Brief Overview:
As cyber threats become more sophisticated, regulatory expectations are evolving just as quickly. Building on its recent data governance initiative, the RBI has now issued comprehensive directions on cybersecurity and cyber resilience for commercial banks, embedding cyber risk management firmly within the governance framework of banks.
Technical Details:
1) Cyber risk moves to the boardroom: Boards must take ownership of cyber resilience through approved governance frameworks, periodic policy reviews, oversight of IT strategy, cybersecurity, business continuity and disaster recovery, supported by dedicated Board committees, a chief information security officer, and independent audit mechanisms.
2) Always-on cyber defence: Banks must implement baseline cybersecurity controls, establish a ‘Cyber Security Operations Centre’ for continuous surveillance, conduct periodic vulnerability assessments and penetration testing for all the critical and internet facing systems, and put in place cyber incident response and recovery management policy and related procedures.
3) Vendor risk stays with the bank: The bank shall carefully evaluate the need for outsourcing critical processes and selection of vendor / partner based on comprehensive risk assessment. The bank shall also regularly conduct effective due diligence, oversight, and management of third-party vendors / service providers and partners. Further, the bank shall also establish appropriate policies and procedures to evaluate, assess, approve, review, control and monitor the risks and materiality of all its vendor / outsourcing activities.
JC Takeaways:
The directions make cyber resilience a Board-level governance and risk priority, not just an IT issue. Further, banks shall also remain liable for any outsourcing of any critical processes to third-party vendors. Banks should now proactively assess their governance, technology, outsourcing, monitoring, testing and incident response frameworks, and begin remediation early to address compliance, operational and contractual gaps.
For further details, please see:
RBI – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions 2026
For any queries/clarifications, please feel free to ping us and we will be happy to chat:
