guides
Security Guides
Step-by-step cybersecurity guides covering VAPT, compliance, and protecting your Indian business from cyber threats.
108 articles
How to Roll Out a Password Manager Across an Indian SMB
A vendor-neutral rollout guide for Indian SMBs: pilot, bulk import, dedupe reused passwords, forced rotation, shared vaults, MFA, and offboarding revocation.
End-of-Life Software Risk: An EOL Guide for Indian SMBs
What end-of-support really means for risk, compliance and insurance, how to build an EOL register, and the honest options when you cannot upgrade right away.
Asset Inventory: The Foundation of Security Visibility in India
You cannot secure what you cannot see. Learn how a live asset inventory of servers, SaaS, and domains drives patching, VAPT scope, and incident response.
Business Email Compromise (BEC): How It Works & Defense
How Business Email Compromise (BEC) fraud works — CEO fraud, invoice scams, payroll diversion — and the SPF, DKIM, DMARC, and payment controls that stop it.
The 3-2-1 Backup Rule for Ransomware Recovery in India
Learn the 3-2-1 backup rule for ransomware recovery: immutable copies, offsite storage, RPO/RTO targets, and a tested recovery runbook for Indian SMBs.
Phishing-Resistant MFA: Why It's Time to Move Beyond OTP and SMS
Phishing-resistant MFA explained: why SMS and app OTP get bypassed via SIM swap and real-time phishing, and how to migrate to FIDO2 passkeys and keys.
Vendor Risk Management: Third-Party Security Guide for India
A practical vendor risk management guide for Indian SMBs — risk tiering, SOC 2/ISO 27001 evidence, DPDP contract clauses, and continuous vendor monitoring.
Incident Response Plan: A Step-by-Step Template for SMBs
A step-by-step incident response plan template for Indian SMBs, built on NIST SP 800-61 phases, RACI roles, escalation, and the CERT-In 6-hour reporting rule.
Building a Vulnerability Management Program in India
A practical guide for Indian SMBs to build a vulnerability management program: asset inventory, continuous scanning, CVSS/EPSS prioritisation, and SLAs.
Security Checklist Before Launching a Web App in India
A practical pre-launch web app security checklist for Indian founders covering auth hardening, TLS, security headers, DPDP data handling, and a final VAPT.
How Often Should You Run a VAPT: A Cadence Guide for India
Learn the right VAPT testing cadence for Indian SMBs and fintechs — annual baselines, release triggers, continuous scanning, and compliance requirements.
VAPT vs Vulnerability Scanning: Know the Real Difference
Automated vulnerability scanning vs full VAPT penetration testing: what each finds and misses, and which Indian SMBs need for real compliance readiness.
File Inclusion Attacks: LFI and RFI Explained for Devs
How LFI and RFI let attackers hijack include() and require() calls for disclosure or RCE, plus the allow-list defences Indian dev teams need to ship safely.
Bug Bounty Programs: Should Your Indian Startup Launch One?
A decision guide for Indian startup founders on bug bounty readiness, VDP vs private vs public programs, safe-harbour scope, and why VAPT should come first.
Security on a Zero Budget: Hardening a Startup Pre-Funding
The highest-impact free security controls Indian startups can enable before their first funding round — MFA, backups, patching, and email authentication.
10 Free Security Tools Every Indian Startup Should Use
A curated list of free and open-source security tools Indian startups can use for vulnerability scanning, secrets detection, MFA, and breach monitoring.
Your First Penetration Test: A Preparation Checklist for SMBs
A complete first penetration test preparation checklist for Indian SMBs: define scope, choose test type, set rules of engagement, and plan remediation.
CVSS Scores Explained: How to Prioritise Vulnerabilities
A practical guide to CVSS v3.1 and v4.0 scoring, severity bands, and why base scores alone often mislead vulnerability prioritisation for Indian teams.
How to Read a VAPT Report: A Founder Guide to Findings
A plain-English walkthrough of every VAPT report section — severity, CVSS, PoC, remediation — so Indian founders can prioritise fixes and track closure fast.
Free VAPT for Startups: Zero-Cost Security Audits in India
Free VAPT scans give Indian startups a zero-cost security baseline. Learn what they cover, what they miss, and exactly when a full paid audit becomes necessary.
OSINT Recon: How Attackers Profile Your Company First
How attackers use OSINT reconnaissance to profile Indian SMBs before a phishing attack, and the counter-OSINT defences that shrink your public attack surface.
Student Job Scams: Fake Internships and Deposit Fraud
Fake internships, placement offers, and part-time jobs that demand a deposit or fee first are scams. Learn the red flags and how to recover if you've paid.
Protecting Elderly Parents From Scams: A Practical Guide
A practical guide to protecting elderly parents from scams in India, covering the real scripts, red flags, family rules, and what to do if they already paid.
AI Voice Cloning Scam: When the Panicked Call Is Not Family
A cloned voice of your relative claims an accident or arrest and demands secret money now. Learn the family safe word defence and how to recover fast.
Fake Shopping Sites: Deep Discounts That Take Your UPI Money
Fake shopping sites lure buyers with steep discounts, demand UPI QR payment instead of a real checkout, then use a fake refund fee to take more money.
UPI Collect Request Scam: Approving It Sends Your Money
A UPI collect request looks like an incoming payment, but approving it and typing your PIN sends money out. Know the red flags and recovery steps to take.
Wrong UPI Transfer Scam: The Refund Request That Robs You
A stranger claims they sent money by mistake and asks for a refund via QR code — but scanning it debits you instead. Here's how to spot it and recover fast.
SIM Swap Fraud: When Losing Signal Means You Are Being Robbed
Sudden loss of mobile signal can mean SIM swap fraud is underway. Learn the warning signs, what to do immediately, and how Sanchar Saathi helps you check.
OTP Fraud: Why an Unrequested OTP Means You Are Targeted
Learn every pretext scammers use to steal your OTP, from fake refunds to bank security checks, and the exact steps to take if you have already shared one.
Lottery and Prize Scams: Why Winners Never Pay to Collect
A call or message claims you have won a lottery or prize, then demands a fee to release it. Learn the red flags, what to do now, and how to recover fast.
Investment Trading Group Scam: Fake Profits You Can't Withdraw
Fake SEBI tip groups on WhatsApp and Telegram show fabricated profits, then demand tax or fees before you can withdraw. Here's how to spot it and recover fast.
Fake Customer Care Number Scam: The Refund That Debits You
Scammers plant fake customer care numbers in search results and Maps listings, then ask you to scan a QR code or PIN to get a refund that debits you instead.
KYC Update Scam: The Account Blocked Message Is Fake
A KYC-expiry SMS or call warning your bank account will be blocked today is a scam. Learn the real script, red flags, and how to recover your money fast.
Electricity Bill Scam SMS: The Fake Disconnection Warning
Got an SMS threatening electricity disconnection tonight over an unpaid bill? Here is how the fake remote-access app scam behind it works, and how to stay safe.
Fake Courier Parcel Scam: How the Customs Call Escalates
A call claims your parcel holds drugs, then a fake customs officer threatens arrest. How the scam escalates, and how to verify a real courier or customs call.
Sextortion Video Call Scam: What to Do and Never Do
A stranger video-calls you, secretly records it, then demands money or threatens to leak it. Here is exactly what to do, and never do, if this happens.
Romance and Matrimonial Scams: The Long Con on Indian Users
A romance or matrimonial scam builds months of fake intimacy before a manufactured crisis. Learn the real script, red flags, and how to recover your money fast.
Instant Loan App Scam: Harassment, Blackmail and Your Rights
Predatory instant loan apps demand your contacts and photos, then blackmail you with morphed images over unpaid dues. How to recognise it and fight back.
Task Scam on Telegram: The Fake Work-From-Home Job Trap
Fake work-from-home jobs on Telegram pay tiny amounts to build trust, then demand UPI deposits to unlock earnings that never arrive. Spot it, stop it, recover.
UPI QR Sticker Swap Scam: When You Pay the Wrong UPI ID
A fake QR sticker pasted over a shop's real one sends your UPI payment straight to a scammer. Learn the red flags, what to do right now, and how to recover it.
Digital Arrest Scam: How Fake Police Calls Drain Life Savings
Digital arrest scam explained: how fake CBI, police or ED video calls trap victims and drain their savings, plus exact steps to report and recover money.
Secure Code Review Checklist for Indian Development Teams
A practical secure code review checklist for Indian dev teams: authorization, tenant scoping, secrets, deserialization, and crypto flaws that SAST misses.
How to Scope a VAPT Engagement: An RFP Guide for India
A practical guide to scoping a VAPT engagement and writing a penetration-test RFP for Indian companies, from asset inventory to retest rights and reports.
BYOD Security in India: MDM Without Invading Privacy
Compare full MDM, work-profile containerisation, and app-level MAM to secure company data on personal devices without breaching employee privacy under DPDP.
Shadow IT Discovery: Find the SaaS Apps Nobody Told IT About
Shadow IT discovery helps Indian businesses find unsanctioned SaaS apps holding company data, cutting DPDP compliance risk before it becomes a breach.
E-commerce Account Takeover Fraud: Protecting Indian Retailers
Learn how account takeover fraud drains e-commerce wallets and loyalty points via credential stuffing, and the MFA and rate-limiting controls that stop it.
Employee Offboarding Security Checklist for Indian Businesses
Employee offboarding security checklist for Indian businesses: revoke every access, rotate shared credentials, and recover devices before staff exit risks.
Tabletop Exercises: Testing Your Incident Response Plan
Learn how tabletop exercises test your incident response plan in India, revealing real gaps in ownership, contacts, and legal readiness before a breach.
Business Email Compromise (BEC): How Indian Firms Lose Money
Business Email Compromise (BEC) drains Indian businesses via CEO fraud and invoice fraud. Learn the attack pattern and a practical prevention checklist.
Red Team vs Blue Team vs Purple Team: A Guide for India
A guide to red team, blue team, and purple team testing for Indian security teams: how it differs from VAPT and when your company needs each stage of maturity.
Vulnerability Disclosure Policy: A Guide for Indian Companies
A practical guide to writing a Vulnerability Disclosure Policy for Indian companies: safe harbor language, intake, triage SLAs, and disclosure timelines.
Third-Party Vendor Risk Management for Indian Businesses
A practical guide to third-party vendor risk management for Indian SMBs, covering assessments, questionnaires, contract clauses, and ongoing monitoring.
Dark Web Monitoring India: Complete Guide for Indian Businesses
Dark web monitoring helps Indian businesses detect stolen credentials and data leaks faster. Learn detection workflows, response steps, and DPDP compliance.
Insider Threat Detection India: Complete Prevention Guide
Learn how to detect insider threats in India before a costly breach. Covers UEBA signals, DLP, privileged access, offboarding, and DPDP Act compliance steps.
Ransomware Defense India: Complete Playbook for Indian SMBs
Learn how Indian SMBs can defend against ransomware: kill-chain breakdown, entry vectors, backup strategy, DPDP breach obligations, and CERT-In reporting steps.
Security Champions Program for Indian Tech Companies
A security champions program embeds developer-led security into every squad. Here's how Indian tech companies can build and run one that actually works.
UPI Payment Security: Fraud Prevention for Indian Businesses
Protect your business from UPI payment fraud in India. Covers fake QR code attacks, SIM swap, vishing, and the security controls every Indian SMB must deploy.
Phishing Simulation and Social Engineering Defense in India
Learn how phishing simulations and social engineering awareness training protect Indian companies from credential theft, BEC fraud, and data breaches.
DevSecOps Pipeline for Indian Startups: Shift Left Security
Learn how to implement a DevSecOps pipeline that embeds security into every SDLC stage. A practical shift left security guide for Indian startup teams and CTOs.
Cloud Backup Strategy and the 3-2-1 Rule for Indian SMBs
Cloud backup is the top ransomware control Indian SMBs miss. Learn the 3-2-1 and 3-2-1-1-0 rules, immutable backups, RPO/RTO, and a practical backup policy.
Attack Surface Management for Indian SMBs: A Practical Guide
Attack surface management helps Indian SMBs discover and monitor every exposed asset continuously. Learn the ASM lifecycle and build a low-cost routine.
Incident Response Plan for Indian SMBs: A Step-by-Step Playbook
Build an incident response plan for Indian SMBs meeting CERT-In's 6-hour mandate — with first-hour checklist, RACI, DPDP obligations, and NIST 800-61 phases.
Cybersecurity Budget for Indian SMBs: Spend First Here
Risk-based cybersecurity budgeting for Indian SMBs — prioritize MFA, backups, patching, and VAPT to reduce breach risk and meet DPDP and CERT-In obligations.
Patch Management for Indian SMBs: Fix Vulnerabilities Fast
Patch management stops breaches before they start. Learn how Indian SMBs prioritize CVEs with CVSS, EPSS, and CISA KEV to build a practical patching program.
How to Read a VAPT Report: Guide for Indian Founders and Boards
Learn how to read a VAPT report: interpret CVSS scores, severity ratings, and remediation steps so Indian founders and boards make confident security decisions.
Cyber Insurance in India: What It Covers and How to Qualify
Cyber insurance in India covers breach response, ransomware, and regulatory defence. Learn what controls insurers require to qualify and lower your premium.
Business Continuity and Disaster Recovery for Indian SMBs
BCP and DR planning for Indian SMBs: RTO, RPO, 3-2-1 backups, failover runbooks, cloud DR options, and DPDP/CERT-In compliance requirements in plain language.
Bug Bounty vs VAPT: What Indian Companies Should Choose
Bug bounty vs penetration testing for Indian companies: key differences in compliance value, cost, and coverage — and why VAPT must come first for SMBs.
Third-Party Vendor Risk Management for Indian Companies
TPRM for Indian SMBs: build a vendor inventory, tier by risk, enforce DPAs under DPDP Act 2023, and assess vendor security posture before a breach costs you.
Security Awareness Training for Indian Employees: Full Guide
Security awareness training for Indian employees builds a human firewall. Phishing simulations, role-based training, India lures, and DPDP Act 2023 obligations.
Multi-Factor Authentication: Guide for Indian Businesses
Multi-factor authentication blocks 99% of credential attacks. Understand factor types, bypass methods like SIM swap and AiTM, and deploy MFA for Indian SMBs.
WAF for Indian SMBs: How It Works and When You Need One
A WAF filters malicious HTTP traffic before it hits your server. Learn how WAFs work, what they block, how they compare to VAPT, and when Indian SMBs need one.
Insider Threats in Indian Companies: Detect & Prevent
Insider threats are rising in Indian companies. Detect malicious, negligent, and compromised insiders and apply prevention controls aligned with DPDP Act 2023.
Email Authentication for Indian Businesses: SPF, DKIM and DMARC
SPF, DKIM and DMARC stop email spoofing and BEC attacks on Indian SMBs. Step-by-step guide to DNS records, alignment, DMARC reports and mistakes to avoid.
Zero Trust Architecture for Indian Enterprises: A Practical Guide
Zero Trust Architecture — never trust, always verify — is the security baseline for Indian enterprises facing DPDP, remote work, and credential breaches.
Ransomware Readiness for Indian SMBs: 12 Key Controls
Ransomware readiness checklist for Indian SMBs: 12 controls covering backups, MFA, EDR, and CERT-In 6-hour reporting to stop attacks before encryption.
Penetration Testing vs Vulnerability Scanning: SMB Guide
Penetration testing and vulnerability scanning are not the same. Learn the real difference and how Indian SMBs can build a VAPT program for DPDP compliance.
VAPT for Indian Startups: Why Annual Penetration Testing Is No Longer Optional
Indian startups handling payments, user data, or enterprise clients now face a hard truth: skipping annual VAPT risks failed vendor audits, regulatory exposure under SEBI CSCRF, RBI, and DPDP, and los
Fake UPI QR Code Scams: How to Spot and Avoid Them Before You Pay (2026 Guide)
Fake UPI QR codes are replacing genuine merchant QRs across India. Learn how the scam works, the five checks to make before every payment, what merchants can do, and how to report fraud to 1930 and cy
DPDP Data Breach in India: Your 72-Hour Incident Response Playbook
Step-by-step DPDP Act breach notification playbook for Indian companies. Hour-by-hour guide from detection to DPB notification — with templates and checklists.
Case Study: Enterprise Reduced External Attack Surface 60% in 90 Days
A 4,000-employee enterprise with operations across 6 Indian cities discovered 412 internet-exposed assets in their first month of ASM. By day 90, they had decommissioned, secured, or migrated 247 of them — a 60% surface reduction.
Attack Surface Management India — Bachao.AI Methodology
Bachao.AI's ASM service for Indian enterprises: continuous external attack surface discovery, exposed credential monitoring, third-party risk monitoring. Pricing per asset class, not per endpoint.
Case Study: SaaS Startup Shifted Left, Reduced Production Vulns 80%
A 70-engineer SaaS company had a backlog of 340 known vulnerabilities and a SOC 2 auditor asking how they'd reduce it. Bachao.AI's DevSecOps implementation reduced production vulnerabilities 80% in 6 months — and engineering velocity went up.
DevSecOps Implementation India — Bachao.AI Methodology
Bachao.AI's DevSecOps methodology for Indian SaaS engineering teams: SAST in CI, SCA dependency scanning, secrets detection, container/IaC security, runtime protection. 6-week implementation, then ongoing retainer.
Case Study: Court-Admissible WhatsApp Forensics for Mumbai Corporate Fraud
A Mumbai listed company suspected its procurement head was taking vendor kickbacks. WhatsApp evidence on company-issued and personal phones became central to the investigation. Bachao.AI's forensic team produced Section 65B-certified evidence used in arbitration.
Cyber Forensics India — Bachao.AI Methodology
Bachao.AI's cyber forensics methodology for Indian corporate fraud investigations: court-admissible evidence chain, IT Act Section 65B certification, e-discovery for litigation, mobile device forensics. Used by Indian law firms, in-house counsel, and law enforcement liaison.
Case Study: Fintech API Security Audit Found BOLA + Rate Limit Bypass
A Mumbai fintech with 4 lakh borrowers had Bachao.AI audit their lending platform API. BOLA on the loan-detail endpoint allowed any user to read any other user's loan. Rate limit bypass enabled scraping. Both closed in 1 week.
API Security Testing India — Bachao.AI Methodology
Bachao.AI's API security testing covers OWASP API Top 10 (2023) + India-specific fintech API patterns. BOLA, broken auth, rate limit bypass, mass assignment, SSRF. 4-day delivery for typical SaaS APIs.
Case Study: UPI App Hardened Against MASVS Findings Before RBI Audit
A UPI app with 12 lakh active users had a scheduled RBI audit in 6 weeks and 23 MASVS findings flagged. The Bachao.AI mobile pentest + remediation sprint closed all findings 2 weeks before the audit.
Mobile App Penetration Testing for Indian Fintechs — Bachao.AI Methodology
Bachao.AI's mobile app pentest covers OWASP MASVS L1 + L2, RBI mobile banking security requirements, and the most common Indian fintech findings. iOS + Android, native + React Native + Flutter.
Case Study: Bengaluru SaaS Closed 47 AWS Misconfigs in 2 Weeks
A 45-person Bengaluru SaaS company on the path to SOC 2 had 47 AWS misconfigurations flagged in audit. Working with Bachao.AI, they closed 41 critical findings in 2 weeks and the remaining 6 in 6 weeks. Series B due diligence cleared.
AWS Security Audit India — Bachao.AI Methodology
Bachao.AI's AWS security audit covers IAM, network, data, logging, incident response, and compliance. 5-day delivery for typical SaaS workloads. Aligned to AWS Well-Architected Security Pillar + CIS AWS Foundations Benchmark.
Case Study: Chennai NBFC Ransomware Contained in 4 Hours
A Chennai-based NBFC discovered ransomware encrypting servers at 2:47 AM. By 6:51 AM, the attack was contained, evidence was preserved, and CERT-In Rule 3 notification was filed. Here's what happened.
Cyber Incident Response in India — Bachao.AI Methodology
How Bachao.AI handles cyber incidents for Indian companies: 30-minute initial response SLA, CERT-In 6-hour reporting, DPB India notification workflow, and the playbooks for ransomware, breach, and insider threat.
Case Study: Mumbai Bank Red Team Exercise Revealed 4 Critical Detection Gaps
A mid-tier Mumbai-based bank engaged Bachao.AI for an 8-week red team exercise. The blue team detected 7 of 11 attack chains. The 4 missed chains became the priority detection roadmap. Here's what happened.
Red Team Methodology India — How Bachao.AI Runs Adversary Simulation
Bachao.AI's red team methodology for Indian banks, fintechs and large enterprises. Three-phase engagement: reconnaissance, exploitation, detection-evasion testing. Aligned to MITRE ATT&CK + TIBER-EU principles.
Case Study: Mid-Tier Stockbroker Met June 30 SEBI Deadline with 4-Day Audit
A Mumbai-based stockbroker with 80 critical systems and a hard SEBI CSCRF deadline 5 weeks away got their audit submitted in 4 working days. Here's exactly how, and what the audit revealed.
Sample SEBI CSCRF Audit Report (NSE-Submission Format)
What a Bachao.AI-delivered SEBI CSCRF audit report looks like: the table of contents, the findings template, the management certification, and the evidence index. The exact structure that NSE/BSE expects.
SEBI CSCRF Audit Methodology — Bachao.AI 7-Day Sprint
How Bachao.AI delivers a SEBI Cybersecurity & Cyber Resilience Framework audit in 7 working days: scoping, scanning, control mapping, sample testing, and NSE-submission-format report. The exact day-by-day delivery.
Case Study: NBFC Reduced MTTR from 6 Hours to 22 Minutes with Bachao MSSP
A mid-tier NBFC with 240 employees, 3 million customers, and a 6-hour mean time to respond got down to 22 minutes within 4 months. Here's exactly what changed.
Sample MSSP Monthly Report: What Indian Buyers Get
A real (redacted) example of the monthly report Bachao.AI MSSP customers receive. SLO scorecard, S1+S2 incident log, detection coverage map, and the next-30-day detection roadmap.
MSSP for Indian SMBs — Bachao.AI 24×7 SOC Methodology
What a Bachao.AI MSSP engagement looks like operationally: 24×7 SOC tier 1 + tier 2 staffing, mean-time-to-detect under 4 minutes, mean-time-to-respond under 22 minutes, monthly compliance reporting. Pricing per workload, not per endpoint.
Case Study: How a Bengaluru Fintech Used vCISO to Close Series B Security Diligence
Real engagement: a 65-person Bengaluru-based digital lending startup needed SOC 2 Type II readiness in 12 weeks to close their Series B lead investor's diligence requirement. Here's how the Bachao.AI vCISO did it.
Sample vCISO Deliverables: Risk Register, Policy Set, 90-Day Roadmap
What does a Bachao.AI vCISO actually hand over? Real (redacted) samples of the Risk Register, the Acceptable Use Policy, the Incident Response Playbook, and the 90-day Security Roadmap.
vCISO Engagement Methodology — How Bachao.AI Delivers in 90 Days
What a vCISO engagement looks like day-by-day at Bachao.AI: 2-week current-state assessment, 4-week policy + risk register sprint, 6-week compliance closure. The exact deliverables, owners, and review checkpoints.
Virtual CISO Services in India: What You Get, What You Pay, When You Need One (2026)
Virtual CISO (vCISO) services give Indian startups senior security leadership at a fraction of a full-time CISO cost. What a vCISO delivers, what it costs in India (₹1.5L–₹5L/month), and exactly when you need one.
How to Read a VAPT Report: A CTO's Guide
A practical guide for CTOs and tech leaders to understand every section of a VAPT report, interpret CVSS scores, and prioritize remediation effectively.
Security Headers Every Indian Website Needs (With Implementation Guide)
A complete implementation guide for HTTP security headers -- CSP, HSTS, X-Frame-Options, and more -- with copy-paste configs for Nginx, Apache, and Next.js.