The Reserve Bank of India (Small Finance Banks - Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 establish a comprehensive cybersecurity and technology governance framework for Small Finance Banks to ensure secure, resilient, and efficient IT operations. The Directions require Board-approved IT, Information Security, Cybersecurity, Business Continuity, and Disaster Recovery policies, along with effective governance through the IT Strategy Committee, IT Steering Committee, Information Security Committee, Chief Information Security Officer (CISO), and Head of IT Function. Banks must implement robust IT and cybersecurity risk management frameworks, secure IT architecture, information asset management, data protection, access controls, network and
application security, patch and vulnerability management, third-party risk management, cryptographic controls, and secure software development practices. They are also required to establish a Cyber Security Operations Centre (CSOC), conduct continuous monitoring, threat intelligence, Vulnerability Assessment and Penetration Testing (VA/PT), disaster recovery drills, business continuity testing, and
cyber incident response and recovery mechanisms, including reporting cyber incidents to RBI within six hours. The Directions further mandate regular employee, Board, and customer cybersecurity awareness programmes, risk-based transaction monitoring, Information Systems (IS) audits, performance metrics, forensic readiness, and continuous compliance to strengthen cyber resilience. They repeal
earlier cybersecurity guidelines for Small Finance Banks while preserving previous actions and operate in addition to other applicable laws and RBI regulations.