Scoping a phishing simulation programme in India
What has to be decided before the first send: the population and its cohorts, the scope boundary, the cadence, the channels, the exclusions, the escalation contacts and the written authorisation CERT-In requires.
What has to be settled before a phishing simulation programme starts, and in what order? The population and its cohorts, the scope boundary around them, the cadence, the channels, the exclusions and stop conditions, and the escalation contacts. All six land in one document, signed before anything is sent, because CERT-In's audit policy guidelines require it.
Specific written permissions must be obtained from the auditee organization before conducting tests that involve survivability failures, denial-of-service (DoS), process testing, or social engineering.
CISG-2025-02, Version 1.0, 25 July 2025, §13.2.7(ii), p. 50. The order below is the order the decisions fall in: each narrows the next, and the authorisation is written last.
Population and cohorts
Start from named groups with counts, not a headline employee number. A programme scoped as "all staff" produces one figure a year and nothing to read a trend from. Named groups produce a result per group, and the groups are what the clause is written about.
The RBI Directions, 2026, issued 31 July 2026, name the cohorts. For commercial banks, ¶203 makes cybersecurity awareness programmes "mandatory for all new recruits" and annual training the rule "for lower and middle management"; ¶204 adds "annual training to all Board members and Senior Management". Urban co-operative banks under ¶156 carry new recruits plus "web-based quiz and training for lower, middle, and upper management every year" — upper management is named there, and ¶156 sits in Section H, in Chapter V, binding Level III and Level IV UCBs. Cohorts drawn on those lines produce evidence that maps to the paragraph.
Then size them. §15.2.2(iii), pp. 55–56, requires that testing aimed at general staff "must utilize anonymized or statistical techniques—ensuring no individual is personally identified or penalized". A percentage over a cohort of four is an individual result wearing a percentage sign. Set a minimum reporting cohort size and roll smaller teams into their parent function. Where a small population must be measured in its own right, as the executive cohort usually must, agree that it is reported as a count within the cohort.
The scope boundary
The same clause fixes the outer edge. These tests "must only target group of employees explicitly included within the agreed audit scope", and "must not involve external entities such as customers, business partners, vendors, or other third parties, unless specific written consent is obtained from the target organization".
The hard case is the people who sit at your desks and are paid through someone else's contract: contractors, managed service staff, an outsourced service desk, a BPO handling your customers. They read your mail and hold your credentials. Whether a group sits inside the employee population or arrives through a vendor is a question the scope document answers group by group, and where it is the latter the clause points at specific written consent. Settle it with the sourcing contract open, not in week three of the window.
Cadence comes from the clause
Cadence is read off the instrument binding the entity, and it is what turns a set of exercises into a series. One round produces a number. Only a series has a direction, and a schedule that drifts produces rounds that cannot be set against each other.
| Entity or framework | Clause | What it sets |
|---|---|---|
| Commercial banks | ¶202, ¶203, ¶204, pp. 47–48 | "evaluate the awareness level of employees periodically", with the recruit, management and Board cohorts set out above |
| Payments banks; small finance banks | ¶201 | "evaluate the awareness level of employees periodically" |
| Credit information companies | ¶197 | "The CIC shall … evaluate the awareness level of employees periodically" |
| Urban co-operative banks | ¶156, Section H, Chapter V — Level III and Level IV | new recruits, plus the management cohorts to upper management, "every year" |
| NBFCs | ¶35–36, p. 19 | a "formal mechanism to measure and track the effectiveness of such training through periodic assessments or testing", and an "up-to-date repository of the training and awareness status of all users" |
| SEBI CSCRF v1.0 | §3.2 PR.AT, p. 63; periodic-compliance table, row 9 | the Standard: programmes "shall be conducted on a periodic basis"; the table: "Cybersecurity training program (PR.AT.S1) — All REs — Annually" |
Both readings sit in the same circular, so record which one the cadence answers. One clause names the method: GV.RM Guidelines item 1(e), p. 87, standards column GV.RM.S3, applicability "All REs except small-size, self-certification REs (Mandatory)" — "REs shall periodically assess level of employee cybersecurity awareness, for e.g., through phishing test success rate, etc." The words "for e.g." are the regulator's and belong in the scoping note.
Channels
Email is the baseline and, for most programmes, the whole of round one. It reaches the entire population, and it is the channel SEBI's guidelines describe in calling for campaigns that "stress the avoidance of clicking on links and attachments in email" (PR.AT Guidelines, pp. 103–104).
Vishing is scoped separately, only where the authorisation covers it, and as a test of a process rather than of a person. The engagement types at §6, pp. 14–17, are given as "including, but not limited to", and this work sits under (x) Process Security Testing and (xvi) Red Team Assessment. What a vishing call answers is whether the service desk's caller-verification procedure survives contact: were the documented steps followed, and do they produce a safe outcome? Name the procedure and its version in the scope document and the result is a finding against a control. Left unnamed, it is an anecdote about one person on one afternoon.
Exclusions, stop conditions and escalation contacts
Exclusions are recorded when they are agreed, with the reason. Groups come out of a round for sound reasons: a treasury desk in a settlement window, a function mid-migration, a team already in a disciplinary process. An exclusion carrying no recorded reason is indistinguishable, a year on, from a population the programme quietly stopped measuring. That is what an auditor comparing two rounds sees.
Write at least one stop condition and name who may invoke it. The standard one is collision with a real incident: if a genuine phishing campaign or a live security incident is running against the organisation, the simulation pauses, because a simulated message landing mid-event contaminates the response. Decide in advance who makes that call on each side, what a pause means for sends in flight, and whether the round resumes or is rerun.
Escalation contacts are named people, not role mailboxes, reachable through the execution window, out of hours included: the security contact who can confirm within minutes that a reported message is ours, the service desk owner whose queue fills, the HR partner who takes the first complaint, and the signatory. A list that routes into a ticket queue does not function at the hour it is needed.
The written authorisation
§13.2.7(ii) puts the permission before the test, which makes the authorisation the document every decision above is written into, signed by someone with the authority to give it. The checklist below is its contents page.
The data terms belong in it too
Signed before anything is collected, it is the natural home for the questions about the click dataset. The Digital Personal Data Protection Act, 2023 (Act 22 of 2023) supplies the ground: s.4(1) permits processing on consent or on a legitimate use, and s.7(i) covers processing "for the purposes of employment or those related to safeguarding the employer from loss or liability". Record which ground is relied on. s.8(5) requires reasonable security safeguards, so name where identified per-recipient data sits and who can reach it. s.8(7)(a) requires erasure "as soon as it is reasonable to assume that the specified purpose is no longer being served", so name the point at which the identified dataset is destroyed and the aggregate retained. That date is easier to fix at commissioning than once the data exists.
Pretext boundaries
Rule themes out in advance rather than adjudicating a complaint after the fact. The categories that generate complaints are predictable: pay, bonus and salary revision; medical and benefits claims; redundancy, restructuring and role change; bereavement and family emergency; and any pretext impersonating a named individual inside the organisation. The list has to be written, agreed by the people who will field the reaction, and attached to the authorisation.
Band the pretext difficulty in the same document. A generic lure sent to a broad list is not the same test as one built on an internal process and addressed by name, and it will not return a comparable number. Record the band for each round, so round two can be read against round one on the basis it was designed for.
Before the first send
Ten things should exist in writing, signed, before a single message leaves:
- The population, by named cohort with counts, and the reporting floor for rolling small cohorts up.
- The scope boundary, with each third-party group inside it under specific written consent, or outside it.
- The cadence, and the clause and paragraph it answers.
- The authorised channels, and for vishing the procedure and version under test.
- Every exclusion, with its reason and the date agreed.
- The stop conditions, and who may invoke them on each side.
- The escalation contacts, named and reachable through the window.
- The ruled-out pretext themes and the difficulty band for the round.
- The data terms: the ground relied on, where identified data sits, and when it is erased.
- The §13.2.7(ii) authorisation itself, signed and dated.
A programme holding those ten before round one can answer an auditor out of the documents it ran on. Assembling them afterwards produces the paperwork and the result at the same time, and the two will not agree.
About the author
Parnika Kelkar
Head — People & Culture
Senior HR generalist partnering with leadership to drive talent acquisition, policy design, compliance, and an engaging workplace culture at Security Brigade.
Continue reading
All articles →Spear phishing versus bulk simulation: what changes in the test and in the numbers
A spear campaign and a bulk campaign measure different things over different populations. Why their rates cannot share a trend line, and how a six-person cohort is reported when a percentage would identify people.
Measuring the executive population
RBI ¶204 addresses the Board and Senior Management separately, and CERT-In's reporting rule makes a percentage over twelve people an individual result. What an executive exercise reports instead.
Testing the service desk: vishing as a process control test
A vishing test against the service desk measures a procedure, not a person. What CERT-In's CISG-2025-02 requires before the call, and what the finding should say afterwards.