For years, cybersecurity in Indian banks and financial institutions was treated largely as a technology problem, owned by the CISO and IT team, reported upward through periodic updates, and reviewed mainly at audit time. That framing has changed decisively. With regulators now treating cyber risk as an enterprise level exposure that touches credit decisions, operational continuity, customer trust, and board accountability, cybersecurity is not just an IT risk, it is a shared responsibility that runs through risk management, internal audit, compliance, and business teams alike.
This shift is not simply a matter of good practice. RBI’s Cybersecurity, Technology Risk, Resilience and Assurance Framework directions, issued across banks and NBFCs in 2026, explicitly embed cybersecurity into board governance, audit committee oversight, vendor management, and business continuity planning, functions that sit well outside the traditional IT department. Institutions that continue to treat cyber risk as someone else’s job are likely to find themselves out of step with both regulatory expectation and operational reality.
Why Cybersecurity Has Outgrown the IT Department
Cyber incidents rarely stay contained within technology systems. A ransomware attack halts loan disbursement and payment processing, a data breach triggers regulatory reporting obligations and customer notification requirements, and a third party vendor compromise can expose an institution’s core systems regardless of how well the institution’s own controls are designed. Because the consequences of a cyber event ripple across credit operations, customer service, regulatory standing, and reputation, the responsibility for managing that risk has to be distributed just as widely.
This is precisely why regulatory frameworks now assign explicit cybersecurity responsibilities to functions that traditionally sat outside the technology conversation.
The Role of Risk Management
Risk teams are responsible for treating cyber risk as a core category within the enterprise risk framework, not as a specialised, siloed subject handled only by IT security staff. This means cyber risk needs to be incorporated into the institution’s risk appetite statement, its key risk indicators, and its risk and control self assessment processes, with clear thresholds for what level of cyber exposure is acceptable and what triggers escalation.
Risk teams also need to understand how cyber risk interacts with other risk categories. A cyber incident affecting payment systems is simultaneously an operational risk event, a potential liquidity risk trigger if it disrupts fund transfers, and a reputational risk exposure. Building this cross risk fluency, rather than treating cyber as an isolated technical category, is now a core expectation of the risk function.
The Role of Internal Audit
Internal audit’s role has expanded significantly under the newer regulatory frameworks. Audit committees are now expected to directly oversee information systems audits, rather than receiving cyber findings as a subset of a broader IT audit. This means audit teams need genuine capability to assess the effectiveness of vulnerability assessments, penetration testing cycles, disaster recovery drills, and incident response processes, not simply confirm that these activities took place on schedule.
Audit teams are also increasingly expected to test whether board level governance structures, such as IT Strategy Committees and Information Security Committees, are functioning as intended, with real engagement and challenge, rather than existing only on an organisational chart. This requires auditors to develop cyber risk literacy that goes beyond a checklist approach to genuine substantive assessment.
The Role of Compliance
Compliance teams carry the responsibility of translating dense regulatory cybersecurity requirements into practical policies, procedures, and reporting mechanisms that the rest of the institution can actually follow. This includes ensuring that incident reporting obligations, such as the six hour reporting window for significant cyber incidents through platforms like DAKSH, are built into operational workflows rather than existing only in a policy document.
Compliance also plays a critical role in tracking the growing intersection between cybersecurity regulation and data protection law, since institutions now need to satisfy both financial sector cyber requirements and broader data protection obligations simultaneously. Keeping these frameworks properly mapped against each other, and ensuring institutional policies reflect both, is compliance work, not IT work.
The Role of Business Teams
Business teams, including branch operations, digital banking, lending, and customer service functions, are often the first line of defence against cyber threats, whether through phishing attempts targeting frontline staff, social engineering attacks aimed at customer facing employees, or operational shortcuts that inadvertently create security gaps. Business teams need practical, role specific cyber awareness training, not generic IT security briefings, along with clear escalation paths when something looks wrong.
Business leaders also need enough understanding of cyber risk to factor it into decisions that might otherwise seem purely commercial, such as onboarding a new fintech partner, launching a new digital product, or expanding into new distribution channels. Each of these decisions carries cyber and vendor risk implications that need to be assessed before, not after, the decision is made.
Building a Genuinely Shared Ownership Model
Making cybersecurity a genuinely shared responsibility requires more than issuing a policy that says so. It requires structured, role specific capability building across every function that touches cyber risk, clear lines of accountability that do not collapse back onto the IT team by default, and reporting structures that give the board and senior management real visibility into cyber exposure across the institution, not just a technical status update.
Institutions that succeed at this tend to share a few common practices. They build cyber risk literacy into onboarding and ongoing training for risk, audit, compliance, and business staff, not just technology staff. They embed cyber risk explicitly into enterprise risk registers, audit plans, and compliance monitoring calendars rather than treating it as a parallel, separate track. And they create genuine cross functional forums, not just IT led committees, where risk, audit, compliance, and business leaders discuss cyber exposure together on a regular basis.
Conclusion
Cybersecurity has moved decisively beyond the boundaries of the IT department, and institutions that continue to treat it as a purely technical concern are likely to fall short of both regulatory expectations and operational resilience. Risk teams need to integrate cyber into enterprise risk frameworks, audit teams need genuine capability to test governance and controls substantively, compliance teams need to operationalise complex regulatory requirements, and business teams need practical awareness and decision making capability. Institutions that build this shared ownership deliberately, rather than assuming it will happen organically, will be far better positioned to manage cyber risk as the enterprise wide challenge it has become.
Build This Capability with RMAI
Developing genuine cross functional cyber capability requires more than a single training session. RMAI’s Online Course on Cyber Security and Technology Risk Management in Banking gives risk, audit, compliance, and business professionals a shared foundation in cyber vulnerabilities, governance, and control practices relevant to banking operations.
For risk teams working to embed cyber risk into enterprise risk registers and risk appetite frameworks, the Online Certificate Course in Enterprise Risk Management builds the integrated risk thinking needed to treat cyber alongside credit, market, and operational risk.
For compliance and governance professionals translating regulatory cyber requirements into policy and board oversight structures, the Online Certificate Course on Governance, Risk and Compliance (GRC) connects regulatory obligation with practical governance design.
Since vendor and fintech partnerships carry direct cyber exposure, the Online Certificate Course in Third Party and Vendor Risk Management equips business and risk teams to assess these relationships properly before onboarding.
And for audit and operational risk professionals responsible for testing controls, escalation processes, and incident response substantively rather than procedurally, the Online Certificate Course in Operational Risk Management rounds out the practical skill set this shared responsibility model requires.
To explore the full range of programmes covering credit, market, operational, cyber, and enterprise risk, visit RMAI’s complete suite of risk management courses or the risk management courses page for a programme matched to your team’s needs.