Cybersecurity Compliance for India’s BFSI Sector: Meeting RBI, SEBI, and IRDAI Mandates in 2026

  • Home
  • Cybersecurity Compliance for India’s BFSI Sector: Meeting RBI, SEBI, and IRDAI Mandates in 2026
Cybersecurity Compliance for India’s BFSI Sector: Meeting RBI, SEBI, and IRDAI Mandates in 2026

India’s banking, financial services, and insurance (BFSI) sector sits at the intersection of two forces that have only intensified since 2022: an increasingly aggressive threat landscape and an increasingly prescriptive regulatory environment. A breach at a mid-size private bank or a regional NBFC is no longer just an IT incident — it triggers simultaneous reporting obligations to CERT-In, RBI, SEBI or IRDAI, and potentially the Data Protection Board under the Digital Personal Data Protection (DPDP) Act. The cost of non-compliance now rivals, and sometimes exceeds, the direct cost of the breach itself.

This guide is for CISOs and senior IT leaders in Indian BFSI enterprises who need a clear, consolidated view of the regulatory mandates they must satisfy — and a practical roadmap for building the security operations capability to do so continuously, not just at audit time.

The Regulatory Landscape: Four Frameworks, One Security Programme

Rather than treating each mandate in isolation, the most effective BFSI security teams treat RBI, SEBI, IRDAI, and CERT-In as overlapping requirements that can be satisfied by a single, well-designed security programme. Here is where each framework pushes hardest.

RBI’s IT Risk and Cyber Security Framework

The Reserve Bank of India’s Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (updated through 2024) applies to all Scheduled Commercial Banks, Urban Cooperative Banks (UCBs) above certain thresholds, NBFCs, and Payment Aggregators. Key obligations include:

  • 24×7 Security Operations Centre (SOC): Entities above certain asset thresholds must maintain or procure a round-the-clock SOC capable of real-time threat detection and incident escalation.
  • Vulnerability Assessment and Penetration Testing (VAPT): Quarterly internal VAPT for internet-facing systems; annual third-party VAPT for the full estate.
  • Network Security Architecture: Documented network segmentation, firewall policy review cycles, and intrusion detection/prevention coverage across critical segments.
  • Business Continuity and Disaster Recovery (BCP/DR): RTO/RPO thresholds vary by criticality, with annual tabletop exercises and live DR drills required.
  • Third-Party and Vendor Risk: Cloud service providers and critical IT vendors must undergo due diligence and be contractually bound to security standards.

The RBI also expects entities to align with CERT-In’s 2022 directions (see below), meaning the 6-hour breach notification window is effectively a banking-sector obligation too — with the added weight of a banking regulator watching compliance.

SEBI’s Cybersecurity and Cyber Resilience Framework (CSCRF) 2024

The Securities and Exchange Board of India issued its revised Cybersecurity and Cyber Resilience Framework (CSCRF) in 2024, replacing the older SEBI Cybersecurity Framework of 2015. It applies to all SEBI-regulated entities (SREs): stock exchanges, depositories, brokers, investment managers, RTAs, and KYC registration agencies.

CSCRF introduces a tiered classification (Qualified REs, Mid-size REs, Small REs) with proportionate controls. Key requirements for larger entities include:

  • Cyber Capability Index (CCI): Entities must self-assess and report their CCI score annually. The framework maps directly to NIST CSF functions — Identify, Protect, Detect, Respond, Recover.
  • SOC and SIEM Mandatory for Qualified REs: The largest entities must operate or outsource a SOC with a SIEM platform. Log retention must align with CERT-In’s 180-day direction.
  • Incident Reporting to SEBI CSCRF Portal: Cyber incidents must be reported within 6 hours (initial intimation) with a detailed report within 24 hours.
  • Annual Cyber Audit: Conducted by a CERT-In empanelled auditor; findings must be shared with SEBI. Critical gaps trigger enhanced supervisory scrutiny.
  • Red Team / Adversarial Testing: Qualified REs are expected to conduct adversarial simulation exercises — essentially controlled red-team engagements — at defined intervals.

IRDAI’s Information and Cyber Security Guidelines

The Insurance Regulatory and Development Authority of India’s guidelines for insurers share the same DNA as the RBI and SEBI frameworks but have a few insurance-specific emphases. Insurers hold highly sensitive health, financial, and personal data on millions of policyholders — which is precisely why IRDAI and the DPDP Act intersect so sharply here.

  • Information Security Management System (ISMS): ISO 27001 alignment is strongly recommended; some larger insurers are required to obtain formal certification.
  • Data Localisation and Privacy: Policyholder data must reside on Indian soil; cross-border transfers require careful DPDP Act compliance planning.
  • Cyber Insurance and Risk Transfer: IRDAI encourages insurers to quantify their own cyber risk exposure, creating an interesting obligation where the insurer must model the same threat scenarios they underwrite for clients.
  • Incident Reporting: Aligned with CERT-In’s 6-hour reporting direction for significant incidents. IRDAI also requires entities to report to the regulator within 24 hours of detecting a material cyber incident.

CERT-In Direction 2022: The Cross-Cutting Obligation

The CERT-In Cyber Security Directions of April 2022 (effective June 2022, with subsequent clarifications) cut across every regulated sector in India. For BFSI enterprises, they add operational weight to existing regulatory obligations:

  • 6-Hour Incident Reporting: 20+ categories of incidents — including data breaches, ransomware, unauthorised access, and financial fraud — must be reported to CERT-In within 6 hours of detection. This is a clock that starts ticking the moment your SOC team raises the first alert, not when the post-mortem is complete.
  • 180-Day Log Retention: ICT infrastructure logs (network devices, servers, applications, security systems) must be retained for 180 days, in India. For large BFSI estates with hundreds of FortiGate firewalls, switches, and application servers, this is a significant log volume and storage planning challenge.
  • KYC of Cloud and VPN Users: The directions require organisations to maintain accurate time-synchronised records and enable traceability of users accessing systems via cloud platforms and VPN gateways.
  • NTP Synchronisation: All ICT assets must synchronise to NTP servers in India (NIC’s time server or equivalent). This sounds trivial but is frequently non-compliant in large, multi-vendor estates.

DPDP Act 2023: The Overarching Privacy Layer

The Digital Personal Data Protection Act 2023, with its rules progressively being notified, overlays all of the above with privacy obligations. For BFSI enterprises — who are Significant Data Fiduciaries by virtue of the volume and sensitivity of personal financial data they hold — this means:

  • Personal data breach notification to the Data Protection Board and affected data principals (exact timelines will be set in rules, but current indications align with a 72-hour window for board notification).
  • Documented lawful bases for all personal data processing, with particular scrutiny on data shared with third-party analytics providers or fintech partners.
  • Data minimisation and purpose limitation — directly relevant to how long customer transaction logs, KYC records, and call recordings are retained.

The DPDP Act does not make a BFSI enterprise “compliant” simply by having a firewall or a SOC. But strong security controls — particularly around access governance, encryption, and incident response — are the operational bedrock of demonstrable DPDP compliance.

Common Security Gaps We See in BFSI Estates

After securing networks across Indian banking, NBFC, insurance, and capital-market organisations, we consistently see the same structural weaknesses:

  • Incomplete log coverage: Branch networks, WAN edge devices, and legacy core banking application servers often have no centralised logging. CERT-In’s 180-day retention mandate is unmet because the logs don’t exist — not because they aren’t retained long enough.
  • Alert fatigue in understaffed SOCs: Entities that have deployed a SIEM but haven’t invested in correlation rules and playbook automation find their SOC teams overwhelmed with low-fidelity alerts, missing high-priority signals in the noise.
  • Siloed network visibility: NOC and SOC teams operate from different toolsets. The NOC sees network performance; the SOC sees security alerts. Neither has the full picture when an incident — like an attacker moving laterally across VLAN boundaries — spans both domains.
  • Manual incident response: The 6-hour CERT-In reporting window is simply unrealistic without some degree of automated triage and evidence collection. Organisations that rely on manual processes routinely breach the window, creating regulatory exposure on top of the incident itself.
  • Vendor diversity without unified management: A typical large BFSI estate runs FortiGate firewalls at the perimeter, a mix of Cisco and Juniper switches in the core, wireless APs from multiple vendors, and WAFs and DDoS appliances in the cloud. Getting unified observability across this estate is a persistent challenge.

A Practical Compliance Checklist for BFSI CISOs

Use this as a starting-point gap assessment, not an exhaustive audit framework:

  • ☐ 24×7 SOC in place (internal or outsourced MSSP) with documented escalation procedures
  • ☐ SIEM deployed with centralised log ingestion covering all critical ICT assets (network, endpoint, application)
  • ☐ Log retention policy confirmed at ≥180 days; storage hosted on Indian soil
  • ☐ NTP synchronised across all devices to an Indian NTP source
  • ☐ CERT-In incident reporting runbook tested; team knows the 6-hour window starts at detection, not confirmation
  • ☐ SEBI CSCRF Cyber Capability Index (CCI) self-assessment completed and documented
  • ☐ Annual VAPT by CERT-In empanelled auditor scheduled
  • ☐ FortiGate (or equivalent NGFW) firmware on current, supported version; quarterly patch review cycle in place
  • ☐ Network segmentation reviewed; core banking systems isolated from general staff network
  • ☐ Third-party vendor access governed through PAM or at minimum MFA + time-limited access
  • ☐ DPDP Act data mapping exercise initiated; Significant Data Fiduciary status assessed
  • ☐ Incident response playbooks cover ransomware, data exfiltration, business email compromise, and insider threat scenarios
  • ☐ DR/BCP drill conducted within last 12 months with documented results shared with board

PrahiX Ora: The Unified SecOps Platform We Deploy for BFSI Clients

Meeting the above checklist items requires operational infrastructure that most mid-size BFSI enterprises cannot cost-effectively build in-house. This is where PrahiX Ora — a unified SecOps platform built by PrahiX Tech Pvt Ltd, which PJ Networks deploys and operates for clients — addresses the structural gaps described above across four integrated pillars.

SIEM — CERT-In Compliant Log Retention at Scale. The platform ingests logs from multi-source environments — FortiGate and Fortinet security fabric, switches, endpoints, cloud workloads, and core banking applications — into a single correlation engine. Detection rules are mapped to MITRE ATT&CK, enabling structured detection of the tactics and techniques most relevant to BFSI threats: credential access, lateral movement, and data exfiltration. Critically for BFSI, the platform supports tiered retention (hot, cold, and archive tiers) that is designed to satisfy CERT-In’s 180-day in-country log retention direction without requiring unlimited hot-storage budgets. Attack storyline reconstruction — visualising how a multi-stage attack progressed through the environment — turns what would be days of manual log analysis into an analyst-usable graph within hours.

NMS — Visibility Across Your Entire Multi-Vendor Estate. The network management pillar provides unified observability across FortiGate firewalls, core switches, WAN and SD-WAN links, and wireless access points — regardless of vendor. LLDP and CDP topology discovery automatically maps the network, removing the manual maintenance burden from NOC teams. Network path tracing helps isolate degradation or suspicious traffic flows in multi-hop branch environments. ML-based anomaly detection flags unusual traffic patterns — for example, a branch router suddenly initiating large outbound transfers after business hours — and auto-healing policies can push remediating configurations to devices. For BFSI enterprises with fragmented NOC visibility across dozens of branches, this pillar alone often closes the most significant blind spots.

Video Surveillance (VMS) — Physical and Cyber Under One Operations View. The video surveillance (VMS) pillar supports ONVIF-compliant cameras alongside Hikvision and Dahua device families, with video analytics capabilities (motion zones, object detection, access control integration). For manufacturing, retail banking branches, or multi-site insurance offices, having physical security events — an after-hours server room access — correlated with network events in the same operations console is a capability that most enterprises currently manage across disconnected systems. Consolidating physical and network security operations reduces both tool sprawl and the risk that a coordinated physical-digital attack goes undetected because the two teams weren’t sharing information.

SOAR — Making the 6-Hour Window Realistic. Pre-built playbook connectors automate the most time-critical incident response steps: isolating a compromised endpoint, pushing block rules to FortiGate, generating the structured CERT-In incident notification draft with evidence already attached. For BFSI enterprises, the CERT-In 6-hour reporting window is the most operationally demanding compliance obligation — not because it is difficult to report, but because gathering the evidence, validating the incident scope, and drafting an accurate notification in under six hours is genuinely hard without automation. SOAR automation is what makes that timeline realistic rather than aspirational.

If your BFSI organisation is evaluating unified SecOps platforms or looking to close SIEM, NMS, or SOAR gaps in your current architecture, we are happy to walk you through how PrahiX Ora is deployed and operated in BFSI environments. Contact the PJ Networks team to schedule a conversation.

How PJ Networks Supports BFSI Compliance

PJ Networks operates as a managed security provider with a particular depth in Fortinet technologies — FortiGate NGFW, FortiMail, FortiAnalyzer, FortiSIEM, and the broader Fortinet Security Fabric — alongside our operations of the PrahiX Ora SecOps platform. For BFSI clients, this translates to:

  • 24/7 NOC/SOC: Continuous monitoring with analysts who understand BFSI-specific threat patterns and regulatory reporting obligations. SOC escalation procedures are documented and tested against the 6-hour CERT-In window.
  • FortiGate NGFW Management: Centrally managed firewall policies across branch and HQ environments, with firmware lifecycle management to ensure you are never running an exploited version.
  • ZTNA and Secure Remote Access: Zero Trust Network Access for employees, vendors, and fintech API partners — replacing legacy VPN with identity-aware, least-privilege access policies.
  • MSSP Engagement Models: Whether you need full SOC outsourcing, co-managed SIEM, or specific device management, our engagement models are designed to fit alongside existing in-house teams rather than replace them entirely.
  • Compliance Alignment: Our delivery teams are familiar with RBI, SEBI CSCRF, IRDAI, CERT-In, and DPDP requirements. We help clients build the documentation, evidence packs, and operational procedures that support compliance — not just the controls themselves.

Getting Started: Priority Actions for Q4 2026

If your BFSI organisation is heading into the next RBI/SEBI audit cycle or preparing for your first DPDP Act compliance assessment, these are the highest-priority actions to focus on:

  1. Close the log coverage gap first. CERT-In’s 180-day retention mandate only protects you if the logs actually exist. Map your ICT estate and identify devices that are not currently sending logs to a SIEM or centralised logging platform.
  2. Build and test your CERT-In incident reporting runbook. Tabletop-test a simulated ransomware incident against the 6-hour window. Identify where the manual steps are and prioritise automation there.
  3. Verify NTP synchronisation across all branches. This is a quick win that is frequently missed and creates legal complications when log timestamps don’t align across devices during a post-incident investigation.
  4. Assess your SEBI CCI score if applicable. The self-assessment is a useful diagnostic even for non-SEBI entities, as it identifies which NIST CSF functions are weakest.
  5. Start the DPDP Act data mapping exercise. This is not a security team task alone — it requires legal, compliance, and business stakeholders. Starting now, ahead of full rules notification, gives you the runway to address gaps systematically.

India’s BFSI sector has always operated under significant regulatory scrutiny, and cybersecurity is now a first-tier concern for every financial regulator in the country. The organisations that will navigate 2026 audit cycles with the least disruption are those building continuous, evidence-generating security operations — not those scrambling to produce documentation in the weeks before an inspection.

To discuss how PJ Networks can help your BFSI organisation build or strengthen its security operations capability, get in touch with our team. We offer no-obligation discovery conversations to assess where you stand against the current regulatory requirements.

Leave a Reply

Your email address will not be published. Required fields are marked *