Free tool · Board governance

What should your next cyber board brief say?

Pick your entity class. Get a seven-slide board brief: the instruments that bind you, your reporting clocks, board-level tests and vendor AI — as PowerPoint.

Build your brief

In short
A cyber board brief for an Indian regulated entity should cover five things: which instruments bind it, how fast the first incident filing is due, its external security rating against the industry, the board-level tests its regulator sets, and what its vendors’ AI agents can reach. This tool builds those as seven plain slides, cited to the regulators’ own notifications.

Build your brief

Seven slides, set to your regulator, ready before the board papers go out. Pick your entity class and the slides below rebuild; every reference on them comes from the regulator’s own notification.

The slides are plain on purpose — Arial on white, no logo — so they drop into your own board template. The only mark on them is a footer line.

Your organisation
7slides, for a non-banking financial company.

Board briefing

Cyber risk: what this board needs to know

  • Entity class: Non-Banking Financial Company
  • 5 instruments bind us; the shortest reporting clock is 6 hours from noticing, or being brought to notice
  • Prepared 10 October 2026

1 · What binds us

5 instruments apply — and they are cumulative

InstrumentReferenceNext date
CERT-In Directions, 2022No. 20(3)/2022-CERT-InIn force
RBI Cyber Directions, 2026 (Non-Banking Financial Companies)RBI/DoS/2026-27/461In force
RBI NBFC outsourcing Directions, 2025RBI/DOR/2025-26/363In force
SEBI LODR—In force
DPDP Rules, 2025G.S.R. 846(E)Full compliance with the Rules — 13 May 2027

A filing under one never discharges another.

Each reference read from the issuing regulator’s own notification.

2 · If something happens

The first filing is due 6 hours from noticing, or being brought to notice

WindowFilingGoes to
6 hours from noticing, or being brought to noticeReport the incident to CERT-InCERT-In
6 hours from detectionReport the cyber incident on the DAKSH platformReserve Bank of India
12 hours from occurrence of a material eventMarket disclosure of the event, if the KMP determines it is materialStock exchanges

Not yet in force, plan for it: Intimation to affected Data Principals, and a two-stage report to the Data Protection Board (DPDP Act, 2023 and DPDP Rules, 2025, from 13 May 2027).

3 · Where we stand from outside

How an outsider rates our security today

Our external security rating______On the 300–820 scale
Our industry’s average______And our percentile within it
Ransomware likelihood______As a multiple against companies rated 750+

These three figures come from the complimentary Cyber Risk Rating Report. Request it for our own domain at bitscore.in/solutions/rating-report.

Insurers, customers and supervisors can already see an outside-in rating of us. This slide puts the same number in front of the board.

Fill this slide: request the Rating Report →

4 · Board-level tests

What RBI asks of the board

  • Annual board approval of the three strategies
  • ITSC chaired by an independent director with substantial IT expertise
  • The CISO’s reporting line
  • The six-hour DAKSH filing, owned and rehearsed
  • A measurement in the board pack, not an assurance

Each is answered yes or no from an organisation chart or a board calendar, under RBI/DoS/2026-27/461. SEBI’s CDSL order (20 July 2026, ₹1 crore) traced the breach to an internet-facing server never classed as critical. SEBI held the failure institutional, not individual — deciding what counts as critical is a board-level process.

5 · The new exposure

Our vendors’ AI agents: four things we should know

  • An inventory of vendor AI agents that hold credentials
  • A named human owner per agent
  • Clear kill-switch authority and scope
  • Ongoing disclosure of new agentic capability, not just at onboarding

An agent holding a credential into our environment is a privileged account, whichever vendor operates it.

6 · Decisions for this meeting

What we are asking the board to approve

  • Table the external security rating every quarter, against the industry average — a measurement, not an assurance
  • Name the owner and the out-of-hours deputy for the 6-hour filing to CERT-In
  • Have the critical-asset register checked against an outside-in view of what is internet-facing
  • Commission an inventory of vendor AI agents that hold credentials, each with a named owner
  • Ask for a progress report ahead of the next dated obligation: Full compliance with the Rules, 13 May 2027

Take this away as an editable PowerPoint deck

Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, as plain slides you can edit and drop into your own board template. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.

Sit on a board yourself? Get the eight questions to ask your CISO →

Why the rating slide is blank

Three figures on slide 3 cannot come from an entity class: your external security rating, your industry’s average, and your ransomware likelihood as a multiple against companies rated 750 and above. They are specific to your domain.

Insurers, customers and supervisors can already see an outside-in rating of you. The board should see it first, and see it move. A number that changes between meetings is what turns a cyber update from an assurance into a measurement — the last of the board-level tests in the RBI governance check.

Where every line comes from

Indicative, and not legal advice. Whether an instrument applies is a determination for your compliance and legal team. Every instrument cited here was verified against the issuing regulator's own notification on .

Questions this page answers

What should a CISO put in a board cyber report in India?
The instruments that bind the entity and their next dates, the incident reporting clocks with a named owner for each, an external measurement that moves between meetings, the board-level tests the regulator sets, and the decisions the board is being asked to take. A report of assurances alone — “no significant issues” — is weaker than it was: the 2026 RBI Directions make board review a recurring obligation, and periodic review implies a number the board can question.
Why does the brief leave the rating slide blank?
Because the three figures on it — the organisation’s external security rating, its industry’s average and its ransomware likelihood as a multiple against companies rated 750 and above — are specific to the organisation and cannot be computed from an entity class. They come from the complimentary Cyber Risk Rating Report, requested for the organisation’s own domain.
Can we use our own board template?
Yes, and that is why the slides are plain: Arial on white, no logo, a single footer line. Download the PowerPoint and paste the slides into the company’s own template, or print the page to PDF.
Does the brief cover regulated entities outside RBI?
Yes. SEBI regulated entities, insurers and intermediaries under IRDAI, GIFT City IFSC entities and ordinary body corporates each get the instruments, clocks and board-level tests that apply to them. Regional Rural Banks and Local Area Banks get a brief that says plainly that no member of the 2026 RBI cyber family binds them.

Go deeper on the board slides

This tool is one skill out of nineteen.

What runs on this page is the browser-sized version of boardpack, a skill in BitScoreCoWork — our MIT-licensed Claude plugin. The full version runs against your own Bitsight tenancy and works from your measured attack surface rather than a form. The source is public, so you can read exactly what it does before you run it.

Read the source →The Applied AI practice

Knowing the rule is the easy half.

This page tells you what you owe. It cannot tell you what an attacker already sees. Your organisation has a security rating calculated from signals visible from outside — request the complimentary Cyber Risk Rating Report and find out what it says. No agent, no system access, no questionnaire.

Request my rating →All free tools