Skip to main content

A security awareness platform and a testing firm are not the same purchase

A security awareness platform and an independent testing firm answer different clauses. Which purchase a given RBI, SEBI or CERT-In obligation actually needs, and what each one produces.

By Abhed Indulkar
August 31, 20267 min read

Two different things are sold under the heading of security awareness, and neither substitutes for the other. One is a subscription platform: it delivers courseware to a workforce, records who completed it, and schedules simulated phishing campaigns from a console. The other is an assessment: an outside firm designs pretexts against a defined population, runs them on infrastructure the organisation does not own, and hands back a result the organisation did not generate itself.

Buyers conflate them because both produce a percentage and both are signed off by the same person. In the Indian instruments they answer different clauses, usually separate paragraphs of the same document.

What the platform category is for

The category is KnowBe4, Proofpoint, Hoxhunt, Terranova, Keepnet and others built on the same model. It solves problems a services engagement solves badly.

  • Cadence at low marginal cost. Once the integration is built and the roster syncs, the twelfth campaign of the year costs close to what the second did. An engagement does not amortise that way. Where the cadence is monthly and the population is large, a subscription is the right shape of purchase.
  • A maintained content library. Keeping a module and template library current, in more than one language, is a product problem. It needs a roadmap and a content team.
  • Directory and HR integration. Joiners, movers and leavers arrive from the HR system rather than from a spreadsheet re-exported each quarter. It matters more than it sounds, as the NBFC clause below shows.
  • Self-service scheduling. A compliance lead can launch a campaign next Tuesday. No statement of work, no scoping call, no procurement cycle.
  • The training itself, and the completion record. Courseware, quizzes, module assignment, per-user history, reminders to whoever has not finished. Where a clause requires training to have been delivered and the organisation to show to whom, this is the instrument that produces the artefact.

Those are real strengths. An organisation carrying an annual training mandate across a large workforce, with no platform behind it, should buy one before it commissions anything else.

What an independent assessment produces

Separation of the party that delivers from the party that measures. A quiz score generated by the system that delivered the training is evidence of engagement with that system. A pretext designed outside the organisation, sent from infrastructure it does not control, measures what the workforce did when nobody in the building had configured the test.

Pretexts built from the environment rather than from a library. The organisation's own brand, its vendors, its payroll cycle, a live acquisition, the internal tool everybody uses. A library template measures recognition of a generic lure, an easier question.

Channels beyond email. Vishing within the terms of the authorisation, and physical pretexting where written authorisation covers it. CERT-In lists (x) Process Security Testing among its engagement types, "including, but not limited to" (CISG-2025-02 §6, pp. 14-17), and §15.2.2(iii)'s own phrase is "Social engineering and process testing". A call to the service desk tests a procedure.

The detection walkthrough. What the gateway, the endpoint agent and the monitoring team saw, when, and what they did next. That output is about controls rather than about people.

One question separates the two measurements more cleanly than any feature list. Ask, of any simulation however it is procured, whether the sending infrastructure is allow-listed at the mail gateway. The answer decides whether the number describes the workforce alone or the workforce plus every control in front of it. Both are worth knowing, and they do not belong on one trend line.

The clause that governs the deliverable

CERT-In's Comprehensive Cyber Security Audit Policy Guidelines (CISG-2025-02, Version 1.0, 25 July 2025) name their audience in §4, and the first audience named is CERT-In empanelled auditing organisations. What follows is a rule about the audit and about what the auditor may hand back.

Social engineering and process testing should be conducted in a controlled and ethical manner. When targeting general staff (e.g., untrained or non-security personnel), such testing must utilize anonymized or statistical techniques—ensuring no individual is personally identified or penalized. The purpose is to evaluate overall awareness and the effectiveness of security processes, not to single out individuals.

CISG-2025-02 §15.2.2(iii), pp. 55-56.

Per-user risk scores, leaderboards, manager-visible click lists and automatic enrolment of clickers into remedial training are headline features of the platform category. Where the test is performed by an empanelled auditing organisation, §15.2.2(iii) governs the deliverable and it runs the other way: anonymised or statistical technique, no individual personally identified or penalised, the purpose being overall awareness. That is a constraint on the auditor and on the audit report: §4 fixes the audience, and the clause binds the empanelled auditing organisation performing the test.

The same guideline sets the procurement difference at §13.2.7(ii), p. 50: "Specific written permissions must be obtained" from the auditee organisation before tests involving process testing or social engineering. Whichever purchase is made, somebody must be able to produce that document, name the population it covers, and say who signed it. An engagement carries one by construction. A campaign scheduled from a console is authorised by whoever holds the login, which is a governance question worth settling before the first send.

Which purchase a given obligation needs

ClauseWhat it asks forWhich purchase answers it
RBI Directions, 2026 — Commercial Banks ¶203, ¶204Awareness programmes mandatory for all new recruits; annual training for lower and middle management; annual training to all Board members and Senior ManagementDelivery plus a completion record. A platform, an LMS, or a facilitator for the Board session
Urban Co-operative Banks ¶156Mandatory programmes for new recruits, and web-based quiz and training for lower, middle and upper management every year. Section H sits in Chapter V, which binds Level III and Level IV UCBsA platform. The clause names the web-based quiz as the method, and it reaches upper management
NBFCs ¶35An ongoing information security training and awareness programme for all usersDelivery, at the cadence the programme sets
Commercial Banks ¶202; Payments Banks ¶201; Small Finance Banks ¶201; Credit Information Companies ¶197Evaluate the awareness level of employees periodicallyAn assessment with a result. Who performs it is a procurement decision
NBFCs ¶36A formal mechanism to measure and track the effectiveness of such training through periodic assessments or testing, and an up-to-date repository of the training and awareness status of all usersBoth. The mechanism is a test; the repository is a records system, and the roster usually lives in the platform
SEBI CSCRF §3.2 PR.AT, p. 63, and PR.AT Guidelines, pp. 103-104Mandatory awareness programmes, extended to privileged users, third parties, senior executives and the Board. The Standard says "periodic"; the periodic-compliance table says "Cybersecurity training program (PR.AT.S1) — All REs — Annually"Delivery plus a completion record, at annual cadence
SEBI CSCRF GV.RM Guidelines, item 1(e), p. 87 (GV.RM.S3)"REs shall periodically assess level of employee cybersecurity awareness, for e.g., through phishing test success rate, etc." Applicability: all REs except small-size, self-certification REs (Mandatory)An assessment. SEBI requires the periodic assessment, and names phishing test success rate as an example of how

How to tell which one you are buying

Read the verb in the clause.

Where it says train, conduct programmes, provide, or names a quiz, the purchase is delivery and the artefact is a completion record. Buy the platform. Measuring awareness in a workforce that has never been trained measures the hiring pool.

Where it says evaluate, assess, or measure the effectiveness, the purchase is an assessment, and the questions are who performs it, what the deliverable contains, and whether the result would persuade somebody who did not commission it. Where the clause says both, as NBFC ¶36 does inside a single paragraph, the repository is the join between the two.

RBI drew this line itself: ¶203 trains and ¶202 evaluates, in consecutive paragraphs of the same Direction. The numbers move by entity type, as the table shows, and one paragraph number quoted across entities is wrong for most of them.

The common audit failure is not an absent programme. It is one purchase reported against both clauses: a completion percentage offered as evidence that awareness was evaluated, or a click rate offered as evidence that training was delivered.

What to hold, whichever you buy

Four artefacts, the same four in both cases. The written authorisation, naming the population and the window, per §13.2.7(ii). The population as it stood on the day, because a rate means nothing without its denominator. The result, in the form the clause asks for. And a retention decision.

That last one is usually the one nobody owns. Both purchases create a dataset that names employees. The Digital Personal Data Protection Act, 2023 provides the ground for processing it at s.7(i), "for the purposes of employment or those related to safeguarding the employer from loss or liability", and s.8(7)(a) attaches an erasure obligation, "as soon as it is reasonable to assume that the specified purpose is no longer being served". Whoever holds the click list holds that obligation. Ask, before either contract is signed, where the dataset will sit, who can see it, and what remains once the purpose has been served.

About the author

Abhed Indulkar

Lead — ShadowMap

Senior full-stack engineer and ShadowMap product lead. 5+ years building security platforms across Vue.js, Laravel, React, Python, Django, AWS, and Azure. Architects the technology that powers continuous attack surface monitoring.