Cybersecurity Insights & Guides
Expert insights on cybersecurity, vulnerability management, and digital defence strategies.
ATM Switch and CBS Providers: The Controls Your Bank Customers Must Now Impose on You
Four of the six RBI Directions require banks to impose named cybersecurity controls on their ATM Switch and core banking service providers by contract — 24 of them for commercial banks, 37 for urban co-operative banks. The obligation flows down even where it does not sit at the top.
Foreign Bank Branches and Comply-or-Explain: What Paragraph 4 Actually Buys You
The RBI Directions, 2026 contain exactly one comply-or-explain device, and it applies only to foreign banks operating in India through branch mode. It covers four chapters and sixteen named paragraph groups — and it is a relaxation subject to RBI accepting your explanation, not an exemption.
Case Study: Moving a Commercial Bank from Annual Testing to the Paragraph 151 Cadence
A commercial bank running annual point-in-time VAPT re-scoped to the RBI Directions, 2026 — six-monthly vulnerability assessment, production-environment testing, cloud in scope, and a quarterly closure pack for the ITSC and ISC that did not previously exist as an artefact.
RBI Cybersecurity Directions for Small Finance Banks, Payments Banks and Credit Information Companies
Three entity types, three instruments, no internal tiering — which means the full baseline binds from day one. SFBs and payments banks are expressly carved out of the commercial banks Direction, which confuses people who assume it covers them.
RBI Cybersecurity Directions for Urban Co-operative Banks: Finding Your Level
The four Levels in RBI/DoS/2026-27/437 are set by digital depth and payment-system interconnectedness, not asset size. UPI, IMPS or CTS membership lifts a small bank to Level II, where VA/PT begins.
RBI Cybersecurity Directions for NBFCs: Which Chapter Applies to Your Layer
RBI/DoS/2026-27/461 does not apply uniformly. Chapter III binds Base Layer NBFCs under ₹500 crore and Core Investment Companies, Chapter IV binds Base Layer at ₹500 crore and above, and Chapter V binds Middle Layer and above. The bands are mutually exclusive.
Paragraph 148: The One RBI Obligation You Are Not Allowed to Satisfy In-House
Most of the RBI Directions, 2026 are outcome-based. Paragraph 148 is not — it names the delivery model, requiring anti-phishing and anti-rogue-app takedown services from external service providers. An internal capability does not discharge it.
RBI VAPT Requirements in 2026: Six Months, Twelve Months, and What "Critical and/or DMZ" Means
Vulnerability assessment every six months, penetration testing every twelve. The scope is disjunctive, the cloud extension is new, and "annual VAPT" — which we published ourselves until this month — understates the tested cadence by half.
Paragraph 158: When a Breach Becomes Your Auditor's Deficiency
Three paragraphs of the RBI Directions, 2026 govern how a bank must handle its testing vendor — and one of them makes a later breach of a tested system a recorded deficiency against the auditor, carried into renewal. There is no counterpart in the 2016 framework or the 2023 Master Direction.
OWASP Mobile Top 10 (2024): The Definitive Guide for Indian Mobile App Teams
A reference walkthrough of every risk in the OWASP Mobile Top 10 (2024 release) — what each risk means in plain English, how attackers exploit it on Android and iOS, what your engineering team should fix, and how a CERT-In empanelled pentest validates the fix.
SEBI CSCRF for Custodians: AUC Tiers & CCI Obligations
Custodians under SEBI CSCRF: Assets Under Custody drives three-tier classification (₹1L Cr, ₹10L Cr thresholds), CCI self-assessment at QRE, and what custodians of every size must do.
SEBI CSCRF for KRAs & QRTAs: The April 2025 Demotion & What It Means
KYC Registration Agencies were reclassified from MII to Qualified RE in April 2025. QRTAs (≥2 Cr folios) remain at MII tier. What changed, what stayed, and what KRAs and QRTAs must do now.
SEBI CSCRF for AIFs & VCFs: Manager-Level Corpus Rule
CSCRF for Alternative Investment Funds and Venture Capital Funds: the April 2025 manager-level classification, corpus thresholds, sub-100-client exemptions, and what AIF/VCF managers must do.
SEBI CSCRF for AMCs & Mutual Funds: AUM-Tiered Classification & Qualified RE Obligations
Asset Management Companies under SEBI CSCRF: AUM-tiered classification (₹10k Cr, ₹1L Cr thresholds), Qualified RE obligations, ISO 27001 voluntary status, and what AMCs of every size must do.
SEBI CSCRF for Stock Brokers: The Two-Parameter Rule, Thresholds & QSB → QRE Link
SEBI's April 2025 CSCRF amendment rewrote stock-broker classification: clients OR trading volume determines your tier, and the higher of the two wins. How the two-parameter rule works, what each tier requires, and the QSB auto-classification.
The Principle of Exclusivity and Equivalence Under SEBI CSCRF: A Guide for Multi-Regulator Entities
SEBI's August 2025 clarifications introduced two principles for entities regulated by multiple bodies: Exclusivity (CSCRF covers only SEBI-regulated activities) and Equivalence (duplicate audits not required if the other regulator's framework matches). Here's how they work.
SEBI CSCRF Data Localisation in Abeyance: What Regulated Entities Should Know
SEBI's Data Localisation mandate (PR.DS.S2) has been in regulatory abeyance since December 2024. What this means for compliance planning, what stays binding, and what to do instead of building a localisation programme that may never activate.
August 2025 SEBI CSCRF Technical Clarifications: ISO 27001, PM Revision & More
SEBI's August 2025 technical clarifications made ISO 27001 voluntary for QREs, downgraded Mobile App Security and BAS/CART to recommendatory, narrowed critical-systems scope, and introduced multi-regulator principles. Decoded.
What Changed in the April 2025 SEBI CSCRF Amendment
SEBI's April 2025 CSCRF amendment rewrote stock-broker thresholds with a two-parameter rule, reclassified KRAs from MII to QRE, clubbed AIFs+VCFs at the manager level, and introduced the HSM mandate. Here's what every regulated entity needs to know.
SEBI CSCRF in 2026: A Complete Guide for SEBI Regulated Entities
A comprehensive guide to SEBI's Cybersecurity and Cyber Resilience Framework — the 5-tier model, 22 entity types, amendment history through Aug 2025, and what every regulated entity needs to do in FY 2026-27.
SEBI's May 2026 AI Vulnerability Detection Advisory: What Every Regulated Entity Must Do Now
SEBI just issued an advisory on AI tools like Claude Mythos that find vulnerabilities at speed and scale. 10 directives, 19 regulated-entity categories, and a 90-day path to readiness — decoded.
VAPT vs Penetration Testing: Which Do You Actually Need?
The terms get used interchangeably in Indian procurement RFPs, but they describe different things. What the distinction means for scoping, cost, and the report you receive.
How to Choose a CERT-In Empanelled Security Auditor
CERT-In empanelment is a qualifying criterion, not a substitute for due diligence. Here is what to evaluate when shortlisting auditors for a regulated engagement.
Manual vs Automated Penetration Testing: The Real Difference
Scanners excel at pattern matching. Manual testing covers what they cannot. Here is the real gap, with examples of findings each approach reliably catches and misses.
RBI Cybersecurity Framework in 2026: What Replaced It, and What Banks Must Do Now
The framework you are looking for was repealed on 31 July 2026, along with 627 other circulars. Six new Directions replaced it, one per class of regulated entity, all in force on issuance. What changed, what carried forward, and the cadence most guidance is stating incorrectly.
OWASP Top 10 Explained for Business Leaders
A non-technical walk through the OWASP Top 10 — the ten classes of web application risk that account for the bulk of breaches we see in real engagements — and what each one actually costs your business.
Have a question this did not answer?
Our team answers regulatory and testing questions directly — no discovery call required to get a straight answer.
Talk to our team