Decipher
Book a Call Get Started
Home / Security / Security for BFSI
Industry: Banks, NBFCs, Payment Aggregators & Insurers

Cyber security for Indian BFSI, tuned to RBI, PCI and DPDP

Channel VAPT that reads like the RBI CSITE inspectors want to read it. DDoS defence on payment endpoints that has survived Diwali settlement peaks. PCI-DSS scope work that actually cuts the audit surface. IS Audit evidence packs that hold up when the auditor pushes back. Built for banks, NBFCs, payment aggregators and insurers by a team that has sat across the table from Indian regulators.

80+
VAPT engagements shipped
< 30 min
MTTR on Sev-1 alerts
99.99%
Uptime under L7 flood
7
Compliance regimes supported
Threat Surface for BFSI

Four attack shapes every Indian BFSI CISO is planning against right now

Volumetric DDoS on payment endpoints. Attackers know settlement windows. They know when NPCI, RTGS and card networks are busy. Bot networks flood UPI callback URLs and card auth endpoints at exactly the moment a queue backup will turn into a customer-facing failure. Standard cloud WAF rules do not stop this on their own. You need scrubbing capacity, tuned rate limits, and a runbook the on-call team has rehearsed.

Credential stuffing and account takeover. Every leaked password dump from the last five years gets replayed against retail banking logins within days. Static rate limits do not catch a distributed attack running at 4 requests per minute per IP across 40,000 IPs. Device fingerprinting, velocity checks on failed OTPs, and impossible-travel rules on session logins are the baseline now, not a nice-to-have.

Insider misuse and privileged access sprawl. Ex-employees still holding VPN certs. Third-party vendors with jump-host access nobody reviewed in 18 months. Shared service accounts sitting in cron jobs. Every RBI CSITE cycle finds these, and every one of them is what shows up in a breach post-mortem.

API abuse and enumeration on open banking surfaces. Account Aggregator, UPI intents, TPAP APIs. Every new integration is a new surface. Consent tokens, request signing, replay windows, and BIN-range rate limits have to be right before the API goes live, not after a breach notification.

Why BFSI teams pick us

We speak the regulator's language, not just the vendor's

Most security vendors run generic playbooks. We ship BFSI-specific ones. Report formats match what RBI CSITE, NPCI compliance and IRDAI inspectors expect. Change control paperwork is written to survive an IS Audit sample review. Every action gets logged in a way your DP officer can hand to the regulator inside 72 hours if a breach notification is triggered.

See full security service
What We Do

Six security engagements for Indian BFSI

Channel VAPT (Web, Mobile, API, Network)

Named-tester penetration testing on internet banking, mobile app, public API, and internal network. CVSS 3.1 scoring, PoC screenshots, remediation retest included. Report format matches what CSITE inspectors and NPCI empanelled auditors expect.

Signed by named tester

DDoS Mitigation for Payment Infra

Cloudflare Magic Transit, AWS Shield Advanced or Imperva on transaction endpoints. Rate-limit rules per BIN, per device, per merchant. L7 playbook rehearsed with the on-call team. Runbook that stands up on a settlement Saturday.

Survived Diwali peaks

RBI CSITE & IS Audit Readiness

Gap assessment against the RBI Cyber Security Framework. Control mapping to CSITE questionnaire. Evidence pack for IS Audit sample review. Board-level briefing pack. Sit-in support during the actual inspection window.

Auditor-ready evidence

PCI-DSS Scope Reduction & Readiness

Tokenisation architecture, network segmentation of CHD environments, PII flow mapping. Cuts the audit boundary before the QSA walks in. Internal ASV scan management. Annual pen test done in the format PCI DSS 4.0 requires.

Smaller audit surface

Transaction Monitoring & Fraud Signal Integration

Wire your fraud engine outputs into the SOC alert graph. Correlate device fingerprint, login velocity, and transaction patterns. Feed high-confidence alerts into the case management workflow the ops team already uses.

Fewer false positives

Incident Response Retainer & CERT-In Reporting

24x7 on-call incident commander. Containment playbook for ransomware, data exfil, insider misuse. CERT-In 6-hour reporting support. Quarterly tabletop exercise with your CISO office. Post-incident review pack for the board and RBI.

CERT-In deadline coverage

Regulatory inspection scheduled? VAPT window closing?

15-min call. Tell us the scope, the deadline, and the auditor. We come back with a fixed-price plan and named tester CVs in 48 hours.

Book Free 15-min Call
Tech Stack We Use

Boring, battle-tested tools that BFSI auditors already recognise

If your team already runs Splunk, Qradar or Sentinel, we operate inside it. No rip-and-replace. We agree on the stack in writing during scoping.

Edge & WAF

Cloudflare Magic Transit AWS Shield Advanced Imperva AWS WAF / F5

VAPT Toolchain

Burp Suite Pro Nessus Pro Nuclei MobSF / Frida

SIEM & Detection

Wazuh Splunk / Qradar Microsoft Sentinel Falco (runtime)

Endpoint & EDR

CrowdStrike Falcon SentinelOne Microsoft Defender

Secrets & PAM

HashiCorp Vault AWS Secrets Manager CyberArk (where mandated)

Cloud Posture

AWS Security Hub Azure Defender for Cloud Prisma Cloud / Wiz
Compliance We Prep You For

Regimes Indian BFSI has to answer to

RBI Cyber Security Framework

Full control mapping, IS Audit evidence, CSITE inspection prep, board briefing.

PCI-DSS 4.0

Scope reduction, tokenisation architecture, ASV coordination, annual pen test.

DPDP Act 2023

Consent architecture, purpose limitation, 72-hour breach notification playbook.

ISO 27001

Statement of Applicability, risk register, internal audit cycle, cert body handover.

SOC 2 Type II

For NBFCs and fintechs selling into US and UK enterprises. Trust criteria mapping.

CERT-In Directions

6-hour incident reporting workflow, log retention for 180 days, SLA integration.

NPCI Compliance

TPAP and PSP guidelines, security audit format, callback URL hardening.

IRDAI Cyber Guidelines

Applicable to insurers and web aggregators, mapped alongside RBI framework.

Pricing

Fixed-scope engagements, fixed prices

Engagement
Channel VAPT

Web + mobile + API + network surface. Named tester. CVSS scoring. Remediation retest included. Report in the format Indian regulators recognise.

Rs. 1.5-6 L
Sprint
RBI CSITE / IS Audit Prep

Gap assessment, control mapping, policy library, evidence pack, board briefing. Sit-in support during inspection window.

Rs. 4-8 L
Setup
Payment DDoS + WAF

Edge scrubbing, WAF rules for payment APIs, rate-limit per BIN / device / merchant, L7 runbook, tabletop rehearsal. Vendor licence billed separately.

Rs. 2-4 L
Ongoing
Managed SOC + IR Retainer

24x7 alert triage, phishing takedown, on-call incident commander, quarterly tabletop, CERT-In reporting workflow. Flat monthly.

Rs. 80k-2.5 L/mo
FAQ

Questions BFSI CISOs ask on every call

Yes. We map controls to the RBI Cyber Security Framework, prepare the evidence pack that CSITE inspectors ask for, and sit with your CISO through the mock inspection. We have seen the exact objections inspectors raise on change management, privileged access review, log retention, and vendor risk. We produce the artefacts that stand up to that scrutiny rather than a generic ISO checklist.

Reports are signed by a named lead tester with a public CV, CVSS 3.1 scoring on every finding, proof-of-concept screenshots, and a remediation retest included. Format matches what RBI CSITE, SEBI and NPCI empanelled auditors expect. If your board asks for CERT-In empanelled tester sign-off on the covering letter, we arrange that through a partner CERT-In firm at no markup.

Layered defence. Cloudflare Magic Transit or AWS Shield Advanced at the network edge for volumetric traffic. WAF rules tuned for the specific request shape of your payment API. Rate limits per client IP, per device fingerprint, per BIN range. Bot rules that separate legitimate merchant traffic from scripted enumeration. Runbook for L7 attacks so the on-call team knows exactly what knob to turn at 2am on a settlement day.

Yes, and the two overlap but do not replace each other. RBI rules cover confidentiality and integrity of customer data. DPDP adds specific obligations around consent capture, purpose limitation, breach notification within 72 hours, and the right of erasure for non-KYC data. We do a DPDP gap review against your existing RBI-aligned controls and fill only the delta so you are not re-doing work.

Full readiness up to the QSA audit. Scope reduction through tokenisation and network segmentation is usually where we save the most cost. We work with your acquiring bank or QSA of choice for the certifying audit, produce the required policies, do the internal vulnerability scans, help configure the PCI SSC-approved scanning vendor, and run the annual penetration test PCI requires.

Yes. If you already run Splunk, Wazuh, ArcSight, Sentinel, or Qradar we work inside it. Core banking integrations (Finacle, Flexcube, TCS BaNCS) are read-only unless a specific control needs a change. We do not force a stack swap. The stack you run is agreed in writing at scoping so there is no surprise licence cost during rollout.

Channel VAPT (web + mobile + API): typically Rs. 1.5 to 6 lakh depending on surface size. RBI CSITE / IS Audit readiness sprint: Rs. 4 to 8 lakh. Payment infra DDoS + WAF setup: Rs. 2 to 4 lakh plus vendor licence. Monthly managed SOC + incident response retainer: Rs. 80,000 to 2.5 lakh depending on log volume and coverage window. Fixed-price scoping in 48 hours after a short call.
Explore More

Related services

Get inspection-ready before the deadline

15-min call. Tell us the regulator, the scope, the deadline. We come back with a fixed-price plan and named tester CVs in 48 hours.

Decipher Assistant
Typically replies instantly