The RBI Cyber Security Framework for Fintech is a set of guidelines and standards designed to protect the financial sector from cyber attacks and other security threats. This includes measures such as regular security audits, the implementation of strong encryption techniques, and the development of contingency plans to deal with cyber attacks.
One of the key aspects of the RBI’s cyber security framework is the requirement for fintech companies to implement a “multi-layered security architecture”. This means that fintech companies must have multiple layers of security in place, each of which is designed to protect against a different type of cyber threat. For example, a fintech company might have one layer of security that is designed to protect against malware attacks, while another layer might be focused on protecting against phishing attacks.
Another important aspect of the RBI’s cyber security framework is the requirement for fintech companies to implement “end-to-end encryption”. This means that all sensitive data, such as customer financial information and transaction details, must be encrypted from the moment it is entered into a fintech company’s systems until it is accessed by the customer. This ensures that even if a cyber attacker were to gain access to a fintech company’s systems, they would not be able to access or read any of the sensitive data.
The framework is divided into three main pillars: governance and risk management, technology and operations, and cyber security controls. It includes guidelines on topics such as cyber security policies, data protection, incident response, and cyber security awareness.
One of the key impacts of the framework has been to raise awareness among fintech companies of the need to prioritize cyber security. Many fintech firms in India were previously focused primarily on innovation and growth, with little emphasis on security. The RBI framework has helped to change this mentality, with fintech firms now recognizing the importance of investing in cyber security to protect their customer’s sensitive data and prevent costly security breaches.
The framework has also led to an increase in the adoption of secure technologies and practices among fintech companies. For example, many firms have implemented secure encryption protocols and two-factor authentication to protect their customers’ data, and have put in place robust incident response plans to deal with cyber attacks.
However, the inadequacy of this framework is illustrated from the fact that Indian banks reported 248 data breaches in 2022. This enforced the RBI to notify the master direction on ‘Information Technology Governance, Risk, Controls and Assurance Practices’ in November 2023, which will take effect from April 1, 2024. It prescribes procedures and framework for strategic alignment, risk management, resource management, performance management and business continuity/ disaster recovery management. It also provides for periodic reviews of risks, IT and information security risk management framework, information security policy and cyber security policy.
The framework provides for the constitution of three major committees by the regulated entities — IT strategy committee of the board, IT steering committee and information security committee.. Further, the regulated entities have been recommended to conduct disaster recovery drills at least on a half-yearly basis for critical information and back up data in a secured manner as a business continuity measure.

