Skip to main content

Security Awareness

How Indian organisations measure security awareness: phishing simulation methodology, the authorisation and reporting rules that govern it, and the evidence RBI, SEBI and CERT-In actually ask for.

23 guides. Published by Security Brigade. Last reviewed .

Buying one

What it costs, who is qualified to do it, and what you receive at the end.

Spear phishing versus bulk simulation: what changes in the test and in the numbers

A spear campaign and a bulk campaign measure different things over different populations. Why their rates cannot share a trend line, and how a si…

Scoping a phishing simulation programme in India

What has to be decided before the first send: the population and its cohorts, the scope boundary, the cadence, the channels, the exclusions, the…

Measuring the executive population

RBI ¶204 addresses the Board and Senior Management separately, and CERT-In's reporting rule makes a percentage over twelve people an individual r…

Testing the service desk: vishing as a process control test

A vishing test against the service desk measures a procedure, not a person. What CERT-In's CISG-2025-02 requires before the call, and what the fi…

What an auditor asks to see from an awareness programme

The eight questions an auditor puts to a security awareness programme, the RBI, SEBI, CERT-In and DPDP clause behind each of them, and the answer…

What an awareness evidence repository actually contains

RBI asks NBFCs to keep an up-to-date repository of the training and awareness status of all users. Read as a specification: the population, the c…

The report route: where a suspicious email goes, and what happens to it

Report rate is the only number in a phishing programme that measures a behaviour you want. It exists only if there is somewhere to report to, sta…

Why two quarters of click rates are not comparable

A click rate belongs to one population, one pretext and one moment. What has to be held constant between rounds, what changes quietly, and how to…

Which Indian instrument says what about security awareness

The clause reference for employee cyber security awareness in India: the RBI Directions, 2026 across six entity types, SEBI CSCRF, CERT-In CISG-2…

A security awareness platform and a testing firm are not the same purchase

A security awareness platform and an independent testing firm answer different clauses. Which purchase a given RBI, SEBI or CERT-In obligation ac…

What each number in a phishing simulation report measures

A phishing simulation returns a small set of numbers, and each supports a narrow claim. What click rate, credential submission, time-to-click, re…

The clause that names phishing testing, and exactly what it says

One clause in the SEBI CSCRF names phishing testing. It is on page 87, it sits in the Risk Management guidelines, and "for e.g." are the regulato…

NBFC ¶36: measure the training, and keep the repository

The RBI Directions, 2026 place four separately auditable requirements on an NBFC in one paragraph. What ¶36 asks for, phrase by phrase, and what…

Who may be in the target population of a phishing simulation

CERT-In's audit policy guidelines confine a phishing simulation's target population to agreed employee groups. SEBI directs regulated entities to…

What the click list may and may not be used for

A simulation produces a list of names. CERT-In's guidelines require anonymised or statistical results with no individual identified or penalised,…

How a phishing simulation runs, and what you receive

A phishing simulation is a measurement exercise over a defined employee population: what is agreed before it runs, what the campaign does, and wh…

Cyber security awareness: what a programme can and cannot change

An awareness programme changes what an organisation does, not what any individual knows. What the RBI, SEBI and CERT-In instruments require, what…

The awareness clauses of the RBI Directions, 2026, entity by entity

The RBI Directions, 2026 carry an employee awareness obligation for every supervised entity, and the paragraph number differs in each. Which clau…

The lawful basis for testing your own staff

A phishing simulation produces personal data about identifiable employees. DPDP s.4(1) gives two grounds for processing it, s.7(i) is the employm…

What CERT-In's audit policy guidelines require of a phishing simulation

CERT-In's audit policy guidelines already set the rules for a phishing simulation in India: specific written permission before, anonymised or sta…

Turning this into a measurement

Measure the human layer, and evidence it.

Completion rates prove attendance. A phishing simulation with a stated population, a documented method and a report rate proves whether people notice and whether they tell anybody. Describe who has to be covered and what you need to evidence, and you will get the scope, the method and the reporting format in writing. Security Brigade is CERT-In empanelled and publishes this site.