| RBI | Master directions, master circulars and notifications covering IT governance, information security and cyber resilience, outsourcing of IT services, digital lending and incident reporting — read from the several sources RBI publishes them on, in priority order, so one broken listing page does not silence the authority. | Attack Surface Management |
| What ShadowMap produces here is the external half: the group’s internet-facing estate resolved from its apex domains outward and attributed to the entity that owns it, with the date each asset entered scope and the date any asset left it. Whether that satisfies a particular clause is a determination for your assessor and your compliance function, and the row at the foot of this table says where that work is properly done. |
| SEBI | The Cybersecurity and Cyber Resilience Framework and its amendments, tracked as it changes rather than as it stood when somebody last read it. SEBI’s circulars, guidelines, regulations and enforcement orders are read separately, because the cyber-resilience material does not reliably appear in any one of them. | Continuous Automated Red-Teaming |
| Every validation probe is recorded with its evidence, its timestamp, the scope profile that bounded it and an audit identifier, so activity against your estate reconciles against your own logs rather than arriving as an unexplained spike. Validation runs where it is safe and authorised, and the named exclusions and rate limits that bounded a run are part of the same record — so what was not tested is written down beside what was. |
| IRDAI | Information and cyber-security guidelines for insurers and intermediaries, and the material covering outsourced and intermediated distribution — which is to say, the estate an insurer is answerable for but does not operate. | Third-Party Risk Management |
| Insurance distribution is the clearest case of an estate carrying your name from outside your change control: corporate agents, brokers, web aggregators and bancassurance partners, each running their own properties and each holding customer data. They are assessed with the same method used on your own estate, and they arrive observed rather than tested: an insurer cannot grant permission over an intermediary’s own servers, and we do not proceed as though it had. |
| NPCI | Circulars and operating guidelines for the payment systems it runs, and the advisories issued to participants — the layer at which an impersonation aimed at a retail customer stops being a marketing problem and becomes a payments one. | Brand Protection |
| A cloned payment page or a republished mobile application is a customer-facing exposure that no internal control can see, because none of it is running on anything you own. Confirmed cases arrive with the evidence pack already assembled and you authorise the filing; nothing is dispatched without that attestation. Takedowns are unlimited, subject to the fair-use boundary stated in your contract. |
| Beyond India | The same registry carries MAS and the CSA in Singapore, DORA with the EBA and ECB at EU level, the FCA, PRA and NCSC in the United Kingdom, APRA in Australia, the CBUAE and DFSA in the Emirates, the SEC, OCC and FFIEC in the United States, and the PCI Security Standards Council globally. | Regulatory Intelligence |
| Depth in India is evidence of how the capability was built, not the edge of where it runs. A group supervised in Mumbai is frequently also supervised in Singapore, London or Dubai, and items are scoped against the authorities, entity types, industries and geographies you configure — Scheduled Commercial Bank or NBFC under RBI, Stock Broker or Registrar and Transfer Agent under SEBI, Major Payment Institution under MAS. |
| Assessment | Deliberately not this. Reading a finding against a clause, testing whether the control behind it works, and signing the opinion a supervisor eventually asks for are consulting work rather than a monitoring output — and treating the two as interchangeable is the most expensive kind of overclaim in this sector. | Security Brigade |
| Same firm, different work — ShadowMap is Security Brigade’s product, and the assessment practice is the older half of the business. ShadowMap produces the dated evidence; the practice does the interpretation, the testing and the report a regulator will read. Where you need both they compose cleanly, and where you only need one we would rather say which. |