Key takeaways
- RBI issued separate Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions for seven types of regulated entities on 31 July 2026, and they took effect immediately.110
- For critical systems and DMZ systems with a customer interface, a vulnerability assessment is due at least once every six months and a penetration test at least once every 12 months (commercial banks, paragraph 151).1
- After a project or system upgrade goes live, the VA and PT must run on the production environment (paragraph 152 for commercial banks, paragraph 124 for NBFCs).13
- Banks must report cyber incidents on RBI's DAKSH platform within six hours of detection and also notify CERT-In, which has its own 6-hour rule.18
- The status of closing VA and PT findings must go to the IT Strategy Committee and the Information Security Committee at least every quarter (paragraph 161).1
- Red teaming is still optional: paragraph 162 says a bank "may" run it, the same stance as the 2016 framework.14
Most bank security teams have a folder called "VAPT 2025". It holds one report, from one engagement, dated one month. Then a new mobile banking release goes live, a vendor changes an API gateway, and the folder stays the same. On 31 July 2026, RBI rewrote the rules that decide whether that folder is enough. For critical and customer-facing systems, the answer is now written in plain numbers: six months, 12 months, and again after every major change.
Last reviewed on 16 September 2026 against the RBI Directions for commercial banks, small finance banks and NBFCs (31 July 2026), the RBI Cyber Security Framework (2 June 2016) and the CERT-In Directions (28 April 2022).
Not legal advice. This guide quotes the RBI texts we could read in full: commercial banks, small finance banks and NBFCs. Paragraph numbers differ between entity types, and RBI may amend the texts. Check the latest version of the Directions that applies to your entity before you rely on any clause number here.
What are the RBI Cybersecurity Directions 2026?
The RBI Cybersecurity Directions 2026 are a set of Master Directions titled "Cybersecurity, Technology: Risk, Resilience and Assurance Framework", issued by RBI's Department of Supervision on 31 July 2026. Each regulated entity type gets its own text. They pull cyber security, IT governance, testing, incident reporting and resilience rules into one binding document per entity type.
The commercial bank version carries reference RBI/DoS/2026-27/410. It says the Directions "shall come into effect immediately upon issuance".1 The small finance bank version (RBI/DoS/2026-27/419) and the NBFC version (RBI/DoS/2026-27/461) use similar wording: they "come into force with immediate effect".23 There is no phase-in window in these texts.
The Directions were part of a larger clean-up. On the same day, RBI repealed 628 supervisory circulars and replaced them with 64 consolidated Directions.9 The cyber texts are the ones security teams care about most, because they turn many older "should" statements into dated, checkable duties.
How the commercial bank text is organised
The commercial bank Directions follow a clear structure. Knowing it saves time when an auditor quotes a paragraph number.
- Chapter I: preliminary (scope, commencement, definitions).
- Chapter II: role of the Board.
- Chapter III: IT governance and oversight, including the IT Strategy Committee and the CISO.
- Chapter IV: IT and information security risk management.
- Chapter V: baseline cybersecurity and resilience requirements, which is where the VA and PT section (paragraphs 149 to 161) and red teaming (paragraph 162) sit.
- Later chapters: the cyber security operations centre, information systems audit, and the repeal chapter.1
The last number explains why RBI is pressing. IBM's 2026 study puts the average breach in India at ₹25.5 crore, up 15.9% in a year, and the financial sector at ₹40.9 crore, the highest of any Indian sector it measured.12
Who do the new directions apply to?
The RBI Cybersecurity Directions 2026 were issued as seven separate texts: commercial banks, small finance banks, payments banks, urban co-operative banks, All India Financial Institutions, NBFCs and credit information companies. Each text applies only to its own entity type, and the paragraph numbers differ, so teams must read the version written for them.
The table below lists the seven texts. We read the commercial bank, small finance bank and NBFC texts in full on the RBI website. For the other four, the reference numbers come from a published summary, so confirm them against your own copy.10
| Entity type | Reference | Where the VA/PT rules sit |
|---|---|---|
| Commercial banks | RBI/DoS/2026-27/410 | Paras 149 to 161; cadence in para 151 (verified) |
| Small finance banks | RBI/DoS/2026-27/419 | Paras 148 to 160; cadence in para 150 (verified) |
| Payments banks | RBI/DoS/2026-27/428 | Check your copy |
| Urban co-operative banks | RBI/DoS/2026-27/437 | Graded by Levels I to IV; check your copy |
| All India Financial Institutions | RBI/DoS/2026-27/456 | Check your copy |
| NBFCs | RBI/DoS/2026-27/461 | Paras 121 to 130, Chapter V; cadence in para 121 (verified) |
| Credit information companies | RBI/DoS/2026-27/470 | Check your copy |
Commercial banks
The commercial bank text covers banking companies, corresponding new banks and the State Bank of India. Small finance banks, payments banks and local area banks are outside it.11 Small finance banks and payments banks have their own texts.
NBFCs: the layer decides the duty
This is where the RBI cyber security guidelines for NBFCs get detailed. The NBFC Directions apply to every NBFC registered under the RBI Act, 1934, the Factoring Regulation Act, 2011 or the National Housing Bank Act, 1987. The duties then split by layer (paragraph 3):3
- Chapter III: Base Layer NBFCs with assets below ₹500 crore, plus core investment companies. Short and basic: a board-approved IT and information security policy, access controls, maker-checker, backups with periodic testing (paragraph 8).
- Chapter IV: Base Layer NBFCs with assets of ₹500 crore and above. Adds a vulnerability management process (paragraph 23), a change management policy (paragraph 41) and six-hour incident reporting on DAKSH (paragraph 28).
- Chapter V: Middle, Upper and Top Layer NBFCs, excluding core investment companies. This is where the fixed VA and PT cadence sits (paragraphs 121 to 130).
A common misread. Some summaries say the six-month and 12-month cadence applies to "all NBFCs". In the NBFC text we read, paragraph 121 sits in Chapter V. Base Layer NBFCs do not get a fixed interval, but those with assets of ₹500 crore and above still need a vulnerability management process under paragraph 23.3
What did the 2026 directions replace?
The 2026 Directions repeal the existing directions, instructions and guidelines on cybersecurity framework and IT governance for each entity type. RBI communicated the repeal in circular DoS.CO.PPG.66/11.01.005/2026-27 dated 31 July 2026. For banks, that is the body of rules that started with the 2 June 2016 Cyber Security Framework.
The repeal paragraph in the commercial bank text reads: "the existing Directions, instructions, and guidelines relating to Cybersecurity Framework and IT Governance as applicable to Commercial Banks stand repealed".1 The NBFC text (paragraph 155) repeals the rules on "Information Technology Framework and IT Governance" for NBFCs.3 Both texts say actions already taken under the old rules stay governed by them, and past penalties and proceedings are not affected.
The texts do not list each repealed circular by name in the paragraphs we read. By their own description, the repealed set covers the 2016 Cyber Security Framework for banks and the 2023 RBI IT governance master direction, which was titled "Information Technology Governance, Risk, Controls and Assurance Practices". To be certain for your entity, check the annex of circular DoS.CO.PPG.66.
A short history
RBI's cyber rules have tightened in steps. A working group chaired by G. Gopalakrishna, then an RBI Executive Director, published its report on 21 January 2011. RBI turned it into guidelines on 29 April 2011 (RBI/2010-11/494).56 On 2 June 2016, RBI issued the Cyber Security Framework in Banks. Its baseline controls asked banks to "periodically conduct vulnerability assessment and penetration testing exercises" and to report incidents "within two to 6 hours".4
The fixed cadence came with the 7 November 2023 Master Direction on IT governance, which took effect on 1 April 2024. Its paragraph 26 set VA at least every six months and PT at least every 12 months for critical and DMZ customer-facing systems.7 The 2026 Directions keep that cadence, and now it sits inside a single cyber rulebook per entity type.
How often must banks and NBFCs run VAPT under the new rules?
Under the RBI VAPT guidelines in the 2026 Directions, critical systems and DMZ systems with a customer interface need a vulnerability assessment at least once every six months and a penetration test at least once every 12 months. Non-critical systems follow a risk-based interval that the entity sets. Testing also runs before go-live, after go-live and after changes.
Here is the core text for commercial banks, paragraph 151: "For critical information systems and / or those in the DMZ having customer interface, VA shall be conducted at least once in every six months and PT at least once in 12 months. For non-critical information systems, a risk-based approach shall be adopted to decide the requirement and periodicity of conduct of VA / PT."1
The small finance bank text has the same rule in paragraph 150.2 The NBFC text has it in paragraph 121, for Middle Layer NBFCs and above, with the non-critical rule split out into paragraph 123.3
| Rule | Commercial banks | Small finance banks | NBFCs (Middle Layer and above) |
|---|---|---|---|
| VA every 6 months, PT every 12 months (critical, DMZ customer-facing) | Para 151 | Para 150 | Para 121 |
| Risk-based interval for non-critical systems | Para 151 | Para 150 | Para 123 |
| Test across the lifecycle: pre-implementation, post-implementation, after changes | Para 150 | Para 149 | Para 121 |
| Post-implementation VA/PT on production | Para 152 | Para 151 | Para 124 |
| Fix findings in a time-bound manner | Para 153 | Para 152 | Para 125 |
| Trained and independent testers | Para 155 | Para 154 | Para 122 |
| Closure status to ITSC and ISC every quarter | Para 161 | Para 160 | Check paras 126 to 130 |
VA and PT are not the same job
The Directions treat vulnerability assessment and penetration testing as two activities with two clocks. A VA finds and scores known weaknesses across many assets. A PT tries to exploit them, the way an attacker would, to show real impact. If your team or vendor blurs the two, our guide on vulnerability assessment vs penetration testing explains the difference and what each report should contain.
Paragraph 154 also asks for a documented VA/PT approach that covers scope, coverage and a vulnerability scoring method, such as CVSS (the Common Vulnerability Scoring System). It applies to systems hosted in the cloud too.1
When is your next VA and PT due?
Pick your entity type and system type, say whether a major change just went live, and enter your last test dates. The result shows the minimum cadence, the paragraph to cite and the evidence to keep.
Indicative only. Dates use calendar months from your last test and do not account for board-approved policies that set shorter intervals. Paragraph numbers are from the RBI texts dated 31 July 2026; check the version that applies to your entity. Not legal advice.
Plan your next test with Arxiis →What counts as a critical or customer-facing system?
A critical or customer-facing system under the RBI Directions is one the entity itself classes as critical, or one placed in the DMZ with a customer interface, such as internet banking, mobile apps, payment gateways and public APIs. The Directions leave the critical list to each entity, so a documented, board-backed asset classification is the real starting point.
- DMZ (demilitarised zone)
- A network segment that sits between the internet and the internal network. Systems that the public must reach, like web servers, API gateways and mobile app back ends, live here. A DMZ system "having customer interface" is one that customers use directly.
Paragraph 149 of the commercial bank text sets the wide net: VA and PT "periodically for all the critical and internet facing systems". Paragraph 150 names the asset kinds: "critical, internet facing web / mobile applications, servers, and network components".1 So the scope is not just the app. It includes the servers and network devices behind it.
A simple way to sort your assets
- Always in the six and 12 month cycle: internet banking, mobile banking back ends, UPI and card switches, payment gateways, customer-facing APIs, and anything in the DMZ that customers touch.
- Usually critical, by your own classification: core banking, loan management, treasury, SWIFT-connected systems, identity and privileged access systems, and the SOC tooling that watches them.
- Risk-based interval: internal tools with no customer data and no path to critical systems. Write down the interval you chose and why.
Tip for the asset register. Add three columns to every row: "critical (Y/N)", "DMZ customer interface (Y/N)" and "last VA / last PT date". That single sheet answers most of the scoping questions an inspector will ask about paragraph 151.
What changes after a major release or change?
After a major release or system upgrade, the RBI Directions require VA and PT on the changed system as part of its lifecycle, and the post-implementation test must run on the production environment. For commercial banks, paragraph 150 covers pre-implementation, post-implementation and after-change testing, and paragraph 152 requires the production run.
Paragraph 152 reads: "In the post implementation (of IT project / system upgrade) scenario, the VA / PT shall be performed on the production environment. Under unavoidable circumstances, if the PT is conducted in test environment, the bank shall ensure that the version and configuration of the test environment resembles the production environment."1 The NBFC text has the production rule in paragraph 124.3
This is the rule most programmes break. Teams test in UAT, sign off, and go live with different settings, secrets, WAF rules and integrations. The production run exists to catch exactly that gap.
What a clean post-change test looks like
- Pre-implementation: test the release in a staging copy that matches production in version and configuration.
- Go-live gate: link the change ticket to the test plan, so the release cannot close without a post-implementation test booked.
- Production test: run VA and PT on the live system in an agreed window, with rules of engagement signed by the system owner.
- Fix and retest: close findings "in a time-bound manner" (paragraph 153) and keep the retest evidence.
- Reset the clock: record the date. For critical systems, your next VA is due within six months and your next PT within 12.
Base Layer NBFCs with assets of ₹500 crore and above do not have this production rule in their chapter. They do need a board-approved change management policy that assesses the risks of each change (paragraph 41).3
If you ship changes every week, a once-a-year engagement cannot keep up with this rule. Our piece on the 363-day blind spot of annual pentests shows how much of the year goes untested, and VAPT cost in India in 2026 breaks down what a higher cadence costs.
What else do the directions require?
Beyond testing, the RBI Cybersecurity Directions 2026 set a six-hour incident reporting window on DAKSH, independence and competence checks for VA/PT auditors, quarterly board committee oversight, a CISO who reports to the risk executive, half-yearly disaster recovery drills and vendor risk controls. Each carries its own paragraph number.
Incident reporting: two six-hour clocks
Paragraph 182 of the commercial bank text says: "The bank shall report cyber incidents within six hours of detection on DAKSH platform" and "shall also pro-actively notify CERT-In regarding cyber incidents".1 DAKSH is RBI's supervisory monitoring system. The NBFC text has the same six-hour DAKSH rule in paragraphs 28 and 141.3 The small finance bank text has it in paragraph 181.2
Separately, the CERT-In Directions of 28 April 2022 require listed cyber incidents to be reported to CERT-In "within 6 hours of noticing such incidents", and logs to be kept for a rolling 180 days in India.8 Our explainer on CERT-In guidelines for 6-hour reporting and VAPT audits covers that side in detail. Build one incident workflow that meets both clocks.
Who may run the tests
Paragraph 155: "VA / PT shall be conducted by appropriately trained and independent information security experts / auditors." Paragraph 156 asks the bank to check the auditor's qualification, expertise, credentials and competence when it selects, engages or renews them. Paragraph 157 asks that reports state "reasonable assurance" for each area in scope. Paragraph 158 asks for ongoing review of the auditor's performance.1
On CERT-In empanelment, paragraph 159 says that "in case of CERT-In empanelled auditors, the bank shall be guided by CERT-In's Comprehensive Cyber Security Audit Policy Guidelines". Read plainly, the text expects banks may use empanelled auditors. The paragraphs we read do not make empanelment the only route. Capital market entities face a different rule, covered in our guide to SEBI CSCRF VAPT requirements.
Board and committee oversight
- IT Strategy Committee: at least three directors, including the chair (paragraph 17(1)), meeting at least every quarter (paragraph 18), for commercial banks.1
- VA/PT follow-up: findings are tracked by the information security and IS audit teams and senior management (paragraph 160), and closure status goes to the ITSC and ISC at least quarterly (paragraph 161).1
- CISO: reports directly to the Executive Director, or equivalent, who oversees risk management (paragraph 28(6)).1
- NBFCs: the board approves technology and cybersecurity policies and reviews them at least once a year (paragraph 6). For Middle Layer and above, the ITSC meets at least quarterly (paragraph 72). For Base Layer NBFCs with assets of ₹500 crore and above, the ITSC chair must be an independent director and no more than six months may pass between meetings (paragraph 15).3
Resilience and third parties
For commercial banks, disaster recovery drills for critical systems must run at least every half year (paragraph 165).1 For NBFCs in Chapter V, paragraph 117 asks for vendor risk assessment and controls, in proportion to risk, that cover concentration risk, conflicts of interest, single points of failure, customer data protection, high availability and supply chain risk. It applies to third-party arrangements that fall outside RBI's outsourcing directions.3
Vendors matter here. Verizon's 2026 report found third-party involvement in 48% of breaches, and exploitation of vulnerabilities was the top way attackers got in, at 31%.13
Red teaming
Paragraph 162: "The bank may conduct red teaming exercises to identify the vulnerabilities and the business risk, assess the efficacy of the defences and check the mitigating controls already in place by simulating the objectives and actions of an attacker."1 The 2016 framework used almost the same words, with "may be used".4 So red teaming is encouraged, not required. The small finance bank text has it in paragraph 161.2
How should you prepare for the next RBI inspection?
To prepare for an RBI inspection under the 2026 Directions, map every critical and DMZ customer-facing system to its last VA and PT dates, keep reports with CVSS scores and independent tester details, show post-change production tests, and show quarterly closure reports to the IT Strategy Committee. Evidence should trace from asset to finding to fix.
Use this checklist. Each line maps to a paragraph in the commercial bank text; NBFC and small finance bank teams can use the table above to find their numbers.
- Asset register with a critical flag and a DMZ customer-interface flag for every system (paras 149 to 151).
- Documented VA/PT approach covering scope, coverage, scoring method (for example CVSS) and cloud-hosted systems (para 154).
- VA reports no more than six months apart, and PT reports no more than 12 months apart, for each in-scope system (para 151).
- Risk-based interval note for non-critical systems, with the reasoning written down (para 151).
- Change records linked to pre-implementation and post-implementation test reports, with the production run clearly marked (paras 150 and 152).
- Written justification if any PT ran in a test environment, plus proof that its version and configuration matched production (para 152).
- Remediation tracker with target dates, fix dates and retest evidence, plus checks that known CVEs do not come back (para 153).
- Tester file: independence statement, qualifications, credentials and the firm's selection or renewal note (paras 155 and 156).
- Assurance statement in each report for every area in scope (para 157), and an auditor performance review (para 158).
- ITSC and ISC minutes showing VA/PT closure status every quarter (para 161).
- Incident log with detection time and DAKSH submission time, plus the CERT-In notification (para 182).
- DR drill records for critical systems, at least half-yearly (para 165).
Where do teams usually fail?
Teams usually fail RBI VAPT requirements on timing and evidence rather than effort: one yearly engagement that misses the second VA, post-change tests run only in UAT, findings closed without retest proof, and critical systems missing from scope. The Directions reward a steady, dated trail more than one large annual report.
Six gaps we see often
- "Annual VAPT" contracts. One engagement a year covers the PT but not the second VA. The result is a missed half-yearly VA on every critical system.
- Scope drift. The contract lists last year's apps. The new API gateway, the partner integration or the cloud-hosted service is not in it, even though paragraph 154 covers cloud systems.
- UAT-only testing. The release was tested before go-live, but nobody ran the production test that paragraph 152 asks for.
- Findings with no end. Reports list issues, but there is no dated fix or retest. Paragraph 153 asks for time-bound fixes and no repeat of known CVEs.
- Board packs without VA/PT status. The ITSC sees a cyber dashboard but not the closure status of VA/PT observations every quarter.
- Two clocks, one process. The SOC reports to CERT-In but has no DAKSH step, or the reverse.
The deeper problem is speed. CrowdStrike's 2026 threat report puts average eCrime breakout time, the time from first access to moving deeper into the network, at 29 minutes.14 Verizon found that only 26% of known exploited vulnerabilities were fully fixed, with a median of 43 days to patch.13 A six-month cadence is the legal floor, not a safety margin.
Frequently asked questions
Is annual VAPT enough under the RBI Cybersecurity Directions 2026?
No, not for critical systems or DMZ systems with a customer interface. For those, the Directions ask for a vulnerability assessment at least once every six months and a penetration test at least once every 12 months. So one yearly engagement covers the PT but leaves the second VA missing. Systems also need testing before go-live, after go-live and after changes.
When did the RBI Cybersecurity Directions 2026 come into force?
RBI issued the Directions on 31 July 2026, and they took effect at once. The commercial bank text says they come into effect immediately upon issuance, and the small finance bank and NBFC texts say they come into force with immediate effect. There is no phase-in period in these texts, so inspections can test against them now.
Do the RBI directions require CERT-In empanelled auditors for VAPT?
The bank Directions ask for appropriately trained and independent information security experts or auditors, and they set out checks on qualification, expertise and credentials. They say that where a bank uses CERT-In empanelled auditors, it should be guided by CERT-In's audit policy guidelines. Many banks choose empanelled firms, but the text quoted here does not make empanelment the only route.
Does RBI require red teaming for banks?
No. Paragraph 162 of the commercial bank Directions says a bank may conduct red teaming exercises that simulate the objectives and actions of an attacker. The word is may, not shall, which matches the 2016 framework. Red teaming is a good way to test detection and response, but the mandatory testing rule is the VA and PT cadence.
Do the new VAPT rules apply to all NBFCs?
The fixed cadence in paragraph 121 of the NBFC Directions sits in Chapter V, which covers Middle, Upper and Top Layer NBFCs, excluding core investment companies. Base Layer NBFCs with assets of 500 crore rupees and above must run a vulnerability management process under paragraph 23. Smaller Base Layer NBFCs follow basic controls in Chapter III. Check which layer you are in.
How fast must a bank report a cyber incident to RBI?
Within six hours of detection, on RBI's DAKSH supervisory platform. Paragraph 182 of the commercial bank Directions sets this, and it also asks banks to notify CERT-In proactively. Separately, the CERT-In Directions of 28 April 2022 require reporting of listed incidents to CERT-In within 6 hours of noticing them. Plan one workflow that meets both clocks.
Is the RBI 2016 Cyber Security Framework still valid?
Treat the 2026 Directions as the current rulebook. For commercial banks, they repeal the existing directions, instructions and guidelines on the cybersecurity framework and IT governance, as communicated in circular DoS.CO.PPG.66 dated 31 July 2026. The 2016 framework sat in that body of rules. Check the repeal list for your own entity type to confirm.
Keep the six-month clock without a six-week wait
The 2026 Directions ask for a steady rhythm: tests every six months, every 12 months, and after each major change, with a clean evidence trail. A report that takes weeks to arrive makes that rhythm hard to keep.
Arxiis is an autonomous AI red teaming and penetration testing platform. A multi-agent AI crew handles OSINT, exploitation, lateral movement and reporting, and it produces a pentest report in hours instead of weeks. It is a testing tool, not a regulator-approved auditor, so your independent tester and governance choices under paragraphs 155 and 156 stay yours.
- Post-change tests on time: run a fresh test when a release goes live, instead of waiting for the next engagement.
- Evidence inspectors can read: CVSS-scored, MITRE ATT&CK-mapped findings with compliance overlays for 11 frameworks, including RBI, CERT-In and SEBI CSCRF.
- Wide coverage: 26 security modules across 6 attack vectors: ransomware, Active Directory, cloud, web applications, containers and credentials.
- Data stays with you: fully on-premise deployment, so test data never leaves your environment, on an MIT-licensed open-source core.
Your company gets defended every day.
Sources
- Reserve Bank of India, "Reserve Bank of India (Commercial Banks - Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026", RBI/DoS/2026-27/410, 31 July 2026. rbi.org.in
- Reserve Bank of India, "Reserve Bank of India (Small Finance Banks - Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026", RBI/DoS/2026-27/419, 31 July 2026. rbi.org.in
- Reserve Bank of India, "Reserve Bank of India (Non-Banking Financial Companies - Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026", RBI/DoS/2026-27/461, 31 July 2026. rbi.org.in
- Reserve Bank of India, "Cyber Security Framework in Banks", RBI/2015-16/418, 2 June 2016 (Annex 1 and Annex 3). rbi.org.in (PDF)
- Reserve Bank of India, "Report of the Working Group on Information Security, Electronic Banking, Technology Risk Management and Cyber Frauds", January 2011. rbidocs.rbi.org.in (PDF)
- TaxGuru (reproducing RBI circular RBI/2010-11/494), "Working Group on Information Security, Electronic Banking, Technology Risk Management and Cyber Frauds: Implementation of recommendations", 29 April 2011. taxguru.in
- TaxGuru (reproducing RBI/DoS/2023-24/107), "Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices", 7 November 2023. taxguru.in
- CERT-In, Ministry of Electronics and IT, "Directions under sub-section (6) of section 70B of the Information Technology Act, 2000", 28 April 2022. cert-in.org.in (PDF)
- SCC Online, "RBI Repeals 628 Supervisory Circulars After Consolidating Instructions into 64 Directions", 8 August 2026. scconline.com
- BitScore, "RBI Cybersecurity Directions 2026: All Seven Explained", 2026 (used for the reference numbers of the payments bank, UCB, AIFI and CIC texts). bitscore.in
- MediaNama, "Lowdown: RBI issues new cybersecurity framework for commercial banks", August 2026. medianama.com
- IBM India, "India Records Its Highest Average Cost of a Data Breach at INR 255 Million (INR 25.5 Crore) in 2026", 3 August 2026. in.newsroom.ibm.com
- Verizon, "2026 Data Breach Investigations Report", May 2026. verizon.com
- CrowdStrike, "2026 Global Threat Report", 2026. crowdstrike.com