Skip to main content
BFSI

BFSI Cybersecurity

CERT-In empanelled cybersecurity services for BFSI organisations. 6,700+ assessments delivered since 2006.

6,700+
Assessments Delivered
1,000+
Enterprise Clients
150+
Security Professionals
Since 2006
Founded · CERT-In 2008

Challenges

Security challenges in BFSI

1

RBI Directions, 2026: six-monthly vulnerability assessment, annual penetration testing and six-hour incident reporting on DAKSH, in force since 31 July with no transition period

2

SEBI CSCRF mandates across exchanges, brokers, depositories, AMCs, and KRAs

3

Legacy core banking systems with integration points that multiply attack surface

4

Digital payment security across UPI, IMPS, NEFT, RTGS corridors

5

Third-party vendor risk across fintech partners, payment gateways, and cloud providers

6

Real-time fraud detection and transaction monitoring gaps

Trusted by

ICICI Bank
NPCI
HDFC
Mahindra
Aditya Birla
PhonePe
Pernod Ricard
Swiggy
Asian Paints
Yes Bank
Tata Play
Larsen & Toubro
Voltas
DHL Express
Etihad Airways
Amazon Pay
Go Digit
Pharmeasy
BillDesk
Jubilant Foods
UltraTech
Titan
Infosys
Capgemini
Groww
Sephora

The label

BFSI is three supervisors, not one buyer

The acronym groups firms by what they sell. Cyber supervision groups them by who licenses them, and those two groupings do not line up.

A bank, a broker and an insurer inside the same group answer to three different regulators, on three different instruments, with three different testing calendars and three different places to file the result. A group security function that runs one annual programme and reports it upward is running one programme against three standards, and will satisfy whichever one it was designed around. The gaps do not announce themselves — they appear at a supervisory inspection, or in a diligence questionnaire from a counterparty who reads the other regulator's rulebook.

The calendars

Same group, three testing obligations

Each row is the instrument that actually binds, the cadence it sets, and where the report goes when it is done.

If you areThe instrumentTesting cadenceReport goes to
A bank, SFB, Payments Bank or Credit Information Company RBI Cybersecurity, Technology: Risk, Resilience and Assurance Directions, 2026 — six entity-specific instruments issued 31 July 2026, in force on issuance. VA at least every six months and PT at least every 12 months, for critical systems and / or those in the DMZ with a customer interface. Either limb triggers it. Cyber incidents to DAKSH within six hours of detection.
An NBFC The NBFC Directions, which split their population three ways by Scale Based Regulation layer (¶3) rather than applying whole. The six-month VA and twelve-month PT sit at ¶121, and reach the Middle Layer and above. A Base Layer NBFC below the threshold receives three paragraphs in total. DAKSH within six hours (¶28, ¶141). Housing Finance Companies file to NHB, not RBI.
A broker, depository participant, AMC, custodian or RTA SEBI CSCRF, which classifies you into a tier first and then applies obligations to that tier. The tier test is different for almost every entity category. Set by tier, not by a single sector rule. The tier itself turns on client counts, assets or activity depending on which registration you hold. Brokers and DPs through their exchange or depository; most others to SEBI. Advisers and analysts to BSE Ltd.
An insurer or insurance intermediary IRDAI Information and Cyber Security Guidelines, 2026 (IRDAI/GA&HR/CIR/MISC/51/4/2026, 6 April 2026), which replaced the 2023 guidelines. Governed by that instrument rather than by the RBI or SEBI calendars — a distinction group functions routinely miss when they standardise on the banking programme. Per the guidelines applicable to insurers and intermediaries.
A payment aggregator or gateway The PA-PG Master Direction, administered separately from the 31 July 2026 consolidation and untouched by it. An annual system and cybersecurity audit — and this one names the auditor: it must be CERT-In empanelled. To RBI, per the Master Direction.
Worth stating plainly because the opposite is often assumed: empanelment is written into this instrument by name, as it is into the data-localisation system audit report and into SEBI CSCRF.

A bank, SFB, Payments Bank or Credit Information Company

Testing cadence
VA at least every six months and PT at least every 12 months, for critical systems and / or those in the DMZ with a customer interface. Either limb triggers it.
Report goes to
Cyber incidents to DAKSH within six hours of detection.

An NBFC

Testing cadence
The six-month VA and twelve-month PT sit at ¶121, and reach the Middle Layer and above. A Base Layer NBFC below the threshold receives three paragraphs in total.
Report goes to
DAKSH within six hours (¶28, ¶141). Housing Finance Companies file to NHB, not RBI.

A broker, depository participant, AMC, custodian or RTA

Testing cadence
Set by tier, not by a single sector rule. The tier itself turns on client counts, assets or activity depending on which registration you hold.
Report goes to
Brokers and DPs through their exchange or depository; most others to SEBI. Advisers and analysts to BSE Ltd.

An insurer or insurance intermediary

The instrument
IRDAI Information and Cyber Security Guidelines, 2026 (IRDAI/GA&HR/CIR/MISC/51/4/2026, 6 April 2026), which replaced the 2023 guidelines.
Testing cadence
Governed by that instrument rather than by the RBI or SEBI calendars — a distinction group functions routinely miss when they standardise on the banking programme.
Report goes to
Per the guidelines applicable to insurers and intermediaries.

A payment aggregator or gateway

The instrument
The PA-PG Master Direction, administered separately from the 31 July 2026 consolidation and untouched by it.
Testing cadence
An annual system and cybersecurity audit — and this one names the auditor: it must be CERT-In empanelled.
Report goes to
To RBI, per the Master Direction.

Worth stating plainly because the opposite is often assumed: empanelment is written into this instrument by name, as it is into the data-localisation system audit report and into SEBI CSCRF.

The estate

What a BFSI assessment has to reach

Financial firms concentrate risk in the paths that move money and the paths that authorise it — and those are frequently not the same systems.

Payment rails and the switch

UPI, IMPS, NEFT and RTGS integrations, card switching where present, and the reconciliation that would be the only thing to notice an altered instruction.

The identity layer

The identity provider is the actual perimeter. Conditional access, privileged access to critical systems, and the session and token lifetimes that decide how long a stolen credential stays useful.

Customer channels

Internet banking, the mobile application as a shipped artefact, and the onboarding journey — including video KYC, which is a fraud surface as much as a customer one.

Machine paths

API and algo gateways, partner integrations and co-lending interfaces. They authenticate with long-lived keys, run without a person watching, and are routinely scoped out as "back-end".

The shared provider

Core banking, switching or registry functions run on somebody else's infrastructure. The obligation does not move with the operation, and the contract is where the testing right has to exist.

Recovery, exercised

Failover tested at production data volumes rather than reviewed on paper — including whether the interfaces counterparties reconnect through were part of the drill.

Where this goes wrong

One programme, designed around whichever regulator shouted loudest

The common failure in a diversified group is not neglect — it is standardisation on the wrong template. A group that grew out of banking runs the banking calendar everywhere, and its broking arm is measured against a tier test it never took. A group that grew out of broking treats the CSCRF submission as the annual event, and its NBFC arm discovers at the Middle Layer threshold that a different instrument has been binding since the day it crossed. The fix is not more testing. It is establishing, per registration, which instrument binds, what it asks for, and where the result is filed — and then building one programme that satisfies the strictest of them rather than the most familiar.

Frequently Asked Questions

We hold banking and broking licences in one group. Can one VAPT satisfy both?

One engagement can, if it is scoped to the stricter of the two and reported so that each supervisor gets what its own instrument asks for. What does not work is one report written for one regulator and forwarded to the other — the scope definitions differ, the cadences differ, and the filing routes differ. Establish both obligations first, then scope once against the union.

Does RBI require a CERT-In empanelled auditor?

Empanelment is written by name into several instruments that reach financial firms — the PA-PG Master Direction's annual system and cybersecurity audit, the system audit report under the payment-data localisation requirement, and SEBI CSCRF. Beyond that, the 2026 Directions make the regulated entity assess the qualification, professional expertise, credentials and competency of the testing firm and of the named personnel, at every selection and renewal, and where an empanelled auditor is engaged, CERT-In's audit policy guidelines are imported into the supervisory relationship. Empanelment is how that assessment gets evidenced.

Secure Your BFSI Organisation

One scoping call to align on scope, methodology, and timing.

Request a Scoping Call →