BFSI Cybersecurity
The RBI Directions set the cadence: vulnerability assessment every six months, penetration testing every twelve, and incident reporting inside six hours. SEBI CSCRF adds its own obligations for exchanges, brokers, depositories and AMCs. Most of the exposure sits where a core banking platform built in an earlier decade meets UPI, IMPS and RTGS corridors that expect an answer in real time.
Challenges
Security challenges in BFSI
RBI Directions, 2026: six-monthly vulnerability assessment, annual penetration testing and six-hour incident reporting on DAKSH, in force since 31 July with no transition period
SEBI CSCRF mandates across exchanges, brokers, depositories, AMCs, and KRAs
Legacy core banking systems with integration points that multiply attack surface
Digital payment security across UPI, IMPS, NEFT, RTGS corridors
Third-party vendor risk across fintech partners, payment gateways, and cloud providers
Real-time fraud detection and transaction monitoring gaps
Trusted by
The label
BFSI is three supervisors, not one buyer
The acronym groups firms by what they sell. Cyber supervision groups them by who licenses them, and those two groupings do not line up.
A bank, a broker and an insurer inside the same group answer to three different regulators, on three different instruments, with three different testing calendars and three different places to file the result. A group security function that runs one annual programme and reports it upward is running one programme against three standards, and will satisfy whichever one it was designed around. The gaps do not announce themselves. They appear at a supervisory inspection, or in a diligence questionnaire from a counterparty who reads the other regulator's rulebook.
The calendars
Same group, three testing obligations
Each row is the instrument that actually binds, the cadence it sets, and where the report goes when it is done.
| If you are | The instrument | Testing cadence | Report goes to |
|---|---|---|---|
| A bank, SFB, Payments Bank or Credit Information Company | RBI Cybersecurity, Technology: Risk, Resilience and Assurance Directions, 2026. Six entity-specific instruments issued 31 July 2026, in force on issuance. | VA at least every six months and PT at least every 12 months, for critical systems and / or those in the DMZ with a customer interface. Either limb triggers it. | Cyber incidents to DAKSH within six hours of detection. |
| An NBFC | The NBFC Directions, which split their population three ways by Scale Based Regulation layer (¶3) instead of applying whole. | The six-month VA and twelve-month PT sit at ¶121, and reach the Middle Layer and above. A Base Layer NBFC below the threshold receives three paragraphs in total. | DAKSH within six hours (¶28, ¶141). Housing Finance Companies file to NHB, not RBI. |
| A broker, depository participant, AMC, custodian or RTA | SEBI CSCRF, which classifies you into a tier first and then applies obligations to that tier. The tier test is different for almost every entity category. | Set by tier, not by a single sector rule. The tier itself turns on client counts, assets or activity depending on which registration you hold. | Brokers and DPs through their exchange or depository; most others to SEBI. Advisers and analysts to BSE Ltd. |
| An insurer or insurance intermediary | IRDAI Information and Cyber Security Guidelines, 2026 (IRDAI/GA&HR/CIR/MISC/51/4/2026, 6 April 2026), which replaced the 2023 guidelines. | Governed by that instrument, not by the RBI or SEBI calendars. Group functions routinely miss the distinction when they standardise on the banking programme. | Per the guidelines applicable to insurers and intermediaries. |
| A payment aggregator or gateway | The PA-PG Master Direction, administered separately from the 31 July 2026 consolidation and untouched by it. | An annual system and cybersecurity audit. This one names the auditor: it must be CERT-In empanelled. | To RBI, per the Master Direction. |
| Empanelment is written into this instrument by name, as it is into the data-localisation system audit report and into SEBI CSCRF. | |||
A bank, SFB, Payments Bank or Credit Information Company
- Testing cadence
- VA at least every six months and PT at least every 12 months, for critical systems and / or those in the DMZ with a customer interface. Either limb triggers it.
- Report goes to
- Cyber incidents to DAKSH within six hours of detection.
An NBFC
- The instrument
- The NBFC Directions, which split their population three ways by Scale Based Regulation layer (¶3) instead of applying whole.
- Testing cadence
- The six-month VA and twelve-month PT sit at ¶121, and reach the Middle Layer and above. A Base Layer NBFC below the threshold receives three paragraphs in total.
- Report goes to
- DAKSH within six hours (¶28, ¶141). Housing Finance Companies file to NHB, not RBI.
A broker, depository participant, AMC, custodian or RTA
- Testing cadence
- Set by tier, not by a single sector rule. The tier itself turns on client counts, assets or activity depending on which registration you hold.
- Report goes to
- Brokers and DPs through their exchange or depository; most others to SEBI. Advisers and analysts to BSE Ltd.
An insurer or insurance intermediary
- The instrument
- IRDAI Information and Cyber Security Guidelines, 2026 (IRDAI/GA&HR/CIR/MISC/51/4/2026, 6 April 2026), which replaced the 2023 guidelines.
- Testing cadence
- Governed by that instrument, not by the RBI or SEBI calendars. Group functions routinely miss the distinction when they standardise on the banking programme.
- Report goes to
- Per the guidelines applicable to insurers and intermediaries.
A payment aggregator or gateway
- The instrument
- The PA-PG Master Direction, administered separately from the 31 July 2026 consolidation and untouched by it.
- Testing cadence
- An annual system and cybersecurity audit. This one names the auditor: it must be CERT-In empanelled.
- Report goes to
- To RBI, per the Master Direction.
Empanelment is written into this instrument by name, as it is into the data-localisation system audit report and into SEBI CSCRF.
The estate
What a BFSI assessment has to reach
Financial firms concentrate risk in the paths that move money and the paths that authorise it, and those are frequently not the same systems.
Payment rails and the switch
UPI, IMPS, NEFT and RTGS integrations, card switching where present, and the reconciliation that would be the only thing to notice an altered instruction.
The identity layer
The identity provider is the actual perimeter. Conditional access, privileged access to critical systems, and the session and token lifetimes that decide how long a stolen credential stays useful.
Customer channels
Internet banking, the mobile application as a shipped artefact, and the onboarding journey, including video KYC, which is a fraud surface as much as a customer one.
Machine paths
API and algo gateways, partner integrations and co-lending interfaces. They authenticate with long-lived keys, run without a person watching, and are routinely scoped out as "back-end".
The shared provider
Core banking, switching or registry functions run on somebody else's infrastructure. The obligation does not move with the operation, and the contract is where the testing right has to exist.
Recovery, exercised
Failover tested at production data volumes, not reviewed on paper. That includes whether the interfaces counterparties reconnect through were part of the drill.
Where this goes wrong
One programme, designed around whichever regulator shouted loudest
The common failure in a diversified group is standardisation on the wrong template, not neglect. A group that grew out of banking runs the banking calendar everywhere, and its broking arm is measured against a tier test it never took. A group that grew out of broking treats the CSCRF submission as the annual event, and its NBFC arm discovers at the Middle Layer threshold that a different instrument has been binding since the day it crossed. The fix is not more testing. It is establishing, per registration, which instrument binds, what it asks for, and where the result is filed, then building one programme that satisfies the strictest of them, never the most familiar.
Services
Recommended Services for BFSI
Regulatory-grade security services for banking, financial services, and insurance
Web Application Penetration Testing
RBI-mandated WAPT for internet banking, trading platforms, loan origination systems, and customer portals.
Learn More →Mobile Application Security Testing
iOS and Android security for mobile banking apps, trading apps, and wallet applications with reverse engineering.
Learn More →AI-Resilient VAPT
SEBI-aligned AI-augmented VAPT covering all 10 Annexure-A directives for REs, AMCs, and exchanges.
Learn More →Secure Code Review
Manual + AI-powered source code analysis for core banking, lending, and payment processing codebases.
Learn More →Red Team Assessment
Realistic adversary simulation using ShadowMap attack surface intelligence against BFSI threat models.
Learn More →Frequently Asked Questions
Can you test core banking without disturbing our UPI, IMPS and RTGS corridors?
Yes, but the corridors set the constraints and they have to be agreed before anything is pointed at them. A core banking platform built in an earlier decade, sitting behind UPI, IMPS, NEFT and RTGS flows that expect an answer in real time, is not a system where the blast radius should be discovered during the test. In practice the work splits. Integration points, message handling and authorisation logic are exercised against a pre-production copy carrying the same interfaces, while anything run against production is limited to what can be shown to be safe and is scheduled with your operations team. Your transaction monitoring and fraud detection will see the testing, so the fraud team is told in advance; an unannounced assessment either generates alerts nobody can triage or teaches the team to dismiss the ones that matter. Where a corridor cannot be replicated faithfully, we say so and scope it as an examination of configuration, access and reconciliation instead of live transaction testing. A report that is explicit about what was not reachable is more useful to your supervisor than one implying coverage it did not have.
We hold banking and broking licences in one group. Can one VAPT satisfy both?
One engagement can, if it is scoped to the stricter of the two and reported so that each supervisor gets what its own instrument asks for. What does not work is one report written for one regulator and forwarded to the other: the scope definitions differ, the cadences differ, and the filing routes differ. Establish both obligations first, then scope once against the union.
Does RBI require a CERT-In empanelled auditor?
Empanelment is written by name into several instruments that reach financial firms: the PA-PG Master Direction's annual system and cybersecurity audit, the system audit report under the payment-data localisation requirement, and SEBI CSCRF. Beyond that, the 2026 Directions make the regulated entity assess the qualification, professional expertise, credentials and competency of the testing firm and of the named personnel, at every selection and renewal, and where an empanelled auditor is engaged, CERT-In's audit policy guidelines are imported into the supervisory relationship. Empanelment is how that assessment gets evidenced.
Proof
What this looked like in BFSI
Secure Your BFSI Organisation
One scoping call to align on scope, methodology, and timing.
Request a Scoping Call →