Open resources
Take it, change it, ship it.
Security in India improves when the baseline material is free. These resources are published under Creative Commons Attribution 4.0: use them commercially, adapt them, build on them. Just credit Threatsys.
CC BY 4.0
- Share: copy and redistribute in any medium
- Adapt: remix, transform and build upon
- Commercial use permitted
- Attribution to Threatsys required
Suggested credit: “Adapted from Threatsys (threatsys.ai), licensed CC BY 4.0.”
The open library
Eleven reference artifacts, every fact traced to a published source. No email gate on any of them. What stays ours is the report templates and the assessment methodology, not the reference material a security team needs to do its job.
Showing 11 of 11
- CC BY 4.0Sortable table, with a raw markdown mirror
India compliance registry
Every cyber security obligation an Indian organisation can be held to, in one table, with the regulator and the trigger against each.
Open it - CC BY 4.0Checklist, 64 items
CERT-In directions readiness checklist
The April 2022 directions turned into checks you can actually run, including the log retention and clock sync duties people miss.
Open it - CC BY 4.0Timeline with a dependency map
DPDP compliance timeline
What the DPDP Act asks for, in the order you have to do it, with the dependencies that decide what you can start today.
Open it - CC BY 4.0Decision map, with a one page printable version
India incident reporting map
One incident can trigger four different reporting duties on four different clocks. This shows you all of them on one page.
Open it - CC BY 4.0Checklist, 210 items
RBI cyber security audit checklist
The controls an RBI supervisory review actually asks about, in the order the inspection tends to move through them.
Open it - CC BY 4.0Tracker sheet
SEBI CSCRF tracker
The Cyber Security and Cyber Resilience Framework broken down by entity type, so you only read the parts that apply to you.
Open it - CC BY 4.0Spreadsheet template with a filled example
AI model inventory template
A register for the AI systems in your organisation, built to satisfy ISO 42001 and to answer the DPDP question about automated processing.
Open it - CC BY 4.0Questionnaire, 82 questions, with a scoring sheet
Vendor security questionnaire
A questionnaire short enough that vendors actually finish it, and pointed enough that the answers tell you something.
Open it - CC BY 4.0Workbook, per platform
Server hardening workbook
Hardening steps for Linux and Windows servers, each with the check command and the evidence an auditor will want.
Open it - CC BY 4.0Workbook, per engine
Database hardening workbook
The same treatment for databases, covering the encryption and audit logging questions that come up in every assessment.
Open it - CC BY 4.0Reference table
PCI DSS SAQ eligibility table
Which self assessment questionnaire you qualify for, laid out by payment channel, with the disqualifiers called out.
Open it
The gated packs, for completeness
A few of the larger workbooks are sent by email rather than posted openly, purely because they are big and we like to send the current version. Same licence, one extra step.
- DPDP Act 2023: 150-point implementation checklist
- ISO 27001 evidence register
- RBI cyber security audit checklist
- PCI DSS v4 evidence checklist
- Vendor security questionnaire
- Decoding the Dark Web: what exists beyond the surface
Using these in your own product?
That is allowed and encouraged. If you are embedding them in a commercial platform we would like to know, mostly because we are curious what you built. There is no obligation to tell us.
Not sure where to start?
Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.












