Resources
The things we wish someone had given us.
Checklists, evidence registers, estimators and report samples, all built out of real engagements. If a thing is not useful on its own, it is not here.
Start here
Three routes in, depending on what is actually in front of you.
- Compliance frameworksISO 27001, SOC 2, PCI DSS, ISO 42001 and the rest. What each one asks for, what it costs, and how long it really takes.Compliance and certification
- Security testing and VAPTHow testing is scoped, what a good report looks like, and how to tell a real penetration test from a scan with a logo on it.Testing services
- India and regulatory auditsCERT-In directions, the DPDP Act, RBI master directions and the SEBI CSCRF. Who they apply to and what they expect of you.India compliance registry
Free tools
Estimators and checkers that give you a number and show their working. Nothing here holds your result hostage for an email address.
- Compliance effort estimatorAbout 4 minutes
- Compliance cost estimatorAbout 5 minutes
- VAPT and security testing cost estimatorAbout 3 minutes
- DPDP penalty exposure calculatorAbout 4 minutes
- Data breach cost calculatorAbout 5 minutes
- Compliance ROI calculatorAbout 4 minutes
- PCI DSS scope checkerAbout 6 minutes
- DPDP readiness checkerAbout 7 minutes
- ISO 27001 readiness checkerAbout 10 minutes
- Free external security assessmentResults in two working days
Open reference material
Published under CC BY 4.0. Every fact cited, no email gate, and you are free to use it commercially.
- India compliance registrySortable table, with a raw markdown mirror
- CERT-In directions readiness checklistChecklist, 64 items
- DPDP compliance timelineTimeline with a dependency map
- India incident reporting mapDecision map, with a one page printable version
- RBI cyber security audit checklistChecklist, 210 items
- SEBI CSCRF trackerTracker sheet
- AI model inventory templateSpreadsheet template with a filled example
- Vendor security questionnaireQuestionnaire, 82 questions, with a scoring sheet
- Server hardening workbookWorkbook, per platform
- Database hardening workbookWorkbook, per engine
- PCI DSS SAQ eligibility tableReference table
Guides and workbooks
The longer packs. We send these by email so you always get the current version, which is the only reason there is a form.
- checklistPDF
DPDP Act 2023: 150-point implementation checklist
Every obligation in the Digital Personal Data Protection Act, broken into 150 concrete checks with an owner and an evidence type against each.
Get it - registerXLSX and PDF
ISO 27001 evidence register
The evidence an ISO 27001 auditor will actually ask for, mapped control by control, so you stop guessing what to collect.
Get it - samplePDF, redacted
VAPT report sample
A real Threatsys report structure with the client details removed. See exactly what you get before you commission anything.
Get it - checklistPDF
RBI cyber security audit checklist
The RBI cyber security framework translated into an audit-ready checklist for banks, NBFCs, payment operators and fintechs.
Get it - checklistPDF
PCI DSS v4 evidence checklist
What a QSA will ask for at each of the twelve requirements, and the scoping mistakes that make assessments expensive.
Get it - questionnaireXLSX
Vendor security questionnaire
A proportionate supplier questionnaire that gets real answers, tiered by the risk the vendor actually presents.
Get it - researchPDF, English
Decoding the Dark Web: what exists beyond the surface
Threatsys research on dark web marketplaces, credential trade and how Indian organisations appear in leaked data.
Get it
Read and watch
Not sure where to start?
Tell us what is actually driving this. A customer questionnaire you cannot answer, a regulator asking questions, a board that wants a number, or something that has already gone wrong. We will point you at the right two or three things from this page, and if none of them fit we will say so.
Not sure where to start?
Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.












