Cybersecurity 2026

INDIA Law and Practice Contributed by: Anoop Narayanan, Priyanka Gupta and Harshita Sakarya, ANA Law Group

from the complex and dynamic environment in which the REs operate. Further, with the aim of improving the cybersecurity framework in India’s financial sector, in August 2024, the SEBI released the Cybersecurity and Cyber Resil - ience Framework (CSCRF), for SEBI-regulated entities (the “Regulated Entities”) which includes, inter alia, the following: • alternative investment funds (AIFs); • bankers to an issue (BTI) and self-certified syndi - cate banks (SCSBs); • clearing corporations; • collective investment schemes (CIS); • credit rating agencies (CRAs); • custodians; • debenture trustees (DTs); • depositories and depository participants; • investment advisers and research analysts; • KYC registration agencies; and • merchant bankers. The CSCRF defines “cyber-resiliency” as “the ability of an organisation to continue to carry out its mis - sion by anticipating and adapting to cyber threats and other relevant changes in the environment and by withstanding, containing, and rapidly recovering from cyber incidents”. The CSCRF is standards-based and broadly aligns with the cyber-resiliency goals of CERT-In’s Cyber Crisis Management Plan for countering cyber-attacks and cyber terrorism. These goals include: anticipating, withstanding, containing, recovering and evolving in response to threats, in addition to the core cyberse - curity objectives of identifying, detecting, protecting, responding and recovering. The CSCRF framework provides a structured methodology to implement vari - ous solutions for cybersecurity and cyber-resiliency. The CSCRF framework supersedes earlier SEBI cir - culars and guidelines. 3.2 ICT Service Provider Contractual Requirements There is no specific definition or provisions dealing with “ICT service providers” under the current cyber - security law framework in India.

Under RBI’s Guidance Note, third-party service pro - viders include, inter alia, cloud service providers and IT/operations vendors. The Guidance Note prescribes that REs should perform a risk assessment and due diligence before entering into arrangements with such third-party service providers. Particularly, the RE should verify whether the third-party service provider has at least an equivalent level of operational resil - ience to safeguard the RE’s critical operations in nor - mal circumstances, and in the event of a disruption. Further, the Guidance Note recommends that a policy approved by the board of directors on the manage - ment of service providers is critical for managing risks associated with reliance on third parties irrespective of whether they are related or unrelated to the RE. Such third-party risk policies should include: • procedures for determining whether there is a need for entering into a third-party arrangement for a service and how to enter into such an arrangement; • sound structuring of the third-party arrangement, including ownership and confidentiality of data, as well as termination rights; • programmes for managing and monitoring the risks associated with the third-party arrangement, including the financial condition of the service provider; • establishment of an effective control environment at the RE and the service provider that should include a register of third-party relationships (that identifies the criticality of different services) and metrics and reporting to facilitate oversight of the service provider; and • execution of comprehensive contracts and/or ser - vice level agreements (which are enforceable) with a clear allocation of responsibilities between the third-party service provider and the RE, provided the ultimate responsibility vests with the RE. REs, in their agreements with the third-party service providers, should also include clauses making the ser - vice provider contractually liable for the performance and risk management practices of its sub-contractors. As per the CSCRF, Regulated Entities are required to identify and classify critical systems based on their sensitivity and criticality for business operations, ser -

199 CHAMBERS.COM

Powered by