Skip to main content
Guides, Templates & Case Studies

Resources & insights for enterprise security teams.

Actionable checklists, compliance guides, and real-world case studies drawn from 6,700+ security assessments across every major industry.

Free Resources

Security checklists & templates

Practical, audit-tested resources built from years of enterprise security experience. Some are downloads, some read in the browser — each card says which.

pdf

Phishing Simulation Scoping Template

The objective, the population and its denominator, scenario difficulty, the measure set that makes report rate the number worth having, the authorisation and handling rules, the evidence record an auditor accepts, the remediation loop, and a worksheet to issue.

rfp_templatepdf
Download Free Resource
pdf

RBI 2026 VA/PT Assurance Checklist

A clause-mapped worksheet for the vulnerability assessment and penetration testing obligations under the RBI Directions, 2026 and their five siblings — cadence, scope, the documented approach, auditor competency, the report-format mandate at paragraph 157, and the breach-triggered deficiency at paragraph 158.

readiness_assessmentpdf
Download Free Resource
pdf

PTaaS Evaluation and Scoping Template

A worksheet for buying continuous penetration testing: what “continuous” has to say in the contract, how a finding gets verified, how scope and price move, what an auditor will accept, and a weighted scorecard.

vendor_checklistpdf
Download Free Resource
pdf

Red Team Engagement Scoping Template

The objective statement, the threat scenario and the evidence behind it, the rules of engagement register, the white cell and its communications plan, detection and response expectations, a scoping worksheet to issue, and the report contents that make the exercise usable afterwards.

rfp_templatepdf
Download Free Resource
pdf

ISO 27001 Clause 9.2 Internal Audit Programme

A programme you can run: the schedule across clauses 4 to 10 and the four Annex A themes, an auditor impartiality register, the nonconformity record, and what a certification body examines at Stage 1 and Stage 2.

readiness_assessmentpdf
Download Free Resource
pdf

PCI DSS Requirement 11.4 Evidence Checklist

A printable gate for the penetration testing evidence a QSA examines under PCI DSS v4.0.1 — the nine methodology elements at 11.4.1, coverage and cadence, the seven segmentation elements at 11.4.5, the retest at 11.4.4, the report contents table, and a finding-to-requirement mapping worksheet.

readiness_assessmentpdf
Download Free Resource
pdf

SBI VSCC Readiness Checklist

A readiness worksheet for the SBI Vendor Site Compliance Certificate, organised around the three published causes of rejection: an incomplete certificate, findings not adequately closed, and an auditor without proper CERT-In empanelment. Includes a self-assessment across the eight assessment areas, a finding-closure register, and a timeline working back from the onboarding date.

readiness_assessmentpdf
Download Free Resource
pdf

ATM and POS Security Audit Checklist

A worksheet for the payment estate: a terminal and channel inventory, the contractual controls the RBI Directions, 2026 require a bank to impose on its ATM Switch service provider under paragraphs 136 to 139, the evidence that provider has to produce, and technical coverage across terminals, transactions, cardholder data, keys and segmentation.

readiness_assessmentpdf
Download Free Resource
pdf

SOC 2 Readiness Checklist

A readiness worksheet for SOC 2: which Trust Services Criteria to put in scope, the Type 1 versus Type 2 decision and when the observation window opens, an evidence-retention audit to run before it does, and a control review grouped the way an auditor will ask for it.

readiness_assessmentpdf
Download Free Resource
pdf

NSE Trading Member VAPT Submission Checklist

A printable worksheet for NSE/INSP/70471: a scope-coverage table for the nine mandated testing areas, a report-contents gate against Annexure 2, an auditor eligibility check against Annexure 3, and a dated plan working back from the submission deadline.

readiness_assessmentpdf
Download Free Resource
pdf

VAPT Pricing Primer

What drives the cost of a penetration test, how many tester-days each engagement type actually takes, and a worksheet for estimating your own budget before you speak to anybody. Publishes no rate on purpose — it has you establish yours, because a printed day rate describes somebody else's market.

guidepdf
Download Free Resource
pdf

Sample Evidence Pack

How a penetration-testing finding becomes audit evidence: the five-link finding-to-control chain, a mapping by finding class across SOC 2, ISO 27001:2022 and PCI DSS v4.0, the artefacts an assessor asks for, seven evidence states, and a worksheet. Every finding in it is synthetic.

readiness_assessmentpdf
Download Free Resource
pdf

Virtual Patching Playbook

Interim controls while a vendor patch is pending: a seven-item decision gate, WAF, ModSecurity, network-ACL and detection recipes for eight vulnerability classes, retirement criteria, and the virtual-patch register that stops a temporary rule becoming permanent infrastructure.

toolkitpdf
Download Free Resource
pdf

ISO 27001:2022 Readiness Checklist

A clause-by-clause readiness checklist with the four Annex A control themes as working tables and a gap-assessment tracker to fill in. A readiness self-assessment, not certification advice.

readiness_assessmentpdf
Download Free Resource
pdf

VAPT RFP Template and Vendor Evaluation Pack

A fillable RFP pack for a penetration-testing procurement: scope tables, a compliance-framework mapping, a weighted vendor evaluation matrix, a pricing comparison and a vendor requirements checklist. Deliberately vendor-neutral — it is a document you send to several firms.

rfp_templatepdf
Download Free Resource
pdf

Microsoft 365 Identity Security Readiness Checklist

24 checks across authentication flows, token and device trust, OAuth consent, data exposure, mailbox integrity and supplier risk. Answerable by your own administrators from the Entra and Microsoft 365 admin centres.

readiness_assessmentpdf
Download Free Resource
pdf

Sample Secure Code Review Report

Sanitised sample secure code review report with SAST + SCA findings, language-specific remediation, supply-chain vulnerability analysis, and OWASP Top 10 coverage.

reportpdf
Download Free Resource
pdf

Sample Web Application Penetration Testing Report

Sanitised sample web application penetration test report with OWASP ASVS L2/L3 coverage, business logic findings, CVSS scoring, and technology-specific remediation guidance.

reportpdf
Download Free Resource
pdf

Sample Network Penetration Testing Report

Sanitised sample network penetration test report covering external/internal infrastructure, AD assessment, MITRE ATT&CK mapping, and infrastructure hardening guidance.

reportpdf
Download Free Resource
pdf

Sample Red Team Assessment Report

Sanitised sample red team assessment report covering full kill-chain simulation, MITRE ATT&CK mapping, OSINT, social engineering, lateral movement, and executive summary.

reportpdf
Download Free Resource
Guide

AI Defence Roadmap Template — IT-Committee Submission

Template for the SEBI Annexure-A item 10 deliverable. 8 sections: current state, threat model, AI VA strategy, SOC transformation and guardrails.

Resource
Read the guide
Guide

CSCRF + SEBI AI Advisory Control Crosswalk

Mapping every SEBI May 2026 advisory directive to its CSCRF control domain. Net-new vs amplifies vs extends. Audit-evidence guidance per row.

Resource
Read the guide
Interactive

CSCRF Readiness Score: SEBI Self-Assessment

Interactive 10-question tool scoring your SEBI CSCRF readiness across entity classification and 5 maturity pillars. Instant tier rating.

Resource
Open the tool
Guide

M-SOC Onboarding Readiness Guide for SEBI-Regulated Entities

4-week M-SOC onboarding readiness for SEBI-regulated entities. Log-source mapping, SIEM/SOAR prerequisites, eligibility determination.

Resource
Read the guide
Guide

Anatomy of a Microsoft 365 Compromise

Stage by stage: how Microsoft 365 attacks on financial institutions unfold, from a compromised supplier mailbox to Graph-based collection.

Resource
Read the guide
Guide

SEBI AI Advisory Self-Assessment Checklist

50+ Annexure-A self-assessment prompts for SEBI

Resource
Read the guide
Guide

SEBI CSCRF + AI Advisory Combined Readiness Guide

Pairs SEBI CSCRF tier obligations with the 10 AI Advisory directives. Per-tier roadmap, evidence checklist and a 90-day implementation sequence.

Resource
Read the guide
Guide

SEBI CSCRF for Stock Brokers & Depository Participants

SEBI CSCRF for stock brokers and depository participants: two-parameter classification, per-tier obligations, DP rules and sub-100-client exemptions.

Resource
Read the guide
Guide

SEBI CSCRF Compliance Calendar 2026-27

Per-tier annual compliance cadence for 22 SEBI-regulated entity categories: VAPT, cyber audit, red teaming, threat hunting, CCI and ISO 27001.

Resource
Read the guide
Guide

SEBI CART: Continuous Automated Red Teaming

SEBI CSCRF mandates half-yearly red teaming for MIIs and Qualified REs. How ShadowMap CART provides continuous automated red teaming between cycles.

Resource
Read the guide
Guide

SEBI CSCRF Compliance Readiness Checklist

SEBI CSCRF current-state checklist: 5-tier model, 22 entity-type thresholds, VAPT and audit cadences, ISO 27001 and M-SOC mandates, AI readiness.

Resource
Read the guide
Guide

SEBI CSCRF Compliance Services — Complete Offering

Security Brigade

Resource
Read the guide
Guide

SEBI CSCRF Tier Self-Assessment Worksheet

Step-by-step worksheet to determine your CSCRF tier: 22 entity types, threshold checks and exemptions. Offline companion to the wizard.

Resource
Read the guide
Guide

ShadowMap for SEBI CSCRF Compliance

How ShadowMap

Resource
Read the guide
Guide

SEBI CSCRF Per-Tier Requirement Cards

Five single-page SEBI CSCRF tier cheatsheets — MII, Qualified, Mid-size, Small-size and Self-certification. Obligations and cadences, print-ready A4.

Resource
Read the guide

Need a custom security assessment?

Our security architects will evaluate your environment and recommend the right approach — whether it's a compliance audit, penetration test, or full red team engagement.

Talk to an Expert