In its cyber security framework for banks, the central bank said the number, frequency and impact of cyberattacks “have increased manifold in the recent past” at banks and other financial institutions, “underlining the urgent need to put in place a robust cyber security/resilience framework at banks and to ensure adequate cyber-security preparedness among banks on a continuous basis.”
The circular comes a week after RBI Deputy Governor S S Mundra said at an event that the central bank would get strict with cyber security flaws at banks and was considering to limit a customer’s liability in case of cyber fraud.
The framework, posted on RBI’s website, warned that banks must improve the current defences in addressing cyber risks as entry barriers are getting lowered, while motivation and resourcefulness of cyber threats continue to rise.
Hence, banks should immediately put in place an adaptive incident response, management and recovery framework to deal with adverse incidents, if and when they occur.
RBI said the cyber strategy of banks should be distinct from the broader IT and security policy of the lender and testing for vulnerabilities should be carried out at regular intervals as cyberattacks can occur at any time and in a manner that may not have been anticipated.
“Recent incidents have highlighted the need to thoroughly review network security in every bank,” the framework said.
In no case, personal information of customers should be divulged, even as the data reside with a third party the bank has employed.
“Banks, as owners of such data, should take appropriate steps in preserving the confidentiality, integrity and availability of the same, irrespective of whether the data is stored/in transit within themselves or with customers or with the third party vendors; the confidentiality of such custodial information should not be compromised at any situation,” the central bank warned.
Banks are expected to be well-prepared to face emerging cyber threats such as “zero-day” attacks, remote access threats, and targeted attacks.
The lenders should also be well aware of how to fight regular threats as denial of service, distributed denial of services (DDoS), ransomware/crypto ware, destructive malware, business email frauds including spam, email phishing, spear phishing, whaling, vishing frauds, drive-by downloads, browser gateway fraud, ghost administrator exploits, identity frauds, memory update frauds, password related frauds, etc.
The banks also must share the data with the central bank and report promptly about any cyber crime they face, it said.
You’ve reached your limit of {{free_limit}} free articles this month.
Subscribe now for unlimited access.
Already subscribed? Log in
Subscribe to read the full story →
Smart Quarterly
₹900
3 Months
₹300/Month
Smart Essential
₹2,700
1 Year
₹225/Month
Super Saver
₹3,900
2 Years
₹162/Month
Renews automatically, cancel anytime
Here’s what’s included in our digital subscription plans
Exclusive premium stories online
Over 30 premium stories daily, handpicked by our editors


Complimentary Access to The New York Times
News, Games, Cooking, Audio, Wirecutter & The Athletic
Business Standard Epaper
Digital replica of our daily newspaper — with options to read, save, and share


Curated Newsletters
Insights on markets, finance, politics, tech, and more delivered to your inbox
Market Analysis & Investment Insights
In-depth market analysis & insights with access to The Smart Investor


Archives
Repository of articles and publications dating back to 1997
Ad-free Reading
Uninterrupted reading experience with no advertisements


Seamless Access Across All Devices
Access Business Standard across devices — mobile, tablet, or PC, via web or app
)