Security Awareness
How Indian organisations measure security awareness: phishing simulation methodology, the authorisation and reporting rules that govern it, and the evidence RBI, SEBI and CERT-In actually ask for.
23 guides. Published by Security Brigade. Last reviewed .
Buying one
What it costs, who is qualified to do it, and what you receive at the end.
Spear phishing versus bulk simulation: what changes in the test and in the numbers
A spear campaign and a bulk campaign measure different things over different populations. Why their rates cannot share a trend line, and how a si…
Scoping a phishing simulation programme in India
What has to be decided before the first send: the population and its cohorts, the scope boundary, the cadence, the channels, the exclusions, the…
Measuring the executive population
RBI ¶204 addresses the Board and Senior Management separately, and CERT-In's reporting rule makes a percentage over twelve people an individual r…
Testing the service desk: vishing as a process control test
A vishing test against the service desk measures a procedure, not a person. What CERT-In's CISG-2025-02 requires before the call, and what the fi…
What an auditor asks to see from an awareness programme
The eight questions an auditor puts to a security awareness programme, the RBI, SEBI, CERT-In and DPDP clause behind each of them, and the answer…
What an awareness evidence repository actually contains
RBI asks NBFCs to keep an up-to-date repository of the training and awareness status of all users. Read as a specification: the population, the c…
The report route: where a suspicious email goes, and what happens to it
Report rate is the only number in a phishing programme that measures a behaviour you want. It exists only if there is somewhere to report to, sta…
Why two quarters of click rates are not comparable
A click rate belongs to one population, one pretext and one moment. What has to be held constant between rounds, what changes quietly, and how to…
Which Indian instrument says what about security awareness
The clause reference for employee cyber security awareness in India: the RBI Directions, 2026 across six entity types, SEBI CSCRF, CERT-In CISG-2…
A security awareness platform and a testing firm are not the same purchase
A security awareness platform and an independent testing firm answer different clauses. Which purchase a given RBI, SEBI or CERT-In obligation ac…
What each number in a phishing simulation report measures
A phishing simulation returns a small set of numbers, and each supports a narrow claim. What click rate, credential submission, time-to-click, re…
The clause that names phishing testing, and exactly what it says
One clause in the SEBI CSCRF names phishing testing. It is on page 87, it sits in the Risk Management guidelines, and "for e.g." are the regulato…
NBFC ¶36: measure the training, and keep the repository
The RBI Directions, 2026 place four separately auditable requirements on an NBFC in one paragraph. What ¶36 asks for, phrase by phrase, and what…
Who may be in the target population of a phishing simulation
CERT-In's audit policy guidelines confine a phishing simulation's target population to agreed employee groups. SEBI directs regulated entities to…
What the click list may and may not be used for
A simulation produces a list of names. CERT-In's guidelines require anonymised or statistical results with no individual identified or penalised,…
How a phishing simulation runs, and what you receive
A phishing simulation is a measurement exercise over a defined employee population: what is agreed before it runs, what the campaign does, and wh…
Cyber security awareness: what a programme can and cannot change
An awareness programme changes what an organisation does, not what any individual knows. What the RBI, SEBI and CERT-In instruments require, what…
The awareness clauses of the RBI Directions, 2026, entity by entity
The RBI Directions, 2026 carry an employee awareness obligation for every supervised entity, and the paragraph number differs in each. Which clau…
The lawful basis for testing your own staff
A phishing simulation produces personal data about identifiable employees. DPDP s.4(1) gives two grounds for processing it, s.7(i) is the employm…
What CERT-In's audit policy guidelines require of a phishing simulation
CERT-In's audit policy guidelines already set the rules for a phishing simulation in India: specific written permission before, anonymised or sta…
Scope and preparation
What to have ready, what can and cannot be tested, and how the boundary gets drawn.
Where the requirement comes from
Which regulators name you — and where the obligation arrives from when none do.
What SEBI CSCRF asks of an awareness programme
SEBI CSCRF puts the awareness obligation in two places: PR.AT sets the training programme and its cohorts, and GV.RM.S3 requires periodic assessm…
Which co-operative banks carry the RBI awareness obligation
The annual web-based quiz at ¶156 of RBI's UCB Directions, 2026 sits in Chapter V, and the applicability table at ¶4 assigns Chapter V by Level.…
Turning this into a measurement
Measure the human layer, and evidence it.
Completion rates prove attendance. A phishing simulation with a stated population, a documented method and a report rate proves whether people notice and whether they tell anybody. Describe who has to be covered and what you need to evidence, and you will get the scope, the method and the reporting format in writing. Security Brigade is CERT-In empanelled and publishes this site.