HomeCirculars › RBI/2013-14/501

Security Incident Tracking Platform for Banks

Current · Source: Reserve Bank of India · RBI/2013-14/501 · issued 26 Feb 2014 · ~1 min read
Quick answerRBI directs all scheduled commercial banks to report information security incidents on IDRBT's new anonymous platform, hosted on INFINET, to enable industry-wide threat sharing and policy improvement.
The rule, in the simplest words
How it plays out — a real example

After a suspicious email was sent to their bank's employees, the CISO quickly reported the incident on IDRBT's Security Incident Tracking Platform, hosted on INFINET. This helped the bank's IT team to take immediate action and prevent potential damage, while also contributing to the industry's shared repository of security incidents.

What changed

RBI introduced a Security Incident Tracking Platform developed by IDRBT, hosted on INFINET, for anonymous reporting of security incidents by banks. The platform is accessible only to Chief Information Security Officers (CISOs) and aims to facilitate information sharing on threats, external attacks, and internal compromises. IDRBT is also coordinating with CERT-In to gather global threat intelligence.

What it means for you

Banks must now actively report all information security incidents on this platform to build a shared repository for the banking industry. This will help fine-tune security policies and enable collective preventive measures. Non-compliance could lead to gaps in threat intelligence and regulatory scrutiny.

What you must do

Who it affects

Chief Information Security Officers (CISOs) of all scheduled commercial banks, IT and information security teams of banks, IDRBT and CERT-In as platform operators

❓ Common questions

What is the Security Incident Tracking Platform?

It is a platform developed by IDRBT, hosted on INFINET, where banks can anonymously report information security incidents to enable industry-wide sharing and threat intelligence.

Who can access this platform?

Only the Chief Information Security Officer (CISO) of each scheduled commercial bank is provided access to maintain confidentiality.

Why is anonymous reporting important?

It encourages banks to share sensitive incident details without fear of exposure, helping build a comprehensive repository for better preventive measures across the industry.

📜 Read the original circular — full text as issued by RBI
RBI/2013-14/501 DIT CO No.1857/07.71.099/2013-14 February 26, 2014 The Chief Information Security Officer (CISO) All Scheduled Commercial banks Dear Sir Security Incident Tracking Platform- Reporting thereon Information on Security, particularly security incidents, external attacks, internal compromises etc. is unique to each bank. Sharing of such information/ incidents/experiences would greatly benefit banks in taking appropriate preventive/corrective measures. As of now, information sharing among banks on these issues is not very prevalent. 2. The National Security Council (NSC) has requested IDRBT to set up necessary facilities to enable sharing of information among banks and also dissemination of information on emerging security threats. Towards this end, IDRBT has developed a Security Incident Tracking Platform where banks would be able to report security incidents in an anonymous manner; thus keeping the information reported by the banks confidential. The platform will be hosted on the INFINET and the access provided only to Chief Information Security Officers (CISOs) of respective banks. IDRBT is simultaneously making arrangements to gather global threat intelligence from various sources in coordination with CERT-In. 3. CISOs of banks are advised to make use of the platform developed by IDRBT by reporting all Information Security related incidents in the above platform. This would not only enable building a repository of security incidents related information for the banking Industry but also help in fine-tuning policies relating to information security from time to time. 4. Please acknowledge the receipt of this circular. Yours faithfully (A S Ramasastri) CGM-in-Charge
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2013-14/501 · issued 26 Feb 2014. The plain-English explanation above is BankPulse’s own independent summary.
🧰 Tools — save, print, templates & related
Worked example & action-note template

Example: if you are a Compliance officer at a bank this circular applies to (Chief Information Security Officers (CISOs) of all scheduled commercial banks, IT and information security teams of banks, IDRBT and CERT-In as platform operators), your first concrete step on “Security Incident Tracking Platform for Banks” is: “Ensure your CISO registers and accesses the Security Incident Tracking Platform on INFINET.” (RBI issued this 26 Feb 2014).

  1. Circular: RBI/2013-14/501 -- Security Incident Tracking Platform for Banks
  2. Issued: 26 Feb 2014
  3. Action required: Ensure your CISO registers and accesses the Security Incident Tracking Platform on INFINET.
  4. Action required: Report all information security incidents, including external attacks and internal compromises, on the platform anonymously.
  5. Action required: Coordinate with IDRBT and CERT-In for threat intelligence updates and integrate insights into your security posture.
  6. Action required: Acknowledge receipt of this circular to RBI as instructed.
  7. Owner: ____________ Target date: ____________
  8. Board/committee approval needed? Y / N
  9. Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.

💬 Banker Discussion

Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.

Loading comments…
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly).
Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=8753&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗