RESOURCESCYBER RISK, EXPLAINED
Straight answers on cyber risk measurement.
How security ratings are calculated, how the platforms differ, what regulators now expect boards to evidence, and what actually moves a score. Written for CISOs, heads of third-party risk, and the directors who have to sign off on all of it.
◆ BITSIGHT, INDEPENDENTLY ASSESSED
- 2026 Forrester Wave™ LeaderCybersecurity Risk Ratings Platforms, Q2 2026Read the report
- 2026 GigaOm Radar LeaderThird-Party Risk ManagementRead the report
- 2026 Gartner® Magic Quadrant™ VisionaryCyber Threat Intelligence TechnologiesRead the report
01FUNDAMENTALS
Start here if security ratings are new. What the number is, how it is calculated, and what counts as good.
- FundamentalsWhat is a cyber security rating?What a rating is, the four families of signal it is built from, and the genuine limits of a number produced without your participation.8 min read →
- FundamentalsWhat is a good Bitsight score?The bands, the peer percentile that matters more than the absolute number, and what "good" means to an insurer, a customer and a board.8 min read →
- FundamentalsCyber insurance and security ratings: what a rating actually changesThe one conversation where a CRO and a CISO read the same number — and where claims about ratings are least often supported.9 min read →
- ReferenceCyber risk ratings glossaryEvery term used across these guides — the scale, the risk vectors, the third-party programme vocabulary, and the Indian regulatory terms no global glossary carries.12 min read →
02REGULATION
What Indian and international regulators now require, instrument by instrument, read from the notifications themselves.
India
- RegulationCyber security regulations in India: which one applies to youThe whole regulatory picture in one table, then a route from your entity type to the instrument that actually governs you.10 min read →
- ReferenceThe Indian cyber regulation registerThe complete list — twenty-five instruments across six regulators — with the date each was last checked at source, published as an open dataset.6 min read →
- RegulationThe RBI Directions of 31 July 2026: which of the seven applies to youNot one instrument but seven, issued the same day. The applicability test first, then the obligations, the timings, and the outsourcing track they deliberately left alone.15 min read →
- RegulationWhat the 2026 RBI Directions ask of an NBFCRBI/DoS/2026-27/461 is not the commercial banks instrument re-addressed. It has six chapters to their eight, and only one of three obligation chapters applies to any given NBFC.8 min read →
- RegulationWhat the 2026 RBI Directions ask of a UCBFour levels set by the digital services a bank actually offers, and the chapters are cumulative. Where the CISO and the operations centre first appear is the part worth knowing before budgeting.8 min read →
- RegulationSEBI CSCRF: what the framework requires, category by categoryWhich category you fall into and why it changes every April, what the framework actually demands, and the circular chain that moved the deadline twice.15 min read →
- RegulationSEBI’s IT Resilience Index has to compute itselfNine weighted parameters, a half-yearly score that must be produced without human hands, and four dates ending 31 March 2027 — for market infrastructure institutions only.7 min read →
- RegulationIRDAI Information and Cyber Security Guidelines, 2026What the April 2026 Guidelines require of insurers, intermediaries and TPAs — and why the CISO reporting line is the provision a board can fail on an organisation chart.11 min read →
- RegulationCERT-In’s six-hour rule: what the 2022 Directions actually requireThe most widely applicable cyber instrument in India, and the least read. Who it binds, when the six-hour clock starts, and the five obligations that are not reporting.13 min read →
- RegulationDPDP security obligations: what Rule 6 asks you to build by May 2027Seven named safeguards, a one-year log retention, and two breach clocks that start on awareness — none of it in force until May 2027, all of it slower to build than to read.12 min read →
- RegulationAgentic AI in India: who answers when the agent actsFour Indian AI instruments, four different legal forces. Which of them actually binds a regulated entity that deploys agents, and what each requires.11 min read →
- RegulationRBI cyber security compliance: what Indian boards must evidenceIndian regulators now expect boards to evidence oversight, not assert it — and on 31 July 2026 the RBI reset the framework across its regulated entities. What that means in practice, and what evidence stands up.11 min read →
- RegulationWhat SEBI’s CDSL order says about the assets you forgot to listA single unlisted internet-facing server cost ₹1 crore, and the disaster recovery site was encrypted too. Why asset inventories fail, and what catches what they miss.9 min read →
Global
- RegulationNIS2, DORA and SEC Reg S-P: what each demands of your vendorsWho is in scope, what each regime demands of third parties, the dates that already passed, and what evidence stands up to a supervisor.12 min read →
- RegulationThe Cyber Resilience Act starts reporting on 11 September 2026One article of the CRA applies more than a year before the rest, it binds non-EU manufacturers directly, and it reaches products you shipped years ago.9 min read →
- RegulationIncident reporting: nine clocks, and none of them start togetherThe trigger, not the duration, is what makes a filing late. Nine clocks across India, the EU and the US, and what each one actually starts from.10 min read →
03PLATFORM
Choosing a platform and then running it: who the vendors are, how they differ, and what it takes to move a score and manage vendor risk once you have one.
- ComparisonCyber security rating vendors in India: how to choose oneWhat a ratings vendor is and is not, who is available in India, and the six criteria that separate them for an Indian buyer.9 min read →
- ComparisonBitsight vs SecurityScorecard, RiskRecon and UpGuardOne comparison, three rivals. Each turns on a different axis, and each section ends with the honest case for buying the other product instead.16 min read →
- PracticeThird-party risk management for Indian BFSIWhy questionnaires fail for vendor risk in BFSI, and how to build a tiered programme with continuous evidence instead.11 min read →
- PracticeSecurity questionnaires or security ratings: what each one can actually seeThe honest boundary between the two, including the four things a rating cannot see — written by a company that sells the rating.10 min read →
- PracticeYour vendors are using AI. What that does to your attack surfaceThe first documented end-to-end autonomous intrusion was a third-party problem. What agentic AI changes about vendor risk, and the questions worth asking.10 min read →
- PracticeAttribution across Indian group structures: whose asset is itThe criterion most shortlists ignore and most deployments stall on — written from delivery experience with Indian conglomerates rather than from a datasheet.9 min read →
- RemediationHow to improve your Bitsight security ratingThe findings that actually move the score, the order to fix them in, and how quickly the rating responds.9 min read →