C# development session - 1


As mentioned in previous blog posts - An approach for securing some sensitive content and The need for serious security I.T, current state of a sophisticated spies / hackers equipment, I am planning to do few live coding sessions over the next few days. Once the code is complete, the code would be available for anyone via Github. Any C# beginner interested in Cryptography, System.Diagnostics.Process are welcome to ask questions.





Live C# development session - 1

Wednesday, December 14, 2022

LightMonitor Initiation - Recorded Video

LightMonitor Initiation - Recorded Video


As mentioned in a previous blog post - LightMonitor Initiation - Live Streaming, I went live at noon on 15/12/2022. This video is about what LightMonitor is about, what is the current landscape of the market, what is the opportunity, some of the ways my product would be different. Some advanced hacking equipment being used by spies / hackers and how to minimize the threat, some secure development practices, some of my favorite software etc...  




NOT associated with the erra / yerra karan, kamalakar, diwakar, kareem, karan, erra/yerra sowmya, erra/yerra sowjanya, zinnabathuni sowjanya, bojja srinivas (was a friend and batchmate, not anymore), mukesh golla (was a friend and classmate, not anymore), erra sowmya, erra sowjanya, thota veera, uttam’s, bandhavi’s, bhattaru’s, thota’s, bojja’s, bhattaru’s.


Mr. Kanti Kalyan Arumilli

B.Tech, M.B.A



Founder & CEO



LightMonitor Initiation - Recorded Video

Monday, December 12, 2022

NIST Cyber Security Framework Part - 1

NIST Cyber Security Framework Part - 1


Cross post - https://kantikalyan.medium.com/nist-cyber-security-framework-part-1-b9bd659ab094


As mentioned in a previous blog post - Moved to India and Cyber Security, I have started studying the Cybersecurity Risk Management Framework Specialization on Coursera. This specialization has 3 courses:

1) NIST CSF - 4 Hours

2) NIST DoD RMF - 4 Hours

3) NIST 800-171 - 6 Hours


I am I.T business owner, I have worked as lead full stack .Net web developer in the past and have aspirations of software architect. Security awareness and expertise is very helpful in my journey towards software architect or even software security architect (fighting the bad guys - hackers). And in general cyber security awareness is a good thing, so I thought I would briefly summarize what I have learnt, this is in a certain way Tier-4 of NIST Cyber Security Framework i.e actively communicating with stake holders (here I am communicating with general public), proactively learning and benefitting the community (raising cyber security awareness for the general public can be considered as benefitting the community). I would say ALight Technology And Services Limited is at Tier-2 and transitioning towards Tier-3, by the end of Q3 2023, ALight Technology And Services Limited would be at Tier-4. I know I am very ambitious, I have been like that since childhood. One ambitious man's company - ALight Technology And Services Limited.


This is a series of blog posts, when I post more blog articles in this series, I would be updating the links in this blog.


"Cybersecurity" is defined as: 

- the protection of information assets by addressing threats to information processed, stored and transported by inter-networked information systems 

- measures taken to protect the integrity of networks, programs and data against "unauthorized" access, damage or attack 

- the state of being protected against the criminal or unauthorized use of electronic data, or the measures taken to achieve this 


Computer security entails: 

- Cybersecurity 

- Physical security 




Cybersecurity vs. information security 

- Information security deals with information 

○ Paper documents 

○ Digital and intellectual property 

○ Verbal or visual files 

○ Communications (regardless of media) 


- Cybersecurity is concerned with protecting the confidentiality, integrity and availability of digital assets 

○ Networks, hardware or software 

○ Information that is processed, stored or transported by networked information systems 



Cybersecurity consists of the triad known as CIA - Confidentiality, Integrity, Availability

Confidentiality: Different information requires different levels of confidentiality. Personal, financial, and medical information requires higher confidentiality.

Integrity: Integrity is about preventing unauthorized modifications / deletion. Preventing authorized subjects from making unauthorized modifications.

Availability: The assurance that authorized subjects can interact with resources.


Terms & Concepts:

Confidentiality: Prevention of unintentional disclosure 

Integrity: Preventing unauthorized modification 

Availability: Accessible to authorized users 

Auditability: Ability to track and reconstruct events from logs 

Identification: Verification of authorized person or process 

Authentication: Proof Of identification 

Authorization: What can you do 

Nonrepudiation: Cannot deny 

Layered security: Defense in depth 

Access control: Limiting access to authorized users or processes 

Security metrics, monitoring: Measuring security activities 

Governance: Providing control and direction 

Strategy: Method of achieving objectives 

Architecture: Used to define the information security strategy. Some examples are:

- Zachman 

- TOGAF (The Open Group Architecture Framework) 

- DODAF (U.S. Department Of Defense architecture framework) 

- MODAF (The British Ministry Of Defense Architecture Framework) 

- SABSA (Sherwood Applied Business Security Architecture)

Management: Overseeing activities 

Risk: The likelihood that a threat source will exploit one or more vulnerabilities 

             - Acceptable level of risk (aka risk appetite) 

Exposure: Being susceptible to asset loss because of a threat exploiting a vulnerability or 

flaw 

Vulnerabilities: NIST Special Publication 800-30 defines vulnerability as "an inherent weakness 

in an information system, security procedures, internal controls, or implementation that could 

be exploited by a threat source." 

Threats: A threat is any person, event or environmental factor that could affect or harm a protected asset.

Residual risk: The risk remaining after controls are put in place 

Impact: The results and consequences of a risk materializing 

Criticality: The higher the value, the more protection it needs. 

Sensitivity: Based on the classification and categorization  

Business impact analysis (BIA): Evaluating the results and consequences of compromise 

Business dependency analysis: An analysis of business resource dependencies, like a supply 

chain review 

Gap analysis: The difference between "what is" and the stated objective 

Controls: Actions to mitigate or reduce risk 

Countermeasures: Actions or process (controls) used to reduce vulnerabilities 

Policies: Management's interpretation of requirements 

Standards: Supports a policy by setting the boundaries 

Attacks: Types of compromises 

Data classification: Determining the sensitivity and criticality of information 


Technologies used in cyber security:

- Firewalls 

- User account administration 

- Intrusion detection and intrusion prevention 

- Antivirus 

- Public key infrastructure (PKI) 

- Secure Sockets Layer (SSL) 

- Single sign-on (SSO) 

- Biometrics 

- Encryption 

- Privacy compliance 

- Remote access 

- Digital signature 

- Electronic data Interchange (EDI) and electronic funds transfer (EFT) 

- Virtual private networks (VPNs) 

- Forensics 

- Monitoring technologies



Key CSF (Cyber Security Framework) attributes

It's a framework, NOT a prescriptive standard! 

- Provides a common language and systematic methodology for managing cyber-risk 

- Is meant to be adapted 

- Does not tell an organization how much cyber-risk is tolerable 

- Enable best practices 

- It's voluntary, except for federal agencies (it's mandatory for them) 

- It's a living document 

- It is intended to be updated as technology and risks change  



The Framework consists of 3 main components:

      - The framework core

      - The framework implementation tiers

      - The framework profiles



The framework consists of 5 functions, 23 categories and 98 sub categories.


Functions (IPDRR):

1) Identify - Develop an organizational understanding to manage cybersecurity risk to

systems, people, assets, data, and capabilities.

2) Protect - Develop and implement appropriate safeguards to ensure delivery of critical

services.

3) Detect - Develop and implement appropriate activities to identify the occurrence of a

cybersecurity event.

4) Respond - Develop and implement appropriate activities to take action regarding a

detected cybersecurity incident

5) Recover - Develop and implement appropriate activities to maintain plans for resilience

and to restore any capabilities or services that were impaired due to a cybersecurity

incident.



Framework Implementation Tiers:
Framework implementation tiers are divided into 4 tiers. Companies adopting Cyber security framework would progress from Tier 1 to Tier 4.


Tier 1: Partial
Risk Management Process – Organizational cybersecurity risk management practices are
not formalized, and risk is managed in an ad hoc and sometimes reactive manner.
Prioritization of cybersecurity activities may not be directly informed by organizational
risk objectives, the threat environment, or business/mission requirements.
Integrated Risk Management Program – There is limited awareness of cybersecurity risk
at the organizational level. The organization implements cybersecurity risk management
on an irregular, case-by-case basis due to varied experience or information gained from
outside sources. The organization may not have processes that enable cybersecurity
information to be shared within the organization.
External Participation – The organization does not understand its role in the larger
ecosystem with respect to either its dependencies or dependents. The organization does
not collaborate with or receive information (e.g., threat intelligence, best practices,
technologies) from other entities (e.g., buyers, suppliers, dependencies, dependents,
ISAOs, researchers, governments), nor does it share information. The organization is
generally unaware of the cyber supply chain risks of the products and services it provides
and that it uses.

Tier 2: Risk Informed
Risk Management Process – Risk management practices are approved by management
but may not be established as organizational-wide policy. Prioritization of cybersecurity
activities and protection needs is directly informed by organizational risk objectives, the
threat environment, or business/mission requirements.
Integrated Risk Management Program – There is an awareness of cybersecurity risk at
the organizational level, but an organization-wide approach to managing cybersecurity
risk has not been established. Cybersecurity information is shared within the organization
on an informal basis. Consideration of cybersecurity in organizational objectives and
programs may occur at some but not all levels of the organization. Cyber risk assessment
of organizational and external assets occurs, but is not typically repeatable or reoccurring.
External Participation – Generally, the organization understands its role in the larger
ecosystem with respect to either its own dependencies or dependents, but not both. The
organization collaborates with and receives some information from other entities and
generates some of its own information, but may not share information with others.
Additionally, the organization is aware of the cyber supply chain risks associated with
the products and services it provides and uses, but does not act consistently or formally
upon those risks. 

Tier 3: Repeatable
Risk Management Process – The organization’s risk management practices are formally
approved and expressed as policy. Organizational cybersecurity practices are regularly
updated based on the application of risk management processes to changes in
business/mission requirements and a changing threat and technology landscape.
Integrated Risk Management Program – There is an organization-wide approach to
manage cybersecurity risk. Risk-informed policies, processes, and procedures are
defined, implemented as intended, and reviewed. Consistent methods are in place to
respond effectively to changes in risk. Personnel possess the knowledge and skills to
perform their appointed roles and responsibilities. The organization consistently and
accurately monitors cybersecurity risk of organizational assets. Senior cybersecurity and
non-cybersecurity executives communicate regularly regarding cybersecurity risk.
Senior executives ensure consideration of cybersecurity through all lines of operation in
the organization.
External Participation - The organization understands its role, dependencies, and
dependents in the larger ecosystem and may contribute to the community’s broader
understanding of risks. It collaborates with and receives information from other entities
regularly that complements internally generated information, and shares information
with other entities. The organization is aware of the cyber supply chain risks associated
with the products and services it provides and that it uses. Additionally, it usually acts
formally upon those risks, including mechanisms such as written agreements to
communicate baseline requirements, governance structures (e.g., risk councils), and
policy implementation and monitoring.

Tier 4: Adaptive
Risk Management Process – The organization adapts its cybersecurity practices based on
previous and current cybersecurity activities, including lessons learned and predictive
indicators. Through a process of continuous improvement incorporating advanced
cybersecurity technologies and practices, the organization actively adapts to a changing
threat and technology landscape and responds in a timely and effective manner to
evolving, sophisticated threats.
Integrated Risk Management Program – There is an organization-wide approach to
managing cybersecurity risk that uses risk-informed policies, processes, and procedures
to address potential cybersecurity events. The relationship between cybersecurity risk and
organizational objectives is clearly understood and considered when making decisions.
Senior executives monitor cybersecurity risk in the same context as financial risk and
other organizational risks. The organizational budget is based on an understanding of the
current and predicted risk environment and risk tolerance. Business units implement
executive vision and analyze system-level risks in the context of the organizational risk
tolerances. Cybersecurity risk management is part of the organizational culture and
evolves from an awareness of previous activities and continuous awareness of activities
on their systems and networks. The organization can quickly and efficiently account for
changes to business/mission objectives in how risk is approached and communicated.
External Participation - The organization understands its role, dependencies, and
dependents in the larger ecosystem and contributes to the community’s broader
understanding of risks. It receives, generates, and reviews prioritized information that
informs continuous analysis of its risks as the threat and technology landscapes evolve.
The organization shares that information internally and externally with other
collaborators. The organization uses real-time or near real-time information to understand
and consistently act upon cyber supply chain risks associated with the products and
services it provides and that it uses. Additionally, it communicates proactively, using
formal (e.g. agreements) and informal mechanisms to develop and maintain strong supply
chain relationships.


NIST Cyber Security Framework Part - 1

Happy Independence Day India 2026

                 India has come far after independence. India has one of the strongest economy, military. When we celebrate independence, we...