AI-FIRST CYBERSECURITY · Always Wise. Always Ahead. +91-95851-60363 info@semperwise.com DOVER, DE, USA

IT services cybersecurity

You hold the keys to your clients. That makes you the way in.

An IT services firm is trusted with what its clients guard most: admin accounts, VPN tunnels, password resets, customer records and source code. Attackers have noticed, and so have your clients’ regulators — who now write audit rights, testing duties and incident terms into your contract. This is what a client’s security review will actually ask, and how to have the evidence ready.

Reviewed 24 September 2026 · 17 sources cited

The short answer

For an IT services company, security is judged through its clients: their audits, their questionnaires and their regulators’ contract clauses. In India, report incidents to CERT-In within six hours and keep 180 days of logs; for foreign clients’ data the DPDP Act still requires reasonable security safeguards. EU financial clients must write audit and testing rights into your contract under DORA Article 30. Start with help-desk identity checks, privileged access and evidence you can hand over.

Why IT services

The vendor is now part of the attack surface.

Clients outsource work and access together. The service desk that resets passwords, the support team that reads customer records and the remote-management console that reaches every endpoint are all, to an attacker, a shorter route than the client’s own perimeter. Verizon’s 2026 Data Breach Investigations Report found that breaches with third-party involvement rose by 60% in a year, to 48% of all breaches in its dataset.

The most-discussed case began with a phone call. Marks & Spencer was attacked on 22 April 2025 and forecast a hit of around £300 million to operating profit. The attackers were reported to have called technology helplines, impersonated employees and had passwords reset; M&S’s chairman told MPs it was “sophisticated impersonation” involving a third party. Tata Consultancy Services ran the retailer’s technology helpdesk, opened an internal investigation and later told MPs it had found “no indicators of compromise within the TCS network”. Whoever was at fault, the lesson for every provider is the same: when a client is breached, the help-desk process becomes the question, and the vendor has to prove a negative in public.

The second route is people with legitimate access. Coinbase disclosed in May 2025 that criminals had bribed outsourced support agents to steal customer data; the agents worked for TaskUs in Indore, and one was caught photographing her screen with a personal phone. Coinbase notified nearly 70,000 customers, refused a $20 million extortion demand and estimated losses of up to $400 million. In March 2026 Telus Digital, another large outsourcer, admitted unauthorised access to “a limited number of our systems”, amid reports that attackers had used Google Cloud credentials taken in an earlier breach at a different supplier.

The third route is the tooling. In May 2025 the DragonForce ransomware group broke into a managed service provider through older flaws in its remote monitoring and management platform, then used that platform to steal data from and encrypt the MSP’s customers. The same month ConnectWise disclosed that a suspected nation-state actor had breached its environment and affected a small number of customers of its remote-access product. One console that reaches every client is one console to protect above all others.

This is why the question clients ask has changed from “are you certified?” to “show me”. The rest of this page covers what they will ask, what their regulators now require them to ask, and which evidence actually answers it.

Evidence

The numbers behind a client’s questions

Global figures from Verizon, Indian figures from IBM’s 2026 study, and the EU supervisors’ own list. Each is linked in the sources.

48% Of breaches involved a third party in Verizon’s 2026 dataset — up 60% on the previous year [1]
19 Critical ICT third-party providers designated under DORA on 18 November 2025, including TCS, Accenture, Capgemini, IBM, Kyndryl and NTT DATA [10]
19% Of Indian breaches began with phishing, including voice and SMS phishing — the most common way in [11]
15% Of Indian breaches began with a supply-chain compromise, the third most common route [11]
₹35.7 cr Average cost of a breach in India’s technology sector in 2026, second only to financial services [11]
+40% Higher median success for phone-based social-engineering simulations than for email ones — about 2% against 1.4% [1]

IBM’s India figures cover organisations of every size. The same study found offensive security testing — penetration testing and red teaming — to be the largest single cost reducer, saving ₹2.47 crore per breach on average.

Obligations that reach you

Your clients’ regulators are now writing your contract.

EU financial clients — DORA. The Digital Operational Resilience Act has applied to EU banks, insurers and investment firms since 17 January 2025. Article 30 tells them what their contracts with ICT providers must contain. Every contract must oblige you to help at no additional cost, or at a cost agreed in advance, when an incident touches the service, and to take part in the client’s security awareness programmes. Where your service supports a critical or important function, the contract must also give the client, an auditor it appoints and its regulator unrestricted rights of access, inspection and audit, and oblige you to participate and fully cooperate in the client’s threat-led penetration test. Nineteen of the largest providers — six of them IT services and consulting firms — were designated in November 2025 as critical providers under direct EU oversight. A mid-sized firm that is not on the list still inherits Article 30, through every EU financial client it serves.

Indian banks and NBFCs — RBI. On 28 November 2025 the Reserve Bank replaced its 2023 IT-outsourcing directions with entity-wise “Managing Risks in Outsourcing” Directions. The direction of travel did not change. In the NBFC version, for example, “service provider” expressly includes sub-contractors, and the regulated entity must carry out regular risk-based audits of its providers including their sub-contractors — it may rely on pooled audits or recognised third-party certifications, but that does not reduce its own responsibility. If you subcontract part of a bank or NBFC engagement, your subcontractor is in scope too. Our RBI framework page covers the regulated entity’s side.

Government clients. CERT-In’s guidelines for government entities tell departments and public-sector enterprises to put information security terms into every outsourcing contract — a right to audit, incident reporting arrangements — and to require the vendor’s audit report and a software bill of materials for what it delivers. Our government page covers what departments now write into tenders.

Your own duties in India. The April 2022 CERT-In Directions apply to “service providers” and to every body corporate: report listed incidents within six hours of noticing them, keep logs of all ICT systems for a rolling 180 days in India, and name a point of contact. An incident on your side is your report to make, not only your client’s. Where you process Indian clients’ personal data, the DPDP Rules require your client to put reasonable security safeguards into its contract with you, and to keep logs for a year.

Assurance, compared

Five things a client asks for — and what each one actually proves

A serious security review asks for several of these at once, because none of them answers everything. Knowing what each proves — and does not — tells you which one a given client needs.

Security questionnairePentest letterISO 27001 certificateSOC 2 Type II reportPublic trust page
What it proves What you say you do, in the client’s own words That a named scope was tested by an independent party on stated dates That a management system for information security exists and was audited against the standard That specific controls operated effectively over a period, in an auditor’s opinion Nothing independently — it is what you choose to publish
Who produces it You The testing firm An accredited certification body — never the consultant who built the system A licensed CPA firm under AICPA standards You
Point in time or period The day you answered The test window The audit, then surveillance audits The observation window the report covers Whenever it was last updated
What it does not prove That the answers are true That anything outside the scope is safe, or that fixes held That a given control works, or that your client’s data is in scope That controls outside the report work, or anything after the window closed Anything a reviewer has not been able to check
How a careful buyer checks it Asks for evidence behind the answers that matter Reads the scope, the dates, the severity counts and the retest status Checks the scope statement and the certification body’s accreditation Reads the auditor’s opinion, the exceptions and the complementary user controls Follows the links to the underlying evidence
Where it helps most Every review — it is the index to everything else Proving recent testing of the systems the client will touch European, Indian and Middle Eastern buyers and tenders North American technology buyers Cutting the number of questionnaires in the first place

We prepare organisations for ISO 27001 and SOC 2; an accredited certification body issues the certificate and a licensed CPA firm issues the SOC 2 report. Our pentest summaries can be published as an assessment certificate at a live link that shows scope and remediation status without exposing findings.

16-question self-check

What your client’s security review will ask

Written the way a client’s vendor-risk team asks it. Tick only what you could show an assessor today — a log, a record, a report — not what you intend to do.

Next step

Bring the questionnaire that is worrying you.

A 30-minute call with a practitioner who has sat on both sides of a vendor review. No charge, and no obligation.

  • Which of your contracts carry DORA, RBI or government audit clauses, and what each one demands of you
  • A test plan for the paths clients ask about: help-desk resets, remote access and the portals they use
  • A written scope and a fixed price, with a retest of every fix included
  • Findings mapped to ISO 27001 and SOC 2 controls, so remediation doubles as audit evidence
Book the call We reply within 24 business hours.

Who is in the room

Four people who will judge your security

Two sit at the client, two at your firm. Each needs something different from the same evidence.

The client’s vendor-risk analyst

Worried about
Whether your answers are true and current, and whether they will be asked why they believed them.
Has to show
A completed questionnaire with evidence behind the answers that matter, and a record of when it was last checked.
What we hand them
An answer library in which each answer retires when its evidence expires, and an assessment certificate link instead of a PDF.

The client’s CISO or regulator-facing auditor

Worried about
Your access into their environment — the help desk, the remote tools, the engineers with admin rights.
Has to show
To their regulator: that audit rights exist in your contract and are actually exercised, under DORA or RBI rules.
What we hand them
Test reports scoped to the services you provide them, and an evidence pack organised by their contract clauses.

Your CTO or delivery head

Worried about
A failed client audit stalling a renewal or a new logo.
Has to show
That controls operate the same way across dozens of client accounts, not only on the one being audited.
What we hand them
One control set mapped to ISO 27001, SOC 2 and each client’s clauses — see the unified control model.

Your service desk manager

Worried about
Being the help desk in the next headline.
Has to show
That identity is verified before every reset, and that the verification leaves a record.
What we hand them
A scoped test of the reset process by phone, with pretexts agreed in advance and results reported in aggregate, and training built from what it finds.

A plan you can run

Ninety days to a client review you can pass

Ordered by where providers are actually breached, then by what clients ask to see.

  1. Weeks 1–2

    Close the reset path

    • Write the identity-verification rule for password and MFA resets: call back on a number already on file, or a manager’s approval
    • Require a second approver for administrator and executive accounts
    • Brief the service desk on voice impersonation, with real examples
    • Make every reset leave a log entry that names the approver
  2. Weeks 3–6

    Take stock of access

    • List every client environment, account, VPN and remote-management tenant your people can reach
    • Replace shared admin credentials with named accounts and multi-factor login
    • Patch remote-management and remote-support tools and restrict their consoles
    • Set log retention to at least 180 days, stored in India
  3. Month 2

    Test what clients will ask about

    • Independent testing of your internet-facing systems, client portals and remote-access paths
    • A scoped social-engineering test of the service desk, with written authorisation
    • Fix, then retest — and keep the closure evidence
    • Rehearse the six-hour CERT-In report and each client’s notice clause
  4. Month 3

    Package the evidence

    • Map every contract’s audit, testing and incident clauses — DORA, RBI, government
    • Build an answer library from the evidence you now hold
    • Choose the ISO 27001 or SOC 2 path your client base actually asks for
    • Publish a trust page and a verifiable assessment certificate

Where SemperWise fits

What we do for IT services firms

Services are people doing the work; SemperWise One is the platform that keeps the evidence current between engagements. Each row says which.

“A client sent us a 300-question security questionnaire.”

SemperWise One™

Answer it once, with evidence, then reuse the answers for the next client. Each answer expires with the evidence behind it, so nothing stale goes out under your name.

Questionnaire automation

“Show us your latest penetration test.”

Service

Testing of your external surface, client-facing portals and remote-access paths. Every finding is confirmed by a person, and a retest is included.

VAPT

“Could someone talk our help desk into a reset?”

Service

An adversary-style assessment that can include phone-based impersonation of your service desk, with the population and pretexts agreed in advance and results reported in aggregate.

Red team assessment

“Our clients need proof we were tested — without the report.”

SemperWise One™

An assessment certificate at a live link that states scope and remediation status and updates as fixes land.

Assessment certificates

“European and Indian clients want ISO 27001.”

Service

We build the management system, run the internal audit and prepare you for Stage 1 and Stage 2. An accredited certification body issues the certificate.

ISO 27001 readiness

“US clients want a SOC 2 Type II.”

Service

Control design against the Trust Services Criteria and the evidence trail for the observation window. A licensed CPA firm issues the report.

SOC 2 readiness

“Forty client accounts, one set of controls.”

SemperWise One™

One control library mapped to ISO 27001, SOC 2, DORA and client clauses, with evidence that carries a collection date and an expiry.

Unified control model

“The APIs our clients’ customers use.”

Service

Object-level authorisation, token handling and tenant separation, tested endpoint by endpoint.

API security testing

Questions

IT Services security — answered.

What buyers in this sector ask us before they commit to anything.

Does the DPDP Act apply when we process foreign clients’ data in India?

Partly. Section 17(1)(d) exempts the processing of personal data of people outside India, carried out by a company in India under a contract with a party outside India, from most of the Act — but it expressly keeps sections 8(1) and 8(5). You remain responsible for compliance and must take reasonable security safeguards to prevent a breach, the duty that carries the Act’s highest penalty of up to ₹250 crore. Your employees’ data and any Indian client’s data are fully in scope, and the CERT-In reporting duty applies either way. Where a case sits at the edge of the exemption, take it to counsel. Our DPDP compliance work covers both sides.

What does DORA Article 30 mean for an Indian IT vendor?

If you provide ICT services to an EU bank, insurer or investment firm, your contract must contain what Article 30 lists. Every contract must oblige you to assist, at no additional cost or at a cost agreed in advance, when an incident touches your service, and to take part in the client’s security awareness programmes. For services supporting critical or important functions, the client, an auditor it appoints and its regulator get unrestricted rights of access, inspection and audit, and you must participate and fully cooperate in its threat-led penetration testing. DORA has applied since 17 January 2025, so these clauses are arriving at renewal time now.

Our client wants to audit us on site. Do we have to agree?

Increasingly, yes — because their regulator requires them to ask. EU financial clients must secure unrestricted audit rights under DORA for critical services, and the RBI’s 2025 outsourcing directions require Indian regulated entities to audit their service providers, including sub-contractors — though they may rely on pooled audits or recognised certifications. Negotiate the practicalities rather than the principle: notice periods, pooled audits where several clients share a service, how confidential information about other clients is protected, and who pays. Then make audits cheap to host by keeping evidence current, so an auditor’s visit is a review of records rather than a scramble.

SOC 2 or ISO 27001 — which will our clients accept?

It depends on who the clients are. North American technology buyers usually ask for a SOC 2 Type II report, issued by a licensed CPA firm; European, Indian and Middle Eastern buyers and most tenders ask for ISO 27001, issued by an accredited certification body. Many IT services firms end up needing both, and the controls overlap heavily, so build one control set and map it to each. Start with whichever your largest current clients ask for by name. Our ISO 27001 and SOC 2 pages explain the readiness work, and why no consultancy can issue either one.

Is a pentest letter enough for a client security review?

It answers one question — was a named scope tested recently by someone independent — and a careful reviewer will read it that narrowly. Expect follow-ups: what exactly was in scope, what was found at each severity, and whether fixes were retested. A letter covering your marketing website says nothing about the remote-access path into the client’s network. Scope testing around what the client will actually touch, include a retest, and give reviewers something they can verify, such as an assessment certificate at a live link, rather than a PDF that goes stale the week it is sent.

How do we stop help-desk social engineering?

Treat a password or MFA reset as a privileged action. Verify identity by calling back a number already on file or with a manager’s approval — never by questions whose answers are on social media. Require a second approver for administrators and executives, log every reset with the approver’s name, and make it acceptable for an agent to refuse and escalate. Then test it: Verizon’s 2026 data found phone-based social-engineering simulations succeed more often than email ones. A test by phone, with the pretexts agreed in advance and results reported without naming individuals, shows whether the rule holds under pressure.

Do we have to report a client’s incident to CERT-In?

The April 2022 CERT-In Directions apply to service providers as well as to every body corporate, and require listed incidents to be reported within six hours of noticing them. If the incident affects systems you operate — your help desk, your remote tools, a platform you run for the client — treat the report as yours to make, and agree in advance with each client who files what, so two reports do not contradict each other. Keep 180 days of logs in India so either of you can answer CERT-In’s follow-up questions. The client’s own contractual and regulatory notices run in parallel.

Can SemperWise carry out the CERT-In empanelled audit our client requires?

No. SemperWise is not CERT-In empanelled, and CERT-In’s audit guidelines forbid empanelled auditors from sub-letting or outsourcing an audit, so we cannot do it quietly on someone else’s letterhead either. Where a client or regulator requires an empanelled audit, you appoint the empanelled firm directly. We do the work around it: readiness, testing between mandatory audits, verifying that fixes hold, and mapping the evidence. We say this before any engagement starts, because the question will come up in your client’s review too.

How do we answer security questionnaires faster without overstating anything?

Answer once, with evidence, and reuse. Most questionnaires ask the same forty or fifty things in different words, so a library of approved answers — each linked to the evidence behind it, with a date — turns a two-week scramble into a review. The discipline that matters is expiry: an answer about last year’s penetration test should not go out after this year’s. A public trust page answers the common questions before they are asked. In SemperWise One, questionnaire automation works this way, with every answer retiring when its evidence does.

Sources

Checked by our research desk on 24 September 2026. Regulations and figures move; where a number here matters to a decision, follow it to the source.

  1. 2026 Data Breach Investigations Report — Verizon, 2026
  2. Mystery of M&S hack deepens as TCS claims none of its systems were compromised — TechRadar, 20 June 2025
  3. M&S ousts Indian outsourcer accused of £300m cyber attack failures — The Telegraph via Yahoo Finance, 26 October 2025
  4. Coinbase breach tied to bribed TaskUs support agents in India — BleepingComputer, 3 June 2025
  5. Outsourcer Telus admits to attack, possibly by ShinyHunters — The Register, 15 March 2026
  6. DragonForce ransomware abuses SimpleHelp in MSP supply chain attack — BleepingComputer, 27 May 2025
  7. ConnectWise breached in cyberattack linked to nation-state hackers — BleepingComputer, 29 May 2025
  8. Digital Personal Data Protection Act, 2023 (section 17 and the Schedule) — MeitY
  9. The European Supervisory Authorities designate critical ICT third-party providers under DORA — European Banking Authority, 18 November 2025
  10. List of designated critical ICT third-party service providers — EBA, EIOPA and ESMA, November 2025
  11. India records its highest average cost of a data breach — Cost of a Data Breach Report 2026 — IBM, 3 August 2026
  12. Regulation (EU) 2022/2554 on digital operational resilience (DORA), Articles 30 and 64 — EUR-Lex
  13. IT outsourcing under the RBI’s 2025 Directions: what has changed — Vinod Kothari Consultants, February 2026
  14. Guidelines on Information Security Practices for Government Entities — CERT-In
  15. Directions under sub-section (6) of section 70B of the IT Act, 2000 — CERT-In, 28 April 2022
  16. Digital Personal Data Protection Rules, 2025 (Rule 6) — MeitY, 13 November 2025
  17. Comprehensive Cyber Security Audit Policy Guidelines, v1.0 — CERT-In, 25 July 2025

All 17 industries we serve

Next step

Walk into the next client review with the evidence ready.

A 30-minute call, no charge. Bring the questionnaire or the contract clause that is worrying you. You leave knowing what it demands and what to fix first; if testing or readiness work makes sense, you get a written scope and a fixed price, with a retest included.