Compliance · RBI
RBI cyber security directions: security awareness training requirements
RBI issued its cybersecurity directions on 31 July 2026 separately for each type of regulated entity, and the awareness-training paragraphs differ. Banks must evaluate employee awareness periodically; larger base-layer NBFCs must measure training effectiveness and keep a record of every user’s training status.
Find your entity type below, then see why phishing simulation helps and what evidence SecurityRing gives you.
Last reviewed 10 October 2026 against the official texts. Not legal advice.
The short answer
RBI in three lines
Who it applies to
Banks, NBFCs, urban co-operative banks, All India Financial Institutions and credit information companies, each under its own Directions.
What it asks on awareness training
It depends on the entity type: from “evaluate the awareness level of employees periodically” (banks) to “measure and track the effectiveness of such training” (NBFCs).
Where phishing simulation fits
It helps you show training and resilience. None of the Directions we reviewed prescribes phishing simulation as the method, but banks must evaluate awareness periodically and NBFCs must measure training through “periodic assessments or testing”.
Who it applies to
Who has to follow RBI
RBI’s 2026 Directions on Cybersecurity, Technology: Risk, Resilience and Assurance Framework are dated 31 July 2026, apply with immediate effect and replaced the earlier cybersecurity and IT governance directions. There is one set per entity type. This page covers the seven below; if your entity type is not listed, read its own Directions on RBI’s website.
Paragraph numbers differ between sets, so cite the one for your entity type.
| Entity type | Awareness and training paragraphs | What they ask for |
|---|---|---|
| Commercial Banks | ¶200, ¶202, ¶203, ¶204 | Targeted awareness for key personnel; evaluate employee awareness periodically; mandatory awareness programmes for new recruits and annual training for lower and middle management; annual training for the Board and Senior Management. |
| Small Finance Banks | ¶199, ¶201, ¶202, ¶203 | The same four items as commercial banks, numbered differently. |
| Payments Banks | ¶199, ¶201, ¶202, ¶203 | The same four items as commercial banks, numbered differently. |
| Urban Co-operative Banks | ¶59–65 (all UCBs); ¶155–157 (Levels III and IV) | Awareness at all staff levels and training on basic controls, including not clicking email links (¶63). Levels III and IV: mandatory awareness programmes for new recruits and a web-based quiz and training every year for lower, middle and upper management (¶156). |
| NBFCs (Base Layer, ₹500 crore and above) | ¶29, ¶35, ¶36 (Chapter IV) | A robust, ongoing training and awareness programme for all users, reviewed and updated; a formal mechanism to measure effectiveness through periodic assessments or testing; an up-to-date repository of every user’s training status; Board familiarisation. |
| NBFCs (Base Layer under ₹500 crore, Core Investment Companies, and Middle Layer and above) | Chapters III and V | We found no user-training paragraph in these chapters of the published text. Confirm with your compliance team how your layer is treated. |
| All India Financial Institutions | ¶195, ¶197, ¶198, ¶199 | The same four items as commercial banks, numbered differently. |
| Credit Information Companies | ¶195, ¶197, ¶198, ¶199 | The same four items as commercial banks, numbered differently. |
What it asks for
What RBI asks for on awareness training
The clauses that matter, with their numbers. “Official wording” is quoted exactly; “Our paraphrase” is our summary in plain words.
Commercial Banks ¶202Official wording
The bank shall evaluate the awareness level of employees periodically.
Commercial Banks ¶203Official wording
The bank shall establish a mechanism for continuous and adaptive capacity building to strengthen cybersecurity management. Cybersecurity awareness programmes shall be mandatory for all new recruits, and annual training shall be conducted for lower and middle management.
Commercial Banks ¶204Our paraphrase
Keep the Board and Senior Management aware of evolving cyber threats, and give all Board members and Senior Management annual training on IT and cybersecurity risks and evolving best practices.
NBFCs (Chapter IV) ¶35Official wording
The NBFC shall establish and implement a robust, ongoing information security training and awareness program for all users. This program shall be periodically reviewed and updated to remain aligned with evolving IT landscapes, emerging cyber threats, and the NBFC’s information security framework.
NBFCs (Chapter IV) ¶36Official wording
The NBFC shall deploy a formal mechanism to measure and track the effectiveness of such training through periodic assessments or testing. The NBFC shall also maintain an up-to-date repository of the training and awareness status of all users.
Urban Co-operative Banks ¶63Official wording
The UCB shall conduct awareness and training programmes for its staff on basic information security controls, including applicable Do’s and Don’ts and incident reporting procedures. The UCB shall educate employees to strictly avoid clicking any links received via email (to prevent phishing / spear-phishing attacks).
Urban Co-operative Banks ¶156 (Levels III and IV)Official wording
The UCB shall conduct mandatory cybersecurity awareness programs for new recruits and web-based quiz and training for lower, middle, and upper management every year.
Phishing simulation
Why phishing simulation helps
Phishing simulation lets you show that people were trained and that they were tested. Four reasons it helps come first; then, so you are not misled, we say exactly what the framework text itself asks for.
Test
A realistic simulated attack
SecurityRing sends a realistic simulated attack to your employees.
Teach
A short lesson after the click
A short lesson opens straight after the click, designed to take under two minutes.
Evidence
A report a reviewer can read
Campaign report, completion records, trend report and audit trail, exported as PPT, PDF or CSV.
Campaign results
Evidence for RBI review
- People tested
- Opened
- Clicked
- Completed the lesson
In the report
- Completion records
- Trend report
- Audit trail
Export as
- PPT
- CSV
Show training and resilience
Employees are tested with realistic attacks, not only shown a course. Your reports show who was tested, how they behaved and what followed, so you can evidence resilience as well as training.
Faster, with less chasing
A simulation reaches people in their inbox. There is no long course to schedule and no constantly chasing employees to finish it, so your time goes where it is needed.
A short lesson at the right moment
When someone clicks, a short lesson opens straight away on the exact attack they just met, designed to take under two minutes. That saves you and your employees time compared with a long course.
Reports a reviewer can read
The campaign report, per-person completion records, executive trend report and dated audit trail, exported as PPT, PDF or CSV, serve as evidence of security training and phishing awareness and of actual resilience testing. Offer them alongside your other evidence.
Banks must evaluate employee awareness periodically (¶202; AIFIs and CICs ¶197), and larger Base Layer NBFCs must measure and track training effectiveness “through periodic assessments or testing” (¶36). A recurring simulation gives you dated results per campaign and by department, and the executive trend report shows change over time. The lesson after a click and the completion records show follow-up for the people who clicked. Urban co-operative banks are told to educate staff not to click email links (¶63); a simulation shows how staff behave when they meet one.
What RBI says
None of the Directions we reviewed prescribes phishing simulation as the method.
Banks must evaluate employee awareness periodically without saying how; NBFCs must measure training effectiveness “through periodic assessments or testing”, wording a simulation can meet but that does not name one; urban co-operative banks must educate staff to avoid clicking email links and run a web-based quiz and training.
The “simulation exercises” the bank Directions mention (¶188 for commercial banks) are cyber drills run under bodies such as CERT-In and IDRBT, not employee phishing tests. A phishing simulation is a reasonable way to do the periodic evaluation or testing, but that is your choice and your supervisor’s call.
Evidence from SecurityRing
Evidence for RBI from SecurityRing
SecurityRing gives evidence for the employee-awareness paragraphs. This is how its outputs line up, by what the paragraph asks for.
| What RBI asks | Evidence from SecurityRing |
|---|---|
| Evaluate employee awareness periodically (banks ¶202; AIFIs and CICs ¶197) | Phishing simulation results per campaign and by department, and the executive trend report showing change over time. |
| Measure and track training effectiveness through periodic assessments or testing (NBFCs ¶36) | Recurring campaigns can serve as the periodic test, with a campaign report for each. Confirm with your supervisor that this satisfies ¶36. |
| Keep an up-to-date repository of every user’s training and awareness status (NBFCs ¶36) | Per-person lesson-completion records with dates for people who clicked, exported as CSV, PPT or PDF. ¶36 asks for the status of all users, so combine this with your own training records. |
| Awareness programmes for new recruits (banks ¶203) | SecurityRing does not run onboarding courses. New joiners can be added to your employee list and included in campaigns. |
| Annual training for the Board and Senior Management (banks ¶204) | Not delivered by SecurityRing. The executive trend report (PPT export) can support a Board briefing on exposure. |
What SecurityRing produces
- Campaign report. For each campaign: sent, opened, clicked, video completed and training completed, time to action, results by department, location, seniority and manager cohort, repeat exposure and recommended follow-up.
- Completion records. A per-person roster for each campaign, with drill-downs, showing who was phished, who finished the lesson and when. The lesson goes to people who act on a simulation, so this is not a record of training for your whole workforce.
- Executive trend report. Across campaigns over a six-month lookback: phishing exposure score, trends by department and senior management, response speed and a 30-day action plan.
- Audit trail. A dated interaction audit trail for each campaign: what each recipient did and when.
- PPT, PDF and CSV export. Download the campaign and executive trend reports as PPT, PDF or CSV for your auditor, or present them on screen.
What it does not do
- SecurityRing does not provide Board or management training courses, or onboarding courses for new recruits.
- SecurityRing’s lesson goes to people who click or submit in a simulation, not to every employee. Where a requirement covers all staff, keep your baseline training programme and use SecurityRing for simulation results and follow-up.
- SecurityRing’s reports are not mapped to RBI clause numbers. You decide which report supports which clause, and your auditor decides whether it is enough.
- The Directions also cover customer awareness and many other controls. SecurityRing covers employee phishing and deepfake awareness only.
This page is a plain-language summary for GRC teams, not legal advice. SecurityRing gives you evidence for the awareness-training part of a framework and helps you demonstrate it. Using SecurityRing does not make you compliant, it is not a certification, and no regulator or standards body endorses it. Your auditor or regulator decides whether the evidence is enough.
What do RBI’s cybersecurity directions require for employee awareness training?
It depends on entity type. Commercial, small finance and payments banks must evaluate employee awareness periodically, run mandatory programmes for new recruits, train lower and middle management every year and train the Board annually. NBFCs in Chapter IV must run ongoing training for all users, measure its effectiveness and keep a status record. See the table for each type.
How does phishing simulation help with RBI’s directions, and are they required?
A simulation lets you show both training and resilience, with dated results per campaign and a trend report. Banks must evaluate awareness periodically without naming a method, NBFCs must use periodic assessments or testing, and urban co-operative banks must educate staff not to click email links. A phishing simulation is one reasonable way to do the periodic evaluation or testing, but the Directions do not prescribe it.
Which NBFCs have an explicit user-training paragraph?
In the published NBFC Directions, ¶35–36 sit in Chapter IV, which applies to Base Layer NBFCs with assets of ₹500 crore and above. We did not find a user-training paragraph in Chapter III (smaller Base Layer NBFCs and Core Investment Companies) or Chapter V (Middle Layer and above). Confirm how your layer is treated with your compliance team.
Does using SecurityRing make a bank or NBFC RBI-compliant?
No. SecurityRing helps you demonstrate the employee-awareness paragraphs with campaign reports, completion records and trend reports. It does not deliver Board training, is not mapped to RBI paragraph numbers, and no regulator endorses it. RBI and your auditors decide whether you comply.
Sources and how we checked
Last reviewed 10 October 2026. Read from the Directions pages on rbi.org.in on 10 October 2026 (commercial banks and small finance banks show “Updated as on October 01, 2026”). Paragraph numbers are those of each set. RBI may amend the Directions; check the live text. We reviewed only the seven sets listed; other entity types have their own Directions.
- RBI (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026
- RBI (Small Finance Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026
- RBI (Payments Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026
- RBI (Urban Co-operative Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026
- RBI (Non-Banking Financial Companies – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026
- RBI (All India Financial Institutions – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026
- RBI (Credit Information Companies – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026
See the evidence your RBI reviewer will read
Book a demo to see how a campaign report, completion records and the executive trend report would look for your team, and how they line up with RBI.