Home India Ministry of Finance Parliament Question: Cybersecurity Measures for Indian Banki...
Date: 2025-08-18 Category: Not Applicable State: Union Government Country: India

Parliament Question: Cybersecurity Measures for Indian Banking Infrastructure

Issued by Ministry of Finance · Not Applicable

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

Executive Summary: This document summarizes the Indian government's response to a parliamentary inquiry regarding cybersecurity measures for Indian banking infrastructure. It outlines the auditing processes conducted by CERT-In empanelled organizations, the supervisory measures undertaken by RBI, and the guidelines issued to banks for strengthening their cybersecurity framework. The document also provides data on cyber incidents reported by scheduled commercial banks between 2020 and 2024. Key Points / Main Content: Auditing and Supervision: * CERT-In has empanelled 200 'Information Security Auditing Organisations' to audit the Indian banking sector, including vulnerability assessments and penetration testing. * From January 2021 to June 2025, CERT-In empanelled organizations conducted 29,751 audits for the banking sector. * RBI's Cyber Security IT Risk Group (CSITE) conducts ongoing onsite and offsite supervision of cybersecurity risks for supervised entities. * RBI does not maintain state-wise data on cyber incidents. Cyber Incident Data: * The number of cyber incidents and their financial impact reported by scheduled commercial banks to RBI for the last five calendar years are as follows: * 2020: 36 incidents, financial impact of Rs 1.5 crore * 2021: 59 incidents, financial impact of Rs 6.7 crore * 2022: 98 incidents, financial impact of Rs 5.8 crore * 2023: 66 incidents, financial impact of Rs 4.2 crore * 2024: 82 incidents, financial impact of Rs 114.77 crore * The final financial impact of cyber incidents could be lower due to subsequent recoveries by banks. Cybersecurity Guidelines and Compliance: * RBI issues circulars and guidelines to banks to strengthen their cybersecurity framework, including: * Master Direction on Digital Payment Security Controls (February 18, 2021) * Master Direction on Outsourcing of Information Technology Services (April 10, 2023) * Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (November 7, 2023) * Banks are required to implement these guidelines in a time-bound manner. * RBI's CSITE team assesses the implementation of cybersecurity guidelines through onsite and offsite inspections. * Vulnerabilities found during inspections are addressed with the concerned banks for remediation and compliance. Impact Analysis: Scheduled Commercial Banks: * Impact: Banks are subject to audits by CERT-In empanelled organizations and supervision by RBI's CSITE team. They must adhere to RBI's cybersecurity guidelines and address any identified vulnerabilities. * Action Required: Banks need to engage with CERT-In empanelled auditors, comply with RBI's cybersecurity directives, implement necessary controls, and remediate vulnerabilities identified during inspections. Reserve Bank of India (RBI): * Impact: RBI is responsible for the ongoing supervision of cybersecurity risks in the banking sector and for issuing guidelines to strengthen banks' cybersecurity frameworks. * Action Required: RBI needs to continue conducting onsite and offsite inspections, issuing timely guidelines, and ensuring banks' compliance with cybersecurity norms. Indian Computer Emergency Response Team (CERT-In): * Impact: CERT-In plays a role in empanelling auditing organizations and facilitating audits within the banking sector. * Action Required: CERT-In needs to maintain and update the panel of empanelled organizations, ensuring their competence in conducting cybersecurity audits.

Key Entities Referenced

Reserve Bank of India: The central bank of India, responsible for regulating the banking sector and issuing cybersecurity guidelines. Indian Computer Emergency Response Team: A government organization responsible for handling cybersecurity incidents and creating a panel of Information Security Auditing Organisations. Cyber Security IT Risk Group: A group within the Reserve Bank of India that undertakes supervisory measures related to cyber security risks of supervised entities. Andhra Pradesh: A state in India, mentioned in the context of cyber fraud incidents and compliance of cybersecurity requirements. Shri Pankaj Chaudhary: The Minister of State in the Ministry of Finance. Master Direction on Digital Payment Security Controls: A circular issued by the Reserve Bank of India on February 18, 2021, to strengthen cyber security framework. Master Direction on Outsourcing of Information Technology Services: A circular issued by the Reserve Bank of India on April 10, 2023, to strengthen cyber security framework. Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices: A circular issued by the Reserve Bank of India on November 7, 2023, to strengthen cyber security framework.
Official Source Record View Original Source →
See Full Document Text
GOVERNMENT OF INDIA MINISTRY OF FINANCE DEPARTMENT OF FINANCIAL SERVICES LOK SABHA UNSTARRED QUESTION NO:3969 ANSWERED ON THE MONDAY, 18 AUGUST, 2025/ SRAVANA 27, 1947 (SAKA) CYBERSECURITY MEASURES FOR INDIAN BANKING INFRASTRUCTURE 3969. SHRI PUTTA MAHESH KUMAR: Will the Minister of FINANCE be pleased to state: (a) whether the Government has undertaken any survey/audit regarding cyber fraud measures and policies of Indian banking infrastructure during the last five years; (b) if so, the details thereof and the total number of cyberfraud incidents reported/investigated and losses suffered by banks during the last five years, State-wise especially in Andhra Pradesh; (c) the list of banks found to be non-compliant of the cybersecurity requirements during the last five years and the action taken against such banks, State-wise especially from Andhra Pradesh; and (d) whether the Government has set any timeline for all banks to be compliant with the cybersecurity norms as prescribed by the Reserve Bank of India ANSWER THE MINISTER OF STATE IN THE MINISTRY OF FINANCE (SHRI PANKAJ CHAUDHARY) (a) and (b): The Indian Computer Emergency Response Team (CERT-In) has created a panel of 'Information Security Auditing Organisations' for auditing, including vulnerability assessment and penetration testing of computer systems, networks, websites, cloud & applications of various organizations in Indian banking sector. Currently, there are 200 organisations empanelled by CERT-In to provide auditing services which are being consulted frequently by the entities in Government and vital sectors, including banking for their auditing requirements. During January 2021 to June 2025, 29,751 audits were conducted by CERT-In empanelled auditing organizations for the banking sector. Further, Cyber Security & IT Risk Group (CSITE) of Reserve Bank of India (RBI) undertakes comprehensive onsite and offsite supervisory measures on an ongoing basis with regard to cyber security risk of its Supervised Entities. RBI has informed that it does not maintain State-wise data of Cyber-incidents. However, the number of cyber incidents and its financial impact reported by scheduled commercial banks to RBI, in the last five calendar years are as follows: Calendar Year Number of cyber incidents reported Financial Impact in Rs* 2020 36 ₹1.5 crore 2021 59 ₹6.7 crore 2022 98 ₹5.8 crore 2023 66 ₹4.2 crore 2024 82 ₹114.77 crore *The amount is collated based on the reporting by the scheduled commercial banks. The final financial impact could be lower, depending upon the subsequent recoveries, if any, made by the scheduled commercial banks (c) and (d) RBI from time to time, issues various circulars/ guidelines to the banks to strengthen their cyber security framework, which inter-alia includes, Master Direction on Digital Payment Security Controls dated February 18, 2021, Master Direction on Outsourcing of Information Technology Services dated April 10, 2023, Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices dated November 7, 2023, etc. These circulars/ guidelines are required to be implemented by the banks in a time bound manner. The implementation of cyber security related guidelines is assessed periodically through onsite and offsite inspections by the CSITE team of RBI and vulnerabilities found, if any, are taken up with concerned banks for remediation and necessary compliance. ******

Continue your research