Five services for businesses that hold customer data, take payments, or are being asked security questions they cannot yet answer. Every engagement is delivered personally, never subcontracted, and closes with documentation you can file or hand to a client.
Most Indian SMEs can be spoofed and do not know it. Check your own domain before you talk to anyone — including us.
India threat reporting, 2026.
No small-business exemption.
Right now, without any hacking at all, a stranger can send an email that appears to come from your director. For most Indian SMEs this is simply true, and it takes an afternoon to fix.
| Format | Duration | Scale | Fee |
|---|---|---|---|
| Audit & report | 2 days | Single domain | On request |
| Full setup | 1 week | Domain + all senders | On request |
| Setup + enforcement | 6 weeks | Staged to p=reject | On request |
| Ongoing monitoring | Monthly | Report + adjustments | On request |
Fixing spoofing before running a phishing simulation means the simulation measures your people rather than a hole in your DNS. It is also the cheapest security work with a visible result, which makes it a sensible way to find out whether you want to work with us at all.
Controlled, harmless simulated phishing emails that measure how your organisation actually behaves. You get a number, not an opinion.
| Format | Duration | Scale | Fee |
|---|---|---|---|
| Baseline Simulation | 1 campaign | Up to 50 staff | On request |
| Baseline + Debrief | 1 campaign + session | Up to 50 staff | On request |
| Simulate–Train–Retest | 2 campaigns + training | Up to 50 staff | On request |
| Quarterly Programme | 4 campaigns/yr | Whole company | On request |
No passwords are ever captured. Results are reported in aggregate, and individual results are used only for targeted training — never for disciplinary action. Written authorisation is required before any campaign begins.
A structured assessment of your web application or network for known weaknesses — every automated finding validated by hand, prioritised by real risk to your business, and written so your developers can act on it.
| Format | Duration | Scale | Fee |
|---|---|---|---|
| Web application | 3–5 days | Single application | On request |
| External network | 2–4 days | Public-facing assets | On request |
| Attack surface review | 1–2 days | Passive OSINT only | On request |
| Retest | 1 day | Previously reported findings | Included once |
This is a vulnerability assessment. It identifies and validates weaknesses and rates them by risk. It is not a full penetration test — we do not attempt to exploit findings, chain them together or demonstrate breach impact. Plenty of providers sell one and call it the other. We would rather tell you the difference and let you decide which one you actually need.
No testing of any kind begins without a signed authorisation naming the exact systems, the agreed window and the permitted techniques. Testing a system without written authorisation is an offence under the Information Technology Act 2000. We hold ourselves to the same standard we teach our students.
India's Digital Personal Data Protection Rules were notified in November 2025. Core obligations become fully enforceable in May 2027. If you collect customer data, this applies to you.
| Format | Duration | Scale | Fee |
|---|---|---|---|
| Readiness Check | 1 week | Assessment only | On request |
| Essentials Pack | 3 weeks | Assessment + core docs | On request |
| Complete Pack | 6 weeks | Full documentation + training | On request |
| Annual Review | 1 week/yr | Reassessment + refresh | On request |
SpiderX Defense is a cybersecurity practice, not a law firm. This engagement does not constitute legal advice, and there is no such thing as a DPDP certification. We provide a readiness assessment and documentation — the compliance obligation remains yours as Data Fiduciary.
Practical training for the people attackers actually target — accounts, sales, HR and operations. Built around your business, not a generic template.
| Format | Duration | Scale | Fee |
|---|---|---|---|
| Awareness session — onsite | 2 hours | Up to 40 staff | On request |
| Awareness session — online | 2 hours | Up to 60 staff | On request |
| Extended session | 4 hours | Up to 40 staff | On request |
| Annual programme | 4 sessions/yr | Whole company | On request |
If a client has sent you a security questionnaire asking whether staff receive awareness training, tell us — we will make sure the documentation answers it directly.
Start with a scoping conversation at no charge. Tell us what you are trying to solve and we will tell you honestly whether we are the right fit — or point you elsewhere if we are not.