Cyber Incident Reporting by Banks: CERT-In and RBI Rules
Two regulators, one six-hour clock. Here is who a bank tells, how fast, and what changed in 2026.
When a bank's internet banking server is hit by ransomware at 2 a.m., the clock starts for the bank, not just for the customers. Two regulators expect to hear within six hours: CERT-In, under directions issued in 2022 under the IT Act, and RBI, under its 2026 cyber security Directions. If customers lose money, separate fraud reporting duties follow.
This page sets out who the bank reports to, how fast, and what changed in 2026. It is the bank's obligation. How a customer reports a crime to the police is a different process.
You save ₹300
- Full 120-question mocks
- Cyber law coverage
- Module-wise practice
One payment, no subscription · Valid for 2 months
Who the Bank Reports To, and How Fast
CERT-In
What
Any of the 20 incident types in Annexure I of the Directions
Deadline
Within 6 hours of noticing it or being told of it
Source
CERT-In Directions of 28 April 2022, under IT Act section 70B(6)
RBI, on the DAKSH platform
What
Cyber incidents
Deadline
Within 6 hours of detection
Source
RBI Cybersecurity, Technology Risk Directions, 2026, para 182
RBI, through the Fraud Monitoring Return (FMR)
What
Each fraud, including fraudulent electronic banking or digital payment transactions committed on the bank
Deadline
Immediately, not later than 14 days from classification as fraud
Source
RBI Fraud Risk Management Directions, 2026
RBI's Central Payments Fraud Information Registry
What
Disputed, suspected or attempted payment system frauds
Deadline
As RBI's CPFIR instructions require
Source
RBI Fraud Risk Management Directions, 2026
Police, SFIO or CBI
What
Frauds, by amount and type of bank
Deadline
Immediately
Source
RBI Fraud Risk Management Directions, 2026
| Report to | What | Deadline | Source |
|---|---|---|---|
| CERT-In | Any of the 20 incident types in Annexure I of the Directions | Within 6 hours of noticing it or being told of it | CERT-In Directions of 28 April 2022, under IT Act section 70B(6) |
| RBI, on the DAKSH platform | Cyber incidents | Within 6 hours of detection | RBI Cybersecurity, Technology Risk Directions, 2026, para 182 |
| RBI, through the Fraud Monitoring Return (FMR) | Each fraud, including fraudulent electronic banking or digital payment transactions committed on the bank | Immediately, not later than 14 days from classification as fraud | RBI Fraud Risk Management Directions, 2026 |
| RBI's Central Payments Fraud Information Registry | Disputed, suspected or attempted payment system frauds | As RBI's CPFIR instructions require | RBI Fraud Risk Management Directions, 2026 |
| Police, SFIO or CBI | Frauds, by amount and type of bank | Immediately | RBI Fraud Risk Management Directions, 2026 |
The Rest of the CERT-In Directions
They apply to service providers, intermediaries, data centres, body corporates and government organisations, so banks are covered.
- check_circleReport through email, phone or fax to CERT-In, in the formats on its website.
- check_circleSynchronise all system clocks with the NTP servers of the National Informatics Centre or the National Physical Laboratory, so log timestamps line up across systems.
- check_circleKeep logs of all ICT systems for a rolling 180 days, within Indian jurisdiction, and hand them over with an incident report or on CERT-In's order.
- check_circleDesignate a point of contact for CERT-In.
- check_circleFailing to provide information or comply is punishable under section 70B(7) of the IT Act: imprisonment up to one year, or a fine up to ₹1 crore, or both. The fine was ₹1 lakh until the Jan Vishwas Act raised it from 30 November 2023.
Terms the Questions Use
- Cyber event
- Any observable occurrence in an information system. A failed login is an event.
- Cyber incident
- A cyber event that adversely affects the cyber security of an information asset, whether malicious or not. RBI's definition includes IT incidents as well as attacks.
- DAKSH
- RBI's Advanced Supervisory Monitoring System, the platform banks use to report cyber incidents to RBI.
- IB-CART
- Indian Banks Center for Analysis of Risks and Threats, set up by IDRBT. RBI's 2026 Directions say banks may share threat intelligence from incidents with it.
Quick practice on banking operations. No signup.
Inside the Bank: Escalation and Customers
RBI requires a cyber incident response and recovery policy that defines and classifies incidents, gives staff and outsourced staff clear roles, and sets up a way for employees, vendors and customers to report incidents. The bank must have clear plans for escalating incidents to the Board and senior management and for informing customers where required. Incidents are analysed, using forensics if needed, for severity, impact and root cause.
For a branch officer, that means one rule: report suspicious activity internally at once through the bank's channel. The six-hour clock runs from detection by the bank, and detection often starts at a branch.
What Changed in 2026
On 31 July 2026 RBI issued the Commercial Banks Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026, which repeal the existing directions and guidelines on the cyber security framework and IT governance for commercial banks. RBI's repeal list includes the June 2016 Cyber Security Framework circular. The IIBF courseware (2025 edition) predates this change. IIBF's cut-off for the September 2026 to February 2027 sittings is 30 June 2026, before the new Directions, so those papers follow the earlier instructions; sittings from March 2027 (cut-off 31 December 2026) can test the 2026 Directions. Separately, the DPDP Rules, 2025 require a personal data breach to be reported to the Data Protection Board within 72 hours, but that rule starts eighteen months after the Rules were notified in November 2025.
How the IIBF Exam Tests This
Numbers and recipients are the core: six hours for CERT-In, 180 days for logs, NIC or NPL for time sync, and the section of the IT Act that gives CERT-In its power (70B). The usual trap mixes regulators: a question about log retention will offer RBI or I4C as the authority, when the rule comes from CERT-In's directions.
A second trap is the difference between a cyber incident and a fraud. A blocked attack is still a reportable incident; a fraud report to RBI follows only once the bank classifies a case as fraud.
FAQs
Within how many hours must a cyber incident be reported to CERT-In?expand_more
Within 6 hours of noticing it or being told about it, under CERT-In's Directions of 28 April 2022 issued under section 70B(6) of the IT Act.
How long must logs be kept under the CERT-In Directions?expand_more
For a rolling period of 180 days, maintained within Indian jurisdiction, and provided to CERT-In with an incident report or when ordered.
How do banks report cyber incidents to RBI?expand_more
On RBI's DAKSH platform, within six hours of detection, under the 2026 Cybersecurity, Technology Risk Directions. The bank must also notify CERT-In.
Does an unsuccessful cyber attack need to be reported?expand_more
CERT-In's list includes attempts such as targeted scanning of critical systems, and RBI defines a cyber incident by its adverse effect on security, not by whether money was lost. Treat attempts as reportable and let the bank's incident team decide.
Next steps
- RBI Cyber Frameworkarrow_forward
- CERT-In & NCIIPCarrow_forward
- RBI Fraud Reportingarrow_forward
- Reporting Cyber Crimearrow_forward
120 questions, 2 hours, scored instantly.
