Choose Language
Google Translate
Skip to content
Facebook X-twitter Instagram Linkedin Youtube
  • sales@cybernx.com
  • +91 90823 52813
CyberNX Logo
  • Home
  • About
    • About Us
    • CERT-In Empanelled Cybersecurity Auditor
    • Awards & Recognition
    • Our Customers
  • Services

    Peregrine

    • Managed Detection & Response
    • AI Managed SOC Services
    • Elastic Stack Consulting
    • CrowdStrike Consulting 
    • Threat Hunting Services
    • Digital Risk Protection Services
    • Threat Intelligence Services
    • Digital Forensics Services
    • Brand Risk & Dark Web Monitoring
    • Full Stack Observability

    Pinpoint

    • Red Teaming Services
    • Vulnerability Assessment
    • Penetration Testing Services
    • Secure Code Review Services
    • Cloud Security Assessment
    • Phishing Simulation Services
    • Breach and Attack Simulation Services

    nCompass

    • Cybersecurity Audit Services
    • Virtual CISO Services
    • DPDP Act Consulting
    • ISO 27001 Consulting
    • RBI Master Direction Compliance
    • SEBI CSCRF Framework Consulting
    • SEBI Cloud Framework Consulting
    • Security Awareness Training
    • Cybersecurity Staffing Services

    NXRadar

    • SBOM Solutions
    • CBOM Solutions
    • AIBOM Solutions
  • Industries
    • Banking
    • Financial Services
    • Insurance
  • Resources
    Blogs
    Case Studies
    Downloads
    Whitepapers
    Buyer’s Guide
    Research & Guides
  • Careers
  • English
    • English (US)
Contact Us
CyberNX Logo
  • English
    • English (US)
  • Home
  • About
    • About Us
    • CERT-In Empanelled Cybersecurity Auditor
    • Awards & Recognition
    • Our Customers
  • Services

    Peregrine

    • Managed Detection & Response
    • AI Managed SOC Services
    • Elastic Stack Consulting
    • CrowdStrike Consulting
    • Threat Hunting Services
    • Digital Risk Protection Services
    • Threat Intelligence Services
    • Digital Forensics Services
    • Brand Risk & Dark Web Monitoring
    • Full Stack Observability

    Pinpoint

    • Red Teaming Services
    • Vulnerability Assessment
    • Penetration Testing Services 
    • Secure Code Review Services
    • Cloud Security Assessment
    • Phishing Simulation Services
    • Breach and Attack Simulation Services

    nCompass

    • Cybersecurity Audit Services
    • Virtual CISO Services
    • DPDP Act Consulting
    • ISO 27001 Consulting
    • RBI Master Direction Compliance
    • SEBI CSCRF Framework Consulting
    • SEBI Cloud Framework Consulting
    • Security Awareness Training
    • Cybersecurity Staffing Services

    NXRadar

    • SBOM Solutions
    • CBOM Solutions
    • AIBOM Solutions
  • Industries
    • Banking
    • Financial Services
    • Insurance
  • Resources
    Blogs
    Case Studies
    Downloads
    Whitepapers
    Buyer’s Guide
    Research & Guides
  • Careers
  • Contact

Cyber Crisis Management Plan for NBFCs under RBI Supervision: What Changed in 2026

5 min read
20 Views
  • RBI Master Directions

It’s a rare instance to see cyber incidents at an NBFC go wrong at the point of attack. They usually go wrong in the hours that follow – disbursals are down, customers are calling and the team is still deciding whether to pause a service, and often nobody is sure who is allowed to make that call.

The problem is more structural than technical. Much of what NBFCs work from, was inherited from rules shared with banks, sized for a different kind of business, then filed away and never tested. A plan that has never been rehearsed is not the most reliable plan, especially during a cyber incident.

That is now changing. On Jul 31, 2026, the Reserve Bank of India (RBI) issued a cybersecurity framework built only for NBFCs. It states clearly what a cyber crisis management plan for NBFCs under RBI supervision must cover, who owns it and how quickly an incident must reach the regulator.

This post breaks down the four parts every plan needs, what the six-hour reporting clock changes in practice, and where these plans usually lose their value.

Table of Contents

What is a cyber crisis management plan?

A Cyber Crisis Management Plan (CCMP) is a board-approved document. It sets out what your organisation does when a cyber incident stops being a technical problem and starts being a business one.

It is not an incident response runbook. A runbook tells an analyst how to isolate a host. A CCMP tells the business who declares a crisis, who talks to customers, who talks to the regulator and what “recovered” means. RBI treats it as a governance artefact, not an IT document. That distinction puts the plan on the board’s agenda.

What changed for NBFCs on Jul 31, 2026

RBI issued the Reserve Bank of India (Non-Banking Financial Companies – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, effective immediately. The earlier IT Framework and IT Governance instructions for NBFCs stand repealed.

Few things stand out for crisis planning:

  • Obligations now follow your layer: requirements are split by Base Layer below ₹500 crore, Base Layer at ₹500 crore and above, and Middle Layer and above, excluding Core Investment Companies
  • The CCMP is named directly: Base Layer NBFCs at ₹500 crore and above must maintain a CCMP as part of board-approved strategy, and Middle Layer and above must maintain both a cybersecurity policy and a CCMP
  • The board owns it: strategies and policies covering incident response, recovery and cyber crisis management must go to the board for review at least annually
  • Reporting moved to DAKSH: cyber incidents go to RBI on the DAKSH supervisory platform within six hours of detection

Housing finance companies continue to report incidents to the National Housing Bank (NHB) rather than RBI.

The four aspects RBI specifies for the CCMP

RBI defines the crisis resilience lifecycle in four parts. Each one needs a named owner and a tested process, not a paragraph of intent.

4 Pillars of an NBFC Cyber Crisis Management Plan

1. Detection

Everything downstream depends on how fast something gets noticed. Coverage should extend across lending platforms, customer portals, collections systems and third-party integrations. Audit trails and log monitoring are explicit requirements, and they are what makes the six-hour clock survivable.

2. Response

This is where decision rights live. Define who can declare a crisis, who authorises service suspension and who approves customer communication. The plan should also carry pre-drafted escalation paths to senior management and the board.

3. Containment

Containment limits the blast radius while the investigation continues: network segmentation, credential resets, disabling compromised integrations and pausing affected products. Preserving forensic evidence while containing damage is a real tension, so the plan should say which takes priority and who decides.

4. Recovery

Recovery is measured, not declared. Define Recovery Time Objective (RTO) and Recovery Point Objective (RPO) for every critical system, run disaster recovery drills at least half-yearly and confirm that restored backups actually work.

Why the six-hour clock reshapes the plan

The six hours window is triggered by detection, not diagnosis, so the report goes in before anyone knows the root cause. That changes how the plan is written:

  • Two clocks run at once: RBI expects reporting on DAKSH within six hours, and the CERT-In Directions of Apr 28, 2022 require notification to the Indian Computer Emergency Response Team (CERT-In) on a parallel six-hour timeline
  • Access must be pre-arranged: portal registration, credentials and named filers should be sorted long before an incident, with at least one backup
  • Templates beat drafting: keep organisation details pre-filled so the team only completes incident-specific fields, and file what is known rather than waiting for a complete picture

Where NBFC crisis plans lose their value

A CCMP that exists on paper and one that works under pressure are different documents. The common failure points are usually structural:

  • Untested plans: RBI expects periodic drills, including crisis communication testing with vendors and service providers, not just internal tabletop sessions
  • Vendors outside the plan: if a managed service provider or a lending-as-a-service partner is part of the failure, the crisis plan needs to reach them
  • Unclear reporting lines: the Chief Information Security Officer (CISO) cannot report to the head of IT and must place a cybersecurity review before the board or its risk committee quarterly
  • No lessons-learnt loop: findings from drills and past incidents should update the plan, and the board should see that update
  • Stale annexures: contact lists, escalation matrices and vendor details age fast, and they fail first at 2 AM

Conclusion

The 2026 Directions moved crisis management from a documentation exercise to a governance one. Detection, response, containment and recovery each need an owner. The six-hour window needs rehearsal. And the board needs a plan it has actually reviewed.

At CyberNX we help NBFCs and HFCs build a cyber crisis management plan that stands strong in an audit as well as in a real incident. Our RBI Master Direction Compliance service maps your controls to the applicable chapter, closes the gaps and keeps the plan current as your infrastructure and risk profile change. Talk to our experts and find out where your crisis plan stands today.

Cyber crisis management plan for NBFCs under RBI supervision FAQs

What is a cyber crisis management plan for an NBFC?

It is a board-approved plan that defines how an NBFC detects, responds to, contains and recovers from a cyber incident. It covers decision rights, escalation paths, customer communication and regulatory reporting. RBI treats it as part of board-approved strategy, not an IT-owned document.

Which NBFCs need a CCMP under the 2026 Directions?

Base Layer NBFCs with asset size of ₹500 crore and above must put a CCMP in place. Middle Layer, Upper Layer and Top Layer NBFCs, excluding Core Investment Companies, must maintain a cybersecurity policy and a CCMP. Smaller Base Layer entities and Core Investment Companies follow a lighter baseline.

How soon must an NBFC report a cyber incident to RBI?

Within six hours of detection, filed on the DAKSH supervisory platform. CERT-In must be notified in parallel under its 2022 Directions, and housing finance companies report to NHB instead of RBI. The clock starts at detection, so partial reporting followed by updates is the workable approach.

How often should a cyber crisis management plan be tested?

Testing frequency depends on the applicable RBI chapter. For Chapter IV NBFCs, test it at least annually, and sooner if systems or vendors change materially. Disaster recovery drills for critical systems are expected at least half-yearly, and crisis communication drills should include service providers. Every drill should feed updates back into the plan.

Gopakumar Panicker

Author
Gopakumar Panicker
LinkedIn

An accomplished security professional with extensive experience in Digital Security, Cloud Security, Cloud Architecture, Security Operations, and BFSI Compliance, Gopa has contributed to designing and strengthening enterprise-grade security environments, ensuring alignment with both technical and regulatory requirements. His work focuses on building resilient, scalable architectures and guiding organisations in elevating their operational maturity while meeting the stringent expectations of modern BFSI and cloud-driven ecosystems.

Share on

WhatsApp
LinkedIn
Facebook
X
Pinterest

For Customized Plans Tailored to Your Needs, Get in Touch Today!

Connect with us

RESOURCES

Related Blogs

Explore our resources section for insightful blogs, articles, infographics and case studies, covering everything in Cyber Security.
Business Continuity and Disaster Recovery Planning for NBFCs in 2026

Business Continuity and Disaster Recovery Planning for NBFCs: What RBI Now Expects

Every car usually has a spare tire in the boot but almost nobody has ever fitted one. It sits there

How to Conduct an IS Audit That Meets RBI's Requirements

How to Conduct an IS Audit as per RBI’s Requirements

There are two very different ways organisations approach an IS audit. In the first, a team turns up, runs some

RBI Guidelines on Logging and Monitoring for Indian NBFCs

RBI Guidelines on Logging and Monitoring: What NBFCs Must Implement

Every NBFC generates a ton of logs. The servers’ logs. The firewall logs. The lending platform logs, because the vendor

RESOURCES

Cyber Security Knowledge Hub

Explore our resources section for insightful blogs, articles, infographics and case studies, covering everything in Cyber Security.

BLOGS

Stay informed with the latest cybersecurity trends, insights, and expert tips to keep your organization protected.

CASE STUDIES

Explore real-world examples of how CyberNX has successfully defended businesses and delivered measurable security improvements.

DOWNLOADS

Learn about our wide range of cybersecurity solutions designed to safeguard your business against evolving threats.
CyberNX Footer Logo
Book a Free Call

Peregrine

  • Managed Detection & Response
  • AI Managed SOC Services
  • Elastic Stack Consulting
  • CrowdStrike Consulting
  • Threat Hunting Services
  • Digital Risk Protection Services
  • Threat Intelligence Services
  • Digital Forensics Services
  • Brand Risk & Dark Web Monitoring
  • Full Stack Observability

Pinpoint

  • Red Teaming Services
  • Vulnerability Assessment
  • Penetration Testing Services
  • Secure Code Review Services
  • Cloud Security Assessment
  • Phishing Simulation Services
  • Breach and Attack Simulation Services

nCompass

  • Cybersecurity Audit Services
  • Virtual CISO Services
  • DPDP Act Consulting
  • ISO 27001 Consulting
  • RBI Master Direction Compliance
  • SEBI CSCRF Framework Consulting
  • SEBI Cloud Framework Consulting
  • Security Awareness Training
  • Cybersecurity Staffing Services

NXRadar

  • SBOM Solutions
  • CBOM Solutions
  • AIBOM Solutions
  • About
  • CERT-In
  • Awards
  • Careers
  • Sitemap
Facebook Twitter Instagram Youtube

Copyright © 2026 CyberNX | All Rights Reserved | Terms and Conditions | Privacy Policy

  • English
    • English (US)
Copyright © 2026 CyberNX | All Rights Reserved | Terms and Conditions | Privacy Policy
Scroll to Top

WhatsApp us

Not Sure Where to Start with Cybersecurity?

We value your privacy. Your personal information is collected and used only for legitimate business purposes in accordance with our Privacy Policy.