Cybersecurity, GRC and AI governance
KrishanHarwani
I test whether security controls actually work, and help organizations close the gap when they don't.
I didn't start with governance. I started with technology.
During my engineering years, I was fascinated by how systems worked: how applications were built, how data moved, and how technology could solve real problems.
But the more I learned about technology, the more interesting questions started appearing.
What happens when that technology is misconfigured?
Who should have access to it?
What happens when sensitive data is exposed?
How does an organization know whether its security controls actually work?
That curiosity pulled me deeper into cybersecurity.
From technology to security.
I pursued a Master's in Cyber Security and began moving beyond simply understanding how technology works. I wanted to understand how organizations protect it.
That led me into Information Security, Risk Management and Data Privacy. My work became less about individual systems and more about the bigger picture.
People. Processes. Technology. Risk. Controls. Compliance.
Then I discovered the world behind the controls.
As a consultant in Deloitte's Cyber Strategy practice, I worked across very different environments.
HealthcareFinancial servicesFMCGManufacturingRetailMediaMetalsPharma
ISO 27001 and ISO 27701 implementations and sustainment. Internal audits, risk assessments, access reviews, vendor risk, policies, awareness and cybersecurity assessments.
ISO/IEC 27001:2022, Annex A 5.18 Access rights
User access rights are reviewed at regular intervals, and removed when people leave or change roles.
- Owner
- IT Security
- Frequency
- Quarterly
- Design
- Documented and approved
- Status
- Implemented
Review noteDesigned, yes. But is it operating? Nobody has tested it.
A security control on paper doesn't necessarily mean an organization is secure.
- Why
You have to understand why the control exists.
- Test
You have to test whether it works.
- Risk
You have to understand the risk behind it.
- Close
And when something doesn't work, you help the organization actually close the gap.
That changed the way I looked at cybersecurity.
From compliance to understanding risk.
Auditing became one of the ways I learned to see an organization.
A backup control isn't just evidence.
It's about whether the organization can actually recover when something goes wrong.
A policy isn't just a document.
It's about whether people and processes actually follow it.
This is where cybersecurity became more interesting to me.
I stopped looking at controls individually and started looking at the system around them.
And then came AI.
Can the same technology I'm helping organizations govern also make cybersecurity work better?
That led me toward AI management systems and AI-enabled security workflows.
Cybersecurity×Governance×Risk×Privacy×AI
Not AI for the sake of AI.
But AI that can help security teams analyze evidence, identify gaps, understand risk and reduce repetitive work.
Krishan Harwani
Cybersecurity and GRC Consultant
Where I am now.
I spend most of my time building, breaking, and figuring things out.
Cybersecurity is where I started: auditing systems, understanding risks, and learning how organizations protect their technology.
But I don't want to stop there.
These days, I'm experimenting with websites, applications, automation, AI, and security tools, sometimes because I want to solve a problem, and sometimes simply because I want to know how it works.
I'm exploring different corners of technology, from cybersecurity and AI to building things from scratch.
Not everything I build has a grand purpose.
“Can I actually build this?”
And that's what keeps me curious.
The working papers.
Selected engagements. Clients are described by sector, not by name.
Manufacturing, medical devices, oil
DPDP Act 2023 implementation
Implemented India's Digital Personal Data Protection Act for organizations in three sectors, from data mapping to notices and consent.
Nexdigm
FMCG
Internal IT audits
Endpoint security, logical access and segregation of duties, IT asset management, Microsoft 365 configuration, firewall rules, patching and backups.
Deloitte
Media and entertainment
Led an internal audit
User access reviews, incident management and data protection measures, from planning to reporting.
Deloitte
Healthcare, financial services, retail
ISO 27001 and ISO 27701
Implementation and sustainment of security and privacy management systems across several companies, plus ISO 27001 internal audits.
Deloitte
Pharmaceutical and biotech
NIST CSF assessment
Maturity and gap assessment against the NIST Cybersecurity Framework, with a roadmap to close the gaps.
Deloitte
Policy and procedure
SAMA CSF and NCA ECC
Policies and procedures drafted to align with the SAMA Cyber Security Framework and the NCA Essential Cybersecurity Controls.
Deloitte
Financial services
Cloud assessment framework
Helped validate a cloud assessment model and framework through a successful finance sector pilot.
Deloitte
Metals and financial services
Security awareness
Awareness sessions, lock screen posters and security email campaigns for employees.
Deloitte
Across engagements
Risk and proposals
Security risk assessments, vendor risk evaluations, risk closure plans and technical proposals that set out scope, method and deliverables.
Deloitte
HackerOne, Bugcrowd, Zerocopter
Bug bounty, after hours
Access control and exposure findings in commercial programs, plus coordinated disclosures to Dutch public sector organizations. An audit tells you what a company promised. A test tells you whether it held.
Independent
So what's next?
I'm interested in building the bridge between two worlds.
The discipline of cybersecurity and governance.
The possibilities of AI.
I don't just want to understand whether a control exists.
I want to understand whether it works, why it matters, and how we can make the process better.
If that sounds like the work you need done, let's talk.
krishanharwani1@gmail.com