The CMDB
It lies, and everyone knows it.
It was accurate the week it was populated. It has been drifting ever since, and it never described a relationship — only a row.
If you are reachable then you are breachable
Inventory told you what you own. It never told you what an attacker can reach — and agents are about to make that gap fatal.
Setu derives the map from the lake you already paid for, then dispatches named campaigns that close real attack paths to crown jewels.
Time-to-exploit is collapsing from weeks to hours. Stop ranking CVEs. Fix choke points on validated paths.
Sovereign by construction
Setu is designed and engineered in India for Indian regulated industry. Nothing about your estate crosses a border to be understood, because nothing about your estate leaves the building.
LOCALISATION
No cross-border transfer to assess, because there is no transfer.
DPDP ACT 2023
Setu reads what you already lawfully hold. It creates no fresh data estate.
CERT-IN
Reachability context for an incident report, not a week of manual tracing.
GxP / CDSCO
No agent lands on a validated system, so no change control opens.
DEPLOYMENT
Your datacentre or a sovereign Indian cloud region. Your choice, either way.
The problem
Three systems each claim to know your estate. None of them agree, and none of them can tell you whether an attacker can actually get from a contractor’s laptop to a batch record.
The CMDB
It was accurate the week it was populated. It has been drifting ever since, and it never described a relationship — only a row.
The SIEM
Fifty thousand events tell you things happened. They do not tell you which two of them chain into a path to a crown jewel.
The scanner
A critical CVE on an isolated host is noise. A medium on your only jump host is the whole breach. The column cannot tell the difference.
That is the whole compression. Not a smaller queue — a different unit of work, one a team can actually finish and a board can actually read.
How it works
Three beats. One graph.
Agentless reads across the SIEM, the lake, OT protocols and your identity provider. Nothing installed on a validated system, no change window, no sensor tax.
siem · lake · ot-passive · idp sensors: 0
Every identity, host, service account and trust lands in one derived graph — deduplicated, reconciled, and honest about what it could not confirm.
confidence-scored conflicts surfaced, not hidden
PageRank over that graph ranks nodes by blast radius, validated paths get named campaigns, and closed campaigns re-enter the graph as signed fact. Setu reads and reasons — write-back runs through a staged approval gate.
paths → choke points → campaigns proof re-enters graph
Validated paths
A severity column tells you a CVE is bad. It cannot tell you that four service accounts and one unmanaged jump host stand between a phished contractor and a GxP batch record. The graph can.
Cut the choke point and every path through it dies at once. That is one ticket instead of two hundred.
231
identities with a validated path to one crown-jewel account, at a manufacturer we work with. Their asset register named none of them.
Named campaigns
Not a counter that resets every morning. A dispatch you can close, and a signed proof when it is closed.
Q3 · 12 open · 4 board-visible
Q3-PHARMA-JUMPHOST-ISOLATE
One RDP hop carries three paths into the OT cell.
Q3-PHARMA-DLP-RECON
Read access to GxP records from four unowned accounts.
Q3-OT-HISTORIAN-TRUST
Legacy trust lets plant IT reach corporate identity.
Q3-IDENT-SVCACCT-ROTATE
Nine accounts with no owner and no expiry.
Q3-VENDOR-VPN-SCOPE
Contractor tunnel terminates inside the process network.
Q3-PLC-CELL3-SEGMENT
Flat path from engineering VLAN to PLC cell 3.
Q3-MES-ADMIN-TIER
Domain admins log in interactively to the MES.
Q3-CLEANROOM-BADGE-IDP
Physical access system shares identity with corporate.
Q3-BACKUP-CRED-REUSE
One backup account reaches every crown jewel it protects.
Q3-LIMS-EXPORT-PATH
Lab results leave through an unmonitored share.
Q3-OT-JUMP-MFA
The only MFA exemption left is the one that matters.
Q3-SCADA-VENDOR-RDP
Standing remote access for a decommissioned contract.
CTEM, mapped to artifacts
The framework is not the product. The artifacts are.
Stage 1 — Scope
You name what matters — batch records, the historian, the GxP boundary. Setu resolves those names to nodes in the graph instead of asking you to maintain a tag taxonomy.
Artifact
scope.yaml crown_jewels: [MES, historian, PLC-cell-3] regulated: GxP · 21 CFR 11
Scope is an input, not a quarterly project.
See it
DEMO 01 · PATH-VIEW · ILLUSTRATIVE
Pick any node and ask the blast-radius question. Setu returns ranked, evidence-backed paths in seconds — with the choke point already marked.
> reach --from contractor-lt-0417 --to crown_jewelsresolving graph …3 validated paths foundP-1187 contractor → svc-batch-sync → jump-host → MESP-1188 contractor → jump-host → historianP-1191 vendor-vpn → jump-host → PLC-cell-3shared hop: jump-host-rdp ← choke point
Where the data lives
Setu reads in place. Your SIEM, your lake, your OT historian, your identity provider — the telemetry stays exactly where your auditors last found it. Compute moves to the data, never the reverse.
The whole system runs air-gapped, inference included. Nothing about your estate needs a round trip to somebody else’s cloud to be understood.
DEPLOYMENT
No outbound dependency. Inference runs on a local model inside your boundary.
DATA
Setu queries your lake. It does not copy it, index it elsewhere, or hold it.
OT
No agents on validated or safety-relevant systems. Nothing to requalify.
AUDIT
Every closed campaign carries a hash your auditor can check without us.
Who buys Setu
FOR REGULATED ENTERPRISES
You have a plant network you cannot touch, a regulator who wants evidence, and a security team smaller than the estate it defends.
FOR MSSPS & SYSTEM INTEGRATORS
Your clients already pay for a SIEM you manage. Setu turns that same telemetry into named campaigns you can bill, close and prove.
A five-minute read that ends in an honest checklist of where Setu is a fit and where it is not.
Regulatory reality
They ask it in different words, on different clocks. Setu answers all of them from the same derived graph, and leaves a signed artifact behind each time.
| Regulation | What it actually asks | Artifact |
|---|---|---|
| CERT-In Directions2022 · ALL SECTORS | Report cyber incidents within six hours and hold logs in India. The hard part is describing what the intruder could have reached before the clock runs out. | incident-reach.json paths: validated jewels_touched: 2 |
| DPDP Act2023 · PERSONAL DATA | Know where personal data sits and who can get to it. An access list is not an answer when four service accounts chain into the store. | identities_reaching_pii ranked by blast radius |
| SEBI CSCRF2024 · REGULATED ENTITIES | Continuous, measurable cyber resilience with periodic evidence. Not a scan report — a trend a board can re-check next quarter. | posture.q3 csf tier: 2 → 4 |
| RBI cyber frameworkBANKS & NBFCS | Demonstrate control over critical systems and third-party access. Vendor tunnels are where reachability quietly breaks the model. | vendor-scope.diff standing_access: 0 |
| GxP / 21 CFR 11CDSCO · US FDA EXPORT | Validated systems must stay validated. Anything installed on them opens a change-control record you do not want. | agents_installed: 0 change_controls: 0 |
Honest boundaries
| ReplacesYou can turn these off. | Sits besideWe read them, we do not fight them. | Does not touchSay so in the first meeting. |
|---|---|---|
| Spreadsheet crown-jewel registers | Your SIEM and data lake | Endpoint detection and response |
| Manual attack-path workshops | Your vulnerability scanner | Log collection and retention |
| Quarterly posture slide assembly | Your identity provider | Patch deployment |
| Standalone reachability tooling | Your ticketing and change process | Network enforcement |
What we can actually show you
Posture
Setu is a new category entrant. We are not going to show you a Gartner badge we do not have. We will show you a derived graph of your own estate in a two-week evaluation, on your hardware, and you can judge it against whatever you run today.
From the field
Product Direction
Our proposed OpenID SSF integration would connect provider risk changes to business context, investigation priorities and recovery. The Zscaler–CrowdStrike partnership supports this direction.
AI Security
This week, 100+ companies — OpenAI, Anthropic, Google, Microsoft, CrowdStrike among them — published an open letter warning that AI-enabled attacks become far more widespread within months, and calling for collective cyber defense. Meanwhile, Epoch AI's CVE data shows what industrialized discovery already did to the publication rate. The letter asks defenders to share verified fixes. Nobody says what 'verified' means when it has to cross an organizational boundary. We think that is the whole problem.
Detection Engineering
A published red-team teardown walks sixteen steps from a single compromised laptop to full Domain Admin, in hours. Eight of those steps were detected and seven raised incidents, and the domain fell regardless. The failure was sequencing, not sensing: severity was assigned to each event rather than to the position it created. We walk all sixteen steps and show the five places the chain actually breaks, two of them before the attacker ever arrives.
Straight answers
Two weeks, your hardware, your telemetry, no sensors installed. You keep the graph either way.