📣 Send us your press release
Site updates every 15 minutes
Professional Services

RBI Mandates New Cybersecurity Framework for Commercial Banks

India's central bank, the Reserve Bank of India (RBI), has issued a new cybersecurity framework requiring commercial banks to conduct regular vulnerability assessments and penetration tests. The framework replaces existing piecemeal instructions with a unified set of guidelines.

3 August 2026
RBI Mandates New Cybersecurity Framework for Commercial Banks
Image is an AI-generated illustration

The Reserve Bank of India (RBI) has introduced a new, comprehensive cybersecurity framework for commercial banks, effective immediately. This framework consolidates and replaces a patchwork of previous instructions with a unified set of directions focused on technology, risk, resilience, and assurance.

The new regulations mandate that banks conduct vulnerability assessments every six months and penetration tests for critical internet-facing systems annually. Furthermore, disaster recovery drills for critical systems must be performed semi-annually. These requirements apply to commercial banks, excluding small finance banks, payments banks, and local area banks.

The framework details extensive requirements across several key areas. These include rigorous data and information asset management, secure system and infrastructure configurations, robust network and application security practices, and stringent access control and customer authentication measures. It also specifies protocols for email, removable media, and third-party vendor management, alongside operational resilience and incident response.

Banks are required to maintain up-to-date inventories of information assets, classify data based on sensitivity, and protect it throughout its lifecycle. System security necessitates secure configurations, anti-malware deployment, and adherence to strong cryptographic standards. Network and application security will focus on secure development practices and thorough testing.

Key operational mandates include implementing multi-factor authentication for privileged users and critical activities, establishing data loss prevention strategies, and reporting cybersecurity incidents to the DAKSH platform within six hours. The framework also assigns responsibilities to bank boards for approving and reviewing IT and cybersecurity policies annually, with senior management overseeing strategic implementation.

Original source: medianama.com