Two streams. What is changing at RikArena, and what is changing in the threat and
compliance landscape our clients operate in.
Company & product
RikArena updates.
Product Direction
RikArena expands its cyber security practice.
Alongside custom application development, RikArena has built out a dedicated
security practice around Digitus Egis — host intrusion detection, threat
monitoring, response support and compliance evidence.
A flagship cyber security engagement anchors current work.
A current cyber security engagement anchors RikArena's security work, giving
the research team a live operating environment for monitoring practice, detection
tuning and evidence design.
14+ years of delivery across applications and security.
130+ implemented projects and 125+ clients across ERP, finance, healthcare,
education, legal and government remain supported. That experience is the operating
context behind both the product line and the cyber security practice.
Why host-level telemetry is central to modern detection.
Perimeter tooling cannot explain everything. Attacks increasingly move through
legitimate accounts and trusted devices, so RikArena's current research prioritises
host context, audit trails and behavioural signals.
SOC-level auditing added as a standalone engagement.
Organizations increasingly want to know what their monitoring actually covers before
they buy more of it. The audit engagement reviews coverage, alert quality, incident
visibility and response readiness.
The application product line stays fully supported.
Educator, Medicator, Attendance and the custom ERP line remain in active production;
existing clients continue to be supported and the systems remain part of the
credibility story.
The phasing that matters for Indian enterprises — foundational rules are already
live, and the substantive obligations arrive with no stated grace period.
Foundations commence
Foundational provisions of the DPDP Rules take effect.
Enforcement is live
Consent-manager registration plus the enforcement and penalty machinery come into force.
Obligations land
Notice, security safeguards, breach notification, retention, children's data and transfer rules apply.
Summaries of external advisories relevant to the host, application and compliance
environments we work in. Each links to the originating source — always verify
against the vendor or authority before acting.
Exploited in the wild
CISA Known Exploited Vulnerabilities catalog keeps adding host-facing software.
Additions through August 2026 span Oracle (improper access control), Synacor Zimbra
(OS command injection), TrueConf (missing authentication and code injection), MLflow
(SSRF), Microsoft and SharePoint, Broadcom VMware (path traversal) and Apple macOS.
Federal agencies work to fixed KEV remediation dates; for everyone else the catalog
is the cheapest available prioritisation signal.
Our read: most of these are exploited on hosts an organization already
owns and already logs. The gap is usually detection coverage, not patch availability.
CISA urges SharePoint hardening after renewed exploitation.
On-premises SharePoint remains a recurring target, and CISA issued hardening guidance
following new exploitation activity. Collaboration servers hold broad document access
and are frequently under-monitored relative to their value.
Our read: treat on-prem collaboration servers as tier-one monitored
hosts. File access patterns and process behaviour on these boxes carry early signal.
DPDP Rules 2025 — enforcement is live before the substantive obligations land.
Under the published phasing, foundational provisions commenced 13 November 2025;
consent-manager registration and the Act's enforcement and penalty machinery come into
force 13 November 2026; and the substantive obligations — notice, security
safeguards, breach notification, retention and deletion, children's data, cross-border
transfer and data-principal rights — take effect 13 May 2027, with no stated
grace period after that date.
Our read: breach notification and retention obligations are logging
problems before they are legal problems. Organizations that fix evidence quality early
get compliance almost as a by-product.
CERT-In directions still set the operational baseline for Indian enterprises.
Incident reporting timelines, log retention and time synchronisation obligations under
the CERT-In directions remain the day-to-day compliance floor for Indian organizations,
alongside the DPDP phasing. Both assume you can produce trustworthy logs on demand.
Our read: confirm current obligations directly with CERT-In rather
than secondary summaries, then design retention once for both regimes.