Skip to main content

The clause that names phishing testing, and exactly what it says

One clause in the SEBI CSCRF names phishing testing. It is on page 87, it sits in the Risk Management guidelines, and "for e.g." are the regulator's own words. What item 1(e) asks for.

By Trupti Dangeti
August 31, 20267 min read

Indian financial-sector regulation writes about employee awareness in general terms: assess it, train for it, keep a record of who has had what. One clause departs from that and names an instrument. It is in the SEBI Cybersecurity and Cyber Resilience Framework, and it is on page 87 of 205 — inside the Risk Management guidelines, not in the awareness-and-training section where a reader would go looking for it.

"REs shall periodically assess level of employee cybersecurity awareness, for e.g., through phishing test success rate, etc."

That is CSCRF Version 1.0, circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 of 20 August 2024, GV.RM Guidelines, "Risk Management", item 1(e), page 87, standards column GV.RM.S3. The applicability line sits in the row heading on page 86 where that guideline block begins: "All REs except small-size, self-certification REs (Mandatory)." Which category an entity falls into is therefore the first question, and it is a classification question rather than a security one.

Three words in the middle of the sentence carry the clause. The obligation is to periodically assess the level of employee cybersecurity awareness. Phishing test success rate is what the regulator reaches for to illustrate how. "For e.g." is SEBI's own phrase, and it survives every quotation of the clause, including this one.

Where the clause sits is part of what it says

GV.RM is governance and risk management. PR.AT, twenty-four pages earlier at page 63, is Protect: Awareness and Training, and it is where the programme obligations live — mandatory awareness programmes, conducted on a periodic basis, extended by items 2 to 5 to privileged users, third parties, senior executives, the Board, and physical and information security personnel.

Item 1(e) is filed with the risk-management guidelines, which is where an organisation records the inputs it uses to understand its own exposure. Read against its neighbours, the measurement of employee awareness is positioned as a risk input rather than as an output of the training function — something the organisation needs a current reading of.

The placement is also why the clause is easy to miss. A reader looking for what SEBI asks about awareness goes to the awareness section, finds the standard on page 63 and the guidelines on pages 103 and 104, and stops there.

What an example carries

A regulator that writes an obligation in general terms and then names one method has done more than fill space. The regulated entity keeps the choice of how to assess. It makes that choice against a document in which one method appears on the face of the text, and in which the unit of the named result is a rate.

Two practical consequences follow for whoever drafts the policy paragraph that answers it.

The first concerns the shape of the answer. "Level of employee cybersecurity awareness" is a level: something with a value, a previous value, and a date attached to each. The named example is a success rate — a proportion computed across a population, rather than an attendance list or a course-completion figure. An assessment that produces a number over a population, repeated on a cycle, is answering the clause in the form the clause is written in.

The second concerns what an assessor can put the answer beside. Where a different method is used, the position to be demonstrated is that it assesses the same thing: awareness level, across employees, periodically, producing a result that can be read against the previous one. That position is entirely arguable. It is simply longer to argue than pointing at the method the circular itself names.

The word in item 1(e) is "periodically". The cadence stated as a number elsewhere in the circular is attached to a different standard — row 9 of the periodic-compliance table reads "Cybersecurity training program (PR.AT.S1) — All REs — Annually", while the PR.AT Standard on page 63 says periodic. When either cadence is cited, say which of the two it comes from. They are consistent with each other, and they are not interchangeable as citations.

The second place SEBI puts a number on awareness

Annexure-K of the same circular carries the Cyber Capability Index: a set of measures, each with a stated goal, a formula, a target and a weighting. Measure 3, on page 166, is the awareness measure, and it is labelled against the same standard as the training programme.

FieldMeasure 3 — "Security Training Measure [PR.AT.S1]"
Goal"Ensure that organization's personnel are adequately trained to carry out their assigned information security-related duties and responsibilities"
Measure"Percentage (%) of information system security personnel that have received security training within the past one year"
FormulaPersonnel who completed security training in the past year, divided by total information system security personnel, multiplied by 100
Target100%
Weighting5%
Evidence"1. Details of the training/awareness sessions scheduled within the past 1 year. 2. Cyber audit observation against Standard 1 mentioned in 'Protect: Awareness and Training' header…"

Applicability here is narrower than for GV.RM item 1(e). Per GV.OV Guidelines item 1 on page 85, the index is subject to third-party assessment for Market Infrastructure Institutions and to self-assessment for Qualified REs.

Two figures in that table do the work. The target is 100%: total coverage, with no tolerance band written into the target itself. The weighting is 5%, which places the awareness measure inside a composite score rather than beside it. An obligation phrased as "periodic" acquires here a numerator, a denominator, a twelve-month window, a stated evidence list and a share of an index — computed by a third party for an MII, and by the entity itself for a Qualified RE.

Two populations, one circular

Measure 3's denominator is the precision most likely to be lost in a summary. It reads "total information system security personnel" — the people with assigned information security duties, as the measure's own goal statement describes them. It is not headcount.

GV.RM Guidelines item 1(e) is scoped differently. It speaks to employee cybersecurity awareness, which is the workforce.

The circular therefore asks for two things, over two populations, evidenced separately: a training-coverage percentage across security personnel within the past year, and a periodic assessment of awareness level across employees. An entity that computes Measure 3 over total headcount has used the wrong denominator. An entity that offers a completed Measure 3 as its answer to item 1(e) has answered a different question — scored, dated, correct, and about a smaller group.

The awareness obligations, in one place

LocationPageWhat it carriesApplies to
§3.2 PR.AT, Standard item 163Mandatory awareness programmes, established and conducted on a periodic basis; items 2–5 extend it to privileged users, third parties, senior executives, the Board and security personnelREs
Periodic-compliance table, row 9"Cybersecurity training program (PR.AT.S1) — All REs — Annually"All REs
PR.AT Guidelines, items 2–4103–104Employees aware of risks including social engineering attacks and phishing; awareness campaigns stressing avoidance of clicking on links and attachments in email; periodic training extended wherever possible to outsourced staff and third-party service providersREs
GV.RM Guidelines, item 1(e) (GV.RM.S3)87"REs shall periodically assess level of employee cybersecurity awareness, for e.g., through phishing test success rate, etc."All REs except small-size, self-certification REs (Mandatory)
Annexure-K, Measure 3 [PR.AT.S1]166Percentage of information system security personnel trained within the past year; target 100%, weighting 5%MIIs and Qualified REs

If phishing testing is the method

Item 1(e) names the instrument. The conduct rules for running one are written elsewhere, by CERT-In, in the Comprehensive Cyber Security Audit Policy Guidelines, CISG-2025-02, Version 1.0, 25 July 2025. §13.2.7(ii), page 50 requires specific written permissions from the auditee organisation before tests involving process testing or social engineering. §15.2.2(iii), pages 55–56 requires that such testing against general staff use anonymised or statistical techniques, "ensuring no individual is personally identified or penalized", with the purpose stated as evaluating overall awareness and the effectiveness of security processes, and the target limited to employee groups explicitly inside the agreed audit scope.

The two instruments fit together more neatly than their separate origins suggest. The output SEBI names is a rate, which is a population statistic. That is the form CERT-In's clause requires the output of such a test to take. A phishing test run to the CERT-In conduct rules produces the artefact the SEBI clause asks to see.

What to hold

For a regulated entity inside the item 1(e) applicability line, the record that answers the clause is short and specific: the assessment method, the population it covered, the date it ran, the result, and the previous result it can be read against. Periodic means there is more than one, and a single baseline is the start of the record rather than the whole of it.

For MIIs and Qualified REs, add what Annexure-K names as evidence for Measure 3: details of the training and awareness sessions scheduled within the past year, and the cyber audit observation against Standard 1 under the Protect: Awareness and Training header. Compute it over information system security personnel.

And when item 1(e) is quoted — in a policy document, in a board note, in a request for proposal — quote it whole. The obligation is to assess employee awareness periodically. The phishing test is the example SEBI itself chose to name, which is a strong reason to run one and a poor reason to describe it as anything other than what page 87 says it is.

About the author

Trupti Dangeti

Head — Finance & Operations

Manages financial operations and HR functions at Security Brigade, ensuring the firm's operational backbone supports its growing team and client base.