Cybersecurity 2026

INDIA Law and Practice Contributed by: Anoop Narayanan, Priyanka Gupta and Harshita Sakarya, ANA Law Group

• to enhance international co-operation by promot - ing shared understanding and collaborative mech - anisms for securing cyberspace. Building on the 2013 framework, the Data Secu - rity Council of India (DSCI) has conceptualised the National Cyber Security Strategy, 2020, which is under development and represents the most comprehensive attempt to establish an integrated and future-ready cybersecurity framework aligned with India’s rapidly expanding digital footprint. A significant feature of the proposed 2020 strategy is its focus on the governance of emerging technologies. India aims to develop regulatory guidelines for Artificial Intelligence (AI) safety, quantum-resistant encryption, 5G and 6G network security, IoT certification frame - works, and secure cloud adoption standards. In paral - lel, it promotes domestic research and development in cryptography, semiconductors, hardware security modules and cyber-forensics, with the objective of strengthening long-term technological autonomy. Legislative and Regulatory Framework The national strategy is supported by a combina - tion of existing legislation and proposed reforms. The Information Technology Act, 2000, (the “IT Act”) together with the Information Technology (Intermedi - ary Guidelines and Digital Media Ethics Code) Rules, 2021, (the “IT Rules”) forms the primary legal founda - tion for cybersecurity governance. Further, the bind - ing directions and guidelines issued by the national nodal agencies under the IT Act, the Indian Computer Emergency Response Team (CERT-In) and the Nation - al Critical Information Infrastructure Protection Centre (NCIIPC), addresses incident reporting, co-ordinated response, protection of critical systems and enforce - ment against unauthorised access or cyber offences across sectors. Further, the DPDPA mandates the implementation of reasonable security safeguards, requires reporting of personal data breaches, and reinforces organisa - tional accountability for data-related cybersecurity incidents. Additionally, the proposed Digital India Act is intended to modernise India’s digital regulatory architecture and

is expected to introduce enhanced provisions relating to platform governance, cybersecurity obligations and enforcement mechanisms, reflecting the increasing complexity of India’s digital ecosystem. Scope of Cybersecurity Regulations Across Sectors Enhanced cybersecurity regulations are imposed on regulated sectors such as banking, financial services, insurance, telecommunications, power and securities markets. Banking and finance sector The Reserve Bank of India (RBI) has progressively strengthened cybersecurity oversight within the financial sector. In September 2025, RBI issued the Master Directions on Regulation of Payment Aggrega - tors, to consolidate and rationalise the existing pay - ment aggregator regulatory framework and introduce enhanced compliance and operational requirements. The framework mandates licensing for payment aggregators, including cross-border payment aggre - gators, and emphasises strong cybersecurity controls. The Directions also mandate payment aggregators to conduct full merchant KYC checks as per the RBI Know Your Customer Direction, 2016, subject to pre - scribed thresholds. The RBI has also emphasised heightened oversight of cybersecurity risks arising from third-party dependencies and digital fraud. Inci - dent reporting obligations in the banking and finan - cial sector align with national cyber incident reporting timelines to RBI and CERT-In. Insurance sector In the insurance sector, the Insurance Regulatory and Development Authority of India (IRDAI) has sig - nificantly strengthened cybersecurity expectations. The IRDAI Information and Cyber Security Guide - lines, 2023, applicable to insurers and intermediar - ies, require continuous monitoring of ICT systems, retention of security and application logs for extended periods, time-synchronised ICT systems and rapid reporting of cyber incidents to both IRDAI and CERT- In. The guidelines emphasise governance structures, encryption, business continuity planning and vendor risk management, embedding cyber-resilience within

192 CHAMBERS.COM

Powered by