Skip to main content

Cybersecurity Insights & Guides

Expert insights on cybersecurity, vulnerability management, and digital defence strategies.

Compliance Services

ATM Switch and CBS Providers: The Controls Your Bank Customers Must Now Impose on You

Four of the six RBI Directions require banks to impose named cybersecurity controls on their ATM Switch and core banking service providers by contract — 24 of them for commercial banks, 37 for urban co-operative banks. The obligation flows down even where it does not sit at the top.

Security Brigade Editorial Team 09 Aug 2026
Compliance Services

Foreign Bank Branches and Comply-or-Explain: What Paragraph 4 Actually Buys You

The RBI Directions, 2026 contain exactly one comply-or-explain device, and it applies only to foreign banks operating in India through branch mode. It covers four chapters and sixteen named paragraph groups — and it is a relaxation subject to RBI accepting your explanation, not an exemption.

Security Brigade Editorial Team 09 Aug 2026
Compliance Services

Case Study: Moving a Commercial Bank from Annual Testing to the Paragraph 151 Cadence

A commercial bank running annual point-in-time VAPT re-scoped to the RBI Directions, 2026 — six-monthly vulnerability assessment, production-environment testing, cloud in scope, and a quarterly closure pack for the ITSC and ISC that did not previously exist as an artefact.

Security Brigade Editorial Team 09 Aug 2026
Compliance Services

RBI Cybersecurity Directions for Small Finance Banks, Payments Banks and Credit Information Companies

Three entity types, three instruments, no internal tiering — which means the full baseline binds from day one. SFBs and payments banks are expressly carved out of the commercial banks Direction, which confuses people who assume it covers them.

Security Brigade Editorial Team 09 Aug 2026
Compliance Services

RBI Cybersecurity Directions for Urban Co-operative Banks: Finding Your Level

The four Levels in RBI/DoS/2026-27/437 are set by digital depth and payment-system interconnectedness, not asset size. UPI, IMPS or CTS membership lifts a small bank to Level II, where VA/PT begins.

Security Brigade Editorial Team 09 Aug 2026
Compliance Services

RBI Cybersecurity Directions for NBFCs: Which Chapter Applies to Your Layer

RBI/DoS/2026-27/461 does not apply uniformly. Chapter III binds Base Layer NBFCs under ₹500 crore and Core Investment Companies, Chapter IV binds Base Layer at ₹500 crore and above, and Chapter V binds Middle Layer and above. The bands are mutually exclusive.

Security Brigade Editorial Team 09 Aug 2026
Compliance Services

Paragraph 148: The One RBI Obligation You Are Not Allowed to Satisfy In-House

Most of the RBI Directions, 2026 are outcome-based. Paragraph 148 is not — it names the delivery model, requiring anti-phishing and anti-rogue-app takedown services from external service providers. An internal capability does not discharge it.

Security Brigade Editorial Team 09 Aug 2026
Compliance Services

RBI VAPT Requirements in 2026: Six Months, Twelve Months, and What "Critical and/or DMZ" Means

Vulnerability assessment every six months, penetration testing every twelve. The scope is disjunctive, the cloud extension is new, and "annual VAPT" — which we published ourselves until this month — understates the tested cadence by half.

Security Brigade Editorial Team 09 Aug 2026
Compliance Services

Paragraph 158: When a Breach Becomes Your Auditor's Deficiency

Three paragraphs of the RBI Directions, 2026 govern how a bank must handle its testing vendor — and one of them makes a later breach of a tested system a recorded deficiency against the auditor, carried into renewal. There is no counterpart in the 2016 framework or the 2023 Master Direction.

Security Brigade Editorial Team 09 Aug 2026

OWASP Mobile Top 10 (2024): The Definitive Guide for Indian Mobile App Teams

A reference walkthrough of every risk in the OWASP Mobile Top 10 (2024 release) — what each risk means in plain English, how attackers exploit it on Android and iOS, what your engineering team should fix, and how a CERT-In empanelled pentest validates the fix.

Security Brigade Research Team 15 May 2026

SEBI CSCRF for Custodians: AUC Tiers & CCI Obligations

Custodians under SEBI CSCRF: Assets Under Custody drives three-tier classification (₹1L Cr, ₹10L Cr thresholds), CCI self-assessment at QRE, and what custodians of every size must do.

Yash Kadakia & Security Brigade Research Team 06 May 2026

SEBI CSCRF for KRAs & QRTAs: The April 2025 Demotion & What It Means

KYC Registration Agencies were reclassified from MII to Qualified RE in April 2025. QRTAs (≥2 Cr folios) remain at MII tier. What changed, what stayed, and what KRAs and QRTAs must do now.

Yash Kadakia & Security Brigade Research Team 06 May 2026

SEBI CSCRF for AIFs & VCFs: Manager-Level Corpus Rule

CSCRF for Alternative Investment Funds and Venture Capital Funds: the April 2025 manager-level classification, corpus thresholds, sub-100-client exemptions, and what AIF/VCF managers must do.

Yash Kadakia & Security Brigade Research Team 06 May 2026

SEBI CSCRF for AMCs & Mutual Funds: AUM-Tiered Classification & Qualified RE Obligations

Asset Management Companies under SEBI CSCRF: AUM-tiered classification (₹10k Cr, ₹1L Cr thresholds), Qualified RE obligations, ISO 27001 voluntary status, and what AMCs of every size must do.

Yash Kadakia & Security Brigade Research Team 06 May 2026

SEBI CSCRF for Stock Brokers: The Two-Parameter Rule, Thresholds & QSB → QRE Link

SEBI's April 2025 CSCRF amendment rewrote stock-broker classification: clients OR trading volume determines your tier, and the higher of the two wins. How the two-parameter rule works, what each tier requires, and the QSB auto-classification.

Yash Kadakia & Security Brigade Research Team 06 May 2026

The Principle of Exclusivity and Equivalence Under SEBI CSCRF: A Guide for Multi-Regulator Entities

SEBI's August 2025 clarifications introduced two principles for entities regulated by multiple bodies: Exclusivity (CSCRF covers only SEBI-regulated activities) and Equivalence (duplicate audits not required if the other regulator's framework matches). Here's how they work.

Yash Kadakia & Security Brigade Research Team 06 May 2026

SEBI CSCRF Data Localisation in Abeyance: What Regulated Entities Should Know

SEBI's Data Localisation mandate (PR.DS.S2) has been in regulatory abeyance since December 2024. What this means for compliance planning, what stays binding, and what to do instead of building a localisation programme that may never activate.

Yash Kadakia & Security Brigade Research Team 06 May 2026

August 2025 SEBI CSCRF Technical Clarifications: ISO 27001, PM Revision & More

SEBI's August 2025 technical clarifications made ISO 27001 voluntary for QREs, downgraded Mobile App Security and BAS/CART to recommendatory, narrowed critical-systems scope, and introduced multi-regulator principles. Decoded.

Yash Kadakia & Security Brigade Research Team 06 May 2026

What Changed in the April 2025 SEBI CSCRF Amendment

SEBI's April 2025 CSCRF amendment rewrote stock-broker thresholds with a two-parameter rule, reclassified KRAs from MII to QRE, clubbed AIFs+VCFs at the manager level, and introduced the HSM mandate. Here's what every regulated entity needs to know.

Yash Kadakia & Security Brigade Research Team 06 May 2026
Compliance Services

SEBI CSCRF in 2026: A Complete Guide for SEBI Regulated Entities

A comprehensive guide to SEBI's Cybersecurity and Cyber Resilience Framework — the 5-tier model, 22 entity types, amendment history through Aug 2025, and what every regulated entity needs to do in FY 2026-27.

Yash Kadakia & Security Brigade Research Team 06 May 2026
Compliance Services

SEBI's May 2026 AI Vulnerability Detection Advisory: What Every Regulated Entity Must Do Now

SEBI just issued an advisory on AI tools like Claude Mythos that find vulnerabilities at speed and scale. 10 directives, 19 regulated-entity categories, and a 90-day path to readiness — decoded.

Yash Kadakia & Security Brigade Research Team 05 May 2026
Consulting Services

VAPT vs Penetration Testing: Which Do You Actually Need?

The terms get used interchangeably in Indian procurement RFPs, but they describe different things. What the distinction means for scoping, cost, and the report you receive.

Security Brigade Editorial Team 29 Apr 2026
Compliance Services

How to Choose a CERT-In Empanelled Security Auditor

CERT-In empanelment is a qualifying criterion, not a substitute for due diligence. Here is what to evaluate when shortlisting auditors for a regulated engagement.

Security Brigade Editorial Team 29 Apr 2026
Consulting Services

Manual vs Automated Penetration Testing: The Real Difference

Scanners excel at pattern matching. Manual testing covers what they cannot. Here is the real gap, with examples of findings each approach reliably catches and misses.

Security Brigade Editorial Team 29 Apr 2026
Compliance Services

RBI Cybersecurity Framework in 2026: What Replaced It, and What Banks Must Do Now

The framework you are looking for was repealed on 31 July 2026, along with 627 other circulars. Six new Directions replaced it, one per class of regulated entity, all in force on issuance. What changed, what carried forward, and the cadence most guidance is stating incorrectly.

Security Brigade Editorial Team 29 Apr 2026
Consulting Services

OWASP Top 10 Explained for Business Leaders

A non-technical walk through the OWASP Top 10 — the ten classes of web application risk that account for the bulk of breaches we see in real engagements — and what each one actually costs your business.

Security Brigade Editorial Team 29 Apr 2026

Have a question this did not answer?

Our team answers regulatory and testing questions directly — no discovery call required to get a straight answer.

Talk to our team