Resources
Guides, templates, and educational content about cyber security awareness.
Downloads
Free, no obligation. We email a confirmation link, then the file.
Guides and templates
Spear phishing versus bulk simulation: what changes in the test and in the numbers
A spear campaign and a bulk campaign measure different things over different populations. Why their rates cannot share a trend line, and how a six-person cohort is reported when a percentage would identify people.
Scoping a phishing simulation programme in India
What has to be decided before the first send: the population and its cohorts, the scope boundary, the cadence, the channels, the exclusions, the escalation contacts and the written authorisation CERT-In requires.
Measuring the executive population
RBI ¶204 addresses the Board and Senior Management separately, and CERT-In's reporting rule makes a percentage over twelve people an individual result. What an executive exercise reports instead.
Testing the service desk: vishing as a process control test
A vishing test against the service desk measures a procedure, not a person. What CERT-In's CISG-2025-02 requires before the call, and what the finding should say afterwards.
What moves the effort of a phishing simulation programme
Very little of the effort in a phishing simulation scales with headcount. The six drivers that actually move it, and how to place a programme in a small, medium or large band before asking for a proposal.
What an auditor asks to see from an awareness programme
The eight questions an auditor puts to a security awareness programme, the RBI, SEBI, CERT-In and DPDP clause behind each of them, and the answers that fail.
What an awareness evidence repository actually contains
RBI asks NBFCs to keep an up-to-date repository of the training and awareness status of all users. Read as a specification: the population, the cohorts, the dates, the methods, the results and the retention.
The report route: where a suspicious email goes, and what happens to it
Report rate is the only number in a phishing programme that measures a behaviour you want. It exists only if there is somewhere to report to, staffed by somebody who answers. How to build that route.
Why two quarters of click rates are not comparable
A click rate belongs to one population, one pretext and one moment. What has to be held constant between rounds, what changes quietly, and how to build an awareness series that supports a comparison.
Which Indian instrument says what about security awareness
The clause reference for employee cyber security awareness in India: the RBI Directions, 2026 across six entity types, SEBI CSCRF, CERT-In CISG-2025-02 and the DPDP Act, with paragraph and page numbers.
A security awareness platform and a testing firm are not the same purchase
A security awareness platform and an independent testing firm answer different clauses. Which purchase a given RBI, SEBI or CERT-In obligation actually needs, and what each one produces.
What each number in a phishing simulation report measures
A phishing simulation returns a small set of numbers, and each supports a narrow claim. What click rate, credential submission, time-to-click, report rate and repeat exposure each measure.
The clause that names phishing testing, and exactly what it says
One clause in the SEBI CSCRF names phishing testing. It is on page 87, it sits in the Risk Management guidelines, and "for e.g." are the regulator's own words. What item 1(e) asks for.
What SEBI CSCRF asks of an awareness programme
SEBI CSCRF puts the awareness obligation in two places: PR.AT sets the training programme and its cohorts, and GV.RM.S3 requires periodic assessment of the awareness level. What each asks, and which REs carry it.
Which co-operative banks carry the RBI awareness obligation
The annual web-based quiz at ¶156 of RBI's UCB Directions, 2026 sits in Chapter V, and the applicability table at ¶4 assigns Chapter V by Level. The Level is settled first.
NBFC ¶36: measure the training, and keep the repository
The RBI Directions, 2026 place four separately auditable requirements on an NBFC in one paragraph. What ¶36 asks for, phrase by phrase, and what has to exist before a supervisor asks to see it.
Who may be in the target population of a phishing simulation
CERT-In's audit policy guidelines confine a phishing simulation's target population to agreed employee groups. SEBI directs regulated entities to extend training to outsourced staff. Both hold.
What the click list may and may not be used for
A simulation produces a list of names. CERT-In's guidelines require anonymised or statistical results with no individual identified or penalised, and a programme that ignores that rule destroys its own report rate.
How a phishing simulation runs, and what you receive
A phishing simulation is a measurement exercise over a defined employee population: what is agreed before it runs, what the campaign does, and what the report and the debrief actually contain.
Cyber security awareness: what a programme can and cannot change
An awareness programme changes what an organisation does, not what any individual knows. What the RBI, SEBI and CERT-In instruments require, what a programme moves, and what it cannot.
The awareness clauses of the RBI Directions, 2026, entity by entity
The RBI Directions, 2026 carry an employee awareness obligation for every supervised entity, and the paragraph number differs in each. Which clause binds a bank, an NBFC, a CIC or a UCB, and what each one asks for.
The lawful basis for testing your own staff
A phishing simulation produces personal data about identifiable employees. DPDP s.4(1) gives two grounds for processing it, s.7(i) is the employment ground, and s.8 governs the dataset on either.
What CERT-In's audit policy guidelines require of a phishing simulation
CERT-In's audit policy guidelines already set the rules for a phishing simulation in India: specific written permission before, anonymised or statistical results after, and no individual identified or penalised.