Skip to main content
Intelligence · Programme context

The RBI, the SEC, the ECB and the MAS all publish on their own schedule.

ShadowMap tracks 31 supervisory, national and standards authorities across India, the United States, the European Union, the United Kingdom, Singapore, the UAE and Australia, and screens the non-cyber majority out before it ever reaches you. Most of what any regulator publishes is not about security at all. What survives is analysed into a structured obligation — binding or advisory, the deadline the document actually states, the security domains it touches, the entity types it names — and routed to the part of the platform that holds your evidence for it. That is programme context and a dated monitoring record. It is not a compliance opinion.

31
Authorities under monitoring
7
Territories, plus global standards
91
Publication sources fetched

What this is

A monitoring capability, not a compliance opinion

Regulatory intelligence in ShadowMap watches what supervisory, national and standards authorities publish across seven territories, and turns it into something your programme can act on and evidence.

Two boundaries. The first: everything on this page is programme context. ShadowMap tells you what an authority published, when, what it obliges and by when the document says so. Whether a given instrument binds your entity, and what it obliges you to do about it, is a determination for your compliance function and your legal advisers — we do not issue compliance opinions and this page is not one. The second: this is deliberately not compliance advisory. Assessment, gap analysis and framework readiness work is Security Brigade's practice, and the honest answer is to send you there — securitybrigade.com — rather than build a thinner second version of it here.

Coverage

Seven territories, and the standards body that has none

Coverage is a maintained registry inside the product, not a page somebody updates by hand. All 31 authorities are named below — 23 of them outside India — because a coverage claim you cannot check is not a coverage claim. Territories are listed alphabetically, and the count of each one’s publication sources is in the methodology at the foot of the page.

TerritoryAuthorities trackedWhat is monitored
Australia APRA, ACSC Prudential standard CPS 234 and the practice guides around it, prudential news and publications, national alerts and advisories including the joint advisories issued with partner agencies
APRA is one of the six authorities with entity-type profiling configured, alongside the RBI, SEBI, IRDAI, MAS and CBUAE — so an item can be scoped to an Authorised Deposit-taking Institution the same way it is scoped to a Scheduled Commercial Bank.
European Union ENISA, ECB, EBA, EDPB, DORA DORA technical and implementing standards, EBA ICT risk-management guidelines, ECB material including the TIBER-EU threat-led testing framework, EDPB guidelines and binding decisions, ENISA threat landscapes and NIS2 guidance
DORA and NIS2 are the two instruments most often asked about here, and both place explicit obligations on third-party ICT risk and supplier monitoring. That is where vendor exposure — assessed with the same outside-in methodology applied to your own estate — produces dated, per-vendor evidence rather than an annual questionnaire.
India RBI, SEBI, CERT-In, IRDAI, TRAI, NPCI, MeitY, NCIIPC Master directions, master circulars and notifications, the SEBI CSCRF and its amendments, Section 70B directions and the CISG guideline series, insurance and payments guidelines, telecom directions, national critical-infrastructure material
Eight authorities and 40 of the 91 publication sources — the deepest coverage in the registry by a distance. Why it is sourced that hard, and what each authority contributes, is the section immediately below.
Singapore MAS, CSA Singapore Technology risk management guidelines and the cyber hygiene notice, outsourcing guidelines, incident notification and reporting instructions, national alerts, advisories and the legislation and guidelines listing
United Arab Emirates CBUAE, DFSA, UAE-CSC Central-bank rulebook, legislation and information-security standards, DFSA cyber reports, guides, handbooks and consultation papers covering the DIFC, the national cyber strategy and NIAF material
United Kingdom NCSC, FCA, PRA, ICO NCSC advisories, alerts and guidance including the Cyber Assessment Framework, FCA operational-resilience and critical-third-party material, PRA supervisory statements, ICO enforcement notices and UK GDPR guidance
United States CISA, NIST, SEC, OCC, FFIEC, FTC CISA binding operational directives and cybersecurity advisories, NIST CSF 2.0, SP 800-series and FIPS publications, SEC cyber disclosure rulemaking, OCC bulletins and alerts, the FFIEC IT Examination Handbook, FTC Safeguards Rule enforcement
Global standards PCI Security Standards Council PCI DSS and the secure-software and card-production standards around it
Items with no single territory are carried as global rather than forced into a country. Adding an authority is a registry entry and a resync, so an authority you are supervised by that is missing here is a request rather than a roadmap item.

Australia

Authorities tracked
APRA, ACSC
What is monitored
Prudential standard CPS 234 and the practice guides around it, prudential news and publications, national alerts and advisories including the joint advisories issued with partner agencies

APRA is one of the six authorities with entity-type profiling configured, alongside the RBI, SEBI, IRDAI, MAS and CBUAE — so an item can be scoped to an Authorised Deposit-taking Institution the same way it is scoped to a Scheduled Commercial Bank.

European Union

Authorities tracked
ENISA, ECB, EBA, EDPB, DORA
What is monitored
DORA technical and implementing standards, EBA ICT risk-management guidelines, ECB material including the TIBER-EU threat-led testing framework, EDPB guidelines and binding decisions, ENISA threat landscapes and NIS2 guidance

DORA and NIS2 are the two instruments most often asked about here, and both place explicit obligations on third-party ICT risk and supplier monitoring. That is where vendor exposure — assessed with the same outside-in methodology applied to your own estate — produces dated, per-vendor evidence rather than an annual questionnaire.

India

Authorities tracked
RBI, SEBI, CERT-In, IRDAI, TRAI, NPCI, MeitY, NCIIPC
What is monitored
Master directions, master circulars and notifications, the SEBI CSCRF and its amendments, Section 70B directions and the CISG guideline series, insurance and payments guidelines, telecom directions, national critical-infrastructure material

Eight authorities and 40 of the 91 publication sources — the deepest coverage in the registry by a distance. Why it is sourced that hard, and what each authority contributes, is the section immediately below.

Singapore

Authorities tracked
MAS, CSA Singapore
What is monitored
Technology risk management guidelines and the cyber hygiene notice, outsourcing guidelines, incident notification and reporting instructions, national alerts, advisories and the legislation and guidelines listing

United Arab Emirates

Authorities tracked
CBUAE, DFSA, UAE-CSC
What is monitored
Central-bank rulebook, legislation and information-security standards, DFSA cyber reports, guides, handbooks and consultation papers covering the DIFC, the national cyber strategy and NIAF material

United Kingdom

Authorities tracked
NCSC, FCA, PRA, ICO
What is monitored
NCSC advisories, alerts and guidance including the Cyber Assessment Framework, FCA operational-resilience and critical-third-party material, PRA supervisory statements, ICO enforcement notices and UK GDPR guidance

United States

Authorities tracked
CISA, NIST, SEC, OCC, FFIEC, FTC
What is monitored
CISA binding operational directives and cybersecurity advisories, NIST CSF 2.0, SP 800-series and FIPS publications, SEC cyber disclosure rulemaking, OCC bulletins and alerts, the FFIEC IT Examination Handbook, FTC Safeguards Rule enforcement

Global standards

Authorities tracked
PCI Security Standards Council
What is monitored
PCI DSS and the secure-software and card-production standards around it

Items with no single territory are carried as global rather than forced into a country. Adding an authority is a registry entry and a resync, so an authority you are supervised by that is missing here is a request rather than a roadmap item.

India

Where the coverage goes deepest, and what pays for it

Eight of the 31 authorities are Indian, and between them they carry 40 of the 91 publication sources in the registry — more than the United States, the European Union and the United Kingdom combined.

CERT-In empanelment since 2008 meant RBI, SEBI and IRDAI expectations were operational knowledge at Security Brigade long before they were a product feature, and it shows in the sourcing rather than in a badge. The RBI is read from its master directions, master circulars, notifications, press releases and legal-framework pages as five separate streams. SEBI is read from its circulars, guidelines, regulations and enforcement orders separately, because the cyber-resilience material does not reliably appear in any one of them, and its portal is rendered rather than fetched because it will not answer a plain request. CERT-In carries its Section 70B directions alongside its homepage, so a direction is picked up the day it is posted. NPCI alone contributes twelve circular streams — UPI, RuPay, IMPS, NACH, AePS, NETC and the rest — because payment-scheme security instructions are published per scheme and consolidated nowhere. MeitY covers the IT Act, the DPDP Act and the AI governance guidelines; NCIIPC covers critical-infrastructure advisories and responsible-disclosure guidance; TRAI covers telecom directions and regulations. The pipeline that runs over all of it is the same one that runs over the SEC and the FCA, and so is the boundary: what an instrument obliges your entity to do remains a determination for your compliance function.

The mechanism

From an authority’s website to something worth reading

A financial regulator publishes overwhelmingly about things that are not security. The work is not fetching the documents; it is throwing almost all of them away without throwing away the one that mattered.

What arrives

Severity you can audit the rule for

Severity here is not a house style. It is assigned under fixed, published rules, and whether an instrument binds you is carried on a separate axis — so guidance can never be quietly read as an obligation.

Severity you can audit the rule for
StateWhat it meansWhat follows
Critical A binding obligation with a stated deadline under 90 days and penalties attached to missing it. This one moves dates in the programme plan.
High Binding, with either a stated deadline or significant penalties. Plan against it inside the current cycle.
Medium Advisory or best-practice guidance — and the value anything unclassifiable falls back to, so nothing is silently promoted upward. Read it, decide, and record the decision.
Low Informational. Awareness. No obligation implied and none claimed.
Key
  • Dated and enforceable
  • Binding — plan for it
  • Guidance — your call
  • Informational

Evidence

Did the control run, on what date, over what scope, with what result

That is the question an auditor actually asks, and it is why regulatory intelligence sits inside the platform rather than beside it. A control that exists and a control that operated are different things, and only one of them leaves a record.

What the auditor asksThe artefact that answers itWhere it comes from
Did the monitoring run, and over what? Per-asset detection timestamps and the attributed inventory each run covered, with the date an asset entered scope and the date any asset left it Asset Explorer
Who touched our systems, and what did they do? Each validation probe recorded with its evidence, its timestamp and its outcome, so a challenged finding can be reconstructed rather than re-argued Continuous Automated Red-Teaming
Validation runs only where it is safe and authorised. The scan profile, the named exclusions and the rate limit that bounded a run are part of the same record, so the answer to "what did you not test" is written down alongside the answer to "what did you".
What did the team decide about this finding? The four-state disposition — Needs Review, Investigating, Accepted Risk, Closed — with the assignee, the comment thread and the timestamps Action Center
The analyst decision and the scanner’s own detection status are deliberately separate axes: a re-scan can never silently erase a decision a person made, and a decision can never hide an exposure that is still live. Accepted Risk is held as a documented exception rather than a deletion, which is exactly the form an examiner asks for.
Was it handled inside the timeframe our own policy commits to? SLA policy records, including the breaches SLA policies
The breaches are in the record too, and that is deliberate. A monitoring trail showing only the occasions you met your own SLA is not evidence; an auditor who cannot find a single miss in a year stops trusting the whole set.
What has the team actually been doing with findings? A chronological feed of assignments, status changes, tags, comments and shares, each against the specific finding it was performed on Activity logs
Who changed the monitoring configuration itself? The actor, the action, the source IP and the timestamp for every privileged change — members and roles, integrations and cloud sources, SLA and tag rules, two-factor status Audit logs
ShadowMap produces the record. Whether that record satisfies a particular clause is a judgement for your auditor and your advisers.

Did the monitoring run, and over what?

The artefact that answers it
Per-asset detection timestamps and the attributed inventory each run covered, with the date an asset entered scope and the date any asset left it
Where it comes from
Asset Explorer

Who touched our systems, and what did they do?

The artefact that answers it
Each validation probe recorded with its evidence, its timestamp and its outcome, so a challenged finding can be reconstructed rather than re-argued
Where it comes from
Continuous Automated Red-Teaming

Validation runs only where it is safe and authorised. The scan profile, the named exclusions and the rate limit that bounded a run are part of the same record, so the answer to "what did you not test" is written down alongside the answer to "what did you".

What did the team decide about this finding?

The artefact that answers it
The four-state disposition — Needs Review, Investigating, Accepted Risk, Closed — with the assignee, the comment thread and the timestamps
Where it comes from
Action Center

The analyst decision and the scanner’s own detection status are deliberately separate axes: a re-scan can never silently erase a decision a person made, and a decision can never hide an exposure that is still live. Accepted Risk is held as a documented exception rather than a deletion, which is exactly the form an examiner asks for.

Was it handled inside the timeframe our own policy commits to?

The artefact that answers it
SLA policy records, including the breaches
Where it comes from
SLA policies

The breaches are in the record too, and that is deliberate. A monitoring trail showing only the occasions you met your own SLA is not evidence; an auditor who cannot find a single miss in a year stops trusting the whole set.

What has the team actually been doing with findings?

The artefact that answers it
A chronological feed of assignments, status changes, tags, comments and shares, each against the specific finding it was performed on
Where it comes from
Activity logs

Who changed the monitoring configuration itself?

The artefact that answers it
The actor, the action, the source IP and the timestamp for every privileged change — members and roles, integrations and cloud sources, SLA and tag rules, two-factor status
Where it comes from
Audit logs

ShadowMap produces the record. Whether that record satisfies a particular clause is a judgement for your auditor and your advisers.

How the figures are derived

Where the coverage counts come from

A coverage number is only useful if you can see what was counted. These are direct counts of the regulator registry that ships in the product, not a tally maintained separately from the thing it describes.

31 authorities and 91 sources, counted from the registry the monitoring runs against As of August 2026
  • A direct count of the regulator entries configured in the product, read from the same registry the ingestion runs against. When the configuration moves, the numbers move with it.
  • One entry per supervisory, national or standards authority, counted once however many publication streams it operates. The RBI is one authority even though its master directions, master circulars, notifications, press releases and legal-framework pages are each fetched separately.
  • The 91 is the count of those streams — the individual feeds, listing pages and rendered fetches configured across the 31 authorities. India carries 40 of them, the United States 15, the UAE nine, the European Union and the United Kingdom eight each, Singapore five, Australia four, and the global card standards two.
  • 23 of the 31 authorities are outside India, and 15 are American, British or EU-level. Both are counts of the same registry, taken the same way as the 31.
  • Every authority in the count is named in the coverage table above. There is no unpublished remainder inflating the figure.
  • Territory follows the authority that issues the instrument, not the text of the document. Bodies whose standards apply everywhere are carried as global rather than assigned to a country they happen to be incorporated in, which is why seven territories account for 30 of the 31 authorities and the thirty-first sits outside all of them.
  • Regulatory Intelligence is a section of the product with its own preferences and notification frequency, not a briefing somebody compiles by hand each month.

Deliberately excluded

  • No legal interpretation. Nothing here tells you whether an instrument binds your entity.
  • No mapping of a published item to a clause in your own control framework. Where you need that, it is assessment work, and Security Brigade does it properly at securitybrigade.com.
  • No filing, submission or regulatory-reporting workflow. ShadowMap watches what authorities publish; it lodges nothing on your behalf.
  • No claim over material that is not published. Supervisory correspondence addressed to your entity never reaches us, and should not.
  • No scan-derived applicability. This is a shared intelligence stream tailored by the profile you configure, not a match against your discovered assets — and the page says so where it makes the claim, not only here.

Questions buyers actually ask

Before you evaluate this

We are supervised in more than one country. Can the feed be scoped to that?

That is what the preferences are for. You select the authorities, entity types, industries and geographies that apply to you, and the timeline, the counts above it and the notification cadence are all scoped to that selection. Entity types are specific to each authority, and they are configured for six of them: the RBI, SEBI and IRDAI in India, and MAS, CBUAE and APRA outside it. A group supervised by the RBI in India, the FCA in the United Kingdom and MAS in Singapore sets all three and reads one queue rather than holding three subscriptions and reconciling them by hand.

Can it tell us whether a circular applies to our entity?

It can narrow it a long way, and then it stops — deliberately. Items are scoped and prioritised against the profile you configure, and each one carries the entity types the instrument itself names: Scheduled Commercial Bank or NBFC under the RBI, Stock Broker or Registrar and Transfer Agent under SEBI, Major Payment Institution under MAS, Authorised Deposit-taking Institution under APRA. What we will not do is convert that into a determination that the instrument binds you. That is a legal question about your registration and your permissions, and it belongs to your compliance function and your advisers, not to a monitoring platform.

How is this different from subscribing to the regulators we care about?

A subscription gives you everything an authority publishes, and for most financial regulators the overwhelming majority of that is not about security at all. Here the non-cyber body is screened out deterministically before anything is analysed, individual CVE advisories are pushed back to vulnerability management where they belong, and what remains is asked whether it actually changes a rule. What reaches you is then structured rather than attached: the requirements, the entity types, the domains, binding or advisory, and the deadline the document itself states. The second difference is the record. The monitoring around it is dated, scoped and logged, which is the form an auditor asks for and the form an inbox cannot produce.

Which authorities do you track, and can you add one?

All 31 are named in the coverage table on this page — six in the United States, five at EU level, four in the United Kingdom, three in the UAE, two each in Singapore and Australia, eight in India, and the PCI Security Standards Council globally. Adding one is a registry entry and a resync rather than a release, so an authority you are supervised by that is missing is a request rather than a roadmap item. Ask and we will tell you what it would take and when.

See the estate your obligations actually apply to

One apex domain, two business days. The written snapshot carries what we found from outside, and the dated record of the monitoring that found it.