Whitepapers

Operator research.
Multi-quarter studies, real estates.

Long-form whitepapers grounded in real engagement data — pricing benchmarks, detection uplift curves, multi-cloud misconfiguration baselines. Each is email-gated and ships as a PDF the same business day. No drip sequence, no newsletter enrolment.

3
Papers
174
Pages of research
460
Engagements behind them
Why these papers

Three studies, one operator lens.

Each paper is written by the operator who ran the underlying engagements — not a marketing team paraphrasing analyst reports. The data set is ours, the anonymisation is ours, and the conclusions are the ones we would defend in a board meeting.

We publish three papers a year, in May. If you want to receive them as they ship — and nothing else — request a copy below and we will add you to the whitepaper-only list.

Available Whitepapers

Three papers. Published 2026-05-20.

State of VAPT in India 2026

PDF64 PAGES

Pricing, scoping, retest discipline, and vendor performance across 240 Indian engagements.

A 64-page operator study of 240 VAPT engagements run across Indian SaaS, BFSI, healthtech, and public-sector estates over the last 18 months. Day-rate distribution, fixed-fee bands, retest performance, finding-density benchmarks by surface, and the structural reasons cheap pentests stay cheap.

Best for

CISOs and security leads scoping multi-quarter VAPT programmes in India. Procurement teams calibrating budget envelopes for FY26 / FY27.

Open whitepaper page

Red Team ROI 2026

PDF52 PAGES

Measuring adversary simulation value: detection uplift, MTTR, and dwell-time reduction across 40 engagements.

How forty enterprise red team engagements moved the dial on detection efficacy, mean-time-to-respond, and observed dwell time. Includes the spend-vs-uplift curve, the three SOC maturity inflection points, and the failure modes that make red teams expensive theatre.

Best for

CISOs, SOC leads, and audit committees evaluating red team spend against measurable detection and response outcomes.

Open whitepaper page

Cloud Security Benchmarks 2026

PDF58 PAGES

AWS, Azure, and GCP misconfiguration baselines, IAM exposure rates, and finding-density across 180 cloud estates.

A multi-cloud benchmark study of 180 production estates — AWS, Azure, GCP, and hybrid. IAM exposure rates, top ten misconfigurations by cloud, finding-density per 100 accounts, IMDSv1 prevalence, and the controls that genuinely move the score.

Best for

Platform engineering leads, cloud security architects, and CTOs benchmarking their estate against comparable production environments.

Open whitepaper page

Want the underlying data?

For qualified buyers we can share the anonymised dataset behind each whitepaper under a short mutual NDA. Useful if you are benchmarking your own programme and want comparable peer numbers.