The Reserve Bank of India (RBI), on July 31, 2026, issued the Reserve Bank of India (All India Financial Institutions – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, establishing a comprehensive cybersecurity and technology governance framework for All India Financial Institutions (AIFIs), namely EXIM Bank, NABARD, SIDBI, NHB, and NaBFID. The Directions came into force with immediate effect and prescribe minimum standards for cyber resilience, information security, technology governance, and assurance.
The Directions require AIFIs to strengthen Board oversight, IT governance, cybersecurity policies, risk management frameworks, and information security controls. They also mandate implementation of robust safeguards covering data leak prevention, application and network security, vulnerability and patch management, user access controls, business continuity and disaster recovery, cyber incident response, security awareness, third-party risk management, cyber security operations centres (SOC), and information systems audits to enhance operational resilience.
Further, the framework introduces comprehensive requirements for continuous monitoring, real-time threat defence, forensic readiness, risk-based transaction monitoring, Red Teaming exercises, customer awareness, and governance of cybersecurity operations. The Directions aim to strengthen the cyber resilience, technology risk management, and operational security posture of AIFIs against evolving cyber threats.
[Notification No. RBI/DoS/2026-27/456]