Executive Summary:
This document summarizes the Indian government's response to a parliamentary inquiry regarding cybersecurity measures for Indian banking infrastructure. It outlines the auditing processes conducted by CERT-In empanelled organizations, the supervisory measures undertaken by RBI, and the guidelines issued to banks for strengthening their cybersecurity framework. The document also provides data on cyber incidents reported by scheduled commercial banks between 2020 and 2024.
Key Points / Main Content:
Auditing and Supervision:
* CERT-In has empanelled 200 'Information Security Auditing Organisations' to audit the Indian banking sector, including vulnerability assessments and penetration testing.
* From January 2021 to June 2025, CERT-In empanelled organizations conducted 29,751 audits for the banking sector.
* RBI's Cyber Security IT Risk Group (CSITE) conducts ongoing onsite and offsite supervision of cybersecurity risks for supervised entities.
* RBI does not maintain state-wise data on cyber incidents.
Cyber Incident Data:
* The number of cyber incidents and their financial impact reported by scheduled commercial banks to RBI for the last five calendar years are as follows:
* 2020: 36 incidents, financial impact of Rs 1.5 crore
* 2021: 59 incidents, financial impact of Rs 6.7 crore
* 2022: 98 incidents, financial impact of Rs 5.8 crore
* 2023: 66 incidents, financial impact of Rs 4.2 crore
* 2024: 82 incidents, financial impact of Rs 114.77 crore
* The final financial impact of cyber incidents could be lower due to subsequent recoveries by banks.
Cybersecurity Guidelines and Compliance:
* RBI issues circulars and guidelines to banks to strengthen their cybersecurity framework, including:
* Master Direction on Digital Payment Security Controls (February 18, 2021)
* Master Direction on Outsourcing of Information Technology Services (April 10, 2023)
* Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (November 7, 2023)
* Banks are required to implement these guidelines in a time-bound manner.
* RBI's CSITE team assesses the implementation of cybersecurity guidelines through onsite and offsite inspections.
* Vulnerabilities found during inspections are addressed with the concerned banks for remediation and compliance.
Impact Analysis:
Scheduled Commercial Banks:
* Impact: Banks are subject to audits by CERT-In empanelled organizations and supervision by RBI's CSITE team. They must adhere to RBI's cybersecurity guidelines and address any identified vulnerabilities.
* Action Required: Banks need to engage with CERT-In empanelled auditors, comply with RBI's cybersecurity directives, implement necessary controls, and remediate vulnerabilities identified during inspections.
Reserve Bank of India (RBI):
* Impact: RBI is responsible for the ongoing supervision of cybersecurity risks in the banking sector and for issuing guidelines to strengthen banks' cybersecurity frameworks.
* Action Required: RBI needs to continue conducting onsite and offsite inspections, issuing timely guidelines, and ensuring banks' compliance with cybersecurity norms.
Indian Computer Emergency Response Team (CERT-In):
* Impact: CERT-In plays a role in empanelling auditing organizations and facilitating audits within the banking sector.
* Action Required: CERT-In needs to maintain and update the panel of empanelled organizations, ensuring their competence in conducting cybersecurity audits.
Key Entities Referenced
Reserve Bank of India: The central bank of India, responsible for regulating the banking sector and issuing cybersecurity guidelines.
Indian Computer Emergency Response Team: A government organization responsible for handling cybersecurity incidents and creating a panel of Information Security Auditing Organisations.
Cyber Security IT Risk Group: A group within the Reserve Bank of India that undertakes supervisory measures related to cyber security risks of supervised entities.
Andhra Pradesh: A state in India, mentioned in the context of cyber fraud incidents and compliance of cybersecurity requirements.
Shri Pankaj Chaudhary: The Minister of State in the Ministry of Finance.
Master Direction on Digital Payment Security Controls: A circular issued by the Reserve Bank of India on February 18, 2021, to strengthen cyber security framework.
Master Direction on Outsourcing of Information Technology Services: A circular issued by the Reserve Bank of India on April 10, 2023, to strengthen cyber security framework.
Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices: A circular issued by the Reserve Bank of India on November 7, 2023, to strengthen cyber security framework.
GOVERNMENT OF INDIA
MINISTRY OF FINANCE
DEPARTMENT OF FINANCIAL SERVICES
LOK SABHA
UNSTARRED QUESTION NO:3969
ANSWERED ON THE MONDAY, 18 AUGUST, 2025/ SRAVANA 27, 1947 (SAKA)
CYBERSECURITY MEASURES FOR INDIAN BANKING INFRASTRUCTURE
3969. SHRI PUTTA MAHESH KUMAR:
Will the Minister of FINANCE be pleased to state:
(a) whether the Government has undertaken any survey/audit regarding cyber fraud measures
and policies of Indian banking infrastructure during the last five years;
(b) if so, the details thereof and the total number of cyberfraud incidents reported/investigated
and losses suffered by banks during the last five years, State-wise especially in Andhra Pradesh;
(c) the list of banks found to be non-compliant of the cybersecurity requirements during the
last five years and the action taken against such banks, State-wise especially from Andhra
Pradesh; and
(d) whether the Government has set any timeline for all banks to be compliant with the
cybersecurity norms as prescribed by the Reserve Bank of India
ANSWER
THE MINISTER OF STATE IN THE MINISTRY OF FINANCE
(SHRI PANKAJ CHAUDHARY)
(a) and (b): The Indian Computer Emergency Response Team (CERT-In) has created a panel
of 'Information Security Auditing Organisations' for auditing, including vulnerability
assessment and penetration testing of computer systems, networks, websites, cloud &
applications of various organizations in Indian banking sector. Currently, there are 200
organisations empanelled by CERT-In to provide auditing services which are being consulted
frequently by the entities in Government and vital sectors, including banking for their auditing
requirements. During January 2021 to June 2025, 29,751 audits were conducted by CERT-In
empanelled auditing organizations for the banking sector.
Further, Cyber Security & IT Risk Group (CSITE) of Reserve Bank of India (RBI) undertakes
comprehensive onsite and offsite supervisory measures on an ongoing basis with regard to
cyber security risk of its Supervised Entities. RBI has informed that it does not maintain State-wise data of Cyber-incidents. However, the number of cyber incidents and its financial impact
reported by scheduled commercial banks to RBI, in the last five calendar years are as follows:
Calendar Year Number of cyber incidents reported Financial Impact in Rs*
2020 36 ₹1.5 crore
2021 59 ₹6.7 crore
2022 98 ₹5.8 crore
2023 66 ₹4.2 crore
2024 82 ₹114.77 crore
*The amount is collated based on the reporting by the scheduled commercial banks. The final financial impact
could be lower, depending upon the subsequent recoveries, if any, made by the scheduled commercial banks
(c) and (d) RBI from time to time, issues various circulars/ guidelines to the banks to strengthen
their cyber security framework, which inter-alia includes, Master Direction on Digital Payment
Security Controls dated February 18, 2021, Master Direction on Outsourcing of Information
Technology Services dated April 10, 2023, Master Direction on Information Technology
Governance, Risk, Controls and Assurance Practices dated November 7, 2023, etc. These
circulars/ guidelines are required to be implemented by the banks in a time bound manner. The
implementation of cyber security related guidelines is assessed periodically through onsite and
offsite inspections by the CSITE team of RBI and vulnerabilities found, if any, are taken up
with concerned banks for remediation and necessary compliance.
******