| European Union | DORA, EBA, ECB, ENISA, EDPB | DORA Article 24(6) requires every financial entity other than a microenterprise to ensure, at least yearly, that appropriate tests are conducted on all ICT systems and applications supporting critical or important functions. Article 25(1) sets out the techniques those tests may draw on as a non-exhaustive list, applied proportionately. Article 28(3) requires a maintained register of information covering all contractual arrangements for the use of ICT services provided by third parties. | Third-Party Risk Management |
| Article 24(4) puts the testing programme in the hands of "independent parties, whether internal or external", and a continuous outside-in record is one input to that programme rather than the programme itself. Where this monitoring bears most directly is the third-party half: the Article 28(3) register is a list of arrangements, and what a list of arrangements does not carry is what each of those providers currently looks like from the internet. That is assessed with the identical categories, maths and bands applied to your own estate, dated per run. |
| United Kingdom | FCA, PRA, ICO, NCSC | The FCA and PRA operational-resilience regime requires a firm to identify its important business services, set an impact tolerance for each, map the people, processes, technology, facilities and information those services depend on, and scenario-test its ability to remain within tolerance through severe but plausible disruption. Under the UK GDPR a personal data breach must be notified to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to individuals’ rights and freedoms. | Dark Web Monitoring |
| Read the operational-resilience rules for what they say rather than for what a vendor page says they say: they are about important business services, impact tolerances and mapping, and the mapping obligation reaches the third parties a service depends on. The 72-hour clock is what this monitoring most directly serves — a credential set attributed to your domains, dated when the source material entered the corpus and dated again when it was detected, is the artefact that establishes when awareness began. |
| United States | SEC, OCC, FFIEC, FTC, NIST | A registrant must file a Form 8-K under Item 1.05 describing a material cybersecurity incident within four business days of determining that it is material, and must describe in its annual report, under Regulation S-K Item 106(b), its processes for assessing, identifying and managing material risks from cybersecurity threats — expressly including whether it engages assessors, consultants, auditors or other third parties, and whether it has processes to oversee risks from third-party service providers. | Attack Surface Management |
| Item 106(b) is a disclosure obligation rather than a testing one, and that is exactly why it belongs in this table: it requires a registrant to describe a programme, in writing, in a filing, once a year, and to say who outside the firm is engaged in it. A monitoring record that states what was examined, when, what was found, and what was deliberately excluded is describable in those terms. A questionnaire returned by a supplier is not. |
| Singapore | MAS, CSA | The MAS Technology Risk Management Guidelines set the supervisory expectation that penetration testing is conducted at least once annually on systems directly accessible from the internet, or whenever those systems undergo major change, alongside vulnerability assessment and adversarial attack simulation. MAS’s binding cyber-hygiene notice addresses administrative accounts, security patching, security standards, network perimeter defence, malware protection and multi-factor authentication. | Continuous Automated Red-Teaming |
| The difference between the two matters and a good deal of published material blurs it: the Technology Risk Management Guidelines are guidelines that MAS supervises against, and the cyber-hygiene notice is a notice. What ShadowMap contributes against an annual testing expectation is the continuous half — dated validation records in the months between tests, run where it is safe and authorised, never the test itself. Entity types configurable against MAS include Full Bank, Wholesale Bank, Licensed Insurer, Capital Markets Services Licensee and Major Payment Institution, so an item scopes to the licence you hold rather than to the sector. |
| Australia | APRA, ACSC | APRA Prudential Standard CPS 234 paragraph 27 requires an APRA-regulated entity to test the effectiveness of its information security controls through a systematic testing programme, at a nature and frequency commensurate with the rate at which vulnerabilities and threats change, the criticality and sensitivity of the asset, the consequences of an incident, the risks of exposure to environments where the entity cannot enforce its own policies, and the materiality and frequency of change. Paragraph 31 requires the sufficiency of that programme to be reviewed at least annually; paragraph 30 requires testing by appropriately skilled and functionally independent specialists. | Security Ratings |
| Paragraph 27(d) — the risks associated with exposure to environments where the entity is unable to enforce its own information security policies — is the closest any instrument in this table comes to describing what this page is about. Paragraph 28 pushes the same obligation into the supply chain, so an entity relying on a third party’s testing has to form a view on whether that testing is commensurate with the same five factors. Entity types configurable against APRA are Authorised Deposit-taking Institution, General Insurer, Life Insurer and Registrable Superannuation Entity. |
| United Arab Emirates | CBUAE, DFSA, UAE-CSC | What the Central Bank of the UAE, the Dubai Financial Services Authority and the UAE Cyber Security Council publish, read from their own sources as it is issued and classified for whether it is binding or advisory and what deadline the document itself states. Entity types configurable against the Central Bank include Licensed Bank, Exchange House, Finance Company, Insurance Company, Payment Service Provider and Stored Value Facility. | Regulatory Intelligence |
| Card payments, everywhere | PCI Security Standards Council | PCI DSS v4.0.1 Requirement 11.4 requires internal and external penetration testing at least once every 12 months and after any significant infrastructure or application change, segmentation testing on the same 12-month cycle, and — for service providers — testing of segmentation controls at least once every six months. The requirement is satisfied by a qualified internal resource or a qualified external third party, with organisational independence from the systems under test. | Attack Surface Management |
| The only instrument in this table whose text is identical in Mumbai, Frankfurt and Memphis, which is why a group supervised in several places tends to standardise on it first. What the monitoring contributes is the boundary as it actually resolves from outside — the hosts, certificates, providers and forgotten campaign properties answering for your payment domains — because a scope defined from a diagram and a scope defined from DNS are rarely the same scope. |
| India | RBI, SEBI, IRDAI, NPCI, CERT-In, NCIIPC | RBI master directions and notifications on IT governance, information security, cyber resilience, outsourcing of IT services, digital lending and incident reporting; the SEBI Cybersecurity and Cyber Resilience Framework and its amendments; IRDAI information and cyber-security guidelines for insurers and intermediaries; NPCI circulars and operating guidelines for the payment systems it runs; and CERT-In’s directions and advisories. Each is set out authority by authority in the section below. | The India section, below |
| The deepest coverage in the registry, and the reason the capability exists at all: CERT-In empanelment since 2008 made RBI, SEBI and IRDAI expectations operational knowledge at Security Brigade years before they were anybody’s product feature. It shows in the sourcing — SEBI is read from its circulars, guidelines, regulations and enforcement orders separately, because the cyber-resilience material does not reliably appear in any one of them, and RBI is read from several listing pages in priority order so one broken page does not silence the authority. |
| Assessment | Security Brigade | Deliberately not this. Reading a finding against a clause, testing whether the control behind it works, and signing the opinion a supervisor eventually asks for are consulting work rather than a monitoring output — and treating the two as interchangeable is the most expensive kind of overclaim in this sector. | securitybrigade.com |
| Same firm, different work — ShadowMap is Security Brigade’s product, and the assessment practice is the older half of the business. ShadowMap produces the dated evidence; the practice does the interpretation, the testing and the report a regulator will read. Where you need both they compose cleanly, and where you only need one we would rather say which. |