BFSI Cybersecurity
CERT-In empanelled cybersecurity services for BFSI organisations. 6,700+ assessments delivered since 2006.
Challenges
Security challenges in BFSI
RBI Directions, 2026: six-monthly vulnerability assessment, annual penetration testing and six-hour incident reporting on DAKSH, in force since 31 July with no transition period
SEBI CSCRF mandates across exchanges, brokers, depositories, AMCs, and KRAs
Legacy core banking systems with integration points that multiply attack surface
Digital payment security across UPI, IMPS, NEFT, RTGS corridors
Third-party vendor risk across fintech partners, payment gateways, and cloud providers
Real-time fraud detection and transaction monitoring gaps
Trusted by
The label
BFSI is three supervisors, not one buyer
The acronym groups firms by what they sell. Cyber supervision groups them by who licenses them, and those two groupings do not line up.
A bank, a broker and an insurer inside the same group answer to three different regulators, on three different instruments, with three different testing calendars and three different places to file the result. A group security function that runs one annual programme and reports it upward is running one programme against three standards, and will satisfy whichever one it was designed around. The gaps do not announce themselves — they appear at a supervisory inspection, or in a diligence questionnaire from a counterparty who reads the other regulator's rulebook.
The calendars
Same group, three testing obligations
Each row is the instrument that actually binds, the cadence it sets, and where the report goes when it is done.
| If you are | The instrument | Testing cadence | Report goes to |
|---|---|---|---|
| A bank, SFB, Payments Bank or Credit Information Company | RBI Cybersecurity, Technology: Risk, Resilience and Assurance Directions, 2026 — six entity-specific instruments issued 31 July 2026, in force on issuance. | VA at least every six months and PT at least every 12 months, for critical systems and / or those in the DMZ with a customer interface. Either limb triggers it. | Cyber incidents to DAKSH within six hours of detection. |
| An NBFC | The NBFC Directions, which split their population three ways by Scale Based Regulation layer (¶3) rather than applying whole. | The six-month VA and twelve-month PT sit at ¶121, and reach the Middle Layer and above. A Base Layer NBFC below the threshold receives three paragraphs in total. | DAKSH within six hours (¶28, ¶141). Housing Finance Companies file to NHB, not RBI. |
| A broker, depository participant, AMC, custodian or RTA | SEBI CSCRF, which classifies you into a tier first and then applies obligations to that tier. The tier test is different for almost every entity category. | Set by tier, not by a single sector rule. The tier itself turns on client counts, assets or activity depending on which registration you hold. | Brokers and DPs through their exchange or depository; most others to SEBI. Advisers and analysts to BSE Ltd. |
| An insurer or insurance intermediary | IRDAI Information and Cyber Security Guidelines, 2026 (IRDAI/GA&HR/CIR/MISC/51/4/2026, 6 April 2026), which replaced the 2023 guidelines. | Governed by that instrument rather than by the RBI or SEBI calendars — a distinction group functions routinely miss when they standardise on the banking programme. | Per the guidelines applicable to insurers and intermediaries. |
| A payment aggregator or gateway | The PA-PG Master Direction, administered separately from the 31 July 2026 consolidation and untouched by it. | An annual system and cybersecurity audit — and this one names the auditor: it must be CERT-In empanelled. | To RBI, per the Master Direction. |
| Worth stating plainly because the opposite is often assumed: empanelment is written into this instrument by name, as it is into the data-localisation system audit report and into SEBI CSCRF. | |||
A bank, SFB, Payments Bank or Credit Information Company
- Testing cadence
- VA at least every six months and PT at least every 12 months, for critical systems and / or those in the DMZ with a customer interface. Either limb triggers it.
- Report goes to
- Cyber incidents to DAKSH within six hours of detection.
An NBFC
- The instrument
- The NBFC Directions, which split their population three ways by Scale Based Regulation layer (¶3) rather than applying whole.
- Testing cadence
- The six-month VA and twelve-month PT sit at ¶121, and reach the Middle Layer and above. A Base Layer NBFC below the threshold receives three paragraphs in total.
- Report goes to
- DAKSH within six hours (¶28, ¶141). Housing Finance Companies file to NHB, not RBI.
A broker, depository participant, AMC, custodian or RTA
- Testing cadence
- Set by tier, not by a single sector rule. The tier itself turns on client counts, assets or activity depending on which registration you hold.
- Report goes to
- Brokers and DPs through their exchange or depository; most others to SEBI. Advisers and analysts to BSE Ltd.
An insurer or insurance intermediary
- The instrument
- IRDAI Information and Cyber Security Guidelines, 2026 (IRDAI/GA&HR/CIR/MISC/51/4/2026, 6 April 2026), which replaced the 2023 guidelines.
- Testing cadence
- Governed by that instrument rather than by the RBI or SEBI calendars — a distinction group functions routinely miss when they standardise on the banking programme.
- Report goes to
- Per the guidelines applicable to insurers and intermediaries.
A payment aggregator or gateway
- The instrument
- The PA-PG Master Direction, administered separately from the 31 July 2026 consolidation and untouched by it.
- Testing cadence
- An annual system and cybersecurity audit — and this one names the auditor: it must be CERT-In empanelled.
- Report goes to
- To RBI, per the Master Direction.
Worth stating plainly because the opposite is often assumed: empanelment is written into this instrument by name, as it is into the data-localisation system audit report and into SEBI CSCRF.
The estate
What a BFSI assessment has to reach
Financial firms concentrate risk in the paths that move money and the paths that authorise it — and those are frequently not the same systems.
Payment rails and the switch
UPI, IMPS, NEFT and RTGS integrations, card switching where present, and the reconciliation that would be the only thing to notice an altered instruction.
The identity layer
The identity provider is the actual perimeter. Conditional access, privileged access to critical systems, and the session and token lifetimes that decide how long a stolen credential stays useful.
Customer channels
Internet banking, the mobile application as a shipped artefact, and the onboarding journey — including video KYC, which is a fraud surface as much as a customer one.
Machine paths
API and algo gateways, partner integrations and co-lending interfaces. They authenticate with long-lived keys, run without a person watching, and are routinely scoped out as "back-end".
The shared provider
Core banking, switching or registry functions run on somebody else's infrastructure. The obligation does not move with the operation, and the contract is where the testing right has to exist.
Recovery, exercised
Failover tested at production data volumes rather than reviewed on paper — including whether the interfaces counterparties reconnect through were part of the drill.
Where this goes wrong
One programme, designed around whichever regulator shouted loudest
The common failure in a diversified group is not neglect — it is standardisation on the wrong template. A group that grew out of banking runs the banking calendar everywhere, and its broking arm is measured against a tier test it never took. A group that grew out of broking treats the CSCRF submission as the annual event, and its NBFC arm discovers at the Middle Layer threshold that a different instrument has been binding since the day it crossed. The fix is not more testing. It is establishing, per registration, which instrument binds, what it asks for, and where the result is filed — and then building one programme that satisfies the strictest of them rather than the most familiar.
Services
Recommended Services for BFSI
Regulatory-grade security services for banking, financial services, and insurance
Web Application Penetration Testing
RBI-mandated WAPT for internet banking, trading platforms, loan origination systems, and customer portals.
Learn More →Mobile Application Security Testing
iOS and Android security for mobile banking apps, trading apps, and wallet applications with reverse engineering.
Learn More →AI-Resilient VAPT
SEBI-aligned AI-augmented VAPT covering all 10 Annexure-A directives for REs, AMCs, and exchanges.
Learn More →Secure Code Review
Manual + AI-powered source code analysis for core banking, lending, and payment processing codebases.
Learn More →Red Team Assessment
Realistic adversary simulation using ShadowMap attack surface intelligence against BFSI threat models.
Learn More →Frequently Asked Questions
We hold banking and broking licences in one group. Can one VAPT satisfy both?
One engagement can, if it is scoped to the stricter of the two and reported so that each supervisor gets what its own instrument asks for. What does not work is one report written for one regulator and forwarded to the other — the scope definitions differ, the cadences differ, and the filing routes differ. Establish both obligations first, then scope once against the union.
Does RBI require a CERT-In empanelled auditor?
Empanelment is written by name into several instruments that reach financial firms — the PA-PG Master Direction's annual system and cybersecurity audit, the system audit report under the payment-data localisation requirement, and SEBI CSCRF. Beyond that, the 2026 Directions make the regulated entity assess the qualification, professional expertise, credentials and competency of the testing firm and of the named personnel, at every selection and renewal, and where an empanelled auditor is engaged, CERT-In's audit policy guidelines are imported into the supervisory relationship. Empanelment is how that assessment gets evidenced.
Secure Your BFSI Organisation
One scoping call to align on scope, methodology, and timing.
Request a Scoping Call →