Cybersecurity, GRC and AI governance

KrishanHarwani

I test whether security controls actually work, and help organizations close the gap when they don't.

A graphite padlock with a steel shackle and a key in its brass cylinder, modelled in Blender.

I didn't start with governance. I started with technology.

During my engineering years, I was fascinated by how systems worked: how applications were built, how data moved, and how technology could solve real problems.

BE Computer Science, first with distinction
Jhulelal Institute of Technology, Nagpur. 2019 to 2022

But the more I learned about technology, the more interesting questions started appearing.

What happens when that technology is misconfigured?

Who should have access to it?

What happens when sensitive data is exposed?

How does an organization know whether its security controls actually work?

That curiosity pulled me deeper into cybersecurity.

From technology to security.

I pursued a Master's in Cyber Security and began moving beyond simply understanding how technology works. I wanted to understand how organizations protect it.

MSc Cyber Security, first with distinction
National Forensic Sciences University, Gandhinagar. 2022 to 2024

That led me into Information Security, Risk Management and Data Privacy. My work became less about individual systems and more about the bigger picture.

People. Processes. Technology. Risk. Controls. Compliance.

Then I discovered the world behind the controls.

As a consultant in Deloitte's Cyber Strategy practice, I worked across very different environments.

HealthcareFinancial servicesFMCGManufacturingRetailMediaMetalsPharma

ISO 27001 and ISO 27701 implementations and sustainment. Internal audits, risk assessments, access reviews, vendor risk, policies, awareness and cybersecurity assessments.

Consultant, Cyber Strategy
Deloitte Touche Tohmatsu India LLP. September 2024 to May 2026

Access Control Policy Status: approved

ISO/IEC 27001:2022, Annex A 5.18 Access rights

User access rights are reviewed at regular intervals, and removed when people leave or change roles.

Owner
IT Security
Frequency
Quarterly
Design
Documented and approved
Status
Implemented

Review noteDesigned, yes. But is it operating? Nobody has tested it.

A security control on paper doesn't necessarily mean an organization is secure.

  1. Why

    You have to understand why the control exists.

  2. Test

    You have to test whether it works.

  3. Risk

    You have to understand the risk behind it.

  4. Close

    And when something doesn't work, you help the organization actually close the gap.

That changed the way I looked at cybersecurity.

From compliance to understanding risk.

Auditing became one of the ways I learned to see an organization.

On paper

An access review isn't just a checklist.

In practice

It's about understanding who can access what, and whether they should.

On paper

A backup control isn't just evidence.

In practice

It's about whether the organization can actually recover when something goes wrong.

On paper

A policy isn't just a document.

In practice

It's about whether people and processes actually follow it.

This is where cybersecurity became more interesting to me.

I stopped looking at controls individually and started looking at the system around them.

And then came AI.

The next question became

Can the same technology I'm helping organizations govern also make cybersecurity work better?

That led me toward AI management systems and AI-enabled security workflows.

ISO/IEC 42001:2023
AI Management Systems Lead Implementer

Cybersecurity×Governance×Risk×Privacy×AI

Not AI for the sake of AI.

But AI that can help security teams analyze evidence, identify gaps, understand risk and reduce repetitive work.

Portrait of Krishan Harwani in a black suit, smiling.

Krishan Harwani

Cybersecurity and GRC Consultant

Based in
Mumbai
Credentials
ISO 27001 LA, ISO 42001 LI

Where I am now.

I spend most of my time building, breaking, and figuring things out.

Cybersecurity and GRC Consultant
Nexdigm. May 2026 to present

Cybersecurity is where I started: auditing systems, understanding risks, and learning how organizations protect their technology.

But I don't want to stop there.

These days, I'm experimenting with websites, applications, automation, AI, and security tools, sometimes because I want to solve a problem, and sometimes simply because I want to know how it works.

I'm exploring different corners of technology, from cybersecurity and AI to building things from scratch.

Not everything I build has a grand purpose.

Sometimes the purpose is simply

“Can I actually build this?”

And that's what keeps me curious.

WebsitesApplicationsAutomationAISecurity toolsCybersecurityBuilding from scratch

The working papers.

Selected engagements. Clients are described by sector, not by name.

Manufacturing, medical devices, oil

DPDP Act 2023 implementation

Implemented India's Digital Personal Data Protection Act for organizations in three sectors, from data mapping to notices and consent.

Nexdigm

FMCG

Internal IT audits

Endpoint security, logical access and segregation of duties, IT asset management, Microsoft 365 configuration, firewall rules, patching and backups.

Deloitte

Media and entertainment

Led an internal audit

User access reviews, incident management and data protection measures, from planning to reporting.

Deloitte

Healthcare, financial services, retail

ISO 27001 and ISO 27701

Implementation and sustainment of security and privacy management systems across several companies, plus ISO 27001 internal audits.

Deloitte

Pharmaceutical and biotech

NIST CSF assessment

Maturity and gap assessment against the NIST Cybersecurity Framework, with a roadmap to close the gaps.

Deloitte

Policy and procedure

SAMA CSF and NCA ECC

Policies and procedures drafted to align with the SAMA Cyber Security Framework and the NCA Essential Cybersecurity Controls.

Deloitte

Financial services

Cloud assessment framework

Helped validate a cloud assessment model and framework through a successful finance sector pilot.

Deloitte

Metals and financial services

Security awareness

Awareness sessions, lock screen posters and security email campaigns for employees.

Deloitte

Across engagements

Risk and proposals

Security risk assessments, vendor risk evaluations, risk closure plans and technical proposals that set out scope, method and deliverables.

Deloitte

HackerOne, Bugcrowd, Zerocopter

Bug bounty, after hours

Access control and exposure findings in commercial programs, plus coordinated disclosures to Dutch public sector organizations. An audit tells you what a company promised. A test tells you whether it held.

Independent

So what's next?

I'm interested in building the bridge between two worlds.

The discipline of cybersecurity and governance.

The possibilities of AI.

I don't just want to understand whether a control exists.

I want to understand whether it works, why it matters, and how we can make the process better.

If that sounds like the work you need done, let's talk.

krishanharwani1@gmail.com