Skip to content
BankPulseBETARegulatory intelligence for Indian banking
Directions · Reserve Bank of India

Reserve Bank of India (Urban Co-operative Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026

UR

The four dates on this rule

At a glanceThis paper sets the cyber and technology risk rules for urban co-operative banks. These Directions apply to every urban co-operative bank. A cyber incident must be reported on the DAKSH platform within six hours of detection.

Official RBI page

What it says

Chapter I. Preliminary

Background

1. Cyber rules for UCBs

This paper sets the cyber and technology risk rules for urban co-operative banks.

2. Start date

These Directions took effect at once.

3. Who is covered

These Directions apply to every urban co-operative bank.

4. Four levels of UCB

A UCB is placed in one of four levels by its digital depth and payment links.

5. Level one covers all

Level one controls apply to every urban co-operative bank, whatever it offers.

6. Level two is net banking

Level two covers a sub member of central payment systems that offers net or mobile banking.

7. Level three is direct

Level three covers a direct member of central payment systems or one with its own ATM switch.

8. Level four is the largest

Level four covers a bank with its own switch and SWIFT, or one hosting data for others.

Chapter II. Role of the Board

1. Board approves the policies

The Board must approve the plans and policies for technology and cyber security.

2. Two directors on the committee

A level four bank may set up an IT Strategy Committee of at least two directors.

Chapter III. Level

Must know

1. No admin rights

Staff must not hold admin rights on their own desktop or laptop.

2. No trivial passwords

The bank must have a password policy and must not use easy or guessable passwords.

3. Split the duties

The person who writes a program must not be the person who runs it.

4. Removable media is barred

As a rule, pen drives and like media are barred unless allowed for a set use.

5. Never open unknown mail

Staff must be taught never to open a file sent from a source they do not know.

6. Warn customers on passwords

The bank must teach customers never to share a password, a one time code or a PIN.

7. Six hours to report

A cyber incident must be reported on the DAKSH platform within six hours of detection.

Do it

8. Grade yourself first

The bank must work out for itself which level it falls in and follow those controls.

9. A separate cyber policy

The cyber security policy must be kept apart from the wider IT policy.

10. Rate each risk

The bank must rate every risk it finds as low, medium, high or very high.

11. Keep an asset register

The asset register must show the kit, where customer data sits, and how critical it is.

12. Store the keys safely

The bank must store encryption keys safely and control who may reach them.

13. Control what gets installed

The bank must control what software can be put on its systems and devices.

14. List the allowed software

The bank must keep one central list of software that is allowed and not allowed.

15. Turn off risky scripts

Browsers must auto update and scripts such as Java and ActiveX must be off when unused.

16. Keep internet apart

Internet use must sit on separate machines, away from the day to day banking systems.

17. Watch heat and water

The bank must watch for breaks in heat, water, smoke, power and access alarms.

18. Change default passwords

Default passwords on network devices and systems must be changed after they go in.

19. Secure the wireless

The bank must secure wireless networks, access points and client systems.

20. Turn remote desktop off

Remote desktop must stay off and open only with an approval, with logs watched.

21. Firewalls at highest setting

Firewalls must be set to the highest security level and checked from time to time.

22. Maker and checker

Sensitive or high value transactions must pass a maker and checker control.

23. Secure the mail system

The bank must guard its mail against spoofing, look alike names and bad files.

24. Bank name in the domain

The bank must use its own name in its email domain, with anti phishing controls.

25. Use DMARC on email

The bank must put DMARC in place on its email names to stop spoofing.

26. Scan media first

Removable media must be scanned for malware before read or write access is given.

27. Destroy media before disposal

Media holding sensitive data must be fully erased or destroyed before it is thrown out.

28. Keep backups offline

The bank must back up important data and keep a copy offline, off the machine.

29. Check the vendor first

Before hiring or renewing a vendor, the bank must test whether it can meet the contract.

30. Assess vendor risk

The bank must assess vendor risk and hold controls that match that risk.

31. Exit terms are needed

The agreement must carry exit terms so the bank is not locked in to one vendor.

32. Right to audit the vendor

The vendor agreement must give the bank a right to audit and RBI a right to inspect.

33. Who pays if it fails

The service agreement must state who answers for a failure of service.

34. Map the data flow

The bank must map how data moves between itself, its vendors and its customers.

35. Switch provider must comply

The ATM switch provider must meet the cyber controls the bank writes into the contract.

36. Watch for new patches

The bank must watch patch notices from makers and CERT-In and apply them fast.

37. Keep a network map

The bank must keep an up to date map of its wired and wireless networks.

38. Block strange devices

The bank must spot devices that are not allowed on the network and block them.

39. Write secure code

The bank must use secure coding when it builds software on its own or with others.

40. Close dormant accounts

The bank must limit failed sign in tries and switch off accounts nobody uses.

41. Stop data leaks

The bank must have a full plan to stop the loss or leak of sensitive data.

42. Card standards apply

The switch provider must meet the payment card industry data security standard.

43. Tell CERT-In as well

The bank must also tell CERT-In about a cyber incident without being asked.

Background

44. Encrypt data on the wire

Standard encryption and integrity checks are needed where sensitive data crosses a network.

45. Two factor for core banking

Signing in to core banking needs a second factor that changes each time.

46. Board briefed once a year

The bank may brief its Board members on IT and cyber risk at least once a year.

47. The bank stays answerable

The bank stays answerable for security risk in work it has given out.

48. Check vendor staff

Background checks and secrecy agreements are needed for all vendor staff.

49. Anti malware everywhere

Anti malware cover is needed on desktops, servers, gateways and message systems.

Chapter IV. Level II Baseline Cybersecurity and Resilience Requirements

Must know

1. Scan twice, test yearly

Critical and public facing applications need a scan every six months.

Do it

2. List every allowed device

The bank must keep one central list of the devices allowed on its network.

3. Layer the boundary

Boundary defence must be layered, with firewalls, proxies and intrusion systems.

4. Support IPv6 traffic

Public facing systems of the bank must be able to carry IPv6 traffic.

5. Set a security baseline

The bank must set and apply a base security setting for every kind of device.

6. Attack test once a year

An attack test must be run at least once a year.

7. Buy anti phishing help

The bank must buy a service that takes down fake sites and rogue apps.

Chapter V. Level III Baseline Cybersecurity and Resilience Requirements

1. Whitelist internet sites

The bank must whitelist the internet sites and systems that staff may reach.

2. Yearly quiz for managers

New recruits must be trained and every manager must take a yearly test.

3. Watch risky transactions

The bank must watch transactions on a risk basis across every channel it runs.

Chapter VI. Level IV Baseline Cybersecurity and Resilience Requirements

Must know

1. Quarterly review to the Board

The security officer must put a cyber readiness review to the Board every three months.

2. Keep the two apart

The security officer must not report to the head of IT and gets no business target.

3. Security committee each quarter

The information security committee must meet at least once every three months.

Do it

4. What the centre must do

The centre must watch, study and escalate incidents and work with outside agencies.

5. Measure with real numbers

The bank must build measures such as patch delay, malware cover and training reach.

6. Keep forensics on standby

The bank must keep network forensic and denial of service help on standby.

7. Two must know technology

At least two members must be technically able and one must have real IT skill.

Background

8. Security officer reports up

The security officer reports to the top risk executive or to the chief executive.

Chapter VII. Repeal and Other Provisions

1. Old cyber rules go

These Directions repeal the earlier cyber framework and IT governance instructions.

2. Other laws still apply

These Directions add to other laws and rules and do not replace them.

BankPulse example. A bank follows these Directions and thinks the matter is closed. It is not. Any other laws, rules, regulations or directions in force still apply on top. Where another one asks for more, the bank does the more.

3. RBI has the last word

RBI may issue clarifications, and its reading of these Directions is final.

BankPulse example. Two banks read the same clause differently. Neither reading settles it. RBI may issue clarifications, and its interpretation of any provision is final and binding on all concerned entities.

The same subject for other kinds of institution

The same subject for other kinds of institution.

Other RBI rules for urban co-operative banks

Every rule page on BankPulse  ·  Questions bankers ask, answered