How to Use the Studio

The studio has two layers: a learning layer (Parts 0–10, useful in sequence for newcomers) and a tools layer (the Reference section in the sidebar). It is for citizens, students, teachers, NGOs, cyber volunteers and small organisations building practical, defensive cyber-safety habits.

The Learning Layer — Parts 0 to 10

Parts 0–2 cover foundations and awareness guidance. Parts 3 and 8 show how to plan a safe response and write a useful awareness note. Parts 4 through 6 explore IT, OT/ICS/SCADA and defensive tools in authorised learning environments only. Part 7 is a practice lab with simulations. Part 9 covers AI/ML security, zero trust and supply-chain risk. Part 10 is a portable reference with checklists, a glossary and source links.

graph LR A["Part 0
Orientation"] --> B["Part 1
Foundations"] B --> C["Part 2
Legal & Regulatory"] C --> D["Part 3
Methodology"] D --> E["Part 4
IT Audit"] D --> F["Part 5
OT/ICS Audit"] E --> G["Part 6
Tools"] F --> G G --> H["Part 7
Simulations Lab"] H --> I["Part 8
Reporting"] I --> J["Part 9
Advanced Topics"] J --> K["Part 10
Annexures"] classDef def fill:#16284a,stroke:#2dd4bf,color:#e8eef9; class A,B,C,D,E,F,G,H,I,J,K def;
Recommended path through the studio. Choose the IT or OT path based on the systems you are learning about; do not test real systems without explicit permission.
Mark sections complete as you go

Click the small circle next to any module in the sidebar to mark it done. Your progress is saved locally in this browser and shown on the home page radar dashboard and sidebar. No account or login needed — everything is stored in this browser.

Install as an offline app

CyberSafe Defender Studio can be installed as a desktop or mobile app that works with zero internet — including its interactive learning tools. Open it with the included launcher rather than double-clicking index.html directly.

Windows: Double-click launch-windows.bat in the studio folder. A terminal opens, Python starts a local server, and your browser opens automatically to http://localhost:8765. Look for the "Install Offline App" button in the hero section, or click the install icon in Chrome/Edge's address bar.

Mac: Right-click launch-mac.sh → Open With → Terminal. The server starts and your browser opens automatically. Install from the address bar icon in Chrome.

After installing: The launcher is no longer needed. The installed app opens directly and works offline. Keep the launcher for future use on a new device.

Interactive Reference Tools

The Reference group at the bottom of the sidebar contains ten interactive tools that you use during an engagement — not just to study. They work entirely offline in your browser with no server or login. Here is what each tool does and when to use it.

Fieldwork Print Cards

When: Before entering the field for each audit domain. What it does: One-page print-ready cards for each of the 14 audit domains (4.1 Governance through 5.4 Safety Systems). Each card lists what to test, what evidence to collect, red flags to watch for, and common findings. Filter by IT or OT, print only the domains in your scope, and carry the cards into the field.

Audit Programme Builder

When: During audit planning, after the preliminary survey. What it does: Select the entity type (Organisation, organisation-IT, organisation-OT, CII, Autonomous Body), audit type (Compliance, VAPT, VfM, Follow-up), and total available fieldwork days. The builder calculates domain priorities based on entity risk profile, generates a full audit programme table with test procedures and evidence requirements for each domain, and estimates time allocation. Print directly from the browser for your working papers.

Risk Register Calculator

When: Continuously during fieldwork as risks are identified. What it does: Log each risk with a title, domain, and 1–5 scores for Likelihood and Impact. The register auto-calculates the Inherent Risk score (L×I), assigns a rating (Critical ≥20 / High ≥12 / Medium ≥6 / Low), and plots all risks live on a 5×5 colour-coded heat-map matrix. Entries persist across sessions. Use this to prioritise findings and brief the auditee on their overall risk profile.

Interview Question Bank

When: Before each interview session. What it does: 156 field-tested questions organised by 11 audit domains and 7 interviewee roles (CISO, Network Admin, System Admin, Application Owner, DBA, Cloud Admin, OT Engineer). Filter by domain and role to build a tailored list for each interview. Check off questions as you ask them — progress saves automatically. Print a session-specific question sheet to take into the interview.

Observation Drafter

When: When drafting audit findings at end of fieldwork or per day. What it does: A 6-step wizard that guides you through the institutional C5 structure — Criteria, Condition, Cause, Effect, Recommendation. Each step provides pre-built templates for each audit domain that you click to pre-fill and customise. The final step generates a formatted observation paragraph ready to copy into your working papers or inspection report. Always replace placeholder text with specifics from your evidence.

Cyber Maturity Scorecard

When: At the end of fieldwork, once you have enough evidence to rate the entity. What it does: Rate the entity on 10 cybersecurity dimensions (Governance, IAM, Network, Endpoint, Application, Data Protection, BCP/DR, Incident Response, OT/ICS, Physical) on a 1–5 maturity scale. Generates a live radar chart and a copy-ready summary paragraph for working papers. Scores persist across sessions.

Regulatory Compliance Matrix

When: When writing findings and needing the correct legal citation. What it does: Maps 11 audit areas to specific clauses in 5 frameworks — applicable cyber law, official incident-response service Directions 2022, data-protection guidance, ISO 27001:2022, and NIST CSF 2.0. Click any clause badge to read exactly what that section requires. Use the reference in the Criteria field of your findings.

Penalty & Liability Calculator

When: When establishing legal consequences for the inspection report. What it does: Select the applicable law and violation type. Returns the exact section reference, maximum penalty or consequence, parties liable, enforcement authority, and audit citation notes. Covers 30+ violation types across cyber-safety law, official incident-response service Directions, data-protection guidance, ISO 27001, and NIST CSF 2.0.

Case Study Walkthroughs

When: During training or before your first engagement of a new entity type. What it does: Three end-to-end audit scenarios — Central Organisation, State organisation with OT systems, and Healthcare Entity — showing how a real engagement unfolds from entity profile through risk assessment, fieldwork plan, key findings, and model report paragraphs. All entities are fictional composites, not real institutional audits.

Final Assessment & Certificate

When: After completing the reading layer (Parts 0–10). What it does: 30 questions across 5 themed rounds — Foundations, Legal & Regulatory, Methodology, Technical Audit, and Reporting. Score 24/30 or higher (80%) to earn a printable Completion Certificate with your name. Each question shows a full explanation after answering, so the assessment also serves as a revision session. Your certificate is stored in the browser — enter your name before starting.

Netraksha — the built-in cyber-safety guide

The chat bubble in the bottom-right corner of every page is Netraksha (नेत्ररक्षा — "the watching eye that protects"). It is not a connected AI and has no internet access. It answers from the studio’s local learning content and a fuzzy search over page titles and sections, with no data leaving your browser. Ask it about incident reporting, network safety or the Purdue Model and it will point you to a relevant section.

Learning Paths

Not everyone starts from zero, so the manual is tagged by level rather than forced into one track.

If you are…Start atWhy
Beginner New to IT/cybersecurity entirelyPart 0 → Part 1 → Part 2 → Part 3 → Part 4You need the vocabulary and legal grounding before any hands-on audit work makes sense.
Intermediate Comfortable with IT, new to security auditsPart 2 → Part 3 → Part 4 → Part 6Skip straight to methodology and the IT audit domains; skim Part 1 for gaps.
Advanced Experienced IT auditor, new to OT/ICSPart 5 → Part 6 → Part 9OT has a fundamentally different risk model — don't assume IT instincts transfer.
All Levels Need to write a finding right nowPart 8 → Part 10Reporting structure and checklists are useful at any stage of experience.

Safety Boundaries and Permission

This studio does not grant authority to inspect systems, accounts, records or people. Use it for awareness, authorised labs and defensive learning only. For a real incident, follow the reporting and escalation procedures that apply to you.

Use only with permission

Only review a device, account, network, log or environment when you have clear authorisation from the owner and an appropriate legal basis.

No sensitive case material

Do not enter or upload illegal media, victim information, live case evidence, passwords, tokens or personal data into this app.

Defensive technical practice

Any technical command or simulation in this studio must be used only in an authorised lab or approved defensive scope. Do not bypass access controls, evade detection or target real systems.

Awareness guidance, not legal advice

Legal and reporting material is a starting point for awareness only. Check current official sources or a qualified professional before acting on legal obligations.

Report genuine cybercrime safely

For an actual cybercrime or immediate safety concern, preserve only lawful information, avoid confronting suspects and contact the appropriate official reporting channel or local emergency service.

Types of Organisations You'll Audit

"Organisation entity" covers a wide spread of IT/OT maturity. Calibrate your expectations and your audit programme accordingly:

Organisations & Organisation Departments

Run e-governance applications, citizen service portals, and back-office systems, often hosted on relevant service provider infrastructure or state data centres / MeghRaj (GI Cloud). Expect a mix of legacy applications and newer cloud-hosted services. IT governance maturity varies enormously by department.

Public Sector Undertakings (organisations)

Often operate both corporate IT (ERP, finance, HR) and, in sectors like power, oil & gas, and manufacturing, OT/ICS environments running production. These are your highest-stakes IT+OT audits — see Part 5.

Autonomous Bodies & Statutory Authorities

Regulators, universities, research bodies. IT footprints are smaller but often hold sensitive personal or research data, raising data-protection guidance considerations (Part 2).

Local Bodies & Urban Infrastructure

Municipal corporations, smart city SPVs, water utilities, traffic management — increasingly running SCADA/IoT for utilities and surveillance, frequently with weaker dedicated IT security staffing than central organisations.

Critical Infrastructure Operators

Power generation/transmission/distribution, ports, railways, telecom backbone. May fall under critical-infrastructure coordination body-notified "Critical Information Infrastructure" — handle with the heightened sensitivity and coordination described in Part 5.9.

Manual Conventions & Icon Legend

The same visual language is used in every module so you can recognise content type at a glance.

Level badges

Beginner Intermediate Advanced All Levels

Risk / severity badges

Critical High Medium Low

Callout types

Info

Background context or a definition you should know.

Field Tip

Practical advice from real audit practice — shortcuts, things to watch for.

Caution

A common mistake or a step that's easy to get wrong.

Critical Warning

Doing this wrong can disrupt a live system — especially relevant in OT.

Other elements

  • Simulation — an interactive, hands-on exercise embedded in the page.
  • Knowledge Check — a short scored quiz at the end of a module.
  • Diagram — a flowchart, architecture, or process diagram.
  • monospace text — exact commands, file paths, or configuration values.
Next: Part 1 — Foundations of Cybersecurity

If any term in this page was unfamiliar — CIA triad, OT, SCADA, IEC 62443 — start there. If you already audit IT systems, you can jump to Part 2.