The Reserve Bank of India (RBI) has heightened supervisory enforcement under its unified Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions. The comprehensive directive binds Scheduled Commercial Banks, Non-Banking Financial Companies (NBFCs), Urban Co-operative Banks, and Payment System Operators to rigorous governance standards. Crucially, the directions mandate that all cyber incidents must be formally reported within six hours of detection via the RBI's centralized DAKSH portal, with concurrent statutory disclosures to CERT-In.

The Six-Hour Incident Disclosure Clock & Multi-Tier Reporting

The mandatory six-hour window represents one of the most stringent regulatory reporting thresholds globally, aligning India's financial sector with national CERT-In mandates under Section 70B of the Information Technology Act.

Regulated Entities (REs) must classify and escalate events according to their systemic severity:

Milestone Required Action Supervisory Channel
T + 6 Hours Initial Incident Notification (root vector, affected systems, preliminary containment) DAKSH Portal & CERT-In Incident Reporting
T + 24 Hours Detailed Technical Update (IOCs, exfiltrated telemetry, forensic telemetry) RBI Cyber Security and IT Risk Cell (CSITE)
T + 14 Days Comprehensive Post-Incident Review & Root Cause Analysis (RCA) Board IT Strategy Committee & RBI Supervisory Panel

Board-Level Governance & Enterprise Accountability

A central pillar of the 2026 framework is the shift from IT operational ownership to explicit Board of Directors accountability. Boards are legally required to:

  • Establish an IT Strategy Committee: Chaired by an independent director, meeting at least quarterly to evaluate cyber maturity and vulnerability backlogs.
  • Appoint an Independent Chief Information Security Officer (CISO): The CISO must report directly to the Executive Director or Board Risk Committee, completely separated from commercial business targets and IT operations.
  • Continuous Third-Party Risk Oversight: Continuous monitoring and SLA enforcement for cloud hosting providers, core banking SaaS vendors, and payment gateway APIs.

Technical Requirements: 180-Day Log Retention & Threat Hunting

The directions mandate concrete, auditable engineering controls across financial infrastructure:

  • 180-Day Immutable Log Retention: All perimeter firewalls, Active Directory domain controllers, VPN concentrators, and database transaction engines must ship logs to an off-site, write-once-read-many (WORM) SIEM architecture for a minimum of 180 days.
  • Automated Disaster Recovery (DR) Drills: Core banking engines (CBS) must conduct unannounced live switchovers to secondary Disaster Recovery sites at least twice annually, proving recovery point objectives (RPO) within seconds and recovery time objectives (RTO) under two hours.
  • API Security Gateways: Implementation of mutual TLS (mTLS), strict token expiration, and real-time behavioral rate limiting across all open banking and UPI integration endpoints.