Indian banking: measuring inward, monitoring outward, reporting upward
How four major Indian commercial banks run Security Posture Management across their own estate and Third-Party Risk Management across their suppliers — and why the peer benchmark became the most-used exhibit in their board packs.
UPDATED 10 AUGUST 2026 · REVIEWED BY NIMITT JHAVERI
The outcome
Why this study is anonymised
The banks described here are large and systemically significant. Their security programmes are, by policy, not publicly discussed — which is itself a reasonable control. This study therefore runs anonymised: the practices, the sequence and the outcomes are as observed across the cohort, with no institution identified and no institution-specific figure disclosed.
The starting point
A large Indian bank does not lack security data. It runs a Cyber Security Operations Centre, a vulnerability management programme, half-yearly assessments, annual penetration tests, an Information Systems Audit function and a vendor onboarding process with a questionnaire attached to it. The problem was never volume of data. It was that none of it was independent, continuous and comparable at the same time.
Three gaps recurred across the cohort.
- The estate was larger than the inventory. Regional offices, acquired entities, campaign microsites, sponsored bank subsidiaries, digital-lending partner integrations and legacy domains left behind after a migration. The internet-facing footprint genuinely attributable to the group was consistently wider than the asset register described — and the worst findings lived in the delta, because nobody patches an asset nobody has recorded.
- Third-party assurance was an artefact, not a signal. Payment processors, core banking vendors, cloud hosts, business correspondents, collection agencies, KYC providers, card personalisation bureaux, ATM managed-service operators. A bank of this size contracts with hundreds to thousands of suppliers, and the ones that mattered were assured by a questionnaire the vendor completed once, filed, and rarely re-read. A vendor's posture can collapse in a fortnight. Nothing in the process would have detected it.
- The board pack asserted rather than evidenced. “No material incidents this quarter” is a statement by the party being overseen, about itself. It is necessary and entirely insufficient — and after 31 July 2026, visibly so.
What changed for banks specifically
On 31 July 2026 the Reserve Bank of India issued the Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 (RBI/DoS/2026-27/410), in force immediately. It is one of seven instruments issued that day, one per entity class, which between them replaced a scattered body of circulars across the RBI's regulated universe — which one applies to whom covers the full set.
For directors the significant change is that obligations are now specified rather than implied: annual board approval of the IT, cybersecurity and business continuity strategies; an IT Strategy Committee of at least three directors chaired by an independent director with substantial IT expertise; a senior CISO reporting into the executive overseeing risk; a cybersecurity policy held separately from the IT policy; and an IS Audit function under Audit Committee oversight.
Alongside it sit the obligations that do not go away: SEBI's CSCRF with its prescribed reporting formats for group entities in the securities market, CERT-In's six-hour incident reporting, the RBI's own six-hour clock on DAKSH, and DPDP obligations phasing to 13 May 2027.
The operative sentence for a board pack is unchanged in kind but sharper in degree: periodic review implies something to review. A measurement that does not move between meetings cannot be interrogated at one.
SPM: the estate, measured every day
Security Posture Management was pointed inward first, at the bank's own external estate.
- Attribution before measurement. Onboarding resolved the group's real external footprint across parent, subsidiaries, sponsored entities and acquired brands — an exercise that in Indian banking structures is non-trivial, and one that routinely surfaces live assets absent from the asset register entirely.
- A daily 250–900 rating with twelve months of history, so the trend is visible rather than inferred and a quarter-on-quarter movement can be explained rather than estimated.
- Findings mapped to frameworks automatically — NIST CSF 2.0, ISO 27001, and RBI and SEBI expectations — which removes the manual crosswalk that otherwise consumes the fortnight before an audit.
- The score-response forecast to size the rating impact of a proposed fix before the quarter's remediation capacity is committed, and Dynamic Remediation to claim the credit once the work is done — requesting an immediate rescan rather than waiting for the ordinary observation schedule. Findings differ by an order of magnitude in how much they move the score; treating them as equivalent wastes the scarcest resource in the bank.
- Subsidiary management, where the group runs insurance, asset management, securities and NBFC entities under one holding structure and the board wants one consolidated view plus the ability to drill into an underperforming entity.
TPRM: the ecosystem, monitored without asking
Third-Party Risk Management was pointed outward, at a supplier base that in banking is both very large and very concentrated. Across the cohort, 300+ third parties are under continuous, evidence-based monitoring — the tiered critical and important suppliers, rather than every contracted counterparty.
- Continuous monitoring across a universe of 40 million+ rated companies, so the great majority of an existing vendor portfolio is already rated on day one — no onboarding wait, no vendor cooperation required, no contractual amendment needed.
- Tiering with a floor. Critical vendors — those holding regulated customer data, or whose outage stops a payment rail — carry a contractual minimum rating, a named internal owner and an escalation path measured in days. Important and standard tiers carry lighter, pre-agreed responses. The thresholds matter less than the fact that each tier has a different pre-agreed response.
- Alerting on movement, not absolutes. A supplier sliding forty points in a month is telling the bank something a static rating never will.
- Fourth-party concentration. When a single cloud region, payment switch or managed-service operator sits behind thirty suppliers, an incident there is a correlated failure across the portfolio rather than an isolated vendor problem. Several institutions found their genuine single point of failure was a company they had never contracted with.
- Dark and deep web intelligence across 1,000+ underground forums for credentials and data associated with suppliers — the earliest external signal available for a class of compromise that otherwise surfaces at the breach notification.
- Questionnaires kept only where contractually required, and then AI-assisted, with pre-filled vendor profiles and automated response analysis rather than a manual chase.
The highlight: peer benchmarking as board and regulatory evidence
This is the exhibit that changed the meeting.
A rating on its own answers where are we. It is useful, and it is not yet a governance instrument, because a director has no way to calibrate it. A number in isolation means nothing to an audit committee. The same number set against an Indian BFSI peer distribution, with the bank's twelve-month trajectory drawn against the peer average, is a governance instrument — it answers the question a director actually asks, which is not “what is our score” but “compared to whom, and are we falling behind?”
Across the cohort the peer benchmarking report is now used in four places.
- The quarterly board and Risk Committee pack. One page: current rating, twelve-month trend line, peer distribution for Indian banking, and the delta. It is read by directors without translation, and it prompts the follow-up question — why did we move — which is precisely the question a board should be asking and previously had no hook for.
- The IT Strategy Committee. The composition test in the 2026 Directions puts genuinely IT-experienced independent directors in the chair. Those directors interrogate a trended, benchmarked measurement in a way they cannot interrogate a status narrative. The benchmark is what makes the discussion technical without making it unreadable.
- Supervisory and audit interaction. When the question is “evidence your continuous oversight”, the answer is a dated, externally calculated, independently produced series that the bank did not generate about itself and could not have backdated. That is a materially different artefact from a management assertion or an annual point-in-time assessment.
- Setting the vendor floor. The same peer distribution establishes what a defensible minimum rating for a critical banking vendor actually is. A floor argued from sector data survives a procurement escalation; a floor picked by the security team does not.
The consistent internal observation from CISOs in the cohort: benchmarking moved the board conversation from justifying the security budget to deciding where the gap to peers is unacceptable. Those are different conversations, and only one of them ends in a decision.
Why the result holds up
Not because the number is high, but because of where it comes from. The rating is calculated independently of the institution being assessed, from external, attacker-visible signals whose reporting the institution does not control. That is the property that lets a supervisor, an auditor, a cyber insurer or a correspondent bank treat it as evidence rather than as a claim — and it is the same property that makes it usable on the vendor side, where a tier assigned from a continuously observed rating is a measurement of a supplier rather than an assertion about one.
One boundary is worth stating plainly, because BitScore states it to every banking client: a rating is not compliance. It does not satisfy the 2026 Directions, CSCRF, the CERT-In Directions or DPDP, and it says nothing about internal controls, incident response capability or consent architecture. It evidences external hygiene, supports third-party due diligence, and converts an assertion into a measured position a director can interrogate. Presented as regulatory cover, it would be a serious misreading of both the regulation and the rating.
What BitScore adds
Bitsight Technologies provides the global rating platform. BitScore Cybertech LLP provides the India delivery layer that determines whether it is actually used: asset attribution across Indian group and subsidiary structures, INR contracting, onboarding into an existing GRC and vendor-management process, framework mapping to the instruments a bank is actually examined against, and the ongoing work of getting an alert to an owner who acts on it. Most programmes stall on adoption rather than licensing — which is the part a reseller relationship alone does not solve.
This study is anonymised at the clients' request. Practices and outcomes are as observed across the cohort; no institution is identified and no institution-specific figure is disclosed. Regulatory positions are summarised as at August 2026 from public sources and are general information, not legal advice — confirm applicability and current status with your own counsel and compliance function. Bitsight ratings are calculated by Bitsight Technologies, Inc. from external, attacker-visible signals and change over time. BitScore Cybertech LLP is an authorised Bitsight partner.
See where you actually stand.
The complimentary Cyber Risk Rating Report gives you the same baseline this programme started from — your rating, your peer benchmark against Indian BFSI, and the findings that move it. No agent, no system access, no questionnaire.