Skip to main content
Industry · Banking, insurance and capital markets

Wherever you are supervised, the estate you are judged on is mostly not the one you operate.

ShadowMap watches the parts of a financial institution’s exposure that sit outside its own change control — credentials belonging to staff, branches and agents; impersonation aimed at retail customers; and the external estate of the processors and partners doing regulated work on your behalf. One correlated exposure model, continuously, from outside, and where it is safe and authorised the exposure is tested rather than asserted. Every run leaves a dated, scoped record, which is what turns monitoring into evidence — in each of the jurisdictions that will ask you for it.

“A regulator asks what is exposed and by when it will be fixed. The answer has to hold up in an inspection, not a slide.”

12B+
Breach and credential records
31
Authorities tracked, from the RBI to the SEC
CERT-In
Empanelled security auditor since 2008 — Security Brigade

The frame

The best-defended part of your estate is the part least likely to be the problem

A bank’s own network is the most heavily controlled, most frequently tested and most closely examined thing it owns. The exposure that produces incidents sits on the other side of it: on the people who work for you, the customers who trust your name, and the firms you have outsourced regulated processing to.

Two boundaries. The first is what this is. ShadowMap runs continuous outside-in monitoring and produces a dated, scoped record of what was examined, when, and what was found — including what it deliberately did not examine. It is not a compliance opinion, and nothing on this page tells you whether a particular direction, regulation or framework binds your entity. The second is what it is not. Gap analysis against a framework, control testing, remediation advisory and the assessor sign-off a supervisor eventually asks for are consulting engagements. They are Security Brigade’s practice, at securitybrigade.com, and the honest answer is to send you there rather than build a thinner second version of the same work here. What ShadowMap contributes is the layer underneath it: the monitoring evidence an assessor asks for and a self-assessment questionnaire structurally cannot produce. The registry that layer runs against carries the authorities you are actually supervised by rather than one market’s — RBI, SEBI and IRDAI in India, DORA and the EBA at Union level, the FCA and the PRA in the United Kingdom, the SEC and the FFIEC in the United States, and MAS, APRA, the Central Bank of the UAE and the PCI Security Standards Council beyond them. India is where the depth is greatest, because CERT-In empanelment since 2008 made those expectations operational knowledge at Security Brigade long before they were anybody’s product feature. It is not where the monitoring stops, and for a group with a branch in London and a licence in Singapore it never was.

Where the exposure sits

What is exposed, and whose it turns out to be

Each row below is a different question about whose asset this is, and each is answered in a different part of the platform. The limits sit in the rows, because a boundary declared three sections later is a boundary nobody read.

The estateWhat is observed from outsideWhere it is workedThe job it becomes
Staff, branch and agent credentials Credential and session artefacts attributed to your domains in stealer-log and breach material, assembled per compromised device rather than per row — so the cookies, tokens, autofill data and access paths that came off one machine arrive together. Where it is safe and authorised, each credential is probed and carries an explicit state, so a stale password is separable from a session that still opens something. Dark Web Monitoring Responding to leaked credentials
Scale here is structural, not incidental. A retail institution’s identity population is not its headcount: it is headcount plus the branch and franchise network, plus tied agents, appointed representatives, business correspondents and direct selling agents, plus the outsourced collections, verification and contact-centre staff who hold a login on your systems without ever appearing on your payroll. Those identities are compromised on machines you do not manage and cannot instrument, which is the whole reason the finding has to arrive from outside rather than from an endpoint agent.
Retail-customer impersonation Cloned net-banking and payment pages, mobile applications republished into third-party and side-load markets, support desks opened on messaging platforms in your name, and profiles carrying named executives — matched against your registered marks, your real properties and your own site copy rather than against your brand name as a keyword. Brand Protection Removal, filed on your authorisation
Disposition is harder in this sector than in almost any other, because the legitimately authorised population is enormous and looks identical from outside. A business correspondent’s local page, an appointed representative’s own site and a bancassurance partner’s microsite carry the same signals as an outright impersonation; the difference is contractual, and no external signal reveals it. Matches therefore arrive attributed against your own agent and partner register where you have supplied one, and as an explicit question where you have not — rather than as a guess counted as a detection.
Processors, partners and the providers underneath them The external estate of the processors, payment switches, identity-verification and KYC providers, collections agencies and fintech partners you nominate — scored with the identical categories, maths and bands applied to your own estate — together with the hosting, DNS, mail, certificate and authentication providers each one actually resolves to. Third-Party Risk Management Onboarding a vendor without waiting on a questionnaire
Concentration is the finding this sector gets that others largely do not, and it is only visible across a portfolio rather than one supplier at a time. A shared upstream that several critical suppliers depend on becomes a counted fact with a date on it — including the providers you hold no contract with and therefore have no standing to question. Vendor-side findings arrive observed and untested: authorisation over another firm’s systems is not yours to give, and every finding says which mode it is in.
Subsidiaries, and the estate nobody registered Every hostname answering from the public internet across the apex domains of the group — the lending, asset-management, broking and insurance arms, in each country they are licensed in — plus the co-branded and white-label properties that carry your name on somebody else’s domain, and the acquired estates still running on the naming conventions of the firm they were bought from. Attack Surface Management Seeing every subsidiary from one place
A financial group is rarely one supervised entity. It is several, often under different authorities in different countries, frequently with their own technology function and their own procurement — which is how a campaign microsite for a product retired four years ago stays online, on a domain nobody at the centre has ever seen, still carrying a login form.

Staff, branch and agent credentials

What is observed from outside
Credential and session artefacts attributed to your domains in stealer-log and breach material, assembled per compromised device rather than per row — so the cookies, tokens, autofill data and access paths that came off one machine arrive together. Where it is safe and authorised, each credential is probed and carries an explicit state, so a stale password is separable from a session that still opens something.
Where it is worked
Dark Web Monitoring

Scale here is structural, not incidental. A retail institution’s identity population is not its headcount: it is headcount plus the branch and franchise network, plus tied agents, appointed representatives, business correspondents and direct selling agents, plus the outsourced collections, verification and contact-centre staff who hold a login on your systems without ever appearing on your payroll. Those identities are compromised on machines you do not manage and cannot instrument, which is the whole reason the finding has to arrive from outside rather than from an endpoint agent.

Retail-customer impersonation

What is observed from outside
Cloned net-banking and payment pages, mobile applications republished into third-party and side-load markets, support desks opened on messaging platforms in your name, and profiles carrying named executives — matched against your registered marks, your real properties and your own site copy rather than against your brand name as a keyword.
Where it is worked
Brand Protection

Disposition is harder in this sector than in almost any other, because the legitimately authorised population is enormous and looks identical from outside. A business correspondent’s local page, an appointed representative’s own site and a bancassurance partner’s microsite carry the same signals as an outright impersonation; the difference is contractual, and no external signal reveals it. Matches therefore arrive attributed against your own agent and partner register where you have supplied one, and as an explicit question where you have not — rather than as a guess counted as a detection.

Processors, partners and the providers underneath them

What is observed from outside
The external estate of the processors, payment switches, identity-verification and KYC providers, collections agencies and fintech partners you nominate — scored with the identical categories, maths and bands applied to your own estate — together with the hosting, DNS, mail, certificate and authentication providers each one actually resolves to.
Where it is worked
Third-Party Risk Management

Concentration is the finding this sector gets that others largely do not, and it is only visible across a portfolio rather than one supplier at a time. A shared upstream that several critical suppliers depend on becomes a counted fact with a date on it — including the providers you hold no contract with and therefore have no standing to question. Vendor-side findings arrive observed and untested: authorisation over another firm’s systems is not yours to give, and every finding says which mode it is in.

Subsidiaries, and the estate nobody registered

What is observed from outside
Every hostname answering from the public internet across the apex domains of the group — the lending, asset-management, broking and insurance arms, in each country they are licensed in — plus the co-branded and white-label properties that carry your name on somebody else’s domain, and the acquired estates still running on the naming conventions of the firm they were bought from.
Where it is worked
Attack Surface Management

A financial group is rarely one supervised entity. It is several, often under different authorities in different countries, frequently with their own technology function and their own procurement — which is how a campaign microsite for a product retired four years ago stays online, on a domain nobody at the centre has ever seen, still carrying a login form.

One event, three readers

In this sector a finding is read three times before anyone acts on it

Security operations, the compliance function and the risk committee are looking at the same confirmed credential and asking three different questions of it. A platform that answers only the first one has created work for the other two.

Worked example

A credential on a payments operations account comes back Confirmed Working

What security operations needs from it
The device case rather than the row: which machine was compromised, what else came off it — session cookies, an OAuth refresh token, autofill data, the internal tools the browser history shows it reached — and which access path this particular credential opens. The action is a rotation today and a check for session persistence, and the queue is ordered by which credentials still authenticate rather than by how many exist.
What the compliance function needs from the same event
Not the credential. The record around it: the date the source material entered the corpus, the date it was detected and attributed, the scope the run covered and the exclusions that bounded it, who dispositioned it and when, and whether it was handled inside the timeframe your own policy commits to — with the misses in the record rather than filtered out of it. A group supervised in more than one country has more than one clock running on the same event, and they do not all start at the same moment; what a record like this fixes is when awareness began. A control that exists and a control that operated are different things, and only one of them leaves a trail an examiner can reproduce.
What the risk committee is actually asking
Whether this is one account or a pattern. Whether the same exposure sits in the agent network, in the subsidiary that runs its own technology function, and at the processors handling your card traffic. That question is not answerable from an incident record at all; it is answerable from a portfolio view that has been running long enough to show a direction of travel, which is why the reporting line and the response line are fed by the same monitoring rather than assembled separately.

Regulatory monitoring

One estate, several supervisors, one dated record

A group with an Indian parent, a London branch and a Singapore licence answers to several authorities about the same external estate. ShadowMap tracks what each of them publishes and produces the monitoring record underneath it: of the 31 authorities in the registry, 28 are tagged to this sector and 22 of those sit outside India. What it will not do is tell you whether an instrument binds your entity — that is a legal determination, and it belongs to your compliance function and your advisers.

Where you are supervisedAuthorities in the registryWhat the published instruments requireWhere the dated evidence sits
European Union DORA, EBA, ECB, ENISA, EDPB DORA Article 24(6) requires every financial entity other than a microenterprise to ensure, at least yearly, that appropriate tests are conducted on all ICT systems and applications supporting critical or important functions. Article 25(1) sets out the techniques those tests may draw on as a non-exhaustive list, applied proportionately. Article 28(3) requires a maintained register of information covering all contractual arrangements for the use of ICT services provided by third parties. Third-Party Risk Management
Article 24(4) puts the testing programme in the hands of "independent parties, whether internal or external", and a continuous outside-in record is one input to that programme rather than the programme itself. Where this monitoring bears most directly is the third-party half: the Article 28(3) register is a list of arrangements, and what a list of arrangements does not carry is what each of those providers currently looks like from the internet. That is assessed with the identical categories, maths and bands applied to your own estate, dated per run.
United Kingdom FCA, PRA, ICO, NCSC The FCA and PRA operational-resilience regime requires a firm to identify its important business services, set an impact tolerance for each, map the people, processes, technology, facilities and information those services depend on, and scenario-test its ability to remain within tolerance through severe but plausible disruption. Under the UK GDPR a personal data breach must be notified to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to individuals’ rights and freedoms. Dark Web Monitoring
Read the operational-resilience rules for what they say rather than for what a vendor page says they say: they are about important business services, impact tolerances and mapping, and the mapping obligation reaches the third parties a service depends on. The 72-hour clock is what this monitoring most directly serves — a credential set attributed to your domains, dated when the source material entered the corpus and dated again when it was detected, is the artefact that establishes when awareness began.
United States SEC, OCC, FFIEC, FTC, NIST A registrant must file a Form 8-K under Item 1.05 describing a material cybersecurity incident within four business days of determining that it is material, and must describe in its annual report, under Regulation S-K Item 106(b), its processes for assessing, identifying and managing material risks from cybersecurity threats — expressly including whether it engages assessors, consultants, auditors or other third parties, and whether it has processes to oversee risks from third-party service providers. Attack Surface Management
Item 106(b) is a disclosure obligation rather than a testing one, and that is exactly why it belongs in this table: it requires a registrant to describe a programme, in writing, in a filing, once a year, and to say who outside the firm is engaged in it. A monitoring record that states what was examined, when, what was found, and what was deliberately excluded is describable in those terms. A questionnaire returned by a supplier is not.
Singapore MAS, CSA The MAS Technology Risk Management Guidelines set the supervisory expectation that penetration testing is conducted at least once annually on systems directly accessible from the internet, or whenever those systems undergo major change, alongside vulnerability assessment and adversarial attack simulation. MAS’s binding cyber-hygiene notice addresses administrative accounts, security patching, security standards, network perimeter defence, malware protection and multi-factor authentication. Continuous Automated Red-Teaming
The difference between the two matters and a good deal of published material blurs it: the Technology Risk Management Guidelines are guidelines that MAS supervises against, and the cyber-hygiene notice is a notice. What ShadowMap contributes against an annual testing expectation is the continuous half — dated validation records in the months between tests, run where it is safe and authorised, never the test itself. Entity types configurable against MAS include Full Bank, Wholesale Bank, Licensed Insurer, Capital Markets Services Licensee and Major Payment Institution, so an item scopes to the licence you hold rather than to the sector.
Australia APRA, ACSC APRA Prudential Standard CPS 234 paragraph 27 requires an APRA-regulated entity to test the effectiveness of its information security controls through a systematic testing programme, at a nature and frequency commensurate with the rate at which vulnerabilities and threats change, the criticality and sensitivity of the asset, the consequences of an incident, the risks of exposure to environments where the entity cannot enforce its own policies, and the materiality and frequency of change. Paragraph 31 requires the sufficiency of that programme to be reviewed at least annually; paragraph 30 requires testing by appropriately skilled and functionally independent specialists. Security Ratings
Paragraph 27(d) — the risks associated with exposure to environments where the entity is unable to enforce its own information security policies — is the closest any instrument in this table comes to describing what this page is about. Paragraph 28 pushes the same obligation into the supply chain, so an entity relying on a third party’s testing has to form a view on whether that testing is commensurate with the same five factors. Entity types configurable against APRA are Authorised Deposit-taking Institution, General Insurer, Life Insurer and Registrable Superannuation Entity.
United Arab Emirates CBUAE, DFSA, UAE-CSC What the Central Bank of the UAE, the Dubai Financial Services Authority and the UAE Cyber Security Council publish, read from their own sources as it is issued and classified for whether it is binding or advisory and what deadline the document itself states. Entity types configurable against the Central Bank include Licensed Bank, Exchange House, Finance Company, Insurance Company, Payment Service Provider and Stored Value Facility. Regulatory Intelligence
Card payments, everywhere PCI Security Standards Council PCI DSS v4.0.1 Requirement 11.4 requires internal and external penetration testing at least once every 12 months and after any significant infrastructure or application change, segmentation testing on the same 12-month cycle, and — for service providers — testing of segmentation controls at least once every six months. The requirement is satisfied by a qualified internal resource or a qualified external third party, with organisational independence from the systems under test. Attack Surface Management
The only instrument in this table whose text is identical in Mumbai, Frankfurt and Memphis, which is why a group supervised in several places tends to standardise on it first. What the monitoring contributes is the boundary as it actually resolves from outside — the hosts, certificates, providers and forgotten campaign properties answering for your payment domains — because a scope defined from a diagram and a scope defined from DNS are rarely the same scope.
India RBI, SEBI, IRDAI, NPCI, CERT-In, NCIIPC RBI master directions and notifications on IT governance, information security, cyber resilience, outsourcing of IT services, digital lending and incident reporting; the SEBI Cybersecurity and Cyber Resilience Framework and its amendments; IRDAI information and cyber-security guidelines for insurers and intermediaries; NPCI circulars and operating guidelines for the payment systems it runs; and CERT-In’s directions and advisories. Each is set out authority by authority in the section below. The India section, below
The deepest coverage in the registry, and the reason the capability exists at all: CERT-In empanelment since 2008 made RBI, SEBI and IRDAI expectations operational knowledge at Security Brigade years before they were anybody’s product feature. It shows in the sourcing — SEBI is read from its circulars, guidelines, regulations and enforcement orders separately, because the cyber-resilience material does not reliably appear in any one of them, and RBI is read from several listing pages in priority order so one broken page does not silence the authority.
Assessment Security Brigade Deliberately not this. Reading a finding against a clause, testing whether the control behind it works, and signing the opinion a supervisor eventually asks for are consulting work rather than a monitoring output — and treating the two as interchangeable is the most expensive kind of overclaim in this sector. securitybrigade.com
Same firm, different work — ShadowMap is Security Brigade’s product, and the assessment practice is the older half of the business. ShadowMap produces the dated evidence; the practice does the interpretation, the testing and the report a regulator will read. Where you need both they compose cleanly, and where you only need one we would rather say which.

European Union

Authorities in the registry
DORA, EBA, ECB, ENISA, EDPB
What the published instruments require
DORA Article 24(6) requires every financial entity other than a microenterprise to ensure, at least yearly, that appropriate tests are conducted on all ICT systems and applications supporting critical or important functions. Article 25(1) sets out the techniques those tests may draw on as a non-exhaustive list, applied proportionately. Article 28(3) requires a maintained register of information covering all contractual arrangements for the use of ICT services provided by third parties.
Where the dated evidence sits
Third-Party Risk Management

Article 24(4) puts the testing programme in the hands of "independent parties, whether internal or external", and a continuous outside-in record is one input to that programme rather than the programme itself. Where this monitoring bears most directly is the third-party half: the Article 28(3) register is a list of arrangements, and what a list of arrangements does not carry is what each of those providers currently looks like from the internet. That is assessed with the identical categories, maths and bands applied to your own estate, dated per run.

United Kingdom

Authorities in the registry
FCA, PRA, ICO, NCSC
What the published instruments require
The FCA and PRA operational-resilience regime requires a firm to identify its important business services, set an impact tolerance for each, map the people, processes, technology, facilities and information those services depend on, and scenario-test its ability to remain within tolerance through severe but plausible disruption. Under the UK GDPR a personal data breach must be notified to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to individuals’ rights and freedoms.
Where the dated evidence sits
Dark Web Monitoring

Read the operational-resilience rules for what they say rather than for what a vendor page says they say: they are about important business services, impact tolerances and mapping, and the mapping obligation reaches the third parties a service depends on. The 72-hour clock is what this monitoring most directly serves — a credential set attributed to your domains, dated when the source material entered the corpus and dated again when it was detected, is the artefact that establishes when awareness began.

United States

Authorities in the registry
SEC, OCC, FFIEC, FTC, NIST
What the published instruments require
A registrant must file a Form 8-K under Item 1.05 describing a material cybersecurity incident within four business days of determining that it is material, and must describe in its annual report, under Regulation S-K Item 106(b), its processes for assessing, identifying and managing material risks from cybersecurity threats — expressly including whether it engages assessors, consultants, auditors or other third parties, and whether it has processes to oversee risks from third-party service providers.
Where the dated evidence sits
Attack Surface Management

Item 106(b) is a disclosure obligation rather than a testing one, and that is exactly why it belongs in this table: it requires a registrant to describe a programme, in writing, in a filing, once a year, and to say who outside the firm is engaged in it. A monitoring record that states what was examined, when, what was found, and what was deliberately excluded is describable in those terms. A questionnaire returned by a supplier is not.

Singapore

Authorities in the registry
MAS, CSA
What the published instruments require
The MAS Technology Risk Management Guidelines set the supervisory expectation that penetration testing is conducted at least once annually on systems directly accessible from the internet, or whenever those systems undergo major change, alongside vulnerability assessment and adversarial attack simulation. MAS’s binding cyber-hygiene notice addresses administrative accounts, security patching, security standards, network perimeter defence, malware protection and multi-factor authentication.
Where the dated evidence sits
Continuous Automated Red-Teaming

The difference between the two matters and a good deal of published material blurs it: the Technology Risk Management Guidelines are guidelines that MAS supervises against, and the cyber-hygiene notice is a notice. What ShadowMap contributes against an annual testing expectation is the continuous half — dated validation records in the months between tests, run where it is safe and authorised, never the test itself. Entity types configurable against MAS include Full Bank, Wholesale Bank, Licensed Insurer, Capital Markets Services Licensee and Major Payment Institution, so an item scopes to the licence you hold rather than to the sector.

Australia

Authorities in the registry
APRA, ACSC
What the published instruments require
APRA Prudential Standard CPS 234 paragraph 27 requires an APRA-regulated entity to test the effectiveness of its information security controls through a systematic testing programme, at a nature and frequency commensurate with the rate at which vulnerabilities and threats change, the criticality and sensitivity of the asset, the consequences of an incident, the risks of exposure to environments where the entity cannot enforce its own policies, and the materiality and frequency of change. Paragraph 31 requires the sufficiency of that programme to be reviewed at least annually; paragraph 30 requires testing by appropriately skilled and functionally independent specialists.
Where the dated evidence sits
Security Ratings

Paragraph 27(d) — the risks associated with exposure to environments where the entity is unable to enforce its own information security policies — is the closest any instrument in this table comes to describing what this page is about. Paragraph 28 pushes the same obligation into the supply chain, so an entity relying on a third party’s testing has to form a view on whether that testing is commensurate with the same five factors. Entity types configurable against APRA are Authorised Deposit-taking Institution, General Insurer, Life Insurer and Registrable Superannuation Entity.

United Arab Emirates

Authorities in the registry
CBUAE, DFSA, UAE-CSC
What the published instruments require
What the Central Bank of the UAE, the Dubai Financial Services Authority and the UAE Cyber Security Council publish, read from their own sources as it is issued and classified for whether it is binding or advisory and what deadline the document itself states. Entity types configurable against the Central Bank include Licensed Bank, Exchange House, Finance Company, Insurance Company, Payment Service Provider and Stored Value Facility.
Where the dated evidence sits
Regulatory Intelligence

Card payments, everywhere

Authorities in the registry
PCI Security Standards Council
What the published instruments require
PCI DSS v4.0.1 Requirement 11.4 requires internal and external penetration testing at least once every 12 months and after any significant infrastructure or application change, segmentation testing on the same 12-month cycle, and — for service providers — testing of segmentation controls at least once every six months. The requirement is satisfied by a qualified internal resource or a qualified external third party, with organisational independence from the systems under test.
Where the dated evidence sits
Attack Surface Management

The only instrument in this table whose text is identical in Mumbai, Frankfurt and Memphis, which is why a group supervised in several places tends to standardise on it first. What the monitoring contributes is the boundary as it actually resolves from outside — the hosts, certificates, providers and forgotten campaign properties answering for your payment domains — because a scope defined from a diagram and a scope defined from DNS are rarely the same scope.

India

Authorities in the registry
RBI, SEBI, IRDAI, NPCI, CERT-In, NCIIPC
What the published instruments require
RBI master directions and notifications on IT governance, information security, cyber resilience, outsourcing of IT services, digital lending and incident reporting; the SEBI Cybersecurity and Cyber Resilience Framework and its amendments; IRDAI information and cyber-security guidelines for insurers and intermediaries; NPCI circulars and operating guidelines for the payment systems it runs; and CERT-In’s directions and advisories. Each is set out authority by authority in the section below.
Where the dated evidence sits
The India section, below

The deepest coverage in the registry, and the reason the capability exists at all: CERT-In empanelment since 2008 made RBI, SEBI and IRDAI expectations operational knowledge at Security Brigade years before they were anybody’s product feature. It shows in the sourcing — SEBI is read from its circulars, guidelines, regulations and enforcement orders separately, because the cyber-resilience material does not reliably appear in any one of them, and RBI is read from several listing pages in priority order so one broken page does not silence the authority.

Assessment

Authorities in the registry
Security Brigade
What the published instruments require
Deliberately not this. Reading a finding against a clause, testing whether the control behind it works, and signing the opinion a supervisor eventually asks for are consulting work rather than a monitoring output — and treating the two as interchangeable is the most expensive kind of overclaim in this sector.
Where the dated evidence sits
securitybrigade.com

Same firm, different work — ShadowMap is Security Brigade’s product, and the assessment practice is the older half of the business. ShadowMap produces the dated evidence; the practice does the interpretation, the testing and the report a regulator will read. Where you need both they compose cleanly, and where you only need one we would rather say which.

India, in depth

Six authorities, each read from the places it actually publishes

Indian supervisory language groups this sector as BFSI, and the depth here is real. Each authority below is fetched from its own listing pages, feeds and archives in priority order, so a site redesign that breaks one source does not silence the regulator. What arrives is the published item, classified for whether it binds and by when the document itself says so — not a reading of whether it binds you.

RBI

Master directions, and the estate they reach

Master directions, master circulars and notifications covering IT governance, information security and cyber resilience, outsourcing of IT services, digital lending and incident reporting. What ShadowMap produces underneath them is the external half: the group’s internet-facing estate resolved from its apex domains outward and attributed to the entity that owns it, with the date each asset entered scope and the date any asset left it. Entity types run from Scheduled Commercial Bank and Small Finance Bank through NBFC, Payment System Operator, Payment Aggregator and Prepaid Payment Instrument Issuer.

SEBI

The Cyber Resilience Framework, tracked as it changes

The Cybersecurity and Cyber Resilience Framework and its amendments, tracked as they are published rather than as the framework stood when somebody last read it. Circulars, guidelines, regulations and enforcement orders are read separately, because the cyber-resilience material does not reliably appear in any one of them. Every validation probe is recorded with its evidence, timestamp, scope profile and audit identifier, so activity against your estate reconciles against your own logs rather than arriving as an unexplained spike. Entity types include Stock Exchange, Stock Broker, Depository Participant, Registrar and Transfer Agent and Credit Rating Agency.

IRDAI

The distribution estate an insurer does not operate

Information and cyber-security guidelines for insurers and intermediaries, and the material covering outsourced and intermediated distribution — which is to say, the estate an insurer is answerable for but does not run. Corporate agents, brokers, web aggregators and bancassurance partners each operate their own properties and each hold customer data. They are assessed with the same method used on your own estate, and they arrive observed rather than tested: an insurer cannot grant permission over an intermediary’s servers, and we do not proceed as though it had.

NPCI

Where an impersonation becomes a payments problem

Circulars and operating guidelines for the payment systems it runs, and the advisories issued to participants — the layer at which a fake page aimed at a retail customer stops being a marketing problem. A cloned payment page or a republished mobile application is a customer-facing exposure no internal control can see, because none of it runs on anything you own. Confirmed cases arrive with the evidence pack assembled and you authorise the filing; nothing is dispatched without that attestation. Takedowns are unlimited, subject to the fair-use boundary stated in your contract.

CERT-In

Directions, advisories, and the audit that sits beside them

Directions issued under Section 70B of the Information Technology Act and the advisory series that accompanies them, read as they are published. This is also where the two halves of the firm meet most visibly: a CERT-In empanelled auditor is what an Indian institution engages for the audit itself, Security Brigade has held that empanelment since 2008, and the monitoring record ShadowMap produces is what an auditor asks for and a point-in-time engagement cannot generate on its own.

NCIIPC

Advisories for the systems declared protected

Guidance and advisories from the National Critical Information Infrastructure Protection Centre, which covers financial services among the sectors in its remit. Whether a particular system of yours has been declared a protected system under Section 70 of the Information Technology Act is a determination made by government, not by a monitoring platform — what ShadowMap contributes is the dated external record of the estate those systems are reached through.

Attribution order

A financial group cannot be scoped alphabetically

Each step below is only answerable once the one above it is, which is why the order is load-bearing rather than presentational. Concentration risk arrives last because it is not visible until everything above it has been attributed.

Most used in this sector

Where banking and financial services programmes start

Attack Surface Management

Continuous outside-in discovery of the internet-facing estate — including the origin infrastructure sitting behind your edge.

Dark Web Monitoring

A proprietary stealer-log collection with permanent raw-source retention, so improved extraction improves your history as well as your present.

Brand Protection

Impersonation detection across domains, social platforms, app stores and executive identity — ending in removal, not an alert.

Domain Monitoring

Look-alike, typosquatted and permutation domains detected at registration, scored for intent, and routed for removal.

Phishing and Domain Takedown

Orchestrated removal across registrars, hosts, platforms and app stores, with every lifecycle state published — including the ones that fail.

Continuous Automated Red-Teaming

Where it is safe and authorised, exposure is tested rather than asserted — and the evidence, the scope and the audit identifier are handed to you.

AI Review

Four published verdicts, two separate score fields, a queue nothing is ever deleted from — and a published list of where we deliberately did not use AI.

Third-Party Risk Management

The same outside-in methodology applied to your vendors, with the identical categories, maths and bands used on your own estate.

Threat Intelligence

Actor, malware, CVE and indicator data correlated against the technology actually discovered on your estate — which is the only thing that makes it relevant.

Security Ratings

A rating is an output, never the product. The findings underneath it are what you act on.

Regulatory Intelligence

Advisory and directive tracking across 31 regulators in seven territories, as programme context — never as legal advice.

Questions buyers actually ask

Before you evaluate this

We are supervised outside India too. Is this built for Indian institutions?

It is built for the estate, and an estate does not have a nationality — a stealer log, a cloned payment page and a supplier’s exposed admin panel look the same from outside wherever the firm is licensed. The regulatory layer is where the question is fair, so here is the count: the registry carries 31 supervisory and standards authorities, 28 of them are tagged to this sector, and 22 of those 28 sit outside India — DORA, the EBA, the ECB, ENISA and the EDPB at EU level; the FCA, PRA, ICO and NCSC in the United Kingdom; the SEC, OCC, FFIEC, FTC and NIST in the United States; MAS and the CSA in Singapore; APRA and the ACSC in Australia; the Central Bank of the UAE, the DFSA and the UAE Cyber Security Council; and the PCI Security Standards Council globally. You configure the authorities, entity types, industries and geographies you are actually supervised under — Full Bank or Major Payment Institution under MAS, Authorised Deposit-taking Institution under APRA, Licensed Bank under the Central Bank of the UAE, Scheduled Commercial Bank or NBFC under RBI — and items scope to that rather than to a sector. India is the deepest coverage in the set and the reason the capability exists; it is not the edge of it.

We run a SOC and we are audited every year. Where does this sit?

Between them, and it is the gap both are structurally bad at covering. A SOC watches what is instrumented — your network, your endpoints, your logs — and by definition sees nothing on a customer’s device, an agent’s laptop or a processor’s estate. An audit is excellent and it is a point in time: it tells you what was true in the week the assessor was in the building, whether that assessor is a CERT-In empanelled auditor in India, a QSA signing off a cardholder environment, or the independent party a DORA testing programme relies on. This is the continuous outside-in layer in between, running against the estate neither one reaches, and producing a dated record of what was examined and when. It does not replace either. Our own assessment practice is Security Brigade, so if what you actually need is the audit rather than the monitoring, we will say so.

Can it tell us whether we are compliant with a particular circular, regulation or framework?

No, and that is a deliberate boundary. What it does do is narrow the question a long way: you configure the authorities you are supervised by, your entity types, industries and geographies, and each item carries what the instrument obliges, the entity types it names, whether it is binding or advisory, and the earliest date the document itself commits you to. Every date shown can be pointed at in the source text, and a deadline the source does not state is not shown at all. Converting that into a determination that an instrument binds your entity is a legal question about your registration and your permissions, and mapping a published item to a clause in your own control framework is assessment work. Both belong with your compliance function, your advisers and the practice at securitybrigade.com.

Most of our exposure is on customers and agents we do not control. What can you actually do about it?

Three things, and one honest limit. We observe it, because everything described on this page is visible from outside without anybody’s cooperation. We attribute it, which in this sector is the hard half: your own agent, partner and subsidiary registers are inputs, so an authorised distributor or appointed representative is suppressed and stays suppressed rather than resurfacing every month as a fresh candidate. And we remove what has a removal route — the responsible platform, store, registrar or host is resolved into an order and the notice is filed with the evidence pack attached, on your authorisation. The limit: only what is publicly visible is detectable. An operation living entirely inside a closed group or in direct messages leaves no public artefact to match, and some side-load markets have no removal route at all. Where that is the case the finding still reaches you with the distribution URL and the evidence, because your legal team may have a route we do not.

See the exposure your own controls cannot reach

One apex domain, two business days, a written snapshot — what is answering from outside, which credentials are attributed to you, and who is trading on your name. No call required.