Skip to main content
Industry · Banking, insurance and capital markets

The estate a financial institution is judged on is mostly not the one it operates.

ShadowMap watches the parts of a financial institution’s exposure that sit outside its own change control — credentials belonging to staff, branches and agents; impersonation aimed at retail customers; and the external estate of the processors and partners doing regulated work on your behalf. One correlated exposure model, continuously, from outside, and where it is safe and authorised the exposure is tested rather than asserted. Every run leaves a dated, scoped record, which is what turns monitoring into evidence.

“A regulator asks what is exposed and by when it will be fixed. The answer has to hold up in an inspection, not a slide.”

12B+
Breach and credential records
31
Authorities under regulatory monitoring
CERT-In
Empanelled security auditor since 2008 — Security Brigade

The frame

The best-defended part of your estate is the part least likely to be the problem

A bank’s own network is the most heavily controlled, most frequently tested and most closely examined thing it owns. The exposure that produces incidents sits on the other side of it: on the people who work for you, the customers who trust your name, and the firms you have outsourced regulated processing to.

Two boundaries belong here rather than at the foot of the page. The first is what this is. ShadowMap runs continuous outside-in monitoring and produces a dated, scoped record of what was examined, when, and what was found — including what it deliberately did not examine. It is not a compliance opinion, and nothing on this page tells you whether a particular direction, circular or framework binds your entity. The second is what it is not. Gap analysis against a framework, control testing, remediation advisory and the assessor sign-off a supervisor eventually asks for are consulting engagements. They are Security Brigade’s practice, at securitybrigade.com, and the honest answer is to send you there rather than build a thinner second version of the same work here. What ShadowMap contributes is the layer underneath it: the monitoring evidence an assessor asks for and a self-assessment questionnaire structurally cannot produce. India is where that layer has the most depth, because CERT-In empanelment since 2008 made RBI, SEBI and IRDAI expectations operational knowledge at Security Brigade long before they were anybody’s product feature. It is not where the monitoring stops.

Where the exposure sits

What is exposed, and whose it turns out to be

Each row below is a different question about whose asset this is, and each is answered in a different part of the platform. The limits sit in the rows, because a boundary declared three sections later is a boundary nobody read.

The estateWhat is observed from outsideWhere it is workedThe job it becomes
Staff, branch and agent credentials Credential and session artefacts attributed to your domains in stealer-log and breach material, assembled per compromised device rather than per row — so the cookies, tokens, autofill data and access paths that came off one machine arrive together. Where it is safe and authorised, each credential is probed and carries an explicit state, so a stale password is separable from a session that still opens something. Dark Web Monitoring Responding to leaked credentials
Scale here is structural, not incidental. A retail institution’s identity population is not its headcount: it is headcount plus the branch network, plus business correspondents and direct selling agents, plus the outsourced collections, verification and contact-centre staff who hold a login on your systems without ever appearing on your payroll. Those identities are compromised on machines you do not manage and cannot instrument, which is the whole reason the finding has to arrive from outside rather than from an endpoint agent.
Retail-customer impersonation Cloned net-banking and payment pages, mobile applications republished into third-party and side-load markets, support desks opened on messaging platforms in your name, and profiles carrying named executives — matched against your registered marks, your real properties and your own site copy rather than against your brand name as a keyword. Brand Protection Removal, filed on your authorisation
Disposition is harder in this sector than in almost any other, because the legitimately authorised population is enormous and looks identical from outside. A business correspondent’s local page, a bancassurance partner’s microsite and an outright impersonation carry the same signals; the difference is contractual, and no external signal reveals it. Matches therefore arrive attributed against your own agent and partner register where you have supplied one, and as an explicit question where you have not — rather than as a guess counted as a detection.
Processors, partners and the providers underneath them The external estate of the processors, switches, KYC and verification providers, collections agencies and fintech partners you nominate — scored with the identical categories, maths and bands applied to your own estate — together with the hosting, DNS, mail, certificate and authentication providers each one actually resolves to. Third-Party Risk Management Onboarding a vendor without waiting on a questionnaire
Concentration is the finding this sector gets that others largely do not, and it is only visible across a portfolio rather than one supplier at a time. A shared upstream that several critical suppliers depend on becomes a counted fact with a date on it — including the providers you hold no contract with and therefore have no standing to question. Vendor-side findings arrive observed and untested: authorisation over another firm’s systems is not yours to give, and every finding says which mode it is in.
Subsidiaries, and the estate nobody registered Every hostname answering from the public internet across the apex domains of the group — the lending, asset-management, broking and insurance arms — plus the co-branded and white-label properties that carry your name on somebody else’s domain, and the acquired estates still running on the naming conventions of the firm they were bought from. Attack Surface Management Seeing every subsidiary from one place
A financial group is rarely one supervised entity. It is several, often under different regulators, frequently with their own technology function and their own procurement — which is how a campaign microsite for a product retired four years ago stays online, on a domain nobody at the centre has ever seen, still carrying a login form.

Staff, branch and agent credentials

What is observed from outside
Credential and session artefacts attributed to your domains in stealer-log and breach material, assembled per compromised device rather than per row — so the cookies, tokens, autofill data and access paths that came off one machine arrive together. Where it is safe and authorised, each credential is probed and carries an explicit state, so a stale password is separable from a session that still opens something.
Where it is worked
Dark Web Monitoring

Scale here is structural, not incidental. A retail institution’s identity population is not its headcount: it is headcount plus the branch network, plus business correspondents and direct selling agents, plus the outsourced collections, verification and contact-centre staff who hold a login on your systems without ever appearing on your payroll. Those identities are compromised on machines you do not manage and cannot instrument, which is the whole reason the finding has to arrive from outside rather than from an endpoint agent.

Retail-customer impersonation

What is observed from outside
Cloned net-banking and payment pages, mobile applications republished into third-party and side-load markets, support desks opened on messaging platforms in your name, and profiles carrying named executives — matched against your registered marks, your real properties and your own site copy rather than against your brand name as a keyword.
Where it is worked
Brand Protection

Disposition is harder in this sector than in almost any other, because the legitimately authorised population is enormous and looks identical from outside. A business correspondent’s local page, a bancassurance partner’s microsite and an outright impersonation carry the same signals; the difference is contractual, and no external signal reveals it. Matches therefore arrive attributed against your own agent and partner register where you have supplied one, and as an explicit question where you have not — rather than as a guess counted as a detection.

Processors, partners and the providers underneath them

What is observed from outside
The external estate of the processors, switches, KYC and verification providers, collections agencies and fintech partners you nominate — scored with the identical categories, maths and bands applied to your own estate — together with the hosting, DNS, mail, certificate and authentication providers each one actually resolves to.
Where it is worked
Third-Party Risk Management

Concentration is the finding this sector gets that others largely do not, and it is only visible across a portfolio rather than one supplier at a time. A shared upstream that several critical suppliers depend on becomes a counted fact with a date on it — including the providers you hold no contract with and therefore have no standing to question. Vendor-side findings arrive observed and untested: authorisation over another firm’s systems is not yours to give, and every finding says which mode it is in.

Subsidiaries, and the estate nobody registered

What is observed from outside
Every hostname answering from the public internet across the apex domains of the group — the lending, asset-management, broking and insurance arms — plus the co-branded and white-label properties that carry your name on somebody else’s domain, and the acquired estates still running on the naming conventions of the firm they were bought from.
Where it is worked
Attack Surface Management

A financial group is rarely one supervised entity. It is several, often under different regulators, frequently with their own technology function and their own procurement — which is how a campaign microsite for a product retired four years ago stays online, on a domain nobody at the centre has ever seen, still carrying a login form.

One event, three readers

In this sector a finding is read three times before anyone acts on it

Security operations, the compliance function and the risk committee are looking at the same confirmed credential and asking three different questions of it. A platform that answers only the first one has created work for the other two.

Worked example

A credential on a payments operations account comes back Confirmed Working

What security operations needs from it
The device case rather than the row: which machine was compromised, what else came off it — session cookies, an OAuth refresh token, autofill data, the internal tools the browser history shows it reached — and which access path this particular credential opens. The action is a rotation today and a check for session persistence, and the queue is ordered by which credentials still authenticate rather than by how many exist.
What the compliance function needs from the same event
Not the credential. The record around it: the date the source material entered the corpus, the date it was detected and attributed, the scope the run covered and the exclusions that bounded it, who dispositioned it and when, and whether it was handled inside the timeframe your own policy commits to — with the misses in the record rather than filtered out of it. A control that exists and a control that operated are different things, and only one of them leaves a trail an examiner can reproduce.
What the risk committee is actually asking
Whether this is one account or a pattern. Whether the same exposure sits in the agent network, in the subsidiary that runs its own technology function, and at the processors handling your card traffic. That question is not answerable from an incident record at all; it is answerable from a portfolio view that has been running long enough to show a direction of travel, which is why the reporting line and the response line are fed by the same monitoring rather than assembled separately.

Regulatory monitoring

What the dated record carries, authority by authority

Indian supervisory language groups this sector as BFSI, and the depth here is real: RBI, SEBI, IRDAI and NPCI each publish specific expectations about what is watched, reported and evidenced. ShadowMap tracks what each authority publishes and produces the monitoring record underneath it. What it will not do is tell you whether an instrument binds your entity — that is a legal determination, and it belongs to your compliance function and your advisers.

AuthorityWhat is trackedWhere the dated evidence sits
RBI Master directions, master circulars and notifications covering IT governance, information security and cyber resilience, outsourcing of IT services, digital lending and incident reporting — read from the several sources RBI publishes them on, in priority order, so one broken listing page does not silence the authority. Attack Surface Management
What ShadowMap produces here is the external half: the group’s internet-facing estate resolved from its apex domains outward and attributed to the entity that owns it, with the date each asset entered scope and the date any asset left it. Whether that satisfies a particular clause is a determination for your assessor and your compliance function, and the row at the foot of this table says where that work is properly done.
SEBI The Cybersecurity and Cyber Resilience Framework and its amendments, tracked as it changes rather than as it stood when somebody last read it. SEBI’s circulars, guidelines, regulations and enforcement orders are read separately, because the cyber-resilience material does not reliably appear in any one of them. Continuous Automated Red-Teaming
Every validation probe is recorded with its evidence, its timestamp, the scope profile that bounded it and an audit identifier, so activity against your estate reconciles against your own logs rather than arriving as an unexplained spike. Validation runs where it is safe and authorised, and the named exclusions and rate limits that bounded a run are part of the same record — so what was not tested is written down beside what was.
IRDAI Information and cyber-security guidelines for insurers and intermediaries, and the material covering outsourced and intermediated distribution — which is to say, the estate an insurer is answerable for but does not operate. Third-Party Risk Management
Insurance distribution is the clearest case of an estate carrying your name from outside your change control: corporate agents, brokers, web aggregators and bancassurance partners, each running their own properties and each holding customer data. They are assessed with the same method used on your own estate, and they arrive observed rather than tested: an insurer cannot grant permission over an intermediary’s own servers, and we do not proceed as though it had.
NPCI Circulars and operating guidelines for the payment systems it runs, and the advisories issued to participants — the layer at which an impersonation aimed at a retail customer stops being a marketing problem and becomes a payments one. Brand Protection
A cloned payment page or a republished mobile application is a customer-facing exposure that no internal control can see, because none of it is running on anything you own. Confirmed cases arrive with the evidence pack already assembled and you authorise the filing; nothing is dispatched without that attestation. Takedowns are unlimited, subject to the fair-use boundary stated in your contract.
Beyond India The same registry carries MAS and the CSA in Singapore, DORA with the EBA and ECB at EU level, the FCA, PRA and NCSC in the United Kingdom, APRA in Australia, the CBUAE and DFSA in the Emirates, the SEC, OCC and FFIEC in the United States, and the PCI Security Standards Council globally. Regulatory Intelligence
Depth in India is evidence of how the capability was built, not the edge of where it runs. A group supervised in Mumbai is frequently also supervised in Singapore, London or Dubai, and items are scoped against the authorities, entity types, industries and geographies you configure — Scheduled Commercial Bank or NBFC under RBI, Stock Broker or Registrar and Transfer Agent under SEBI, Major Payment Institution under MAS.
Assessment Deliberately not this. Reading a finding against a clause, testing whether the control behind it works, and signing the opinion a supervisor eventually asks for are consulting work rather than a monitoring output — and treating the two as interchangeable is the most expensive kind of overclaim in this sector. Security Brigade
Same firm, different work — ShadowMap is Security Brigade’s product, and the assessment practice is the older half of the business. ShadowMap produces the dated evidence; the practice does the interpretation, the testing and the report a regulator will read. Where you need both they compose cleanly, and where you only need one we would rather say which.

RBI

What is tracked
Master directions, master circulars and notifications covering IT governance, information security and cyber resilience, outsourcing of IT services, digital lending and incident reporting — read from the several sources RBI publishes them on, in priority order, so one broken listing page does not silence the authority.
Where the dated evidence sits
Attack Surface Management

What ShadowMap produces here is the external half: the group’s internet-facing estate resolved from its apex domains outward and attributed to the entity that owns it, with the date each asset entered scope and the date any asset left it. Whether that satisfies a particular clause is a determination for your assessor and your compliance function, and the row at the foot of this table says where that work is properly done.

SEBI

What is tracked
The Cybersecurity and Cyber Resilience Framework and its amendments, tracked as it changes rather than as it stood when somebody last read it. SEBI’s circulars, guidelines, regulations and enforcement orders are read separately, because the cyber-resilience material does not reliably appear in any one of them.
Where the dated evidence sits
Continuous Automated Red-Teaming

Every validation probe is recorded with its evidence, its timestamp, the scope profile that bounded it and an audit identifier, so activity against your estate reconciles against your own logs rather than arriving as an unexplained spike. Validation runs where it is safe and authorised, and the named exclusions and rate limits that bounded a run are part of the same record — so what was not tested is written down beside what was.

IRDAI

What is tracked
Information and cyber-security guidelines for insurers and intermediaries, and the material covering outsourced and intermediated distribution — which is to say, the estate an insurer is answerable for but does not operate.
Where the dated evidence sits
Third-Party Risk Management

Insurance distribution is the clearest case of an estate carrying your name from outside your change control: corporate agents, brokers, web aggregators and bancassurance partners, each running their own properties and each holding customer data. They are assessed with the same method used on your own estate, and they arrive observed rather than tested: an insurer cannot grant permission over an intermediary’s own servers, and we do not proceed as though it had.

NPCI

What is tracked
Circulars and operating guidelines for the payment systems it runs, and the advisories issued to participants — the layer at which an impersonation aimed at a retail customer stops being a marketing problem and becomes a payments one.
Where the dated evidence sits
Brand Protection

A cloned payment page or a republished mobile application is a customer-facing exposure that no internal control can see, because none of it is running on anything you own. Confirmed cases arrive with the evidence pack already assembled and you authorise the filing; nothing is dispatched without that attestation. Takedowns are unlimited, subject to the fair-use boundary stated in your contract.

Beyond India

What is tracked
The same registry carries MAS and the CSA in Singapore, DORA with the EBA and ECB at EU level, the FCA, PRA and NCSC in the United Kingdom, APRA in Australia, the CBUAE and DFSA in the Emirates, the SEC, OCC and FFIEC in the United States, and the PCI Security Standards Council globally.
Where the dated evidence sits
Regulatory Intelligence

Depth in India is evidence of how the capability was built, not the edge of where it runs. A group supervised in Mumbai is frequently also supervised in Singapore, London or Dubai, and items are scoped against the authorities, entity types, industries and geographies you configure — Scheduled Commercial Bank or NBFC under RBI, Stock Broker or Registrar and Transfer Agent under SEBI, Major Payment Institution under MAS.

Assessment

What is tracked
Deliberately not this. Reading a finding against a clause, testing whether the control behind it works, and signing the opinion a supervisor eventually asks for are consulting work rather than a monitoring output — and treating the two as interchangeable is the most expensive kind of overclaim in this sector.
Where the dated evidence sits
Security Brigade

Same firm, different work — ShadowMap is Security Brigade’s product, and the assessment practice is the older half of the business. ShadowMap produces the dated evidence; the practice does the interpretation, the testing and the report a regulator will read. Where you need both they compose cleanly, and where you only need one we would rather say which.

Attribution order

A financial group cannot be scoped alphabetically

Each step below is only answerable once the one above it is, which is why the order is load-bearing rather than presentational. Concentration risk arrives last because it is not visible until everything above it has been attributed.

Most used in this sector

Where banking and financial services programmes start

Attack Surface Management

Continuous outside-in discovery of the internet-facing estate — including the origin infrastructure sitting behind your edge.

Dark Web Monitoring

A proprietary stealer-log collection with permanent raw-source retention, so improved extraction improves your history as well as your present.

Brand Protection

Impersonation detection across domains, social platforms, app stores and executive identity — ending in removal, not an alert.

Domain Monitoring

Look-alike, typosquatted and permutation domains detected at registration, scored for intent, and routed for removal.

Phishing and Domain Takedown

Orchestrated removal across registrars, hosts, platforms and app stores, with every lifecycle state published — including the ones that fail.

Continuous Automated Red-Teaming

Where it is safe and authorised, exposure is tested rather than asserted — and the evidence, the scope and the audit identifier are handed to you.

AI Review

Four published verdicts, two separate score fields, a queue nothing is ever deleted from — and a published list of where we deliberately did not use AI.

Third-Party Risk Management

The same outside-in methodology applied to your vendors, with the identical categories, maths and bands used on your own estate.

Threat Intelligence

Actor, malware, CVE and indicator data correlated against the technology actually discovered on your estate — which is the only thing that makes it relevant.

Security Ratings

A rating is an output, never the product. The findings underneath it are what you act on.

Regulatory Intelligence

Advisory and directive tracking across 31 regulators in 12 jurisdictions, as programme context — never as legal advice.

Questions buyers actually ask

Before you evaluate this

We run a SOC and we are audited by a CERT-In empanelled auditor. Where does this sit?

Between them, and it is the gap both are structurally bad at covering. A SOC watches what is instrumented — your network, your endpoints, your logs — and by definition sees nothing on a customer’s device, an agent’s laptop or a processor’s estate. An audit is excellent and it is a point in time: it tells you what was true in the week the assessor was in the building. This is the continuous outside-in layer in between, running against the estate neither one reaches, and producing a dated record of what was examined and when. It does not replace either. Our own assessment practice is Security Brigade, so if what you actually need is the audit rather than the monitoring, we will say so.

Can it tell us whether we are compliant with a particular circular or framework?

No, and the refusal is deliberate rather than a limitation we are working on. What it does is narrow the question a long way: you configure the authorities you are supervised by, your entity types, industries and geographies, and each item carries what the instrument obliges, the entity types it names, whether it is binding or advisory, and the earliest date the document itself commits you to. A deadline that cannot be pointed at in the text is discarded rather than estimated. Converting that into a determination that an instrument binds your entity is a legal question about your registration and your permissions, and mapping a published item to a clause in your own control framework is assessment work. Both belong with your compliance function, your advisers and — if you want it done properly rather than approximately — the practice at securitybrigade.com.

Most of our exposure is on customers and agents we do not control. What can you actually do about it?

Three things, and one honest limit. We observe it, because everything described on this page is visible from outside without anybody’s cooperation. We attribute it, which in this sector is the hard half: your own agent, partner and subsidiary registers are inputs, so an authorised distributor is suppressed and stays suppressed rather than resurfacing every month as a fresh candidate. And we remove what has a removal route — the responsible platform, store, registrar or host is resolved into an order and the notice is filed with the evidence pack attached, on your authorisation. The limit: only what is publicly visible is detectable. An operation living entirely inside a closed group or in direct messages leaves no public artefact to match, and some side-load markets have no removal route at all. Where that is the case the finding still reaches you with the distribution URL and the evidence, because your legal team may have a route we do not.

See the exposure your own controls cannot reach

One apex domain, two business days, a written snapshot — what is answering from outside, which credentials are attributed to you, and who is trading on your name. No call required.