Compliance & Risk Advisory
Gap assessments, policies and playbooks aligned with RBI, SEBI CSCRF, CERT-In, IRDAI, PCI DSS and DPDP.
Learn more about Compliance & Risk Advisory →The Reserve Bank of India expects regulated entities to run cyber security as a board-level responsibility, not just an IT task. Its directions cover governance, risk management, technical controls, outsourcing, digital payment security and incident reporting.
Which instruments apply to you depends on your licence and category — a scheduled commercial bank, a co-operative bank, an NBFC in a particular layer, or a payment system operator will each have a different set of obligations.
IT strategy, information security and cyber security policies approved and overseen by the board or its committees.
Defined roles such as a senior official responsible for information security, with committees overseeing IT and cyber risk.
Periodic risk assessments and controls covering access, change management, vulnerability management and data protection.
Regular VAPT of critical and internet-facing systems, with findings tracked to closure.
Due diligence, contracts and ongoing monitoring of IT service providers, with the regulated entity remaining accountable.
Security controls for internet banking, mobile banking and payment channels, including fraud monitoring and customer protection.
A Cyber Crisis Management Plan and timely reporting of cyber incidents to RBI and CERT-In as applicable.
Periodic information systems audit covering the areas the directions require.
Aligned with, not endorsed by any regulator. This page is a plain-English summary for awareness — confirm obligations against the latest official circulars or with your compliance officer.
Gap assessments, policies and playbooks aligned with RBI, SEBI CSCRF, CERT-In, IRDAI, PCI DSS and DPDP.
Learn more about Compliance & Risk Advisory →Find and fix weaknesses in apps, APIs, networks and cloud before attackers exploit them.
Learn more about VAPT →Independent review of your systems, controls and architecture against the rules you must follow.
Learn more about Security Audit →Call us when it matters: triage, containment, recovery and regulator reporting support.
Learn more about 24/7 Incident Response →Senior security leadership, policies and vendor risk management without a full-time CISO.
Learn more about vCISO, Governance & Third-Party Risk →It applies to specified categories of regulated entities, including NBFCs in certain regulatory layers. We help you confirm the exact applicability for your entity.
RBI expects regulated entities to be prepared to respond to cyber incidents. A tested Cyber Crisis Management Plan is the standard way to show this.
Some audits must be signed by auditors meeting specific qualifications. We will tell you clearly which parts we deliver and where a qualified partner signs.
We assess where you stand, close the gaps and prepare the evidence your auditors and regulator will ask for.
support@trustnetsecure.com · +91 93229 37312 · +91 88300 61438
Under attack right now? Go to emergency help →
📍 Location not reported
📍 Location not reported
📍 Location not reported
📍 Location not reported
📍 Location not reported
📍 Location not reported
Source: The Hacker News — headlines only, each linking to the original article.