The Reserve Bank of India (RBI) issued a new cybersecurity framework for commercial banks on July 31, 2026. The framework mandates banks to conduct vulnerability assessments every six months, annual penetration tests for critical internet-facing systems, and half-yearly disaster recovery drills. It applies immediately to commercial banks, including the State Bank of India, but excludes small finance banks, payments banks, and local area banks, according to medianama.com.
The new directions replace the previous patchwork of cybersecurity instructions with a unified framework titled 'Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026.' Banks must maintain an up-to-date inventory of information assets, classify data by sensitivity, and implement data loss prevention strategies. They are also required to maintain inventories of authorised and unauthorised software, block unauthorised software, and apply emergency patches for vulnerabilities actively exploited, medianama.com reported.
This framework aims to strengthen the cybersecurity posture of commercial banks amid rising cyber threats. By enforcing regular assessments, penetration tests, and disaster recovery drills, RBI seeks to enhance risk resilience and assurance in banking technology. The move aligns with global trends where regulators are tightening cybersecurity requirements for financial institutions to protect customer data and maintain system integrity.
The RBI framework also requires formal data migration controls with audit trails and business signoffs, and mandates protection of data throughout its lifecycle, including remote wipe capabilities for mobile devices. These measures are effective immediately for all commercial banks covered under the directive, as detailed in the RBI guidelines published on July 31, 2026, medianama.com stated.