Skip to main content

Security Brigade Editorial Team

Regulatory and Technical Research · Security Brigade

RBI Directions 2026 SEBI CSCRF CERT-In empanelment VAPT scoping Regulatory compliance

The editorial team reads the primary sources so you do not have to. Every regulatory piece here is written against the circular, Direction or standard itself and cites the paragraph, and every technical piece is reviewed by the practice lead who runs that kind of engagement.

Articles by Security Brigade Editorial Team

ATM Switch and CBS Providers: The Controls Your Bank Customers Must Now Impose on You

Four of the six RBI Directions require banks to impose named cybersecurity controls on their ATM Switch and core banking service providers by contract — 24 of them for commercial banks, 37 for urban co-operative banks. The obligation flows down even where it does not sit at the top.

August 9, 2026

Foreign Bank Branches and Comply-or-Explain: What Paragraph 4 Actually Buys You

The RBI Directions, 2026 contain exactly one comply-or-explain device, and it applies only to foreign banks operating in India through branch mode. It covers four chapters and sixteen named paragraph groups — and it is a relaxation subject to RBI accepting your explanation, not an exemption.

August 9, 2026

Case Study: Moving a Commercial Bank from Annual Testing to the Paragraph 151 Cadence

A commercial bank running annual point-in-time VAPT re-scoped to the RBI Directions, 2026 — six-monthly vulnerability assessment, production-environment testing, cloud in scope, and a quarterly closure pack for the ITSC and ISC that did not previously exist as an artefact.

August 9, 2026

RBI Cybersecurity Directions for Small Finance Banks, Payments Banks and Credit Information Companies

Three entity types, three instruments, no internal tiering — which means the full baseline binds from day one. SFBs and payments banks are expressly carved out of the commercial banks Direction, which confuses people who assume it covers them.

August 9, 2026

RBI Cybersecurity Directions for Urban Co-operative Banks: Finding Your Level

The four Levels in RBI/DoS/2026-27/437 are set by digital depth and payment-system interconnectedness, not asset size. UPI, IMPS or CTS membership lifts a small bank to Level II, where VA/PT begins.

August 9, 2026

RBI Cybersecurity Directions for NBFCs: Which Chapter Applies to Your Layer

RBI/DoS/2026-27/461 does not apply uniformly. Chapter III binds Base Layer NBFCs under ₹500 crore and Core Investment Companies, Chapter IV binds Base Layer at ₹500 crore and above, and Chapter V binds Middle Layer and above. The bands are mutually exclusive.

August 9, 2026

Paragraph 148: The One RBI Obligation You Are Not Allowed to Satisfy In-House

Most of the RBI Directions, 2026 are outcome-based. Paragraph 148 is not — it names the delivery model, requiring anti-phishing and anti-rogue-app takedown services from external service providers. An internal capability does not discharge it.

August 9, 2026

RBI VAPT Requirements in 2026: Six Months, Twelve Months, and What "Critical and/or DMZ" Means

Vulnerability assessment every six months, penetration testing every twelve. The scope is disjunctive, the cloud extension is new, and "annual VAPT" — which we published ourselves until this month — understates the tested cadence by half.

August 9, 2026

Paragraph 158: When a Breach Becomes Your Auditor's Deficiency

Three paragraphs of the RBI Directions, 2026 govern how a bank must handle its testing vendor — and one of them makes a later breach of a tested system a recorded deficiency against the auditor, carried into renewal. There is no counterpart in the 2016 framework or the 2023 Master Direction.

August 9, 2026

VAPT vs Penetration Testing: Which Do You Actually Need?

The terms get used interchangeably in Indian procurement RFPs, but they describe different things. Here is what the distinction means for scoping, cost, and the kind of report you walk away with.

April 29, 2026

How to Choose a CERT-In Empanelled Security Auditor

CERT-In empanelment narrows the candidate list, but it does not pick a winner. Here is what to actually evaluate when shortlisting auditors for a regulated engagement.

April 29, 2026

Manual vs Automated Penetration Testing: The Real Difference

Scanners are good at what they are good at. Manual testing covers what they cannot. Here is the actual gap, with examples of findings each approach reliably catches and misses.

April 29, 2026

RBI Cybersecurity Framework in 2026: What Replaced It, and What Banks Must Do Now

The framework you are looking for was repealed on 31 July 2026, along with 627 other circulars. Six new Directions replaced it, one per class of regulated entity, all in force on issuance. What changed, what carried forward, and the cadence most guidance is stating incorrectly.

April 29, 2026

OWASP Top 10 Explained for Business Leaders

A non-technical walk through the OWASP Top 10 — the ten classes of web application risk that account for the bulk of breaches we see in real engagements — and what each one actually costs your business.

April 29, 2026