Reference: GILA/ID/URG-012/B2B
Board seat: Independent Director, Non-Executive
Primary board location: Gurugram; predominantly virtual with one operations-centre visit per half year
Meeting model: Monthly risk sessions for 90 days, then quarterly; six board meetings
Mandate type: Immediate Regulatory Vacancy Mandate
Status: Confidential live-search specification; client identity released only after conflict clearance and NDA.
The anonymised enterprise
A listed B2B procurement marketplace connecting small retailers and institutional buyers to manufacturers, with embedded logistics and payment orchestration but no balance-sheet lending.
Gross transaction value exceeds ₹20,000 crore; reported net revenue is ₹1,500–2,100 crore. The Technology & Risk Committee lost its only independent cyber specialist following a sudden medical resignation.
The board problem and strategic reason for appointment
A credential-stuffing campaign has increased account-takeover attempts, although no material breach is confirmed. The board needs immediate technical judgement without implying an incident or turning the new director into the CISO.
The board is not buying a credential. It is appointing an independent decision-maker who can convert this problem into a governed sequence of choices, evidence and accountability. Success will be judged by the quality of decisions and control improvement, not by the number of recommendations made.
Board position, authority and interfaces
Chair of Technology & Risk; member of Audit for IT controls and revenue systems; direct private-session access to CISO, DPO and internal audit.
The appointee will have direct, unfiltered access to the Company Secretary and to the relevant control-function leaders. Any advisory support requested by the board must remain management-executed: the director sets questions, tolerances and evidence standards, but does not become an executive or consultant.
First 12–18 month strategic charter
- Review current threat intelligence, privileged-access exceptions and incident facts under legal protocol; set customer-account takeover and payment-diversion tolerances; test third-party logistics, seller API and cloud concentration recovery; validate GMV, cancellation, incentive and net-revenue data lineage across the reporting stack
- Restore the affected board and committee composition on a documented timetable, while preserving decision validity and escalating any matter that should not proceed during the vacancy.
- Conduct a rapid handover review of open committee actions, whistleblower matters, regulatory correspondence and prior dissent so urgency does not erase institutional memory.
Decision profile sought
Essential evidence
- Board-level cyber or technology-risk leader from marketplace, payments, telecom or high-volume digital operations; incident governance experience; immediate capacity
Differentiators
- Cloud resilience, identity security or digital fraud depth; audit committee experience over automated revenue controls
GILA will assess immediate availability, clean independence, calm judgement in a compressed appointment process, and the exact committee competence lost with the outgoing director. Candidates should expect a case discussion based on an ambiguous board decision from this mandate, not a career-history interview alone.
Independence, suitability and downside diligence
The search will apply Section 149(6), Sections 164–165, Schedule IV and the applicable listing or sector rules to the entity’s legally verified status at the appointment date. Databank/proficiency status, listed-entity directorship and committee ceilings, pecuniary relationships, relatives’ interests, recent audit/advisory work and interlocking directorships will be checked. The appointment is subject to formal legal and secretarial confirmation; this posting is not a substitute for that determination.
Mandate-specific screens: Commercial links to cloud, security or payment vendors under review; investments in direct marketplace competitors; any role that could compromise incident confidentiality.
Before accepting the seat, the candidate will receive under NDA the latest board composition, committee charters, material litigation/regulatory schedule, related-party map, last audited accounts, current D&O policy and the specific risk papers necessary to make an informed liability assessment.
Twelve-month outcomes
The board expects a compliant, fully functioning board without a rushed compromise on competence or independence. For this particular seat, the evidence will be:
- Incident facts and board decisions maintained in a privileged evidence log; account-takeover controls independently tested; critical third-party recovery and KPI lineage reported to both Risk and Audit
Commitment, protection and economics
- Expected load: 15–20 days in first 120 days; 24–30 days annually.
- Terms: Five-year/remainder term as structured; chair differential; cyber-event, privacy and securities D&O cover confirmed.
- Protection: Appointment letter, deed of indemnity where legally available, appropriate D&O cover including discovery/run-off terms, access to independent advice under the board-approved protocol, and complete minuting of dissent.
- Equity: No stock options where the appointment is legally an independent-director seat subject to Section 149(9). Any private-company structure outside that perimeter will be expressly classified and separately advised; no equity is implied by this posting.
Search process
Conflict pre-clearance → GILA/SYMPHONY™ board-fit interview → mandate case → document-led diligence under NDA → references from board peers and control functions → NRC/owner interviews → statutory, regulatory and reputation checks → board recommendation. Candidate consent, disclosures and appointment approvals will follow the law and the entity’s constitutional documents.