The Bank Vault Has Gone Digital
Banking security was once easy to visualise: a guarded branch, a strong vault and controlled access to money. The modern bank looks entirely different. Its most valuable assets increasingly exist in digital form: customer credentials, financial data, transaction records, digital identities, encryption keys, payment infrastructure and interconnected banking applications.
Internet banking, mobile applications, UPI and digital payments, APIs, cloud computing, FinTech partnerships and outsourced technology services have transformed banking in India. They have delivered extraordinary convenience, speed and financial inclusion. But every new digital connection also creates another potential point of vulnerability.
That is the context in which the Reserve Bank of India’s Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 assume significance.
The framework represents more than another layer of banking compliance. It signals an important change in regulatory philosophy: RBI is moving the conversation from whether banks possess cybersecurity controls to ‘whether those controls can actually withstand a cyber incident’.
Cybersecurity Is No Longer an IT Problem
A ransomware attack does not merely affect computers. It can interrupt banking operations. A compromised credential can expose customer information. A vulnerability at a technology vendor can potentially become a vulnerability for the bank. A disruption at critical digital infrastructure can affect thousands or millions of transactions.
Technology risk can therefore rapidly become operational risk, financial risk, reputational risk and even systemic risk.
This explains why cybersecurity can no longer remain confined to the IT department. The new regulatory philosophy requires banks to think in terms of the entire digital ecosystem: technology infrastructure, cybersecurity, third-party dependencies, business continuity, incident response, disaster recovery and Board-level accountability. The question is no longer simply: Can the bank prevent an attack? It is equally: Can the bank detect, withstand, contain and recover from one?
And that is the difference between cybersecurity and cyber resilience.
From Prevention to Resilience
Traditional cybersecurity frameworks were largely built around protection—firewalls, antivirus software, access controls, vulnerability assessments and periodic security audits.
All remain essential. But modern cyber threats have demonstrated an uncomfortable reality: no sophisticated organisation can proceed on the assumption that every attack will always be prevented. The more mature approach is therefore defence in depth.
Prevent where possible. Detect what gets through. Contain the breach. Protect critical operations. Recover rapidly. Investigate the failure. Strengthen the system. Repeat the cycle. In other words, banking cybersecurity is evolving from prevent and protect towards predict, prevent, detect, respond, recover and adapt.
For Indian banks, this means that a cybersecurity policy beautifully drafted and periodically placed before a committee will no longer be enough. What matters increasingly is whether the institution can demonstrate that its cyber controls actually operate when tested. Compliance is moving from documentation to demonstration.
The CISO Moves Closer to the Boardroom
This transition also changes the importance of the Chief Information Security Officer (CISO). The Chief Information Officer and CISO perform complementary but fundamentally different functions.
A CIO enables technology. A CISO must continuously question its security.
The CIO’s responsibility ordinarily encompasses technology strategy, architecture, digital transformation, infrastructure and operational continuity. The CISO’s focus lies upon cyber risk, information security, threat management, incident preparedness and protection of the enterprise. Put simply: The CIO enables resilient technology. The CISO secures a resilient enterprise.
That distinction matters because there can occasionally be an inherent tension between rapid technological deployment and cybersecurity assurance. The security function must possess sufficient institutional independence to question whether convenience, cost or speed is creating unacceptable cyber risk.
Cybersecurity therefore belongs not merely in the server room but increasingly in the boardroom. Boards need not understand every line of code. But they must understand their institution’s critical digital assets, cyber-risk exposure, third-party dependencies, recovery preparedness and potential consequences of a major technology failure.
A Bank Cannot Report What It Cannot Detect
Modern cyberattacks move extraordinarily fast. A compromised account can allow lateral movement across interconnected systems. Malware can spread. Privileges can be escalated. Sensitive data can be extracted. Attackers may even attempt to erase evidence of intrusion. This makes real-time cyber threat detection and incident response critical.
The framework described in the regulatory material places considerable emphasis on Cyber Security Operations Centre capabilities, continuous monitoring, Security Information and Event Management, indicators of compromise, threat intelligence and specialised response teams. The regulatory principle underlying these requirements is straightforward: A bank cannot respond to a cyberattack that it cannot see.
Continuous monitoring therefore becomes more than a cybersecurity tool. It becomes an instrument of operational resilience. Rapid regulatory reporting similarly matters because an attack against one bank may not necessarily be an isolated event. Early intelligence can reveal coordinated attacks, common vulnerabilities or threats spreading across the financial ecosystem.
Your Vendor’s Cyber Risk Is Now Your Risk
Perhaps the most underestimated vulnerability in modern banking lies outside the bank itself. Banks increasingly depend upon cloud providers, software companies, FinTech platforms, data processors, managed service providers and other outsourced technology partners. The traditional concept of vendor management is consequently becoming inadequate. What banks now require is comprehensive Third-Party Risk Management (TPRM) and, increasingly, Extended Enterprise Risk Management.
Outsourcing a function does not outsource responsibility. A bank must know who has access to its systems and data, where information is processed, whether subcontractors are involved, how cyber incidents will be communicated and whether critical operations can continue if a service provider suddenly becomes unavailable. Every material outsourcing relationship should therefore confront a difficult question before the contract is signed: What happens if this vendor fails tomorrow?
Business continuity, data portability, alternate service providers, transition planning and exit readiness must become part of cybersecurity architecture itself.
Cloud adoption raises an equally important governance issue. The infrastructure may belong to a cloud service provider, but accountability for protecting banking operations and customer information ultimately remains with the regulated institution.
Disaster Recovery Must Mean Actual Recovery
Banks have conducted disaster recovery drills for years. But the evolving regulatory philosophy asks a harder question: Did the system merely switch or did the business actually recover?
There is an important difference between technical failover and operational resilience. A meaningful disaster recovery exercise must establish whether customers can continue transacting, payments can settle, employees can perform essential functions, data remains accurate and the institution can operate through a genuine disruption.
This turns Business Continuity Planning (BCP) and Disaster Recovery (DR) from periodic compliance exercises into measurable demonstrations of resilience. A successful test is not one where the backup server starts. It is one where the bank continues banking.
The New Regulatory Currency Is Evidence
This may ultimately prove to be the most important feature of RBI’s evolving cybersecurity approach. Policies remain important. Certifications remain important. Committees, audits and documentation remain necessary. But increasingly, regulators will expect evidence. Show that vulnerabilities were identified. Show that they were remediated. Show who accessed critical systems. Show that cyber incidents can be detected. Show the audit trail. Show that disaster recovery actually works. Show that the Board understands the cyber-risk position. Show that a critical vendor can be replaced without paralysing banking operations.
This is the movement towards continuous cybersecurity assurance. And it changes compliance profoundly. Cybersecurity cannot be something demonstrated once a year to an auditor. It has to become an everyday operational capability.
Digital Trust Is the New Banking Capital
Banking ultimately rests upon trust. Historically, customers trusted banks to safeguard their money. In the digital economy, that trust has expanded. Banks now hold enormous quantities of personal data, financial information, behavioural data, transaction histories and digital identities.
Customers therefore expect two forms of security simultaneously: financial security and digital security. A financially sound bank that is technologically fragile cannot be considered completely resilient.
This is why RBI’s new cybersecurity architecture should be viewed beyond technical compliance. It reflects a larger transformation in Indian financial regulation i.e. the recognition that digital trust, data protection, cybersecurity, operational resilience and financial stability are increasingly interconnected. That is the transition RBI appears to be driving: from cybersecurity on paper to cyber resilience in practice. And in an India where banking is becoming more digital with every transaction, the ability to prove that resilience may soon become as fundamental to a bank as its ability to protect the money entrusted to it.
The next generation of banking regulation will consequently not be judged merely by how many cybersecurity controls a bank possesses. The real test will come on the worst possible day, when systems are attacked, a critical vendor fails, data is threatened or operations are disrupted. Can the bank still protect its customers? Can it continue its essential services? Can it recover without compromising trust?
*Vivek Narayan Sharmais, an Advocate-on-Record at the Supreme Court of India, constitutional law expert, Accredited Mediator and Arbitrator, with over 27 years of experience in constitutional and regulatory law, litigation, arbitration and public policy.

