Resources & insights for enterprise security teams.
Actionable checklists, compliance guides, and real-world case studies drawn from 6,700+ security assessments across every major industry.
Free Downloads
Security checklists & templates
Practical, audit-tested resources built from years of enterprise security experience. Download and use them to strengthen your security posture today.
SBI VSCC Readiness Checklist
A readiness worksheet for the SBI Vendor Site Compliance Certificate, organised around the three published causes of rejection: an incomplete certificate, findings not adequately closed, and an auditor without proper CERT-In empanelment. Includes a self-assessment across the eight assessment areas, a finding-closure register, and a timeline working back from the onboarding date.
ATM and POS Security Audit Checklist
A worksheet for the payment estate: a terminal and channel inventory, the contractual controls the RBI Directions, 2026 require a bank to impose on its ATM Switch service provider under paragraphs 136 to 139, the evidence that provider has to produce, and technical coverage across terminals, transactions, cardholder data, keys and segmentation.
SOC 2 Readiness Checklist
A readiness worksheet for SOC 2: which Trust Services Criteria to put in scope, the Type 1 versus Type 2 decision and when the observation window opens, an evidence-retention audit to run before it does, and a control review grouped the way an auditor will ask for it.
NSE Trading Member VAPT Submission Checklist
A printable worksheet for NSE/INSP/70471: a scope-coverage table for the nine mandated testing areas, a report-contents gate against Annexure 2, an auditor eligibility check against Annexure 3, and a dated plan working back from the submission deadline.
VAPT Pricing Primer
What drives the cost of a penetration test, how many tester-days each engagement type actually takes, and a worksheet for estimating your own budget before you speak to anybody. Publishes no rate on purpose — it has you establish yours, because a printed day rate describes somebody else's market.
Virtual Patching Playbook
Interim controls while a vendor patch is pending: a seven-item decision gate, WAF, ModSecurity, network-ACL and detection recipes for eight vulnerability classes, retirement criteria, and the virtual-patch register that stops a temporary rule becoming permanent infrastructure.
Sample Evidence Pack
How a penetration-testing finding becomes audit evidence: the five-link finding-to-control chain, a mapping by finding class across SOC 2, ISO 27001:2022 and PCI DSS v4.0, the artefacts an assessor asks for, seven evidence states, and a worksheet. Every finding in it is synthetic.
VAPT RFP Template and Vendor Evaluation Pack
A fillable RFP pack for a penetration-testing procurement: scope tables, a compliance-framework mapping, a weighted vendor evaluation matrix, a pricing comparison and a vendor requirements checklist. Deliberately vendor-neutral — it is a document you send to several firms.
ISO 27001:2022 Readiness Checklist
A clause-by-clause readiness checklist with the four Annex A control themes as working tables and a gap-assessment tracker to fill in. A readiness self-assessment, not certification advice.
Microsoft 365 Identity Security Readiness Checklist
24 checks across authentication flows, token and device trust, OAuth consent, data exposure, mailbox integrity and supplier risk. Answerable by your own administrators from the Entra and Microsoft 365 admin centres.
Sample Web Application Penetration Testing Report
Sanitised sample web application penetration test report with OWASP ASVS L2/L3 coverage, business logic findings, CVSS scoring, and technology-specific remediation guidance.
Sample Secure Code Review Report
Sanitised sample secure code review report with SAST + SCA findings, language-specific remediation, supply-chain vulnerability analysis, and OWASP Top 10 coverage.
Sample Network Penetration Testing Report
Sanitised sample network penetration test report covering external/internal infrastructure, AD assessment, MITRE ATT&CK mapping, and infrastructure hardening guidance.
Sample Red Team Assessment Report
Sanitised sample red team assessment report covering full kill-chain simulation, MITRE ATT&CK mapping, OSINT, social engineering, lateral movement, and executive summary.
ShadowMap Sample Report
Sanitised ShadowMap attack surface intelligence report covering external asset discovery, vulnerability assessment, dark web monitoring, and brand protection.
AI Defence Roadmap Template — IT-Committee Submission
Template for the SEBI Annexure-A item 10 deliverable. 8 sections: current state, threat model, AI VA strategy, SOC transformation and guardrails.
CSCRF + SEBI AI Advisory Control Crosswalk
Mapping every SEBI May 2026 advisory directive to its CSCRF control domain. Net-new vs amplifies vs extends. Audit-evidence guidance per row. Free download.
CSCRF Readiness Score: SEBI Self-Assessment
Interactive 10-question tool scoring your SEBI CSCRF readiness across entity classification and 5 maturity pillars. Instant tier rating.
M-SOC Onboarding Readiness Guide for SEBI-Regulated Entities
4-week M-SOC onboarding readiness for SEBI-regulated entities. Log-source mapping, SIEM/SOAR prerequisites, eligibility determination. Free download.
Anatomy of a Microsoft 365 Compromise
Stage by stage: how Microsoft 365 attacks on financial institutions unfold, from a compromised supplier mailbox to Graph-based collection.
SEBI AI Advisory Self-Assessment Checklist
50+ Annexure-A self-assessment prompts for SEBI
SEBI CSCRF + AI Advisory Combined Readiness Guide
Pairs SEBI CSCRF tier obligations with the 10 AI Advisory directives. Per-tier roadmap, evidence checklist and a 90-day implementation sequence.
SEBI CSCRF for Stock Brokers & Depository Participants
SEBI CSCRF for stock brokers and depository participants: two-parameter classification, per-tier obligations, DP rules and sub-100-client exemptions.
SEBI CSCRF Compliance Calendar 2026-27
Per-tier annual compliance cadence for 22 SEBI-regulated entity categories: VAPT, cyber audit, red teaming, threat hunting, CCI and ISO 27001.
SEBI CART: Continuous Automated Red Teaming
SEBI CSCRF mandates half-yearly red teaming for MIIs and Qualified REs. How ShadowMap CART provides continuous automated red teaming between cycles.
SEBI CSCRF Compliance Readiness Checklist
SEBI CSCRF current-state checklist: 5-tier model, 22 entity-type thresholds, VAPT and audit cadences, ISO 27001 and M-SOC mandates, AI readiness.
SEBI CSCRF Compliance Services — Complete Offering
Security Brigade
SEBI CSCRF Tier Self-Assessment Worksheet
Step-by-step worksheet to determine your CSCRF tier: 22 entity types, threshold checks and exemptions. Offline companion to the wizard.
ShadowMap for SEBI CSCRF Compliance
How ShadowMap
SEBI CSCRF Per-Tier Requirement Cards
Five single-page SEBI CSCRF tier cheatsheets — MII, Qualified, Mid-size, Small-size and Self-certification. Obligations and cadences, print-ready A4.
Case Studies
Real-world results from the field
See how enterprises across BFSI, e-commerce, and critical infrastructure have strengthened their security posture with our assessments.
Three-Year Managed Security Partnership with a Global Manufacturing Group
Three-Year Managed Security Partnership with a Global Manufacturing Group
How a Large BFSI Enterprise Reduced Its Attack Surface Exposure by 40%
How a Large BFSI Enterprise Reduced Its Attack Surface Exposure by 40%
How We Secured a $50M Fintech Platform Before Series B
How We Secured a $50M Fintech Platform Before Series B
Blog
Security articles & analysis
Long-form analyses, post-incident write-ups, and field-tested guides from the Security Brigade team.
ATM Switch and CBS Providers: The Controls Your Bank Customers Must Now Impose on You
Four of the six RBI Directions require banks to impose named cybersecurity controls on their ATM Switch and core banking service providers by contract — 24 of them for commercial banks, 37 for urban co-operative banks. The obligation flows down even where it does not sit at the top.
Foreign Bank Branches and Comply-or-Explain: What Paragraph 4 Actually Buys You
The RBI Directions, 2026 contain exactly one comply-or-explain device, and it applies only to foreign banks operating in India through branch mode. It covers four chapters and sixteen named paragraph groups — and it is a relaxation subject to RBI accepting your explanation, not an exemption.
Case Study: Moving a Commercial Bank from Annual Testing to the Paragraph 151 Cadence
A commercial bank running annual point-in-time VAPT re-scoped to the RBI Directions, 2026 — six-monthly vulnerability assessment, production-environment testing, cloud in scope, and a quarterly closure pack for the ITSC and ISC that did not previously exist as an artefact.
Need a custom security assessment?
Our security architects will evaluate your environment and recommend the right approach — whether it's a compliance audit, penetration test, or full red team engagement.
Talk to an Expert