Banks, brokers, and insurers in India each operate under sector-specific cybersecurity and IT-governance directions from RBI, SEBI, and IRDAI respectively.
RBI's cybersecurity framework applies to banks and NBFCs, SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) applies to market intermediaries, and IRDAI's information and cybersecurity guidelines apply to insurers — each prescribing specific controls, audit cadences, and incident-reporting timelines.
Regulators covered
RBI / SEBI / IRDAI
RBI Cybersecurity Framework; SEBI CSCRF; IRDAI IT/Cyber Guidelines