Reserve Bank of India (Urban Co-operative Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026
UR
- Applies toUrban co-operative banks
- StatusIn force
- ImportanceMUST READ
- IssuedJul 31, 2026
- Amendmentsnone tracked
- Length80 points in 5 sections · 8 min read
The four dates on this rule
- PublishedJul 31, 2026The day RBI put this document out.
- Starts to applyNot statedNot stated separately in this document. Read the rule itself before you assume a start date.
- Time to get readyNot statedCannot be worked out until the day it starts to apply is known.
- Last date to actNot statedNo date to act by was found in this document. Other dates may sit inside single paragraphs.
Kept in your browser only. Your desk
Show me the points for
Nothing is removed from the page.
Show me the points about
79 of the 80 points name no product and bind every product. All products.
What it says
Chapter I. Preliminary
Background
1. Cyber rules for UCBs
This paper sets the cyber and technology risk rules for urban co-operative banks.
2. Start date
These Directions took effect at once.
3. Who is covered
These Directions apply to every urban co-operative bank.
4. Four levels of UCB
A UCB is placed in one of four levels by its digital depth and payment links.
5. Level one covers all
Level one controls apply to every urban co-operative bank, whatever it offers.
6. Level two is net banking
Level two covers a sub member of central payment systems that offers net or mobile banking.
7. Level three is direct
Level three covers a direct member of central payment systems or one with its own ATM switch.
8. Level four is the largest
Level four covers a bank with its own switch and SWIFT, or one hosting data for others.
Chapter II. Role of the Board
1. Board approves the policies
The Board must approve the plans and policies for technology and cyber security.
2. Two directors on the committee
A level four bank may set up an IT Strategy Committee of at least two directors.
Chapter III. Level
Must know
1. No admin rights
Staff must not hold admin rights on their own desktop or laptop.
2. No trivial passwords
The bank must have a password policy and must not use easy or guessable passwords.
3. Split the duties
The person who writes a program must not be the person who runs it.
4. Removable media is barred
As a rule, pen drives and like media are barred unless allowed for a set use.
5. Never open unknown mail
Staff must be taught never to open a file sent from a source they do not know.
6. Warn customers on passwords
The bank must teach customers never to share a password, a one time code or a PIN.
7. Six hours to report
A cyber incident must be reported on the DAKSH platform within six hours of detection.
Do it
8. Grade yourself first
The bank must work out for itself which level it falls in and follow those controls.
9. A separate cyber policy
The cyber security policy must be kept apart from the wider IT policy.
10. Rate each risk
The bank must rate every risk it finds as low, medium, high or very high.
11. Keep an asset register
The asset register must show the kit, where customer data sits, and how critical it is.
12. Store the keys safely
The bank must store encryption keys safely and control who may reach them.
13. Control what gets installed
The bank must control what software can be put on its systems and devices.
14. List the allowed software
The bank must keep one central list of software that is allowed and not allowed.
15. Turn off risky scripts
Browsers must auto update and scripts such as Java and ActiveX must be off when unused.
16. Keep internet apart
Internet use must sit on separate machines, away from the day to day banking systems.
17. Watch heat and water
The bank must watch for breaks in heat, water, smoke, power and access alarms.
18. Change default passwords
Default passwords on network devices and systems must be changed after they go in.
19. Secure the wireless
The bank must secure wireless networks, access points and client systems.
20. Turn remote desktop off
Remote desktop must stay off and open only with an approval, with logs watched.
21. Firewalls at highest setting
Firewalls must be set to the highest security level and checked from time to time.
22. Maker and checker
Sensitive or high value transactions must pass a maker and checker control.
23. Secure the mail system
The bank must guard its mail against spoofing, look alike names and bad files.
24. Bank name in the domain
The bank must use its own name in its email domain, with anti phishing controls.
25. Use DMARC on email
The bank must put DMARC in place on its email names to stop spoofing.
26. Scan media first
Removable media must be scanned for malware before read or write access is given.
27. Destroy media before disposal
Media holding sensitive data must be fully erased or destroyed before it is thrown out.
28. Keep backups offline
The bank must back up important data and keep a copy offline, off the machine.
29. Check the vendor first
Before hiring or renewing a vendor, the bank must test whether it can meet the contract.
30. Assess vendor risk
The bank must assess vendor risk and hold controls that match that risk.
31. Exit terms are needed
The agreement must carry exit terms so the bank is not locked in to one vendor.
32. Right to audit the vendor
The vendor agreement must give the bank a right to audit and RBI a right to inspect.
33. Who pays if it fails
The service agreement must state who answers for a failure of service.
34. Map the data flow
The bank must map how data moves between itself, its vendors and its customers.
35. Switch provider must comply
The ATM switch provider must meet the cyber controls the bank writes into the contract.
36. Watch for new patches
The bank must watch patch notices from makers and CERT-In and apply them fast.
37. Keep a network map
The bank must keep an up to date map of its wired and wireless networks.
38. Block strange devices
The bank must spot devices that are not allowed on the network and block them.
39. Write secure code
The bank must use secure coding when it builds software on its own or with others.
40. Close dormant accounts
The bank must limit failed sign in tries and switch off accounts nobody uses.
41. Stop data leaks
The bank must have a full plan to stop the loss or leak of sensitive data.
42. Card standards apply
The switch provider must meet the payment card industry data security standard.
43. Tell CERT-In as well
The bank must also tell CERT-In about a cyber incident without being asked.
Background
44. Encrypt data on the wire
Standard encryption and integrity checks are needed where sensitive data crosses a network.
45. Two factor for core banking
Signing in to core banking needs a second factor that changes each time.
46. Board briefed once a year
The bank may brief its Board members on IT and cyber risk at least once a year.
47. The bank stays answerable
The bank stays answerable for security risk in work it has given out.
48. Check vendor staff
Background checks and secrecy agreements are needed for all vendor staff.
49. Anti malware everywhere
Anti malware cover is needed on desktops, servers, gateways and message systems.
Chapter IV. Level II Baseline Cybersecurity and Resilience Requirements
Must know
1. Scan twice, test yearly
Critical and public facing applications need a scan every six months.
Do it
2. List every allowed device
The bank must keep one central list of the devices allowed on its network.
3. Layer the boundary
Boundary defence must be layered, with firewalls, proxies and intrusion systems.
4. Support IPv6 traffic
Public facing systems of the bank must be able to carry IPv6 traffic.
5. Set a security baseline
The bank must set and apply a base security setting for every kind of device.
6. Attack test once a year
An attack test must be run at least once a year.
7. Buy anti phishing help
The bank must buy a service that takes down fake sites and rogue apps.
Chapter V. Level III Baseline Cybersecurity and Resilience Requirements
1. Whitelist internet sites
The bank must whitelist the internet sites and systems that staff may reach.
2. Yearly quiz for managers
New recruits must be trained and every manager must take a yearly test.
3. Watch risky transactions
The bank must watch transactions on a risk basis across every channel it runs.
Chapter VI. Level IV Baseline Cybersecurity and Resilience Requirements
Must know
1. Quarterly review to the Board
The security officer must put a cyber readiness review to the Board every three months.
2. Keep the two apart
The security officer must not report to the head of IT and gets no business target.
3. Security committee each quarter
The information security committee must meet at least once every three months.
Do it
4. What the centre must do
The centre must watch, study and escalate incidents and work with outside agencies.
5. Measure with real numbers
The bank must build measures such as patch delay, malware cover and training reach.
6. Keep forensics on standby
The bank must keep network forensic and denial of service help on standby.
7. Two must know technology
At least two members must be technically able and one must have real IT skill.
Background
8. Security officer reports up
The security officer reports to the top risk executive or to the chief executive.
Chapter VII. Repeal and Other Provisions
1. Old cyber rules go
These Directions repeal the earlier cyber framework and IT governance instructions.
2. Other laws still apply
These Directions add to other laws and rules and do not replace them.
BankPulse example. A bank follows these Directions and thinks the matter is closed. It is not. Any other laws, rules, regulations or directions in force still apply on top. Where another one asks for more, the bank does the more.
3. RBI has the last word
RBI may issue clarifications, and its reading of these Directions is final.
BankPulse example. Two banks read the same clause differently. Neither reading settles it. RBI may issue clarifications, and its interpretation of any provision is final and binding on all concerned entities.
The same subject for other kinds of institution
The same subject for other kinds of institution.
Other RBI rules for urban co-operative banks
RBI capital adequacy rules for urban co-operative banks 2025
RBI compliance officer and compliance function rules for urban co-operative banks
RBI concurrent audit rules for urban co-operative banks 2026
RBI credit bureau reporting rules for urban co-operative banks 2025
RBI credit card and debit card rules for urban co-operative banks 2025
RBI customer service and fair conduct rules for urban co-operative banks 2025
RBI deposit interest rate rules for urban co-operative banks 2025
Every rule page on BankPulse · Questions bankers ask, answered