Cyber Incident Reporting for Banks: CAIIB ITDB Guide 2026
Cyber incident reporting for banks in India runs on two separate clocks, and CAIIB ITDB candidates lose marks by assuming there is only one. CERT-In's Directions of 28 April 2022 fix a hard six-hour window. The RBI's own expectation of a 2–6 hour intimation comes from the Cyber Security Framework circular of 2 June 2016, not from the newer IT Directions. Knowing which instrument imposes which deadline is the single most examinable fact in this area, and it sits directly on top of the IT Act 2000 and 2008 chapter in your syllabus.
This guide sets out what qualifies as a reportable incident, who the report goes to, what it must contain, and how the governance layer around it is examined.
🚨 What Actually Counts as a Reportable Cyber Incident
A cyber incident is not the same as a cyber attack. An incident is any actual or suspected event that compromises the confidentiality, integrity or availability of information or of the systems that process it — including events with no financial loss and no customer impact.
The statutory anchor is section 70B of the Information Technology Act, 2000, which designates CERT-In as the national nodal agency for incident response and empowers it to call for information and issue binding directions. The 2022 Directions annex a list of incident types that must be reported irrespective of severity.
Categories that a bank will encounter most often include:
- Targeted scanning or probing of critical networks and systems
- Compromise of critical systems, servers or an administrator account
- Unauthorised access to IT systems or to data
- Defacement of a website, or intrusion into a web application or database
- Malicious code attacks — ransomware, trojans, spyware, cryptominers
- Attacks on servers such as database, mail, DNS and on routers
- Identity theft, spoofing and phishing attacks
- Denial of service and distributed denial of service attacks
- Data breach and data leak
- Attacks on IoT devices, and on digital payment systems
Note what this list does not require: proof of loss. A blocked intrusion attempt against a core banking gateway is reportable. Candidates who treat "no money moved, no report" as the rule get the question wrong. The underlying transport and perimeter concepts are covered in the Networking Systems chapter, and the statutory text itself is on India Code.
⚠️ Common Mistake: Treating "reportable" as a function of loss amount. Reportability is a function of incident type, not rupee impact. Severity affects escalation and root-cause depth, never the obligation to report.
⏱️ The Two Clocks: CERT-In's Six Hours and RBI's 2–6 Hours
This is where most CAIIB ITDB answers go wrong. The six-hour deadline is CERT-In's. Under the Directions dated 28 April 2022, a listed incident must be reported within six hours of noticing it or of being brought to notice.
The RBI's Cyber Security Framework in Banks circular of 2 June 2016 is separate. It requires a Board-approved cyber security policy, a Cyber Crisis Management Plan, and intimation of unusual cyber security incidents to the Reserve Bank within a 2–6 hour window using the prescribed template.
The Master Direction on IT Governance, Risk, Controls and Assurance Practices (November 2023) mandates an incident response and recovery framework with root-cause analysis and reporting to the Reserve Bank — but it does not lay down a fixed number of hours. Attributing six hours to the 2023 IT Directions is a factual error.
| Instrument | What triggers reporting | Stated timeline | Fixed hour limit in the text? |
|---|---|---|---|
| CERT-In Directions, 28 Apr 2022 (s.70B IT Act) | Any incident in the annexed list | Within 6 hours of noticing | ✅ Yes — 6 hours |
| RBI Cyber Security Framework, 2 Jun 2016 | Unusual cyber security incidents | 2–6 hours, prescribed template | Yes — 2 to 6 hours |
| RBI Master Direction on IT Governance, Nov 2023 | Incidents under the IR framework | Report and analyse root cause | ❌ No fixed hours stated |
| DPDP Act, 2023 (personal data breach) | Breach of personal data | Intimate Board and affected principals | No fixed hours in the Act |
Read the table as four duties that can fire from one event. A ransomware hit on a customer database triggers CERT-In, the RBI circular, the 2023 Master Direction's IR process and the DPDP intimation duty at once — see DPDP Act breach notification norms for that fourth limb.

🏛️ Who Receives the Report, and in What Order
Sequence matters in the exam and in practice. The bank's Chief Information Security Officer owns the outbound reporting decision; the CISO reports independently of the CIO precisely so that operational pressure cannot suppress an intimation.
The recipients are:
- CERT-In — the national nodal agency under section 70B, by the prescribed channel (email, phone or web portal) within six hours.
- Reserve Bank of India — the supervisory department, per the 2016 framework template and the 2023 Master Direction's IR framework.
- NCIIPC — where the affected system is notified as a protected system or forms part of critical information infrastructure under section 70A.
- NPCI or the relevant payment system operator — where a shared retail payment rail is implicated.
- Board and IT Strategy Committee — through the internal escalation matrix in the Cyber Crisis Management Plan.
- Customers and law enforcement — where data or funds of identified customers are affected.
Non-compliance with a CERT-In direction is not a soft failure. Section 70B makes failure to furnish the called-for information or to comply with a direction a punishable offence, and the RBI treats delayed intimation as a supervisory finding in its own right. Current RBI circulars and master directions are published on rbi.org.in, and policy-rate context that often accompanies these questions is maintained on our RBI rates reference page.
💡 Exam Tip: If a question gives you a timestamp for the attack and a different timestamp for detection, the clock always starts at detection — "noticing or being brought to notice". Compute from the later time.
🧾 What a Complete Incident Report Must Contain
An intimation that says only "we have been attacked" fails the requirement. Both the CERT-In format and the RBI template expect a structured first report, followed by updates as the investigation matures.
The first report should carry:
- Reporting entity details — organisation, CISO name, contact number available round the clock
- Incident type mapped to the annexed category, and whether it is ongoing or contained
- Time of occurrence and time of detection, with the time zone stated
- Affected systems — hostnames, IP addresses, applications, and whether core banking, the payment switch or a customer channel is involved
- Indicators of compromise — file hashes, malicious domains, source IPs, ransom notes
- Estimated impact on customers, transactions and data, marked as provisional
- Immediate containment actions already taken — isolation, credential resets, rule changes
Log integrity is what makes this report defensible. The 2022 Directions require entities to enable and securely maintain ICT system logs for 180 days within Indian jurisdiction, and to synchronise system clocks to NIC or NPL time servers. Without synchronised clocks a bank cannot construct a credible timeline, and without retained logs it cannot answer follow-up queries. The same discipline underpins the transaction-level safeguards in our guide to digital payment security controls.
Payment-channel incidents deserve special care because the customer-facing evidence — disputed entries, card data, terminal logs — decays quickly. Revise the card and channel fundamentals in the Plastic Money chapter before attempting scenario questions.

🛡️ Building the Capability: C-SOC, Drills and Board Oversight
A reporting deadline is only met if detection happens fast, so the examinable content extends to the capability behind the report. The 2016 framework expects banks to run a Cyber Security Operations Centre that monitors continuously, correlates events, and escalates on defined thresholds — not a helpdesk that reacts to complaints.
Four building blocks are consistently tested:
- Cyber Crisis Management Plan (CCMP) — Board-approved, covering detection, containment, response, recovery and communication, with a named escalation matrix
- Continuous surveillance — SIEM correlation, anomaly baselines, and privileged-access monitoring
- Periodic testing — vulnerability assessment, penetration testing, red-team exercises and table-top drills against realistic scenarios
- Third-party and supply-chain oversight — vendor incidents are the bank's incidents; the reporting duty is not outsourced with the service
Detection speed is increasingly a modelling problem rather than a rules problem, which is why the same analytics stack that flags anomalous transactions also shortens the reporting clock — the reasoning is set out in our guide to AI fraud detection in banks, and the newer control surfaces appear in the Emerging Technologies chapter.
One legal footnote worth carrying into the hall: section 43A of the IT Act, which formerly provided compensation for failure to protect sensitive personal data, has been omitted by the DPDP Act, 2023. The security-safeguard obligation now sits in the DPDP framework, while sections 65, 66, 70A and 70B of the IT Act continue to operate. For a change of pace across papers, the same standard-versus-circular reading discipline applies to Ind AS 116 lease accounting in ABFM. More chapter-linked revision sits in our Information Technology and Digital Banking elective hub.

🧠 Practice MCQs: Cyber Incident Reporting for Banks
Q1. Under the CERT-In Directions dated 28 April 2022, a listed cyber incident must be reported within how many hours? (a) 2 hours (b) 6 hours (c) 24 hours (d) 72 hours
Answer: (b) — The Directions require reporting within six hours of noticing the incident or being brought to notice of it.
Q2. The RBI's expectation that unusual cyber security incidents be intimated within 2–6 hours originates from which instrument? (a) The Master Direction on IT Governance, 2023 (b) The IT Act, 2000 (c) The Cyber Security Framework in Banks circular, 2016 (d) The DPDP Act, 2023
Answer: (c) — It comes from the 2 June 2016 circular; the 2023 IT Directions lay down no fixed hour limit.
Q3. CERT-In derives its status as the national nodal agency for incident response from which provision? (a) Section 70B of the IT Act, 2000 (b) Section 43A of the IT Act, 2000 (c) Section 25 of the RBI Act, 1934 (d) Section 8 of the DPDP Act, 2023
Answer: (a) — Section 70B designates CERT-In and empowers it to call for information and issue directions.
Q4. A bank detects targeted scanning of its internet-facing servers. No data was accessed and no loss occurred. What is the correct action? (a) Log it internally only, as there is no loss (b) Report only if scanning repeats for seven days (c) Report only to the Board (d) Report it, because targeted scanning is a listed reportable incident type
Answer: (d) — Reportability depends on the incident type, not on whether financial loss occurred.
Q5. Under the 2022 Directions, ICT system logs must be enabled and securely maintained within Indian jurisdiction for a rolling period of: (a) 90 days (b) 180 days (c) 365 days (d) 30 days
Answer: (b) — Logs must be retained for 180 days, with system clocks synchronised to NIC or NPL time servers.
Want chapter-wise mock tests with 100+ MCQs? Start practising free →
❓ Frequently Asked Questions
Does the six-hour clock start from the attack or from detection?
From detection. The Directions say within six hours of noticing the incident or being brought to notice of it, so an attack that began days earlier still gives you six hours from the moment your team notices it.
Do the RBI IT Directions of 2023 impose a fixed reporting deadline in hours?
No. The 2023 Master Direction mandates an incident response and recovery framework with root-cause analysis and reporting to the Reserve Bank, but states no fixed hour limit. The 2–6 hour expectation comes from the 2016 cyber security framework circular.
Is an incident at an outsourced vendor reportable by the bank?
Yes. Outsourcing transfers the activity, not the accountability. If a service provider's compromise affects the bank's systems, data or customers, the bank's own reporting and escalation obligations apply in full.
What happens if a bank misses the reporting window?
Failure to comply with a CERT-In direction is a punishable offence under section 70B of the IT Act, and the Reserve Bank treats delayed or suppressed intimation as an independent supervisory finding, separate from the incident itself.
🎯 Key Takeaway for Your CAIIB ITDB Prep
Fix three facts and this topic becomes free marks: six hours is CERT-In under section 70B, 2–6 hours is the RBI circular of 2016, and the 2023 IT Master Direction sets a framework rather than a clock. Everything else — the incident list, the report contents, the 180-day log rule — hangs off that skeleton.
Test yourself on the full elective before exam day with our CAIIB course and chapter-wise mock tests.
Prefer revising from a printed book?
Chapter-wise books with MCQs after every chapter — minimal pages, complete coverage, delivered anywhere in India. Every book has a free sample to read first.
82 pages · 297 MCQs
Learning Sessions · Ashish Sir
148 pages · 478 MCQs
Learning Sessions · Ashish Sir
151 pages · 465 MCQs
Learning Sessions · Ashish Sir
148 pages · 375 MCQs
Learning Sessions · Ashish Sir
216 pages · 895 MCQs
Learning Sessions · Ashish Sir
109 pages · 300 MCQs
Learning Sessions · Ashish Sir
104 pages · 360 MCQs
Learning Sessions · Ashish Sir
151 pages · 600 MCQs
Learning Sessions · Ashish Sir
98 pages · 282 MCQs
Learning Sessions · Ashish Sir
131 pages · 672 MCQs
Learning Sessions · Ashish Sir
221 pages · 831 MCQs
Learning Sessions · Ashish Sir
128 pages · 524 MCQs
Learning Sessions · Ashish Sir
107 pages · 445 MCQs
Learning Sessions · Ashish Sir
132 pages · 225 MCQs
Learning Sessions · Ashish Sir
188 pages · 435 MCQs
Learning Sessions · Ashish Sir
117 pages · 236 MCQs
Learning Sessions · Ashish Sir
Learning Sessions · Ashish Sir
118 pages · 299 MCQs
Learning Sessions · Ashish Sir
Learning Sessions · Ashish Sir
Learning Sessions · Ashish Sir
Learning Sessions · Ashish Sir
115 pages · 255 MCQs
Learning Sessions · Ashish Sir
Learning Sessions · Ashish Sir
334 pages · 936 MCQs
Learning Sessions · Ashish Sir
Learning Sessions · Ashish Sir
115 pages · 344 MCQs
Learning Sessions · Ashish Sir
107 pages · 240 MCQs
Learning Sessions · Ashish Sir
90 pages · 150 MCQs
Learning Sessions · Ashish Sir
Learning Sessions · Ashish Sir
Quick quiz on this topic
5 exam-style questions from our free test bank — check yourself before you move on.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.