Measuring the executive population
RBI ¶204 addresses the Board and Senior Management separately, and CERT-In's reporting rule makes a percentage over twelve people an individual result. What an executive exercise reports instead.
An executive cohort is usually about a dozen people. Sometimes it is four. That number is the whole of the difficulty: two requirements meet on it and pull against each other.
The instruments address this population separately. The RBI Directions, 2026 for commercial banks put the Board and Senior Management in their own paragraph, ¶204, distinct from the ¶203 obligation covering lower and middle management. SEBI's CSCRF extends its awareness standard to senior executives and the Board, and asks for a “dedicated program … for Board members”. An obligation written as its own paragraph is evidenced on its own terms.
CERT-In's conduct rules then require the result of a social engineering exercise to be anonymised or statistical, with no individual personally identified. Over a workforce of four thousand a click rate is a statistic. Over twelve it is a roster with the names lightly removed. So the executive exercise is reported as a control finding, not a score: which pretexts worked and why, which processes held, and which delegation structures widened the target surface.
Why the instruments treat this population separately
In the Commercial Banks Direction, Section BB runs across pages 47–48. ¶203 covers the general workforce: “Cybersecurity awareness programmes shall be mandatory for all new recruits, and annual training shall be conducted for lower and middle management”. ¶204 stands on its own and reaches higher: “The bank shall also provide annual training to all Board members and Senior Management”. Beside them sits the measurement clause, ¶202: “The bank shall evaluate the awareness level of employees periodically.” Training and evaluation are separate obligations, and this cohort sits inside both.
The co-operative sector is built differently. UCB Section H, ¶155–157 at page 39, prescribes a method: “The UCB shall conduct mandatory cybersecurity awareness programs for new recruits and web-based quiz and training for lower, middle, and upper management every year.” That reaches upper management, and ¶157 adds a distinct obligation to sensitise the Board periodically. Section H sits in Chapter V, which the applicability table at ¶4 binds to Level III and Level IV UCBs; establish the Level before citing the paragraph.
For NBFCs, ¶36 at page 19 requires an “up-to-date repository of the training and awareness status of all users”. An executive is a user, so the repository accounts for this cohort as it accounts for every other — a coverage question rather than a scoring one, and that distinction carries the rest of this piece.
| Instrument | What it says about this population | Citation |
|---|---|---|
| RBI, Commercial Banks | Annual training to all Board members and Senior Management, separate from lower and middle management | ¶204, pp. 47–48 |
| RBI, Urban Co-operative Banks | Annual quiz and training reaching upper management; periodic Board sensitisation. Chapter V binds Level III and IV | ¶156, ¶157, p. 39 |
| RBI, NBFCs | Training for all users; effectiveness measured through periodic assessments or testing | ¶35–36, p. 19 |
| SEBI CSCRF | Extends the standard to senior executives and the Board, with a dedicated programme for Board members | v1.0, 20 Aug 2024, §3.2 PR.AT, p. 63; Guidelines pp. 103–104 |
What changes in the pretext
A general-population campaign is usually credential-shaped: it measures whether people put a password into a page that asked for one. Against an executive population the pretexts that carry weight are instruction-shaped. A change of bank details on an invoice already in flight. An authorisation requested outside the usual channel and under time pressure. A confidentiality wrapper that discourages the recipient from checking laterally. These are the pretexts usually labelled whaling, and they are shaped like business email compromise rather than credential harvest. The cohort is also impersonated at least as often as it is targeted, and an instruction appearing to come from a director lands on finance, on procurement or on an assistant.
That changes what is being measured. The question is not whether a named individual was alert on a Tuesday. It is whether a payment instruction can be altered on the strength of an email, whether an authorisation can be granted without out-of-band verification, and whether a confidentiality claim suspends a control that would otherwise apply. Those are properties of the organisation.
Why a cohort of twelve cannot be reported as a percentage
CERT-In's Comprehensive Cyber Security Audit Policy Guidelines, CISG-2025-02, Version 1.0, 25 July 2025, set the reporting rule at §15.2.2(iii), pp. 55–56:
“Social engineering and process testing should be conducted in a controlled and ethical manner. When targeting general staff (e.g., untrained or non-security personnel), such testing must utilize anonymized or statistical techniques—ensuring no individual is personally identified or penalized. The purpose is to evaluate overall awareness and the effectiveness of security processes, not to single out individuals.”
The clause gives non-security personnel as its example, and a Board is a non-security population. At this size, removing names achieves nothing. One click in twelve is 8.3 per cent, and anyone who knows the cohort can work it backwards. A heat map with a cell of four is an individual result with extra steps; add a job title to the axis and the cell is a person.
The deliverable is built from the pretext and the process, not the recipient:
- The pretexts that worked, and the property that made each one work — authority, urgency, an in-flight transaction, a confidentiality claim, described at the level of the pretext.
- The processes that did or did not hold — payment authorisation thresholds, out-of-band verification of an instruction change, and the route by which an unusual request reaches the person able to execute it.
- The delegation and mailbox structures that widened the target surface.
- The coverage facts the evidence repository consumes — that the cohort was exercised, when, over which channels, against which pretext bands. Dates and counts identify nobody, and they are what NBFC ¶36 and the metrics at Commercial Banks ¶194 and ¶197 ask for.
The working dataset behind the exercise is identifying by construction, and the DPDP Act, 2023 applies the ordinary duties to it: s.8(5) safeguards, and s.8(7)(a) erasure “as soon as it is reasonable to assume that the specified purpose is no longer being served”. For a twelve-row table, retention is a decision somebody records.
The delegated mailbox, and what the result is evidence of
An executive's mail is frequently read by someone else first: an assistant with delegated access, a shared mailbox, an office that triages and forwards. A pretext that reaches the executive may be actioned by someone never on the target list. §15.2.2(iii) continues:
“Social engineering and process testing must only target group of employees explicitly included within the agreed audit scope. These tests must not involve external entities such as customers, business partners, vendors, or other third parties, unless specific written consent is obtained from the target organization.”
An assistant who is an employee has to be inside the agreed scope explicitly, named or covered by role, before an exercise aimed at the executive reaches them. Where the desk is outsourced — an agency, a shared-services provider, an offshore team — that is a third party, and involving it requires specific written consent obtained from the target organisation. Delegated access is the arrangement most likely to carry a scope over a line drawn without checking the mail flow.
It also decides what the result means. If an instruction was actioned by a delegate, the finding is about who holds authority over an instruction and what verification attaches to it. Recording it as an executive's click would be wrong on the facts before it was wrong under the clause.
So the mail flow is described before the campaign rather than reconstructed after it: who holds delegated access, which mailboxes are shared, whether approvals are relayed by a third person. Otherwise the exercise measures a target surface nobody has documented.
Who authorises a test of the people who authorise things
The authorisation rule is at §13.2.7(ii), p. 50:
“Specific written permissions must be obtained from the auditee organization before conducting tests that involve survivability failures, denial-of-service (DoS), process testing, or social engineering.”
The permission runs from the auditee organisation, and the organisation decides who signs on its behalf. For a general workforce that signature usually sits with the executive who owns security, countersigned by HR and legal. When the target list includes those same people, and above them the Board, the signatory becomes a governance question in its own right.
The instruments point at the answer. ¶204's obligation is a Board obligation, and SEBI's dedicated programme for Board members is a Board-level programme, so a population addressed at Board level is coherently authorised there — by the Board or the committee to which it delegates assurance. What matters is that the authorising body sits outside the target set, visibly in the record.
Whoever signs, the document fixes the population including delegates, the window, the channels, the exclusions, the escalation contacts and the distribution of the result. That last item matters more here than anywhere else: an executive finding is the one most likely to be pulled towards a circulation list with no business holding it.
What to hold
The regulator separated this population, so the programme separates it too: its own cadence, its own pretext design, and its own line in the evidence repository rather than twelve rows in a workforce average. The output is a control finding, not a scoreboard.
Scope the delegates before the exercise, have the authorisation signed by a body outside the target set, and decide who receives the result. Those three are settled before a message is sent, or they are settled badly afterwards.
About the author
Abhinav Awasthi
Lead — VAPT & Security Assessments
Leads Security Brigade's VAPT delivery team, having progressed from Security Consultant to Team Lead. Has executed advanced penetration tests across BFSI, fintech, QSR, and telecom — including ICICI Bank, Domino's, and Jubilant FoodWorks.
Continue reading
All articles →Spear phishing versus bulk simulation: what changes in the test and in the numbers
A spear campaign and a bulk campaign measure different things over different populations. Why their rates cannot share a trend line, and how a six-person cohort is reported when a percentage would identify people.
Scoping a phishing simulation programme in India
What has to be decided before the first send: the population and its cohorts, the scope boundary, the cadence, the channels, the exclusions, the escalation contacts and the written authorisation CERT-In requires.
Testing the service desk: vishing as a process control test
A vishing test against the service desk measures a procedure, not a person. What CERT-In's CISG-2025-02 requires before the call, and what the finding should say afterwards.