
The Reserve Bank of India (RBI) and the Securities and Exchange Board of India (Sebi) have jointly tightened cyber security norms for banks, brokers, and other financial market participants. The new directives, announced on Wednesday, require entities to strengthen their digital defences against a rising wave of cyber attacks targeting the financial sector.
The move comes amid growing concerns over data breaches, ransomware attacks, and online fraud that have hit Indian financial institutions in recent years. Regulators are now pushing for a more robust and uniform cyber resilience framework across the industry.
Under the updated guidelines, all regulated entities must implement stricter access controls, encryption standards, and multi-factor authentication for critical systems. They are also required to conduct periodic vulnerability assessments and penetration testing to identify weak points before attackers do.
Incident reporting has been made more stringent. Any cyber security breach, whether minor or major, must be reported to the respective regulator within a specified timeframe. This will help authorities track threats in real time and issue timely alerts to the wider financial community.
The regulators have also emphasised the need for board-level involvement in cyber security decisions. Firms will now have to designate a senior official as the chief information security officer (CISO), who will be accountable for the entity's cyber defence posture. The CISO will report directly to the board or a board-level committee.
Regular audits by independent third parties have been made compulsory. The audit reports must be submitted to the regulators annually, with any significant findings highlighted for immediate action. This is expected to bring greater transparency and accountability.
India's financial sector has become a prime target for cyber criminals, given the rapid digitisation of payments, trading, and banking services. A single breach at a large bank or stockbroker can compromise lakhs of customer records and erode public trust in the system.
The new framework aims to create a common baseline of security practices across all entities, from the largest public sector bank to the smallest registered broker. It also aligns Indian regulations with global standards such as those set by the Basel Committee and IOSCO.
The regulators have given entities a phased timeline to comply. Larger institutions with critical market infrastructure must comply within six months, while smaller players get up to a year. The RBI and Sebi have warned of penalties for non-compliance, including fines and, in extreme cases, suspension of licences.
Officials have not yet specified the exact penalties, but they have indicated that repeat offenders will face stricter action. The regulators are also expected to issue detailed FAQs and conduct workshops to help entities understand the new requirements.
Industry experts have welcomed the move, though some smaller firms may struggle with the cost and complexity of implementation. However, the long-term benefits of a safer digital ecosystem outweigh the initial compliance burden.
In the coming months, the focus will be on how effectively institutions adapt to these rules and whether the regulators' monitoring mechanisms prove robust enough to deter future attacks. The success of this initiative will depend on continuous cooperation between the public and private sectors.