Orientation
Start here before using any module. It explains the learning paths, safe boundaries, offline tools and visual conventions in CyberSafe Defender Studio.
How to Use the Studio
The studio has two layers: a learning layer (Parts 0–10, useful in sequence for newcomers) and a tools layer (the Reference section in the sidebar). It is for citizens, students, teachers, NGOs, cyber volunteers and small organisations building practical, defensive cyber-safety habits.
The Learning Layer — Parts 0 to 10
Parts 0–2 cover foundations and awareness guidance. Parts 3 and 8 show how to plan a safe response and write a useful awareness note. Parts 4 through 6 explore IT, OT/ICS/SCADA and defensive tools in authorised learning environments only. Part 7 is a practice lab with simulations. Part 9 covers AI/ML security, zero trust and supply-chain risk. Part 10 is a portable reference with checklists, a glossary and source links.
Orientation"] --> B["Part 1
Foundations"] B --> C["Part 2
Legal & Regulatory"] C --> D["Part 3
Methodology"] D --> E["Part 4
IT Audit"] D --> F["Part 5
OT/ICS Audit"] E --> G["Part 6
Tools"] F --> G G --> H["Part 7
Simulations Lab"] H --> I["Part 8
Reporting"] I --> J["Part 9
Advanced Topics"] J --> K["Part 10
Annexures"] classDef def fill:#16284a,stroke:#2dd4bf,color:#e8eef9; class A,B,C,D,E,F,G,H,I,J,K def;
Click the small circle next to any module in the sidebar to mark it done. Your progress is saved locally in this browser and shown on the home page radar dashboard and sidebar. No account or login needed — everything is stored in this browser.
CyberSafe Defender Studio can be installed as a desktop or mobile app that works with zero internet — including its interactive learning tools. Open it with the included launcher rather than double-clicking index.html directly.
Windows: Double-click launch-windows.bat in the studio folder. A terminal opens, Python starts a local server, and your browser opens automatically to http://localhost:8765. Look for the "Install Offline App" button in the hero section, or click the install icon in Chrome/Edge's address bar.
Mac: Right-click launch-mac.sh → Open With → Terminal. The server starts and your browser opens automatically. Install from the address bar icon in Chrome.
After installing: The launcher is no longer needed. The installed app opens directly and works offline. Keep the launcher for future use on a new device.
Interactive Reference Tools
The Reference group at the bottom of the sidebar contains ten interactive tools that you use during an engagement — not just to study. They work entirely offline in your browser with no server or login. Here is what each tool does and when to use it.
When: Before entering the field for each audit domain. What it does: One-page print-ready cards for each of the 14 audit domains (4.1 Governance through 5.4 Safety Systems). Each card lists what to test, what evidence to collect, red flags to watch for, and common findings. Filter by IT or OT, print only the domains in your scope, and carry the cards into the field.
When: During audit planning, after the preliminary survey. What it does: Select the entity type (Organisation, organisation-IT, organisation-OT, CII, Autonomous Body), audit type (Compliance, VAPT, VfM, Follow-up), and total available fieldwork days. The builder calculates domain priorities based on entity risk profile, generates a full audit programme table with test procedures and evidence requirements for each domain, and estimates time allocation. Print directly from the browser for your working papers.
When: Continuously during fieldwork as risks are identified. What it does: Log each risk with a title, domain, and 1–5 scores for Likelihood and Impact. The register auto-calculates the Inherent Risk score (L×I), assigns a rating (Critical ≥20 / High ≥12 / Medium ≥6 / Low), and plots all risks live on a 5×5 colour-coded heat-map matrix. Entries persist across sessions. Use this to prioritise findings and brief the auditee on their overall risk profile.
When: Before each interview session. What it does: 156 field-tested questions organised by 11 audit domains and 7 interviewee roles (CISO, Network Admin, System Admin, Application Owner, DBA, Cloud Admin, OT Engineer). Filter by domain and role to build a tailored list for each interview. Check off questions as you ask them — progress saves automatically. Print a session-specific question sheet to take into the interview.
When: When drafting audit findings at end of fieldwork or per day. What it does: A 6-step wizard that guides you through the institutional C5 structure — Criteria, Condition, Cause, Effect, Recommendation. Each step provides pre-built templates for each audit domain that you click to pre-fill and customise. The final step generates a formatted observation paragraph ready to copy into your working papers or inspection report. Always replace placeholder text with specifics from your evidence.
When: At the end of fieldwork, once you have enough evidence to rate the entity. What it does: Rate the entity on 10 cybersecurity dimensions (Governance, IAM, Network, Endpoint, Application, Data Protection, BCP/DR, Incident Response, OT/ICS, Physical) on a 1–5 maturity scale. Generates a live radar chart and a copy-ready summary paragraph for working papers. Scores persist across sessions.
When: When writing findings and needing the correct legal citation. What it does: Maps 11 audit areas to specific clauses in 5 frameworks — applicable cyber law, official incident-response service Directions 2022, data-protection guidance, ISO 27001:2022, and NIST CSF 2.0. Click any clause badge to read exactly what that section requires. Use the reference in the Criteria field of your findings.
When: When establishing legal consequences for the inspection report. What it does: Select the applicable law and violation type. Returns the exact section reference, maximum penalty or consequence, parties liable, enforcement authority, and audit citation notes. Covers 30+ violation types across cyber-safety law, official incident-response service Directions, data-protection guidance, ISO 27001, and NIST CSF 2.0.
When: During training or before your first engagement of a new entity type. What it does: Three end-to-end audit scenarios — Central Organisation, State organisation with OT systems, and Healthcare Entity — showing how a real engagement unfolds from entity profile through risk assessment, fieldwork plan, key findings, and model report paragraphs. All entities are fictional composites, not real institutional audits.
When: After completing the reading layer (Parts 0–10). What it does: 30 questions across 5 themed rounds — Foundations, Legal & Regulatory, Methodology, Technical Audit, and Reporting. Score 24/30 or higher (80%) to earn a printable Completion Certificate with your name. Each question shows a full explanation after answering, so the assessment also serves as a revision session. Your certificate is stored in the browser — enter your name before starting.
The chat bubble in the bottom-right corner of every page is Netraksha (नेत्ररक्षा — "the watching eye that protects"). It is not a connected AI and has no internet access. It answers from the studio’s local learning content and a fuzzy search over page titles and sections, with no data leaving your browser. Ask it about incident reporting, network safety or the Purdue Model and it will point you to a relevant section.
Learning Paths
Not everyone starts from zero, so the manual is tagged by level rather than forced into one track.
| If you are… | Start at | Why |
|---|---|---|
| Beginner New to IT/cybersecurity entirely | Part 0 → Part 1 → Part 2 → Part 3 → Part 4 | You need the vocabulary and legal grounding before any hands-on audit work makes sense. |
| Intermediate Comfortable with IT, new to security audits | Part 2 → Part 3 → Part 4 → Part 6 | Skip straight to methodology and the IT audit domains; skim Part 1 for gaps. |
| Advanced Experienced IT auditor, new to OT/ICS | Part 5 → Part 6 → Part 9 | OT has a fundamentally different risk model — don't assume IT instincts transfer. |
| All Levels Need to write a finding right now | Part 8 → Part 10 | Reporting structure and checklists are useful at any stage of experience. |
Safety Boundaries and Permission
This studio does not grant authority to inspect systems, accounts, records or people. Use it for awareness, authorised labs and defensive learning only. For a real incident, follow the reporting and escalation procedures that apply to you.
Use only with permission
Only review a device, account, network, log or environment when you have clear authorisation from the owner and an appropriate legal basis.
No sensitive case material
Do not enter or upload illegal media, victim information, live case evidence, passwords, tokens or personal data into this app.
Defensive technical practice
Any technical command or simulation in this studio must be used only in an authorised lab or approved defensive scope. Do not bypass access controls, evade detection or target real systems.
Awareness guidance, not legal advice
Legal and reporting material is a starting point for awareness only. Check current official sources or a qualified professional before acting on legal obligations.
Report genuine cybercrime safely
For an actual cybercrime or immediate safety concern, preserve only lawful information, avoid confronting suspects and contact the appropriate official reporting channel or local emergency service.
Official guidance and applicable law take priority. Confirm current information and seek qualified help before taking action on a real incident.
Types of Organisations You'll Audit
"Organisation entity" covers a wide spread of IT/OT maturity. Calibrate your expectations and your audit programme accordingly:
Run e-governance applications, citizen service portals, and back-office systems, often hosted on relevant service provider infrastructure or state data centres / MeghRaj (GI Cloud). Expect a mix of legacy applications and newer cloud-hosted services. IT governance maturity varies enormously by department.
Often operate both corporate IT (ERP, finance, HR) and, in sectors like power, oil & gas, and manufacturing, OT/ICS environments running production. These are your highest-stakes IT+OT audits — see Part 5.
Regulators, universities, research bodies. IT footprints are smaller but often hold sensitive personal or research data, raising data-protection guidance considerations (Part 2).
Municipal corporations, smart city SPVs, water utilities, traffic management — increasingly running SCADA/IoT for utilities and surveillance, frequently with weaker dedicated IT security staffing than central organisations.
Power generation/transmission/distribution, ports, railways, telecom backbone. May fall under critical-infrastructure coordination body-notified "Critical Information Infrastructure" — handle with the heightened sensitivity and coordination described in Part 5.9.
Manual Conventions & Icon Legend
The same visual language is used in every module so you can recognise content type at a glance.
Level badges
Risk / severity badges
Callout types
Background context or a definition you should know.
Practical advice from real audit practice — shortcuts, things to watch for.
A common mistake or a step that's easy to get wrong.
Doing this wrong can disrupt a live system — especially relevant in OT.
Ties the content back to a specific law, rule, or institutional instrument.
Other elements
- Simulation — an interactive, hands-on exercise embedded in the page.
- Knowledge Check — a short scored quiz at the end of a module.
- Diagram — a flowchart, architecture, or process diagram.
monospace text— exact commands, file paths, or configuration values.
If any term in this page was unfamiliar — CIA triad, OT, SCADA, IEC 62443 — start there. If you already audit IT systems, you can jump to Part 2.