AI-FIRST CYBERSECURITY · Always Wise. Always Ahead. +91-95851-60363 info@semperwise.com DOVER, DE, USA

Financial services cybersecurity · India

Four kinds of firm, four rulebooks, one KYC store to protect.

An NBFC, a lending app’s service provider, a payment aggregator and a stockbroker can all hold the same customer’s PAN, bank statements and phone number — and answer to different rules for protecting them. This page sets out what each one owes after the RBI’s July 2026 NBFC Directions, the lending rules of November 2025 and SEBI’s cyber framework, and follows the path an attacker takes from a partner’s app to a store of KYC documents.

Reviewed 24 September 2026 · 9 sources cited

The short answer

Financial-services cybersecurity in India depends on the licence. NBFCs follow the RBI’s July 2026 cyber Directions in three tiers, with six-hour incident reporting on DAKSH for larger NBFCs. Digital lenders must keep borrower data on servers in India and stop lending apps reading contacts or call logs. Payment aggregators need an annual cyber security audit by CERT-In-empanelled auditors. SEBI-regulated brokers report incidents to SEBI and CERT-In within six hours under the CSCRF.

Why financial services

The data is identical. The rules are not.

Financial services in India is not one regulated sector but several. A lender may be an NBFC; the app a borrower downloads may belong to a lending service provider working for it; the payment may pass through an aggregator; the same customer may trade through a broker regulated by SEBI. Each holds identity documents and bank details. Each answers to a different instrument. For commercial banks, see our banking page; this page is about everyone else.

For NBFCs, the RBI’s July 2026 Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions replaced the earlier IT framework in three tiers. Base-layer NBFCs with assets under ₹500 crore, and core investment companies, need the basics: a Board-approved IT and information security policy, access controls, maker-checker, business continuity and tested backups. At ₹500 crore and above they need a vulnerability-management process and must report cyber incidents on the RBI’s DAKSH platform within six hours. From the middle layer up, they add vulnerability assessment every six months and penetration testing every twelve for critical and customer-facing systems, by independent experts.

For digital lending, the rules now sit in the RBI’s Credit Facilities Directions of November 2025. The NBFC stays responsible for the privacy and security of borrower data, whoever collects it. Lending apps — its own and its service providers’ — must not access files, contacts, call logs or telephony functions. Service providers keep only basic data such as name, address and contact details. All data must be stored on servers in India, and anything processed abroad must be deleted there and brought back within 24 hours.

Payment aggregators follow the RBI’s Master Direction of September 2025, which requires an annual system audit, including a cyber security audit, by CERT-In-empanelled auditors. Brokers and other SEBI-regulated entities follow the Cybersecurity and Cyber Resilience Framework: incidents to SEBI and CERT-In within six hours, and VAPT to a fixed timetable. The data is the same everywhere — which is why a breach at the weakest partner is everyone’s breach.

By licence

What each kind of firm owes — side by side

The instrument that governs you, how fast you report, what testing and audit it demands, and the data rules that come with it. CERT-In’s six-hour reporting duty applies to all of them as well.

WhoMain instrumentReport an incidentTesting and auditData rules
NBFC — base layer, assets under ₹500 crore, and CICs RBI NBFC cyber Directions, 2026 — Chapter III CERT-In, 6 hours Board-approved IT and information security policy, access controls, maker-checker, BCP, tested backups —
NBFC — base layer, ₹500 crore and above Same Directions — Chapter IV RBI on DAKSH, 6 hours A vulnerability-management process —
NBFC — middle layer and above Same Directions — Chapter V RBI on DAKSH, 6 hours, and CERT-In (housing finance companies report to NHB) VA every 6 months, PT every 12, by independent experts —
Digital lender and its lending service providers RBI Credit Facilities Directions, 2025 (digital lending), plus the lender’s own cyber Directions Through the lender, which stays responsible Lender must ensure its service providers meet the RBI’s cyber security standards Servers in India only; data processed abroad back within 24 hours; no access to contacts, call logs or files
Payment aggregator RBI Master Direction on Payment Aggregators, September 2025 CERT-In, 6 hours; incidents reported to the Board Annual system and cyber security audit by CERT-In-empanelled auditors; PCI DSS RBI’s 2018 rules on storing payment system data
Stockbroker, depository participant and other SEBI entities SEBI Cybersecurity and Cyber Resilience Framework, 2024 SEBI and CERT-In, 6 hours; exchanges or depositories too; details in 24 hours VAPT at least yearly (twice for critical infrastructure); audits by CERT-In-empanelled organisations —

Summarised from the RBI and SEBI instruments in the sources; “—” means the instrument’s cyber provisions summarised here do not add a specific data-location rule, not that none applies. General information, not legal advice.

The attack path

From a partner’s app to 36 million KYC files

The composite path behind most fintech data breaches. Each step is a place to test — and a place the attack can be stopped.

  1. 1

    A partner’s app

    A lending app built by a service provider, with API keys in the app, over-broad permissions or a debug endpoint left live. The lender’s rules reach the partner; the attacker does not care whose code it is.

    Mobile app and API testing of every lending app you report to the RBI — your service providers’ included

  2. 2

    The lending API

    An endpoint that trusts the ID in the request: change one number and you are reading another borrower’s application, or another partner’s customers.

    Authorisation between partners, borrowers and staff, tested endpoint by endpoint

  3. 3

    The cloud account

    A leaked access key or a console login without multi-factor authentication. A stockbroker disclosed in 2025 that some of its cloud resources had been compromised — it learned of it from a dark-web monitoring alert.

    Cloud identity, key management and configuration review

  4. 4

    The KYC store

    A storage bucket holding identity documents, readable without authentication. One lender’s bucket held 36 million KYC files and stayed open for about seven weeks after researchers found it.

    Storage exposure, encryption and continuous discovery of what you publish

  5. 5

    Borrowers’ identities in circulation

    The documents that open accounts and loans are now in someone else’s hands. Six-hour reports go to the RBI or SEBI and to CERT-In; from May 2027, DPDP notice to the Board and every affected person.

The breach usually starts at the least-regulated party and ends in the most sensitive store. Testing the partner’s app and the API behind it is cheaper than explaining the KYC files.

Evidence

The numbers that set the pace

Two from reported incidents; the rest from the rules themselves. Each is linked in the sources.

36M KYC files a digital lender left in an unauthenticated cloud storage bucket, found by researchers in November 2024 [5]
6 hours To report a cyber incident — on DAKSH for larger NBFCs, to SEBI and CERT-In for brokers [1]
24 hours To delete borrower data processed outside India and bring it back [2]
₹500 cr Asset size at which a base-layer NBFC moves to the fuller cyber requirements [1]
5 months For SEBI-regulated entities, the deadline to revalidate VAPT fixes after testing ends [4]
1 a year Minimum system and cyber security audits for a payment aggregator, by CERT-In-empanelled auditors [3]

The KYC exposure was reported by the researchers who found it; there was no evidence that anyone else accessed the files.

Where it goes wrong

Three patterns behind fintech breaches

Two from reported incidents in India. The third is the pattern the lending rules are written against.

01

The open bucket

  1. Way inCloud storage created for KYC uploads, with public access left on.
  2. ThenAnyone with the address could list and download the files.
  3. Cost36 million KYC files exposed for about seven weeks at a digital lender — found by researchers, not by the lender.

What we test: Continuous discovery of your cloud storage and what it publishes, and review of the upload pipeline that writes to it.

02

The compromised cloud account

  1. Way inCredentials for a broker’s cloud environment, used by someone else.
  2. ThenClient information taken from cloud resources; the firm learned of it from a dark-web monitoring partner.
  3. CostCredentials changed across the cloud estate and applications, an investigation and a public disclosure — though the firm said clients’ securities, funds and credentials were not affected.

What we test: Cloud identity and access, key management, logging, and how quickly your own monitoring — not a third party’s — would notice.

03

The app that knew too much

  1. Way inA lending app asking for contacts, call logs and file access “for verification”.
  2. ThenBorrower data copied into a service provider’s systems, far beyond what the loan needs.
  3. CostA breach of the lending rules before any attacker arrives — and a far larger breach if one does.

What we test: The permissions each app requests and uses, the data each service provider actually stores, and whether it stays on servers in India.

Next step

Start with your partners’ apps and the store behind them.

A 30-minute call with a practitioner who knows the NBFC, lending, aggregator and SEBI rulebooks. No charge, and no obligation.

  • Which Directions apply to you — and to each partner
  • The apps, APIs and cloud stores to test first
  • Where independent testing fits beside your empanelled audits
  • A fixed price, with a retest of every fix included
Book the call We reply within 24 business hours.

A plan you can run

Ninety days to a defensible position

The order matters more than the budget. Most of the first month is finding out what you and your partners actually run.

  1. Days 1–30

    Find it

    • Confirm which Directions apply to you, and to each lending partner and service provider
    • List every lending app and API — yours and your partners’ — and every store of KYC data
    • Check where each store sits, and that nothing processed abroad stays there beyond 24 hours
    • Multi-factor login on every cloud console and administrative account
  2. Days 31–60

    Test it

    • Test the partner apps and lending APIs for authorisation flaws and over-collected permissions
    • Review cloud storage, access keys and logging
    • Put the six-hour reporting runbook in writing, for DAKSH or SEBI and for CERT-In
    • Book the empanelled audit your licence requires, if it is due
  3. Days 61–90

    Prove it

    • Retest every fix, and record the evidence with its date
    • Put security, data-location and breach-notice clauses into every service-provider contract
    • Rehearse an incident with the people who will file the reports
    • Brief the Board on the Directions that apply and where you stand

Where SemperWise fits

What we do for NBFCs, fintechs and brokers

Services are people doing the work; SemperWise One is the platform that keeps the evidence current between engagements. Each row says which.

“Our lending app — and our partners’.”

Service

Mobile app testing covering permissions, stored secrets, certificate handling and what the app sends to whom.

Mobile app testing

“Our lending and partner APIs.”

Service

Object-level authorisation, token handling and separation between partners and borrowers, tested endpoint by endpoint.

API security testing

“Our cloud.”

Service

Identity, access keys, storage exposure, logging and data location reviewed against how your platform is actually built.

Cloud security assessment

“What are we exposing?”

SemperWise One™

Continuous discovery of internet-facing systems and cloud storage, so an open bucket is found by you first.

Attack surface management

“Our lending service providers.”

SemperWise One™

Vendor assessments against the data and security terms you must impose, with the evidence they send kept and dated.

Vendor and questionnaire tooling

“SEBI’s framework.”

Service

Readiness against the CSCRF for your category, and testing between the empanelled audits it requires.

SEBI CSCRF

“Borrowers’ consent and the DPDP Act.”

Service

A fixed-scope readiness assessment of the data you and your partners hold, dated to the May 2027 duties.

DPDP readiness

Terms

Financial-services security terms, defined

NBFC layers
The RBI’s scale-based classes of NBFC — base, middle, upper and top — which decide how much of the 2026 cyber Directions applies.
CIC
Core investment company — an NBFC that mainly holds investments in group companies; it follows the lightest tier of the cyber Directions.
LSP
Lending service provider — a firm that works for a lender on customer acquisition, underwriting support, collections or the lending app.
DLA
Digital lending app or platform — the app or website through which a loan is offered, whether run by the lender or a service provider.
CIMS
The RBI’s Centralised Information Management System, where lenders report the lending apps they and their service providers use.
DAKSH
The RBI’s supervisory portal, where regulated entities report cyber incidents within six hours.
Payment aggregator
A firm that collects payments for merchants and settles them, authorised by the RBI.
PCI DSS
The card industry’s data security standard, which the payment aggregator rules name as a baseline.
CSCRF
SEBI’s Cybersecurity and Cyber Resilience Framework of August 2024, for brokers, depositories, exchanges and other regulated entities.
VAPT revalidation
Under the CSCRF, the retest that confirms VAPT findings were fixed — due within five months of the test.
KYC
Know your customer — the identity and address documents collected to open an account or loan, and the most valuable data a lender holds.

Questions

Financial Services security — answered.

What buyers in this sector ask us before they commit to anything.

What cybersecurity rules apply to NBFCs in 2026?

The Reserve Bank of India (Non-Banking Financial Companies – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, issued on 31 July 2026 and in force immediately. They apply in three tiers: base-layer NBFCs with assets under ₹500 crore and core investment companies meet baseline requirements; base-layer NBFCs at ₹500 crore and above add IT governance, vulnerability management and six-hour incident reporting on DAKSH; middle-layer NBFCs and above add VA every six months and PT every twelve for critical and customer-facing systems.

What must digital lending apps do with borrower data?

Under the RBI’s Credit Facilities Directions of November 2025, which carry the digital lending rules for NBFCs, lending apps must not access files and media, contact lists, call logs or telephony functions, except one-time access to the camera, microphone or location for onboarding with the borrower’s consent. Service providers may keep only basic data such as name, address and contact details. All data must be stored on servers in India, and data processed abroad must be deleted there and brought back within 24 hours.

Is an NBFC responsible for its lending service provider’s security?

Yes. The lending rules make the NBFC responsible for the privacy and security of borrowers’ personal information on an ongoing basis, including data handled by its service providers, and require it to ensure that it and its service providers meet the RBI’s cyber security standards for digital lending. In practice that means testing partners’ apps and APIs, putting data and breach terms into contracts, and keeping evidence that they were met.

Do payment aggregators need a CERT-In-empanelled audit?

Yes. The RBI’s Master Direction on payment aggregators of September 2025 requires an annual system audit, including a cyber security audit, by CERT-In-empanelled auditors, with the report submitted to the RBI. SemperWise is not CERT-In empanelled: we prepare you for that audit, test between audits and verify fixes, and you appoint the empanelled auditor directly.

How fast must a stockbroker report a cyber incident?

Under SEBI’s Cybersecurity and Cyber Resilience Framework, incidents covered by CERT-In’s directions must be notified to SEBI and CERT-In within six hours of noticing them, and stockbrokers and depository participants must also inform the stock exchanges or depositories within six hours. Detailed information goes on SEBI’s incident reporting portal within 24 hours.

How often must SEBI-regulated entities do VAPT?

Under the CSCRF, entities identified as critical information infrastructure or protected systems must complete VAPT at least twice a year, once in each half of the financial year; the rest at least once a year, starting in the first quarter. The report is due within a month of testing, findings must be closed within three months of the report, and revalidation completed within five months. CSCRF audits are to be done by CERT-In-empanelled auditing organisations unless SEBI specifies otherwise. See our SEBI CSCRF page.

Can a fintech process borrower data outside India?

For digital lending by NBFCs, only briefly. The lending rules require all data to be stored on servers in India; where data is processed outside India, it must be deleted from the servers abroad and brought back to India within 24 hours of processing. Payment aggregators follow the RBI’s 2018 rules on storing payment system data. Check each cloud region and each service provider — including analytics and support tools — against these rules.

Where does the DPDP Act fit?

From about 13 May 2027, NBFCs, lenders, aggregators and brokers become subject to the Digital Personal Data Protection Act’s duties as Data Fiduciaries: reasonable security safeguards, breach notice to the Data Protection Board and each affected person, and a year of logs from their processors. Service providers are Data Processors under contract. The sector rules above still apply alongside. A DPDP readiness assessment maps both.

Sources

Checked by our research desk on 24 September 2026. Regulations and figures move; where a number here matters to a decision, follow it to the source.

  1. Reserve Bank of India (Non-Banking Financial Companies – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 — RBI, 31 July 2026
  2. RBI (Non-Banking Financial Companies – Credit Facilities) Directions, 2025 — TaxGuru (text of the RBI Directions), 28 November 2025
  3. Master Direction on Regulation of Payment Aggregator (PA) — RBI, 15 September 2025
  4. Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities — SEBI, 20 August 2024
  5. Top digital loan firm security slip-up puts data of 36 million users at risk — TechRadar, 2025
  6. Indian stock broker Angel One discloses data breach — SecurityWeek, 3 March 2025
  7. The Great Consolidation: RBI’s subtle shifts; big impacts on NBFCs — Vinod Kothari Consultants, October 2025
  8. Directions under sub-section (6) of section 70B of the IT Act, 2000 — CERT-In, 28 April 2022
  9. Digital Personal Data Protection Rules, 2025 — MeitY, 13 November 2025

All 17 industries we serve

Next step

Know which rulebook you are tested against.

A 30-minute call, no charge. You leave knowing which Directions apply to you and your partners, which apps, APIs and cloud stores to test first, and where independent testing fits beside the empanelled audits your licence requires — with a written scope and fixed price if testing makes sense.