Published by EC-Council Udyam UP-28-0231982 Greater Noida · Delhi NCR
Home / Business
For SMEs, startups and growing businesses

Security work that ends
with a number, not an opinion.

Five services for businesses that hold customer data, take payments, or are being asked security questions they cannot yet answer. Every engagement is delivered personally, never subcontracted, and closes with documentation you can file or hand to a client.

Written authorisation first, always Findings validated by hand Documentation as standard
Jump to: Security Awareness Phishing Simulation Email Security Vulnerability Assessment DPDP Readiness
Business services
For business

Email Security Hardening

Right now, without any hacking at all, a stranger can send an email that appears to come from your director. For most Indian SMEs this is simply true, and it takes an afternoon to fix.

What it covers

  • Full audit of your current SPF, DKIM and DMARC records
  • SPF record built correctly, within the ten-lookup limit
  • DKIM signing configured and verified for every sending service
  • DMARC deployed in monitoring mode, then moved to enforcement in stages
  • Every legitimate sender identified — your mail host, CRM, invoicing tool, marketing platform
  • Aggregate report monitoring so nothing legitimate is silently blocked
  • MTA-STS and TLS reporting where it applies

What you receive

  • Before-and-after audit showing exactly what changed
  • Documented record of every DNS entry and why it exists
  • A register of every service authorised to send as your domain
  • Monthly monitoring report in plain language
  • A staged enforcement plan — monitor, then quarantine, then reject
FormatDurationScaleFee
Audit & report2 daysSingle domainOn request
Full setup1 weekDomain + all sendersOn request
Setup + enforcement6 weeksStaged to p=rejectOn request
Ongoing monitoringMonthlyReport + adjustmentsOn request

Why this is usually the right first step

Fixing spoofing before running a phishing simulation means the simulation measures your people rather than a hole in your DNS. It is also the cheapest security work with a visible result, which makes it a sensible way to find out whether you want to work with us at all.

For business

Phishing Simulation

Controlled, harmless simulated phishing emails that measure how your organisation actually behaves. You get a number, not an opinion.

What it covers

  • Baseline campaign against your staff using realistic, non-distressing themes
  • Measurement of click rate, credential submission and — critically — report rate
  • Department-level breakdown of exposure
  • Awareness session built around your actual results
  • Retest after 4–6 weeks with a comparison report
  • Quarterly programme option for ongoing measurement

What you receive

  • Confidential campaign report with full metrics
  • Department-level analysis
  • Prioritised recommendations
  • Before-and-after comparison for retest engagements
  • Annual summary suitable for audit and insurance evidence
FormatDurationScaleFee
Baseline Simulation1 campaignUp to 50 staffOn request
Baseline + Debrief1 campaign + sessionUp to 50 staffOn request
Simulate–Train–Retest2 campaigns + trainingUp to 50 staffOn request
Quarterly Programme4 campaigns/yrWhole companyOn request

Important

No passwords are ever captured. Results are reported in aggregate, and individual results are used only for targeted training — never for disciplinary action. Written authorisation is required before any campaign begins.

For business

Vulnerability Assessment

A structured assessment of your web application or network for known weaknesses — every automated finding validated by hand, prioritised by real risk to your business, and written so your developers can act on it.

What it covers

  • Written scope and authorisation agreed before any testing begins
  • Asset and service discovery within the agreed scope only
  • Automated vulnerability scanning across the defined targets
  • Manual validation of every finding — false positives removed, not passed on
  • Configuration and hardening review against published benchmarks
  • Authentication, session and access control checks
  • Risk rating using CVSS with business context applied

What you receive

  • Findings report with evidence, severity and reproduction steps
  • Remediation guidance written for developers, not for auditors
  • A prioritised fix list — what to do this week, this month, this quarter
  • Executive summary for people who will not read the technical detail
  • One free retest of remediated findings within 30 days
FormatDurationScaleFee
Web application3–5 daysSingle applicationOn request
External network2–4 daysPublic-facing assetsOn request
Attack surface review1–2 daysPassive OSINT onlyOn request
Retest1 dayPreviously reported findingsIncluded once

What this is, and what it is not

This is a vulnerability assessment. It identifies and validates weaknesses and rates them by risk. It is not a full penetration test — we do not attempt to exploit findings, chain them together or demonstrate breach impact. Plenty of providers sell one and call it the other. We would rather tell you the difference and let you decide which one you actually need.

Authorisation is not optional

No testing of any kind begins without a signed authorisation naming the exact systems, the agreed window and the permitted techniques. Testing a system without written authorisation is an offence under the Information Technology Act 2000. We hold ourselves to the same standard we teach our students.

For business

DPDP Act Readiness

India's Digital Personal Data Protection Rules were notified in November 2025. Core obligations become fully enforceable in May 2027. If you collect customer data, this applies to you.

What it covers

  • Structured gap assessment against the Act and the Rules
  • Complete data inventory — what you hold, why, where, and for how long
  • Consent framework and point-of-collection notices
  • Data Principal rights process — access, correction, erasure, grievance
  • Retention and secure deletion schedule
  • Vendor and processor register with contractual gap analysis
  • Breach response plan and staff briefing

What you receive

  • Data inventory register you can maintain after we leave
  • Gap assessment report with findings rated by severity
  • Privacy notice and consent notice in plain language
  • Documented rights request process with a request log
  • Two-page breach response action card
  • Implementation roadmap with named owners and dates
FormatDurationScaleFee
Readiness Check1 weekAssessment onlyOn request
Essentials Pack3 weeksAssessment + core docsOn request
Complete Pack6 weeksFull documentation + trainingOn request
Annual Review1 week/yrReassessment + refreshOn request

Important

SpiderX Defense is a cybersecurity practice, not a law firm. This engagement does not constitute legal advice, and there is no such thing as a DPDP certification. We provide a readiness assessment and documentation — the compliance obligation remains yours as Data Fiduciary.

For business

Security Awareness Training

Practical training for the people attackers actually target — accounts, sales, HR and operations. Built around your business, not a generic template.

What it covers

  • Phishing and email fraud — spotting a fraudulent email before clicking
  • Business email compromise — the fake payment instruction
  • Payment and UPI fraud — vendor bank changes, QR fraud, OTP social engineering
  • Passwords and accounts — password managers and multi-factor authentication
  • Social engineering — manipulation over phone and messaging
  • Incident reporting — why speed matters more than blame

What you receive

  • Staff desk reference card for every attendee
  • Signed attendance record
  • Individual completion certificates
  • Training summary report for client questionnaires, audits and insurance
  • Private recommendations note for management
FormatDurationScaleFee
Awareness session — onsite2 hoursUp to 40 staffOn request
Awareness session — online2 hoursUp to 60 staffOn request
Extended session4 hoursUp to 40 staffOn request
Annual programme4 sessions/yrWhole companyOn request

Good to know

If a client has sent you a security questionnaire asking whether staff receive awareness training, tell us — we will make sure the documentation answers it directly.

Not sure which service fits?

Start with a scoping conversation at no charge. Tell us what you are trying to solve and we will tell you honestly whether we are the right fit — or point you elsewhere if we are not.