AI-FIRST CYBERSECURITY · Always Wise. Always Ahead. +91-95851-60363 info@semperwise.com DOVER, DE, USA

Banking cybersecurity · India

RBI rewrote the rulebook on 31 July 2026.

On 31 July 2026 the Reserve Bank replaced the 2016 cyber security framework and the 2023 IT governance direction for commercial banks with a single set of Directions — in force the same day, with no transition. This page walks through what changed, what it means for the Board, the CISO, risk and audit, how often everything must now be tested, and the questions to ask any firm that tests a bank.

Reviewed 24 September 2026 · 12 sources cited

The short answer

Indian commercial banks are now governed by the RBI (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, in force from 31 July 2026. They require vulnerability assessment at least every six months and penetration testing at least every twelve for critical and customer-facing systems, half-yearly disaster-recovery drills, a CISO independent of IT, and cyber incidents reported on RBI’s DAKSH platform within six hours, with CERT-In notified too.

July 2026

One rulebook instead of ten years of circulars.

For a decade, bank cyber security in India rested on the Cyber Security Framework in Banks of June 2016, the IT Governance Master Direction of November 2023 and a trail of circulars in between. On 31 July 2026 the Reserve Bank issued the Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, and with them repealed the existing cyber and IT governance instructions for commercial banks. The Directions took effect on the day they were issued. Parallel Directions under the same title went to small finance banks, payments banks, urban co-operative banks — graded into four levels by the digital services they offer — and other regulated entities. Days earlier, Bank of Baroda had said it was running a forensic investigation into an alleged breach in which nearly a terabyte of data was reportedly leaked on the dark web.

Much of the substance is familiar, but it is now in one place and sharper. The Board approves the IT, information security, cyber security, business continuity and cyber crisis frameworks and reviews them at least annually. A Board-level IT Strategy Committee meets at least quarterly, and its members must be technically competent — able to understand and evaluate IT and cyber risk. The CISO must be senior, must not report to the head of IT, must carry no business targets, and must put a review of cyber risk before the Board, its Risk Management Committee or the IT Strategy Committee every quarter.

Testing is where the Directions are most specific. Critical systems, and systems in the DMZ with a customer interface, need vulnerability assessment at least every six months and penetration testing at least every twelve. Web and mobile applications must be tested before and after they go live and after changes, in an environment that closely resembles production, and the scope must go beyond the OWASP Top 10. The closure status of every VA/PT finding goes to the IT Strategy Committee and the Information Security Committee at least quarterly.

And, for the first time in these words, the Directions hold the tester to account. Under paragraph 158, if a system that was assessed is later compromised through a vulnerability the VA/PT should have found and did not, that counts as a deficiency in the auditor’s work — and must weigh on the bank’s decision to renew. Paragraph 155 asks for testing by “appropriately trained and independent information security experts / auditors”. The question is no longer whether a bank had a pentest; it is whether the pentest was good enough.

The Directions in numbers

Six numbers every bank now works to

Each taken from the text of the July 2026 Directions for commercial banks. The paragraph numbers are in the matrix further down.

6 hours To report a cyber incident on RBI’s DAKSH platform, measured from detection — with CERT-In notified as well [1]
6 months Longest gap allowed between vulnerability assessments of critical and customer-facing systems [1]
12 months Longest gap allowed between penetration tests of the same systems [1]
1 full day Minimum length of a disaster-recovery drill run from the alternate site — at least every six months for critical systems [1]
4 a year Minimum number of CISO reviews of cyber risk before the Board, its Risk Committee or the IT Strategy Committee [1]
7 Parallel Directions issued on 31 July 2026 — for commercial, small finance, payments and co-operative banks, and other regulated entities [2]

Minimums, not targets. The Directions add risk-based testing for non-critical systems, testing after every significant change, and red teaming at the bank’s discretion.

2016 to 2027

How bank cyber rules got here — and what comes next

The instruments a bank’s policies, contracts and audit programmes are likely to cite, in order. Two are already repealed for commercial banks.

  1. Jun 2016

    Cyber Security Framework in Banks

    The circular that set the baseline for a decade: a Board-approved cyber security policy separate from the IT policy, a security operations centre, and a cyber crisis management plan. Repealed for commercial banks on 31 July 2026.

  2. Apr 2022

    CERT-In Directions

    Listed cyber incidents reported to CERT-In within six hours of noticing them; logs kept for 180 days within India. These still apply alongside the RBI’s own reporting.

  3. Nov 2023

    IT Governance Master Direction

    IT Strategy Committee, CISO, IS audit, business continuity and disaster recovery brought into one direction, effective 1 April 2024. Repealed for commercial banks on 31 July 2026.

  4. Apr 2025

    The bank.in domain

    Banks asked to move to the exclusive bank.in domain by 31 October 2025, with IDRBT as the registrar, so customers can tell a real bank site from a lookalike. A fin.in domain was planned for other financial entities.

  5. Sep 2025

    Authentication directions

    At least one dynamic authentication factor for every digital payment that is not card-present, a risk-based approach, and full compensation to the customer for any loss from a transaction that did not comply. In force from 1 April 2026.

  6. Nov 2025

    Managing risks in outsourcing

    Entity-wise “Managing Risks in Outsourcing” Directions replaced the 2023 IT-outsourcing direction on 28 November 2025. Contracts that cite the old direction need updating.

  7. Jul 2026

    The 2026 cyber Directions In force now

    One consolidated framework per entity type, in force on the day of issue. For commercial banks: six-hour DAKSH reporting, six-monthly VA, annual PT, half-yearly DR drills, CISO independence and VA/PT auditor accountability.

  8. Oct 2026

    Cross-border card-not-present checks In force now

    Card issuers must have a mechanism to validate non-recurring cross-border card-not-present transactions by 1 October 2026, under the authentication directions.

  9. May 2027

    DPDP Act duties Coming

    Customers’ personal data becomes subject to the DPDP Act’s security safeguards and breach notice — to the Data Protection Board and each affected customer — alongside the RBI’s own reporting.

Summarised from the RBI and CERT-In instruments listed in the sources. Policies and contracts that cite repealed circulars should be updated. General information, not legal advice.

Clause by clause

What gets tested, how often, and who sees it

The testing and review cadence in the 2026 Directions for commercial banks, with paragraph numbers so your calendar can cite them.

WhatMinimum frequencyWhere it goesParagraph
Critical and customer-facing DMZ systems — vulnerability assessment Every 6 months Findings to IS and IS audit teams and senior management; closure to the ITSC and ISC quarterly 151, 160, 161
Critical and customer-facing DMZ systems — penetration test Every 12 months As above 151, 161
Non-critical systems Risk-based As set in the bank’s documented VA/PT approach 151, 154
After go-live or an upgrade Each time On production; any test on a replica must match it, with deviations approved by the ISC 152
Web and mobile applications Before and after go-live, and after changes Scope beyond the OWASP Top 10, in a replica of production 85, 86
Disaster recovery, critical systems Half-yearly Run from the DR site for at least a full working day; major issues fixed and retested before the next drill 165–167
Red teaming At the bank’s discretion To test the efficacy of defences against a simulated attacker 162
Security policies and infrastructure At least annually The Board reviews strategies and policies; the bank reviews its security infrastructure 8, 43
IS audit policy At least annually Approved and reviewed by the Audit Committee of the Board 225

From the RBI (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026. Small finance, payments and co-operative banks should check the equivalent paragraphs in the Directions addressed to them.

In the room

Four people who read the same Directions differently

The Directions give each of them named duties. A security programme that satisfies one and not the others will not survive the next inspection.

Board and IT Strategy Committee

Worried about
Signing off strategies they cannot evaluate — the Directions now require committee members who can understand and evaluate IT and cyber risk.
Has to show
That cyber risk is owned and falling, and that VA/PT findings are closing on time.
What we hand them
A quarterly view of open findings by severity and age, written for directors, and a briefing on what the 2026 Directions ask of the Board.

CISO

Worried about
Carrying the accountability without the reach — every critical system inside the six- and twelve-month cycles, and nothing slipping between them.
Has to show
A testing programme that covers the whole inventory on the Directions’ schedule, and evidence that fixes held.
What we hand them
A testing calendar built from the asset inventory, reports that state assurance per area, and retests that close findings before the next committee meeting.

Chief Risk and Compliance Officers

Worried about
A supervisory observation on something that was “covered” on paper, and third-party risk nobody can see.
Has to show
Traceability from each requirement to evidence — including the vendors and service providers the Directions reach.
What we hand them
Findings mapped to requirements, vendor evidence kept and dated, and a clear line between what the bank tested and what it relied on.

IS auditor and Audit Committee

Worried about
Relying on a VA/PT report that later proves shallow — which paragraph 158 now treats as the auditor’s deficiency.
Has to show
That the tester was independent and competent, and covered the scope it claimed.
What we hand them
The methodology, the scope, an assurance statement for each area, the testers’ credentials and the evidence behind every finding.

Where banks get hurt

Four patterns the Directions are written against

Three from recent events in Indian banking. The fourth is the one the Directions themselves anticipate.

01

The shared service provider

  1. Way inRansomware at a technology provider that ran services for co-operative and regional rural banks.
  2. ThenThe payments operator isolated the provider from the retail payment systems it runs, to stop any spread.
  3. CostCustomers of the banks it served had difficulty using payment systems until an independent forensic review allowed reconnection — the C-Edge incident of July 2024.

What we test: The controls you must impose on service providers by contract, and your own plan for the day a provider is cut off.

02

The lookalike website

  1. Way inA domain one letter away from the bank’s, a login page copied pixel for pixel, a link in an SMS or search ad.
  2. ThenCustomers type their credentials into the attacker’s page.
  3. CostAccount takeover and fraud at scale — the threat the RBI cited when it moved banks to the exclusive bank.in domain, and the reason the Directions require anti-phishing and rogue-app takedown services.

What we test: Which customer-facing sites, apps and mail domains still sit outside bank.in, and whether email authentication is enforced — the Directions require DMARC.

03

The one-time password that was not enough

  1. Way inA customer tricked into reading out an OTP, or a SIM swapped so the OTP arrives elsewhere.
  2. ThenA payment authenticated by factors the attacker controls.
  3. CostSince 1 April 2026, if the transaction did not comply with the authentication directions, the issuing bank compensates the customer in full, without demur.

What we test: Authentication, device binding and step-up checks in your mobile and internet banking, and how each behaves when a number or device changes.

04

The report that missed it

  1. Way inA system that passed its last VA/PT, compromised through a flaw the report did not mention.
  2. ThenAn incident on DAKSH within six hours — and the question of why the testing did not find it.
  3. CostUnder paragraph 158, a deficiency in the auditor’s work that the bank must weigh at renewal; for the bank, an inspection question about how it chose and checked its tester.

What we test: Manual testing beyond the OWASP Top 10, an assurance statement for each area in scope, and the evidence behind every finding.

Next step

Map your systems to the six- and twelve-month cycles.

A 30-minute call with a practitioner who reads the Directions paragraph by paragraph. No charge, and no obligation.

  • Which of your systems fall under paragraph 151 — and which are risk-based
  • What a report must say to give the assurance paragraph 157 asks for
  • Where independent testing fits beside any CERT-In-empanelled audit your policy requires
  • A fixed price, with a retest of every fix included
Book the call We reply within 24 business hours.

Paragraphs 152 to 159

Eight questions to ask any firm that tests a bank

Including us. Each one comes from a paragraph of the 2026 Directions, and each answer should be in writing before the engagement starts.

  1. Are you independent of the systems you will test — and of whoever built or runs them?

    Paragraph 155 asks for independent experts. A firm that also develops, hosts or manages the system is marking its own work.

  2. Who, by name, will do the testing, and what are their qualifications?

    Paragraph 156 asks the bank to weigh the expertise of the personnel engaged, not only of the firm.

  3. Will the report state the assurance you give for each area in scope?

    Paragraph 157 expects reasonable assurance for each area to be stated explicitly in the report — not a list of findings with silence about what was covered.

  4. How do you score findings, and against what?

    Paragraph 154 requires a documented approach with a scoring mechanism such as CVSS — applied to cloud-hosted systems too.

  5. Do you test beyond the OWASP Top 10?

    Paragraph 85 says application assessments must not be restricted to it. Business-logic abuse and broken authorisation rarely show up in a checklist.

  6. Will you test production — and if not, how close is the test environment?

    Paragraph 152 expects post-implementation testing on production, with any replica matching it and deviations approved by the Information Security Committee.

  7. Is a retest of every fix included?

    Paragraph 153 requires time-bound fixes, and paragraph 161 puts closure status before the committees every quarter. A finding is not closed until someone has checked.

  8. Are you CERT-In empanelled — and does our own policy require that for this audit?

    Paragraph 159 applies CERT-In’s audit guidelines when an empanelled auditor is used. SemperWise is not empanelled. Where your policy requires empanelment, appoint that auditor directly; we test between cycles and verify fixes, and say so up front.

Where SemperWise fits

What we do for banks

Services are people doing the work; SemperWise One is the platform that keeps the evidence current between engagements. Each row says which.

“Our six-monthly and annual cycle.”

Service

Vulnerability assessment and penetration testing of critical and customer-facing systems, with per-area assurance statements and a retest of every fix.

VAPT

“Our mobile and internet banking.”

Service

Authenticated testing of apps and APIs — authorisation between customers, authentication and step-up, device binding — beyond the OWASP Top 10.

Mobile app testing

“Would our defences hold against a real attacker?”

Service

A red-team exercise against agreed objectives, to test detection and response as well as prevention.

Red team assessment

“Between the cycles.”

SemperWise One™

Scheduled testing of internet-facing systems with human validation, so a new exposure is found before the next six-monthly assessment.

Continuous penetration testing

“The quarterly committee report.”

SemperWise One™

In SemperWise One, findings, owners, due dates and retest evidence tracked to closure, with an executive view the IT Strategy Committee can read.

RBI compliance in One

“Our vendors and service providers.”

SemperWise One™

Vendor assessments scored against the controls you must impose by contract, with the evidence they send kept and dated.

Vendor and questionnaire tooling

“The six-hour report.”

Service

Incident-reporting runbooks mapped to the DAKSH and CERT-In clocks, rehearsed with the people who will file them.

CERT-In compliance

“Directors who can evaluate cyber risk.”

Service

Briefings for the Board and IT Strategy Committee on the 2026 Directions and on reading a security report critically.

Security training

Terms

Bank cyber-security terms, defined

The 2026 Directions
The Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, issued and in force on 31 July 2026.
ITSC
IT Strategy Committee — the Board-level committee that oversees IT strategy and IT and cyber risk; it meets at least quarterly.
ISC
Information Security Committee — the management committee under the ITSC that manages cyber and information security, headed from the risk management side.
ACB
Audit Committee of the Board — oversees IS audit and approves the IS audit policy.
DAKSH
The Reserve Bank’s Advanced Supervisory Monitoring System, where banks report cyber incidents within six hours.
CSOC
Cyber Security Operations Centre — the function that provides continuous surveillance of the bank’s environment.
CCMP
Cyber Crisis Management Plan — the Board-approved plan covering detection, containment, response and recovery.
VA / PT
Vulnerability assessment (a systematic search for weaknesses) and penetration testing (an attempt to defeat the security controls, as an attacker would).
Red teaming
A simulated adversarial exercise against the bank’s objectives, testing people and processes as well as technology.
RTO / RPO
Recovery time objective (how long a system can be down) and recovery point objective (how much data can be lost).
IB-CART
The Indian Banks – Centre for Analysis of Risks and Threats, set up by IDRBT for sharing threat intelligence among banks.
DMARC
An email authentication standard that stops others sending mail as your domain; the Directions require it.
Comply or explain
The approach for foreign bank branches: listed provisions apply unless the bank gives the RBI a justifiable explanation it accepts.
bank.in
The domain reserved for Indian banks, registered through IDRBT, so customers can recognise genuine bank websites.

Questions

Banking security — answered.

What buyers in this sector ask us before they commit to anything.

What are the RBI’s 2026 cybersecurity Directions for banks?

The Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 were issued on 31 July 2026 and took effect immediately. They consolidate and replace the earlier cyber security framework and IT governance instructions for commercial banks: Board and committee oversight, the CISO’s role, baseline security controls, VA/PT, disaster recovery, incident response, a cyber security operations centre and IS audit. Parallel Directions under the same title apply to small finance banks, payments banks, urban co-operative banks and other regulated entities.

How often must a bank do VAPT under the RBI Directions?

For critical information systems and systems in the DMZ with a customer interface, vulnerability assessment at least once every six months and penetration testing at least once every twelve months (paragraph 151). Non-critical systems follow a risk-based schedule. Testing is also required after implementation or upgrade, on production or an equivalent replica, and web and mobile applications must be tested before and after go-live and after changes. See VAPT for how we scope it.

Does the 2016 Cyber Security Framework still apply?

Not to commercial banks. The 2026 Directions repealed the existing cyber security framework and IT governance directions and instructions for commercial banks on 31 July 2026. Small finance, payments and urban co-operative banks received their own Directions the same day, which likewise replace the earlier instructions for them. Policies, contracts and audit programmes that still cite the 2016 circular or the 2023 IT governance direction should be updated.

How quickly must a bank report a cyber incident?

Within six hours of detection, on the Reserve Bank’s DAKSH platform, under paragraph 182 of the 2026 Directions; the bank must also notify CERT-In, whose own Directions set a six-hour window from noticing an incident. The bank must also escalate to its Board and senior management and inform customers as required. From about May 2027, a breach of customers’ personal data additionally triggers notice under the DPDP Act.

Must VA/PT be done by a CERT-In-empanelled auditor?

The 2026 Directions ask for VA/PT by appropriately trained and independent information security experts or auditors, chosen for their qualifications, expertise and competence; where a CERT-In-empanelled auditor is used, CERT-In’s audit guidelines apply. Many banks’ own policies go further and require empanelment for some audits. SemperWise is not CERT-In empanelled: where your policy requires it, appoint the empanelled auditor directly, and use us for independent testing between cycles and for fix verification.

What does paragraph 158 mean for a bank’s testing firm?

It says that if a system that underwent VA/PT is later compromised through vulnerabilities the VA/PT should have found and did not, that is a deficiency in the auditor’s work, and the bank must factor it in when selecting or renewing the auditor. In practice, banks will want reports that state what assurance is given for each area in scope, named and qualified testers, and testing that goes beyond automated scanning and the OWASP Top 10.

What changed for customer authentication in 2026?

Under the RBI’s authentication directions of September 2025, in force from 1 April 2026, every digital payment that is not card-present needs at least one dynamic authentication factor unique to the transaction, issuers take a risk-based approach, and if a loss arises from a transaction that did not comply, the issuer compensates the customer in full, without demur. Card issuers must also validate non-recurring cross-border card-not-present transactions by 1 October 2026.

Who can the CISO report to under the new Directions?

The CISO must be a senior executive, preferably at General Manager level or equivalent, with no direct reporting line to the head of IT and no business targets. The CISO reports to the Executive Director or equivalent who oversees risk management, is a permanent invitee to the IT Strategy Committee and IT Steering Committee, and must place a review of cyber risk before the Board, its Risk Management Committee or the IT Strategy Committee at least every quarter.

All 17 industries we serve

Next step

Testing that stands up to paragraph 158.

A 30-minute call, no charge. You leave knowing which systems fall under the six-month and twelve-month cycles, what a report needs to say to satisfy the Directions, and where independent testing fits alongside any empanelled audit your policy requires — with a written scope and fixed price if testing makes sense.