Skip to main content

Cybersecurity Insights & Guides

Expert insights on cybersecurity, vulnerability management, and digital defence strategies.

Spear phishing versus bulk simulation: what changes in the test and in the numbers

A spear campaign and a bulk campaign measure different things over different populations. Why their rates cannot share a trend line, and how a six-person cohort is reported when a percentage would identify people.

31 Aug 2026

Scoping a phishing simulation programme in India

What has to be decided before the first send: the population and its cohorts, the scope boundary, the cadence, the channels, the exclusions, the escalation contacts and the written authorisation CERT-In requires.

31 Aug 2026

Measuring the executive population

RBI ¶204 addresses the Board and Senior Management separately, and CERT-In's reporting rule makes a percentage over twelve people an individual result. What an executive exercise reports instead.

31 Aug 2026

Testing the service desk: vishing as a process control test

A vishing test against the service desk measures a procedure, not a person. What CERT-In's CISG-2025-02 requires before the call, and what the finding should say afterwards.

31 Aug 2026

What moves the effort of a phishing simulation programme

Very little of the effort in a phishing simulation scales with headcount. The six drivers that actually move it, and how to place a programme in a small, medium or large band before asking for a proposal.

31 Aug 2026

What an auditor asks to see from an awareness programme

The eight questions an auditor puts to a security awareness programme, the RBI, SEBI, CERT-In and DPDP clause behind each of them, and the answers that fail.

31 Aug 2026

What an awareness evidence repository actually contains

RBI asks NBFCs to keep an up-to-date repository of the training and awareness status of all users. Read as a specification: the population, the cohorts, the dates, the methods, the results and the retention.

31 Aug 2026

The report route: where a suspicious email goes, and what happens to it

Report rate is the only number in a phishing programme that measures a behaviour you want. It exists only if there is somewhere to report to, staffed by somebody who answers. How to build that route.

31 Aug 2026

Why two quarters of click rates are not comparable

A click rate belongs to one population, one pretext and one moment. What has to be held constant between rounds, what changes quietly, and how to build an awareness series that supports a comparison.

31 Aug 2026

Which Indian instrument says what about security awareness

The clause reference for employee cyber security awareness in India: the RBI Directions, 2026 across six entity types, SEBI CSCRF, CERT-In CISG-2025-02 and the DPDP Act, with paragraph and page numbers.

31 Aug 2026

A security awareness platform and a testing firm are not the same purchase

A security awareness platform and an independent testing firm answer different clauses. Which purchase a given RBI, SEBI or CERT-In obligation actually needs, and what each one produces.

31 Aug 2026

What each number in a phishing simulation report measures

A phishing simulation returns a small set of numbers, and each supports a narrow claim. What click rate, credential submission, time-to-click, report rate and repeat exposure each measure.

31 Aug 2026

The clause that names phishing testing, and exactly what it says

One clause in the SEBI CSCRF names phishing testing. It is on page 87, it sits in the Risk Management guidelines, and "for e.g." are the regulator's own words. What item 1(e) asks for.

31 Aug 2026

What SEBI CSCRF asks of an awareness programme

SEBI CSCRF puts the awareness obligation in two places: PR.AT sets the training programme and its cohorts, and GV.RM.S3 requires periodic assessment of the awareness level. What each asks, and which REs carry it.

31 Aug 2026

Which co-operative banks carry the RBI awareness obligation

The annual web-based quiz at ¶156 of RBI's UCB Directions, 2026 sits in Chapter V, and the applicability table at ¶4 assigns Chapter V by Level. The Level is settled first.

31 Aug 2026

NBFC ¶36: measure the training, and keep the repository

The RBI Directions, 2026 place four separately auditable requirements on an NBFC in one paragraph. What ¶36 asks for, phrase by phrase, and what has to exist before a supervisor asks to see it.

31 Aug 2026

Who may be in the target population of a phishing simulation

CERT-In's audit policy guidelines confine a phishing simulation's target population to agreed employee groups. SEBI directs regulated entities to extend training to outsourced staff. Both hold.

31 Aug 2026

What the click list may and may not be used for

A simulation produces a list of names. CERT-In's guidelines require anonymised or statistical results with no individual identified or penalised, and a programme that ignores that rule destroys its own report rate.

31 Aug 2026

How a phishing simulation runs, and what you receive

A phishing simulation is a measurement exercise over a defined employee population: what is agreed before it runs, what the campaign does, and what the report and the debrief actually contain.

31 Aug 2026

Cyber security awareness: what a programme can and cannot change

An awareness programme changes what an organisation does, not what any individual knows. What the RBI, SEBI and CERT-In instruments require, what a programme moves, and what it cannot.

31 Aug 2026

The awareness clauses of the RBI Directions, 2026, entity by entity

The RBI Directions, 2026 carry an employee awareness obligation for every supervised entity, and the paragraph number differs in each. Which clause binds a bank, an NBFC, a CIC or a UCB, and what each one asks for.

31 Aug 2026

The lawful basis for testing your own staff

A phishing simulation produces personal data about identifiable employees. DPDP s.4(1) gives two grounds for processing it, s.7(i) is the employment ground, and s.8 governs the dataset on either.

31 Aug 2026

What CERT-In's audit policy guidelines require of a phishing simulation

CERT-In's audit policy guidelines already set the rules for a phishing simulation in India: specific written permission before, anonymised or statistical results after, and no individual identified or penalised.

31 Aug 2026

Have a question this did not answer?

Our team answers regulatory and testing questions directly — no discovery call required to get a straight answer.

Talk to our team