White papers
Research we did because we needed it.
Published work from the Threatsys team. Written for practitioners, so it assumes you know what a CVE is and gets on with it.
Practical guides and registers
- PDFDPDP Act 2023: 150-point implementation checklistEvery obligation in the Digital Personal Data Protection Act, broken into 150 concrete checks with an owner and an evidence type against each.
- XLSX and PDFISO 27001 evidence registerThe evidence an ISO 27001 auditor will actually ask for, mapped control by control, so you stop guessing what to collect.
- PDF, redactedVAPT report sampleA real Threatsys report structure with the client details removed. See exactly what you get before you commission anything.
- PDFRBI cyber security audit checklistThe RBI cyber security framework translated into an audit-ready checklist for banks, NBFCs, payment operators and fintechs.
- PDFPCI DSS v4 evidence checklistWhat a QSA will ask for at each of the twelve requirements, and the scoping mistakes that make assessments expensive.
- XLSXVendor security questionnaireA proportionate supplier questionnaire that gets real answers, tiered by the risk the vendor actually presents.
Not sure where to start?
Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.












