Skip to main content

What CERT-In's audit policy guidelines require of a phishing simulation

CERT-In's audit policy guidelines already set the rules for a phishing simulation in India: specific written permission before, anonymised or statistical results after, and no individual identified or penalised.

By Siddarth G
August 31, 20267 min read

Two questions decide whether a phishing simulation can be commissioned inside a regulated Indian organisation, and the second one usually arrives within a minute of the first: what will you do to my staff, and what will you hand back? Both answers are already written down, in a published guideline, by the national CERT.

Specific written permission before anything is sent. Anonymised or statistical results afterwards, with no individual personally identified or penalised, against a population limited to the employee groups inside the agreed scope. That regime comes from two clauses of one document: CERT-In's Comprehensive Cyber Security Audit Policy Guidelines, CISG-2025-02, Version 1.0, 25 July 2025.

The document, who it binds, and what it covers

§4 applies the guidelines to two audiences. The first is CERT-In empanelled auditing organisations. Security Brigade is one, so the clauses below are not a position adopted for an article. They are the conditions the work is performed under, and they hold whatever a statement of work happens to say.

§6, pp. 14–17, sets out the engagement types the guidelines cover, "including, but not limited to" twenty-five items. Simulation work of this kind is scoped under (x) Process Security Testing and (xvi) Red Team Assessment. The link is in the operative clause's own opening words — "Social engineering and process testing" — which is how §15.2.2(iii) names the activity it governs.

Before the campaign: specific written permission

"Specific written permissions must be obtained from the auditee organization before conducting tests that involve survivability failures, denial-of-service (DoS), process testing, or social engineering."

CISG-2025-02 §13.2.7(ii), p. 50.

Social engineering sits here beside survivability and denial-of-service testing, the categories where an unannounced test reaches something an operating business cannot afford to have reached by accident. The word carrying the weight is specific. A permission that meets it is issued for the exercise rather than inherited from a general testing clause in a master agreement, and it establishes what the exercise will touch: the employee groups, the window, the channels, and the route by which it can be stopped.

An awareness obligation is discharged across a year rather than in an afternoon, so on a programme the permission is part of the operating rhythm and not a signature collected once at the outset. A quarterly cadence against rotating cohorts produces a series of authorisations, each naming the population it covers. That series is itself the first artefact an auditor can be shown.

During and after: anonymised or statistical, and inside the agreed scope

"Social engineering and process testing should be conducted in a controlled and ethical manner. When targeting general staff (e.g., untrained or non-security personnel), such testing must utilize anonymized or statistical techniques—ensuring no individual is personally identified or penalized. The purpose is to evaluate overall awareness and the effectiveness of security processes, not to single out individuals.

Social engineering and process testing must only target group of employees explicitly included within the agreed audit scope. These tests must not involve external entities such as customers, business partners, vendors, or other third parties, unless specific written consent is obtained from the target organization."

CISG-2025-02 §15.2.2(iii), pp. 55–56.

Four rules come out of those two paragraphs, and a programme has to satisfy all four:

  • Technique. Where general staff are the target — the clause's example is untrained or non-security personnel — the testing must use anonymised or statistical techniques.
  • Consequence. No individual is personally identified or penalised.
  • Purpose. The exercise evaluates overall awareness and the effectiveness of security processes, rather than singling out individuals.
  • Population. Only groups of employees explicitly included within the agreed audit scope. Customers, business partners, vendors and other third parties sit outside it unless specific written consent is obtained from the target organisation.

Read with §13.2.7(ii), that is the authorisation and reporting regime for a workforce phishing programme in India, written end to end: permission before, statistics after, a bounded population, and a purpose stated in the clause itself rather than negotiated per engagement.

There is a second-order effect worth naming, because it is what makes the rule useful rather than merely binding. Since the purpose is fixed — overall awareness and the effectiveness of security processes — the number the exercise produces describes the organisation and not any person inside it. That is what makes it comparable. A figure about a population can be tracked across quarters, split by cohort and put in front of an audit committee. A figure about individuals invites a different reading, and an instrument that changes the behaviour it is measuring stops being an instrument.

What the reporting looks like when the rule is applied

The unit of analysis is the population. Click rate, credential submission, time-to-click, and heatmaps by department and by role, alongside the walkthrough of which controls and which people detected the campaign and which did not. Cohorts and rates, not a list of names. Across successive campaigns the same shape becomes a baseline, a trend, and a record of which cohorts moved.

Per-user risk scores, leaderboards, manager-visible click lists and automatic enrolment of clickers into remedial training are the headline features of the awareness platform category. Where general staff are tested by a CERT-In empanelled auditing organisation, §15.2.2(iii) governs the output, and it points the analysis at the population rather than at the person.

What the organisation does with the cohort view is the part the clause leaves to it. The view shows where the training already in place has landed and where it has not, which departments and roles behave differently from the average, and whether the last intervention moved anything. Measurement and remedy stay separate functions, and it is the measurement that leaves the evidence trail.

The working dataset behind those statistics is personal data for as long as it exists. The Digital Personal Data Protection Act, 2023 requires reasonable security safeguards over it (s.8(5)) and erasure "as soon as it is reasonable to assume that the specified purpose is no longer being served" (s.8(7)(a)). The two instruments interlock cleanly: the identifying data has a purpose that ends once the population figures have been produced, and the anonymised or statistical output §15.2.2(iii) requires is what survives it.

The clauses, and what each one governs

Two separate things are in play. CERT-In's guidelines govern how the test is conducted. The obligation to measure awareness on a schedule sits in the sectoral instruments, and it is what puts the programme on a clock.

Instrument and clauseWhat it governs
CISG-2025-02 §13.2.7(ii), p. 50Specific written permission from the auditee organisation before process testing or social engineering
CISG-2025-02 §15.2.2(iii), pp. 55–56Anonymised or statistical technique for general staff; no individual personally identified or penalised; purpose is overall awareness and process effectiveness
CISG-2025-02 §15.2.2(iii), second paragraphTarget population limited to employee groups explicitly in the agreed audit scope; third parties only on specific written consent
CISG-2025-02 §6, pp. 14–17Engagement types, "including, but not limited to" — (x) Process Security Testing and (xvi) Red Team Assessment
RBI Directions, 2026 (31 July 2026), commercial banks ¶202"The bank shall evaluate the awareness level of employees periodically"
RBI Directions, 2026, NBFCs ¶36A "formal mechanism to measure and track the effectiveness of such training through periodic assessments or testing", plus an up-to-date repository of the training and awareness status of all users
SEBI CSCRF v1.0, GV.RM Guidelines item 1(e), p. 87REs "shall periodically assess level of employee cybersecurity awareness, for e.g., through phishing test success rate" — all REs except small-size, self-certification REs
DPDP Act, 2023, s.8(5) and s.8(7)(a)Safeguards over the click dataset, and erasure once the specified purpose is no longer being served

The RBI paragraph numbers differ by entity: ¶202 for commercial banks, ¶201 for payments banks and for small finance banks, ¶197 for credit information companies, ¶35–36 for NBFCs. A single number quoted across the sector is wrong for most of it, and the sentence a bank is measured against is not the sentence an NBFC is measured against.

What to hold when the programme is done

Four artefacts, each traceable to a clause:

  1. The specific written permission for each campaign window, dated before it and naming the employee groups it covers — §13.2.7(ii).
  2. A report whose findings are population-level and in which no individual is identified — §15.2.2(iii).
  3. A stated retention and erasure position for the dataset behind the report — DPDP s.8(5) and s.8(7)(a).
  4. The population definition itself, recorded per campaign, because next quarter's number only means something measured against a comparable one.

And one question worth asking a provider at scoping rather than at the debrief: which clause governs what you will do to my staff, and which governs what you hand back? In India both of them have a number and a page.

About the author

Siddarth G

Practice Director — Cybersecurity

Leads Security Brigade's offensive security practice with deep expertise in vulnerability research, penetration testing, and red team operations. Ranked Top 80 globally on Bugcrowd.