On August 21, at the Holiday Inn Chennai OMR, we ran the first-ever Vembu Meet and closed the book on one question we’d been asking ourselves for months: would IT and business leaders actually show up for an afternoon about DPDP that wasn’t a legal briefing?

They did. In numbers, and in the room’s energy.

Why now
Vembu Meet isn’t a product launch event or a lead-gen mixer dressed up as a conference. It’s a dialogue series, built city by city, with each edition shaped around the questions that matter most to that city’s businesses and each one meant to feed back into how we build, so the conversations shape our roadmap, not just our marketing calendar.
Chennai also happened to be personal. Vembu was founded here in 2002, and August 21 was World Entrepreneurs’ Day — a fitting day to open a series built on the idea that resilience, like a company, has to be built one deliberate decision at a time.
The room reflected the ambition: founders, CXOs, CIOs, CISOs and IT leaders from MRF Limited, Hyundai Motor India, Rane Holdings, Shriram Chits, Lotte India, BHEL, Rela Hospital, Capgemini, Aricent Technologies, HTC Global Services, SoftwareOne and The KCP Limited, among others — an invite-only, cross-industry mix rather than a single-sector crowd.
Nagarajan Chandrasekaran, Vice President – Product Management at Vembu Technologies, opened with a short welcome note. From there, I (Bhavani Shanmugam, Product Manager at Vembu Technologies) took over as host, moderator and presenter for the rest of the afternoon.

Setting the tone
I delivered the featured session – “Beyond Compliance: Building Cyber Resilience in the DPDP Era” for the day. We went in detail into what DPDP actually asks of businesses and the shift I wanted the room to make: from compliance, to preparedness, to recovery.
Compliance gives you the baseline — notice, consent, data-principal rights, security safeguards. Preparedness is knowing what you’d actually do if something went wrong. And recovery is whether you can prove it, when it matters.
The framing I kept coming back to: compliance is the seatbelt, recovery readiness is the airbag. The seatbelt keeps you protected and compliant day to day, but it doesn’t do anything on the day something actually goes wrong — that’s what the airbag is for, and it’s the part most organisations haven’t tested.
The most useful part of the session, honestly, wasn’t the slides — it was the back-and-forth it triggered. When I asked how often the room actually tests recovery, one attendee answered “quarterly,” and that became a genuinely useful sidebar: quarterly sounds disciplined, but a quarter is a long time to be flying blind if something breaks the day after your last test.
We also talked through the fact that DPDP itself isn’t finished — the Rules are still rolling out in phases, and treating today’s compliance posture as a fixed target rather than something that will keep shifting is its own risk.

The panel: practitioners, not platitudes
The centrepiece was a moderated panel — “Beyond Compliance: Building Cyber Resilience in the DPDP Era” — moderated by me. The panel itself:
- Ramesh Rajaraman, Chief Information Officer, A.M.M. Foundation, Chennai — 40 years across IT services, BFSI and healthcare, spanning IT infrastructure management, cybersecurity, quality, compliance and risk management, business continuity and operational resilience, and a Certified Lead Auditor for ISO 27001 (ISMS)
- Ananda Rajesh A, Head – Technical Consultant, IT, Ultimatum Solutions — 23+ years in IT infrastructure and cybersecurity, with deep hands-on experience in data protection, backup and disaster recovery, business continuity and enterprise IT design
- Nagarajan Chandrasekaran, Vice President – Product Management, Vembu Technologies — nearly 15 years in enterprise backup and data protection, leading product strategy and roadmap for BDRShield and working closely with customers and partners to understand real-world challenges

A few points that stood out from each panelist:
- Ramesh Rajaraman made the case that compliance and cyber resilience go hand in hand — but noted that IT budget decisions still don’t get the management involvement they need, with approvals often delayed or deprioritised until something has already gone wrong. He balanced that with a nod to real progress: boards and leadership teams are far more aware of cybersecurity today than they were even a few years ago
- Ananda Rajesh A pushed back on the instinct to keep adding trendy, feature-heavy products to the stack, assuming more tools automatically means better security — his point was that stacking products isn’t the same as having a coherent security strategy
- Nagarajan Chandrasekaran flagged that awareness and training programs are too often run as a one-time checklist item rather than an ongoing process — something to be “completed” once a year instead of built into how teams actually operate
Taken together, the panel’s throughline was that regulatory compliance alone doesn’t equal resilience. Recovery testing, third-party risk, and genuine management buy-in came up repeatedly as the biggest gaps Indian organisations still carry, and the panel pushed back on treating cyber resilience as an IT problem at all — it was framed, again and again, as a board-level business decision.
The session closed with each panelist finishing one sentence: “Cyber resilience is impossible without ___” — leaving the room with something more memorable than a takeaway deck.
A voice from the field
Between the keynote and the product session, M.V. Giri, DGM at Shriram Chits (India) Pvt. Ltd., walked the audience through 30 years of on-ground IT and backup leadership — what data protection actually looks like from inside an organisation living with it daily, not from a slide. He also shared that Shriram Chits has been running BDRShield for their backups for close to two years now, with plans to expand it further across their environment.

Then we showed the work
Mani Subramanian, Product Manager at Vembu Technologies, closed the day with a live look at BDRShield and XDRShield — mapping specific DPDP requirements (encryption, monitoring, breach detection, backup and recovery, access control) directly to the technical safeguards each platform provides, then demoing them rather than just listing features.

What the room told us
A few lines, straight from the feedback:
- “It was a great event with awesome panel discussion.”
- “Interactive and useful.”
- “Nice & memorable event.”
- “Excellent way of product intro and great explanation.”
- “Very informative.”
- “Good; would like more information about the product.”
That’s the kind of response that makes the extra planning worth it.
Beyond the room
Vembu Meet Chennai also picked up coverage from:
CXOToday
TechCapsules
NowZo
SME Channels
Enterprise IT World
Digital Terminal
Sekar Vembu, our Founder and CEO, said it best: “Compliance was never meant to be the finish line. The DPDP Act gives Indian businesses a clear starting point, but the real test is whether an organisation can actually recover its data, its operations, its customers’ trust when something goes wrong.”
What’s next
Chennai was the pilot, and more editions are on the way — each one shaped around what that city’s leaders are actually wrestling with, not a copy-pasted agenda.
If you want DPDP updates, breach trends and recovery-readiness insights between editions, join Cyber Signals by Vembu on WhatsApp.
And if Chennai proved anything, it’s that the room was ready to move past “are we compliant” and start asking the harder question: are we actually ready for the day something breaks?
Follow our Twitter and Facebook feeds for new releases, updates, insightful posts and more.