Skip to main content

Cybersecurity Insights & Guides

Research, analysis, and practical guidance on cybersecurity, vulnerability management, and digital defence.

Google Play removes unregistered app packages on 30 September 2026

Google removes unregistered Play packages on 30 September 2026, and the sentence that does it carries no country limit. What automatic registration turns on, why the four-country announcement beside it binds someone else, and what to check in Play Console this week.

Yash K & Security Brigade Research Team 20 Sept 2026

PCI SSC revised FAQ 1331: who now agrees SAQ-based scoping

PCI SSC revised FAQ 1331 in August 2026. SAQ-based scoping in a ROC now needs the compliance accepting entity's agreement.

Yash K & Security Brigade Research Team 14 Sept 2026

CERT-In's OEM guidelines: five deliverables, and a named right to test your supplier

Five deliverables CERT-In advises OEMs to maintain, indicative patch timelines for IT and OT, and a named right for buyers to test.

Yash K & Security Brigade Research Team 14 Sept 2026

CERT-In's space framework: an annual empanelled audit, five testing phases

An internal audit every six months, an external audit through a CERT-In empanelled organisation every year, and five testing phases across the mission lifecycle.

Yash K & Security Brigade Research Team 14 Sept 2026

SEBI's MII subsidiary proposal: three tests, one narrow exemption

Three tests decide whether an MII's IT and cyber framework reaches a subsidiary. SEBI's proposal, and the one narrow exemption.

Yash K & Security Brigade Research Team 14 Sept 2026

The Significant Data Fiduciary's Four Duties Under Rule 13

Rule 13's four duties for a Significant Data Fiduciary: a twelve-month DPIA and audit, a Board report, algorithmic due diligence, an India-only restriction.

Yash K & Security Brigade Research Team

DPDP Rule 7: Three Breach Intimations, One Extendable Clock

One breach starts three intimations under DPDP Rule 7. Two are owed without delay; the seventy-two-hour Board filing is extendable on written request.

Yash K & Security Brigade Research Team

DPDP Rule 6: the seven security safeguards, and the runway to May 2027

Rule 6's seven minimum safeguards commence 13 or 14 May 2027. What each limb must produce, and the two that need a budget.

Yash K & Security Brigade Research Team
Compliance Services

ATM Switch and CBS Providers: The Controls Your Bank Customers Must Now Impose on You

Four of the six RBI Directions require banks to impose named cybersecurity controls on their ATM Switch and core banking service providers by contract: 24 of them for commercial banks, 37 for urban co-operative banks. The controls land on the provider, and the bank is the one that has to put them there.

Security Brigade Editorial Team 09 Aug 2026
Compliance Services

Foreign Bank Branches and Comply-or-Explain: What Paragraph 4 Actually Buys You

The RBI Directions, 2026 contain exactly one comply-or-explain device, and it applies only to foreign banks operating in India through branch mode. It covers four chapters and sixteen named paragraph groups. The relaxation is conditional: RBI has to accept your explanation.

Security Brigade Editorial Team 09 Aug 2026
Compliance Services

Case Study: Moving a Commercial Bank from Annual Testing to the Paragraph 151 Cadence

A commercial bank on annual point-in-time VAPT re-scoped its programme to the RBI Directions, 2026: six-monthly vulnerability assessment, production-environment testing, cloud in scope, and a quarterly closure pack for the ITSC and ISC produced for the first time.

Security Brigade Editorial Team 09 Aug 2026
Compliance Services

RBI Cybersecurity Directions for Small Finance Banks, Payments Banks and Credit Information Companies

Small finance banks, payments banks and credit information companies each get their own instrument, and the full baseline binds from day one. SFBs and payments banks are expressly carved out of the commercial banks Direction, so their paragraph numbers come from elsewhere.

Security Brigade Editorial Team 09 Aug 2026
Compliance Services

RBI Cybersecurity Directions for Urban Co-operative Banks: Finding Your Level

The four Levels in RBI/DoS/2026-27/437 are set by digital depth and payment-system interconnectedness, not asset size. UPI, IMPS or CTS membership lifts a small bank to Level II, where VA/PT begins.

Security Brigade Editorial Team 09 Aug 2026
Compliance Services

RBI Cybersecurity Directions for NBFCs: Which Chapter Applies to Your Layer

RBI/DoS/2026-27/461 does not apply uniformly. Chapter III binds Base Layer NBFCs under ₹500 crore and Core Investment Companies, Chapter IV binds Base Layer at ₹500 crore and above, and Chapter V binds Middle Layer and above. The bands are mutually exclusive.

Security Brigade Editorial Team 09 Aug 2026
Compliance Services

Paragraph 148: The One RBI Obligation You Are Not Allowed to Satisfy In-House

The RBI Directions, 2026 are mostly outcome-based. Paragraph 148 also names the delivery model: anti-phishing and anti-rogue-app takedown procured as services from external service providers.

Security Brigade Editorial Team 09 Aug 2026
Compliance Services

RBI VAPT Requirements in 2026: Six Months, Twelve Months, and What "Critical and/or DMZ" Means

Vulnerability assessment every six months, penetration testing every twelve. The scope is disjunctive, the cloud extension is new, and "annual VAPT", which we published ourselves until this month, understates the tested cadence by half.

Security Brigade Editorial Team 09 Aug 2026
Compliance Services

Paragraph 158: When a Breach Becomes Your Auditor's Deficiency

Three paragraphs of the RBI Directions, 2026 govern how a bank must handle its testing vendor. One of them is new: a later breach of a tested system becomes a recorded deficiency against the auditor, carried into renewal.

Security Brigade Editorial Team 09 Aug 2026

OWASP Mobile Top 10 (2024): The Definitive Guide for Indian Mobile App Teams

Every risk in the OWASP Mobile Top 10 (2024 release), taken in turn: what each one means in plain English, how attackers exploit it on Android and iOS, what your engineering team should fix, and how a CERT-In empanelled pentest validates the fix.

Security Brigade Research Team 15 May 2026

SEBI CSCRF for Custodians: AUC Tiers & CCI Obligations

Custodians under SEBI CSCRF: Assets Under Custody drives three-tier classification (₹1L Cr, ₹10L Cr thresholds), CCI self-assessment at QRE, and what custodians of every size must do.

Yash K & Security Brigade Research Team 06 May 2026

SEBI CSCRF for KRAs & QRTAs: The April 2025 Demotion & What It Means

KYC Registration Agencies were reclassified from MII to Qualified RE in April 2025. QRTAs (≥2 Cr folios) remain at MII tier. What changed, what stayed, and what KRAs and QRTAs must do now.

Yash K & Security Brigade Research Team 06 May 2026

SEBI CSCRF for AIFs & VCFs: Manager-Level Corpus Rule

CSCRF for Alternative Investment Funds and Venture Capital Funds: the April 2025 manager-level classification, corpus thresholds, sub-100-client exemptions, and what AIF/VCF managers must do.

Yash K & Security Brigade Research Team 06 May 2026

SEBI CSCRF for AMCs & Mutual Funds: AUM-Tiered Classification & Qualified RE Obligations

Asset Management Companies under SEBI CSCRF: AUM-tiered classification (₹10k Cr, ₹1L Cr thresholds), Qualified RE obligations, ISO 27001 voluntary status, and what AMCs of every size must do.

Yash K & Security Brigade Research Team 06 May 2026

SEBI CSCRF for Stock Brokers: The Two-Parameter Rule, Thresholds & QSB → QRE Link

SEBI's April 2025 CSCRF amendment rewrote stock-broker classification: clients OR trading volume determines your tier, and the higher of the two wins. How the two-parameter rule works, what each tier requires, and the QSB auto-classification.

Yash K & Security Brigade Research Team 06 May 2026

The Principle of Exclusivity and Equivalence Under SEBI CSCRF: A Guide for Multi-Regulator Entities

SEBI's August 2025 clarifications introduced two principles for entities regulated by multiple bodies: Exclusivity (CSCRF covers only SEBI-regulated activities) and Equivalence (duplicate audits not required if the other regulator's framework matches). Here's how they work.

Yash K & Security Brigade Research Team 06 May 2026

SEBI CSCRF Data Localisation in Abeyance: What Regulated Entities Should Know

SEBI's Data Localisation mandate (PR.DS.S2) has been in regulatory abeyance since December 2024. What this means for compliance planning, what stays binding, and what to do instead of building a localisation programme that may never activate.

Yash K & Security Brigade Research Team 06 May 2026

August 2025 SEBI CSCRF Technical Clarifications: ISO 27001, PM Revision & More

SEBI's August 2025 technical clarifications made ISO 27001 voluntary for QREs, downgraded Mobile App Security and BAS/CART to recommendatory, narrowed critical-systems scope, and introduced multi-regulator principles. Decoded.

Yash K & Security Brigade Research Team 06 May 2026

What Changed in the April 2025 SEBI CSCRF Amendment

SEBI's April 2025 CSCRF amendment rewrote stock-broker thresholds with a two-parameter rule, reclassified KRAs from MII to QRE, clubbed AIFs+VCFs at the manager level, and introduced the HSM mandate. Here's what every regulated entity needs to know.

Yash K & Security Brigade Research Team 06 May 2026
Compliance Services

SEBI CSCRF in 2026: A Complete Guide for SEBI Regulated Entities

SEBI's Cybersecurity and Cyber Resilience Framework, covered in one place: the 5-tier model, 22 entity types, amendment history through Aug 2025, and what every regulated entity needs to do in FY 2026-27.

Yash K & Security Brigade Research Team 06 May 2026
Compliance Services

SEBI's May 2026 AI Vulnerability Detection Advisory: What Every Regulated Entity Must Do Now

SEBI has issued an advisory on AI tools like Claude Mythos that find vulnerabilities at speed and scale. What its 10 directives require, how they apply across the 19 regulated-entity categories, and a 90-day path to readiness.

Yash K & Security Brigade Research Team 05 May 2026
Consulting Services

VAPT vs Penetration Testing: Which Do You Actually Need?

Indian procurement RFPs use the two terms interchangeably. What the distinction means for scoping, cost, and the report you receive.

Security Brigade Editorial Team 29 Apr 2026
Compliance Services

RBI Cybersecurity Framework in 2026: What Replaced It, and What Banks Must Do Now

The framework you are looking for was repealed on 31 July 2026, along with 627 other circulars. Six new Directions replaced it, one per class of regulated entity, all in force on issuance. What changed, what carried forward, and the cadence most guidance is stating incorrectly.

Security Brigade Editorial Team 29 Apr 2026
Consulting Services

OWASP Top 10 Explained for Business Leaders

A non-technical walk through the OWASP Top 10. These ten classes of web application risk account for the bulk of breaches we see in real engagements, and this is what each one actually costs your business.

Security Brigade Editorial Team 29 Apr 2026
Consulting Services

Manual vs Automated Penetration Testing: The Real Difference

Scanners match patterns well. Manual testing covers what they cannot. Examples of the findings each approach reliably catches and misses.

Security Brigade Editorial Team 29 Apr 2026
Compliance Services

How to Choose a CERT-In Empanelled Security Auditor

CERT-In empanelment is a qualifying criterion; it does not replace due diligence. What to evaluate when shortlisting auditors for a regulated engagement.

Security Brigade Editorial Team 29 Apr 2026

Have a question the articles do not cover?

Our team answers regulatory and testing questions directly.

Talk to our team