The RBI's 2026 Master Directions on Cybersecurity, Technology Risk, Resilience and Assurance represent a major shift from the 2016 Cyber Security Framework. The new regulations transform cybersecurity from a technical compliance function into a board-driven governance and enterprise risk management responsibility. Banks are now required to establish formal IT governance structures, Board-level oversight, dedicated IT Strategy and Information Security Committees, stronger CISO independence, and a comprehensive Information Systems Audit framework.
The framework introduces mandatory controls for data governance, cryptography, secure software development, vendor risk management, source code escrow, IPv6 readiness, DMRC, teleworking security, business continuity, disaster recovery, and cloud security. It also mandates periodic vulnerability assessments, penetration testing, cyber drills, incident reporting within six hours through the DAKSH platform, and continuous board training. Overall, the 2026 Directions move from advisory guidance to legally binding requirements, making governance, accountability, cyber resilience, and operational assurance central pillars of India's banking cybersecurity framework.
Key Takeaways
● Cybersecurity evolves from an IT issue to a Board-level governance responsibility.
● Mandatory IT governance, risk, resilience, and audit framework introduced.
● Stronger accountability for Boards, CISOs, and senior management.
● Enhanced controls for vendors, cloud, cryptography, remote work, and software security.
● Six-hour cyber incident reporting through the DAKSH platform.
● Mandatory VA/PT, disaster recovery drills, and continuous cyber resilience testing.
● Focus shifts from compliance to proactive resilience and operational assurance.
Enterprises should establish Board-led cybersecurity governance, conduct regular risk assessments, implement Zero Trust architecture, strengthen vendor and third-party risk management, enforce multi-factor authentication, perform periodic vulnerability assessments and penetration testing, maintain disaster recovery readiness, report cyber incidents promptly, conduct continuous security audits, and ensure ongoing employee awareness and compliance.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




