Choose Language
Google Translate
Skip to content
Facebook X-twitter Instagram Linkedin Youtube
  • sales@cybernx.com
  • +91 90823 52813
CyberNX Logo
  • Home
  • About
    • About Us
    • CERT-In Empanelled Cybersecurity Auditor
    • Awards & Recognition
    • Our Customers
  • Services

    Peregrine

    • Managed Detection & Response
    • AI Managed SOC Services
    • Elastic Stack Consulting
    • CrowdStrike Consulting 
    • Threat Hunting Services
    • Digital Risk Protection Services
    • Threat Intelligence Services
    • Digital Forensics Services
    • Brand Risk & Dark Web Monitoring
    • Full Stack Observability

    Pinpoint

    • Red Teaming Services
    • Vulnerability Assessment
    • Penetration Testing Services
    • Secure Code Review Services
    • Cloud Security Assessment
    • Phishing Simulation Services
    • Breach and Attack Simulation Services

    nCompass

    • Cybersecurity Audit Services
    • Virtual CISO Services
    • DPDP Act Consulting
    • ISO 27001 Consulting
    • RBI Master Direction Compliance
    • SEBI CSCRF Framework Consulting
    • SEBI Cloud Framework Consulting
    • Security Awareness Training
    • Cybersecurity Staffing Services

    NXRadar

    • SBOM Solutions
    • CBOM Solutions
    • AIBOM Solutions
  • Industries
    • Banking
    • Financial Services
    • Insurance
  • Resources
    Blogs
    Case Studies
    Downloads
    Whitepapers
    Buyer’s Guide
    Research & Guides
  • Careers
  • English (US)
    • English
Contact Us
CyberNX Logo
  • English (US)
    • English
  • Home
  • About
    • About Us
    • CERT-In Empanelled Cybersecurity Auditor
    • Awards & Recognition
    • Our Customers
  • Services

    Peregrine

    • Managed Detection & Response
    • AI Managed SOC Services
    • Elastic Stack Consulting
    • CrowdStrike Consulting
    • Threat Hunting Services
    • Digital Risk Protection Services
    • Threat Intelligence Services
    • Digital Forensics Services
    • Brand Risk & Dark Web Monitoring
    • Full Stack Observability

    Pinpoint

    • Red Teaming Services
    • Vulnerability Assessment
    • Penetration Testing Services 
    • Secure Code Review Services
    • Cloud Security Assessment
    • Phishing Simulation Services
    • Breach and Attack Simulation Services

    nCompass

    • Cybersecurity Audit Services
    • Virtual CISO Services
    • DPDP Act Consulting
    • ISO 27001 Consulting
    • RBI Master Direction Compliance
    • SEBI CSCRF Framework Consulting
    • SEBI Cloud Framework Consulting
    • Security Awareness Training
    • Cybersecurity Staffing Services

    NXRadar

    • SBOM Solutions
    • CBOM Solutions
    • AIBOM Solutions
  • Industries
    • Banking
    • Financial Services
    • Insurance
  • Resources
    Blogs
    Case Studies
    Downloads
    Whitepapers
    Buyer’s Guide
    Research & Guides
  • Careers
  • Contact

Business Continuity and Disaster Recovery Planning for NBFCs: What RBI Now Expects

5 min read
2 Views
  • RBI Master Directions

Every car usually has a spare tire in the boot but almost nobody has ever fitted one. It sits there for years. Right size, right car, technically ready. But then one night on the highway you find out the air has gone, the jack is somewhere else, or the person meant to change it has never done it before.

Continuity plans are the same way – the backup site exists, the policy is signed. Even the recovery steps are written down in order. The one thing that has never happened is the thing that counts, which is running the actual business on the spare while customers are watching.

The Reserve Bank of India (RBI) has now closed that gap for NBFCs. Recovery is no longer something a lender writes down. It is something they have to show: on the alternate site, through a normal working day, with the results going to the board.

This blog covers what business continuity and disaster recovery planning for NBFCs now involves, how the obligations change by layer, and the few clauses that do most of the work.

Table of Contents

What continuity planning and recovery planning each cover

The two terms get used together so often that the difference gets lost. They answer different questions.

  • Business Continuity Plan (BCP): how the business keeps serving customers during a disruption, covering people, processes, premises and systems
  • Disaster Recovery (DR): how the technology comes back, from which site, how quickly and with how much data intact

DR is a part of BCP. An NBFC can restore its Loan Management System in two hours and still fail its customers if collections staff have nowhere to sit and no approved process to follow.

How the rules change by NBFC layer

RBI issued the Reserve Bank of India (Non-Banking Financial Companies – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 on Jul 31, 2026. Obligations are graded by Scale Based Regulation layer, so two NBFCs can both be compliant while doing very different things.

  • Base Layer below ₹500 crore, and Core Investment Companies: a board-approved BCP policy, board reporting at least once a year and data backup with periodic testing
  • Base Layer at ₹500 crore and above: a full BCP built on Business Impact Analysis, a recovery strategy, backup sites for critical systems, annual testing under worst-case scenarios and results placed before the Chief Information Officer (CIO) and the board
  • Middle Layer and above, excluding Core Investment Companies: the full regime, including half-yearly DR drills, defined recovery targets and vendor resilience testing

6 things a DR drill must actually prove

For Middle Layer NBFCs and above, the drill is where the plan earns its keep. RBI is specific about what a drill has to show.

6 Things a DR Drill Must Prove

1. A real switchover

Testing has to involve actually moving to the DR site and using it as the primary site. A read-only check or a replication report is not a switchover.

2. A full working day

The alternate site must carry usual business operations for a sufficiently long period, covering at least a full working day from Beginning of Day to End of Day. A short window outside business hours does not meet this.

3. Gaps closed before the next cycle

Any major issue found during a drill has to be resolved and tested again before the next drill. Logging a gap and carrying it forward is not enough.

4. Backups that restore

Backed-up data must be periodically restored to check that it is usable. Integrity has to be preserved and the backup itself protected from unauthorised access.

5. Matching configuration

System configurations and deployed security patches at the primary data centre and the DR site must be identical. Configuration drift is the most common reason a technically available DR site fails when it is needed.

6. Vendors inside the test

Continuity and recovery capability has to extend to critical interconnected systems and networks, including those of vendors and partners, with coordinated testing that meets the NBFC’s recovery target.

RTO, RPO and the clause most plans skip

Two numbers anchor the whole exercise. Both need business sign-off, not just an IT estimate.

  • Recovery Time Objective (RTO): how long a system can stay down before the business is harmed. For critical systems, RBI expects this to be minimal and approved by the IT Strategy Committee
  • Recovery Point Objective (RPO): how much data the business can afford to lose. For critical systems, the expectation is near zero

Then comes the clause that rarely makes it into a plan. Where RPO is not zero, the NBFC needs a documented method for reconciling data when operations resume from the alternate site. Some data will be missing. Somebody has to know exactly how it gets rebuilt, who approves the rebuild and how the customer record is corrected.

Recovery targets also have to be defined as measurable metrics for every critical system, alongside metrics for system performance and business resumption. Without those numbers, a drill has no pass mark and the report has nothing to compare against.

Where continuity plans fall short in practice

The gaps are not always technical. They sometimes sit in governance and in the parts of the business that are not IT.

  • Paper-only testing: tabletop reviews are useful, but they do not satisfy a requirement written around actual switchover
  • Sites too close together: primary and DR sites must be geographically separated enough that one threat cannot affect both
  • BCP treated as an IT document: continuity covers people, processes and premises, and the CIO is accountable for keeping it current
  • Outsourcing assumed to transfer risk: continuity preparedness cannot be weakened by outsourcing, and NBFCs are expected to seek active assurance that providers stay ready
  • No audit loop: the Information Systems audit is required to evaluate whether BCP and DR are effective, not just whether documents exist

Conclusion

The direction of travel is clear. A plan on a shared drive counts for very little. What counts is a tested switchover, recovery targets the business has signed off on, gaps that were closed rather than noted and evidence the board has seen.

At CyberNX, we help NBFCs and housing finance companies design and test business continuity and disaster recovery planning for NBFCs that can handle both an inspection and a real outage. Our work spans recovery target definition, DR architecture, drill execution and audit-ready reporting. Talk to our experts to know more about our RBI Master Direction Compliance services.

Business continuity and disaster recovery planning for NBFCs FAQs

What is business continuity and disaster recovery planning for an NBFC?

RBI’s BCP and DR requirements depend on the NBFC’s applicable regulatory layer. Chapter III requires a Board-approved BCP with periodic Board oversight and backup testing. Chapter IV requires a Board-approved BCP with BIA, recovery strategy and at least annual testing, while Chapter V imposes more detailed DR requirements, including half-yearly drills for critical information systems, defined RTO/RPO and actual switchover testing.

How often must an NBFC conduct DR drills

For Middle Layer NBFCs and above, DR drills for critical information systems are required at least half-yearly. Other systems follow a risk-based schedule. Base Layer NBFCs at ₹500 crore and above must test the BCP at least annually and whenever significant IT or business changes occur.

What is the difference between RTO and RPO?

RTO is time and RPO is data. RTO is how long a system can be down before the business suffers. RPO is how far back the recovery point sits, meaning how much recent data is lost. RBI expects minimal RTO and near-zero RPO for critical systems, with a documented reconciliation method if RPO is not zero.

Does a tabletop exercise count as a DR drill

No. RBI’s requirement is written around actual switchover to the alternate site, with the site carrying normal business operations for at least a full working day. Tabletop exercises are valuable for testing decisions and communication, but they sit alongside a live drill rather than replacing it.

Gopakumar Panicker

Author
Gopakumar Panicker
LinkedIn

An accomplished security professional with extensive experience in Digital Security, Cloud Security, Cloud Architecture, Security Operations, and BFSI Compliance, Gopa has contributed to designing and strengthening enterprise-grade security environments, ensuring alignment with both technical and regulatory requirements. His work focuses on building resilient, scalable architectures and guiding organisations in elevating their operational maturity while meeting the stringent expectations of modern BFSI and cloud-driven ecosystems.

Share on

WhatsApp
LinkedIn
Facebook
X
Pinterest

For Customized Plans Tailored to Your Needs, Get in Touch Today!

Connect with us

RESOURCES

Related Blogs

Explore our resources section for insightful blogs, articles, infographics and case studies, covering everything in Cyber Security.
How to Conduct an IS Audit That Meets RBI's Requirements

How to Conduct an IS Audit as per RBI’s Requirements

There are two very different ways organisations approach an IS audit. In the first, a team turns up, runs some

RBI Guidelines on Logging and Monitoring for Indian NBFCs

RBI Guidelines on Logging and Monitoring: What NBFCs Must Implement

Every NBFC generates a ton of logs. The servers’ logs. The firewall logs. The lending platform logs, because the vendor

Building an Information Security Program That Meets RBI Standards

How to Create an Information Security Program That Meets RBI Standards

If you ask five people in a bank to describe their information security program, you will probably get five different

RESOURCES

Cyber Security Knowledge Hub

Explore our resources section for insightful blogs, articles, infographics and case studies, covering everything in Cyber Security.

BLOGS

Stay informed with the latest cybersecurity trends, insights, and expert tips to keep your organization protected.

CASE STUDIES

Explore real-world examples of how CyberNX has successfully defended businesses and delivered measurable security improvements.

DOWNLOADS

Learn about our wide range of cybersecurity solutions designed to safeguard your business against evolving threats.
CyberNX Footer Logo
Book a Free Call

Peregrine

  • Managed Detection & Response
  • AI Managed SOC Services
  • Elastic Stack Consulting
  • CrowdStrike Consulting
  • Threat Hunting Services
  • Digital Risk Protection Services
  • Threat Intelligence Services
  • Digital Forensics Services
  • Brand Risk & Dark Web Monitoring
  • Full Stack Observability

Pinpoint

  • Red Teaming Services
  • Vulnerability Assessment
  • Penetration Testing Services
  • Secure Code Review Services
  • Cloud Security Assessment
  • Phishing Simulation Services
  • Breach and Attack Simulation Services

nCompass

  • Cybersecurity Audit Services
  • Virtual CISO Services
  • DPDP Act Consulting
  • ISO 27001 Consulting
  • RBI Master Direction Compliance
  • SEBI CSCRF Framework Consulting
  • SEBI Cloud Framework Consulting
  • Security Awareness Training
  • Cybersecurity Staffing Services

NXRadar

  • SBOM Solutions
  • CBOM Solutions
  • AIBOM Solutions
  • About
  • CERT-In
  • Awards
  • Careers
  • Sitemap
Facebook Twitter Instagram Youtube

Copyright © 2026 CyberNX | All Rights Reserved | Terms and Conditions | Privacy Policy

  • English (US)
    • English
Copyright © 2026 CyberNX | All Rights Reserved | Terms and Conditions | Privacy Policy
Scroll to Top

WhatsApp us

Not Sure Where to Start with Cybersecurity?

We value your privacy. Your personal information is collected and used only for legitimate business purposes in accordance with our Privacy Policy.