Sekurzen's Virtual CISO Lands in the Chennai Startup Scene

The bootstrapped consultancy, founded by a VMware veteran, is now building its first product to automate DPDP Act compliance.

About Sekurzen Technologies Private Limited

Published

For a founder in Chennai’s bustling tech corridor, the first security hire is often a luxury deferred until after a breach. The budget for a full-time Chief Information Security Officer is out of reach, but the risks are not, especially for companies handling financial or health data under India’s new Digital Personal Data Protection (DPDP) Act. Sekurzen Technologies, a bootstrapped security consultancy founded in early 2025, is betting that a fractional, virtual CISO can be the wedge into this anxious market.

Founded by Santhana Krishna, a former VMware tech lead, the company has operated quietly for its first year, reporting traction through a classic services model. Its website claims 12 clients secured and over 100 vulnerabilities prevented across six industry segments, primarily in FinTech, HealthTech, and EdTech [Sekurzen, retrieved 2024]. The value proposition is straightforward: provide enterprise-grade security leadership and assessments to small and mid-sized businesses without the cost of a full-time executive.

The Wedge of the Virtual CISO

The initial service offering is comprehensive, covering the full spectrum of a modern security program. For a startup, this often begins with a security assessment or a VAPT (Vulnerability Assessment and Penetration Testing) engagement to map their exposure. For those needing ongoing support, Sekurzen offers virtual CISO services, acting as an external security leader who sets strategy, manages risk, and ensures compliance.

The company’s reported metrics suggest this model has found early product-market fit. Beyond the client and vulnerability counts, Sekurzen claims to have delivered over ₹27 lakh (approximately $32,000) in annual savings for its clients [Sekurzen, retrieved 2024]. For cash-conscious startups, framing security as a cost-avoidance and efficiency driver, rather than just a compliance checkbox, is a critical part of the pitch.

From Services to Product

The most recent shift in the company’s trajectory is a move toward product development. While the consultancy arm continues, founder Santhana Krishna’s public profile now describes Sekurzen as building security products for the small and mid-market [LinkedIn, retrieved 2024]. The first of these appears to be a tool built around India’s DPDP Act, a significant new regulatory tailwind that has created urgent demand for compliance solutions [LinkedIn, retrieved 2026].

This pivot makes strategic sense. A product can scale beyond the hours of a consultant, offering a more predictable revenue stream and a tangible asset. The DPDP tool, focused on helping businesses understand and manage their data protection obligations, directly addresses a known pain point for Sekurzen’s target clients in regulated sectors like finance and healthcare.

The Founder’s Track Record

Sekurzen’s credibility rests heavily on the experience of its solo founder, Santhana Krishna. His background includes a three-year stint as a tech lead in Ecosystems Engineering at VMware, where he worked on the vSphere SDK for Perl [Santhana Krishnan - VMware | LinkedIn, retrieved 2026]. This enterprise infrastructure experience is a relevant foundation for advising companies on cloud security and governance.

His public positioning as a fractional CISO and security leader for SMEs suggests a hands-on approach [LinkedIn, retrieved 2024]. The company also lists a small team, including a Senior Technology Architect and a Growth Partner who joined in May 2026, indicating early efforts to build out execution capacity [LinkedIn, retrieved 2024; LinkedIn, retrieved 2026].

Metric Value
Security Assessments 12 clients
Vulnerabilities Prevented 100 count
Reported Client Savings 27 lakh INR

The Competitive Landscape

Sekurzen operates in a crowded but fragmented market. The space for cybersecurity services targeting Indian SMEs includes everything from global managed security service providers (MSSPs) to local IT shops. The company’s differentiation appears to be its specific focus on the startup and scale-up segment, its vCISO offering, and its early bet on DPDP Act tooling.

The risks here are familiar for any services business scaling toward products. The current traction is based on company-reported metrics without independent verification or named customer logos. The transition from consultancy to product company is notoriously difficult, requiring different skills in engineering, product management, and sales.

  • Services dependency. Revenue is likely tied directly to billable hours and project engagements, limiting scalability compared to a software subscription model.
  • Product execution. Building a compliant, effective DPDP tool requires deep regulatory and technical expertise; a misstep could damage the firm’s hard-won consulting credibility.
  • Market education. Selling proactive security and compliance to resource-constrained founders remains a challenge, often requiring a crisis to unlock budget.

Sekurzen’s answer to these challenges seems to be using its consulting work as a discovery engine for its products, building tools that solve the most frequent problems it encounters in the field.

The Next Twelve Months

The coming year will be a critical test of the product vision. Key milestones will be the formal launch of its DPDP compliance tool and the acquisition of its first software customers. The company may also seek its first institutional funding to accelerate product development and hire specialized talent, moving beyond its current bootstrapped, 1-10 employee stage [LinkedIn, retrieved 2024].

For the small businesses and startups Sekurzen serves, the standard of care today is often reactive and piecemeal. Security might mean an annual penetration test, a basic firewall, or, in the worst cases, nothing at all until a breach occurs. The role of a dedicated security leader is seen as a post-Series C luxury. Sekurzen is betting that this gap represents a durable opportunity, first by renting out that leadership by the hour, and eventually by productizing the most common governance and compliance tasks. Their success will depend on whether Indian founders see data protection not as a distant regulatory threat, but as a foundational element of their own business integrity.

Sources

  1. [Sekurzen, retrieved 2024] Sekurzen homepage and services pages | https://www.sekurzen.com/
  2. [LinkedIn, retrieved 2024] Sekurzen Technologies Private Limited company page | https://www.linkedin.com/company/sekurzen
  3. [LinkedIn, retrieved 2024] Santhana Krishna profile | https://www.linkedin.com/in/santanakrishna
  4. [LinkedIn, retrieved 2026] Santhana Krishna profile update | https://www.linkedin.com/in/kkrishnask/
  5. [LinkedIn, retrieved 2026] Vigneshwaran Thirukonda profile | https://www.linkedin.com/in/vigneshwarant/
  6. [Santhana Krishnan - VMware | LinkedIn, retrieved 2026] Santhana Krishna career history | https://www.linkedin.com/in/santhana-krishnan-6497744/
  7. [RocketReach, retrieved 2026] Santhana Krishna contact information | https://rocketreach.co/santhana-krishna-email_842739256

Read on Startuply.vc