The Reserve Bank of India has issued an immediately effective framework governing cybersecurity, technology risk, resilience and assurance at commercial banks. It applies to banking companies other than small finance banks, payments banks and local area banks, as well as corresponding new banks and the State Bank of India. The framework replaces existing directions, instructions and guidelines on cybersecurity and information technology governance for commercial banks while preserving actions and liabilities under the repealed requirements. Banks must establish board-approved technology, information security, cybersecurity, business continuity and incident response policies, reviewed at least annually. Governance requirements include a board-level Information Technology Strategy Committee that meets quarterly, an independent chair with at least seven years of relevant experience, and a Chief Information Security Officer who is independent of the head of information technology and reports to the executive overseeing risk management. Banks must also maintain a continuously monitored Cyber Security Operations Centre, implement risk-based controls across information assets, applications, networks, access management and third-party arrangements, and retain accountability for outsourced security risks, including specified controls for third-party automated teller machine switch providers. Cyber incidents must be reported to the Reserve Bank of India within six hours of detection and proactively notified to the Indian Computer Emergency Response Team. Vulnerability assessments for critical or customer-facing systems in the demilitarized zone are required at least every six months, with penetration tests at least annually. Disaster recovery drills for critical systems must occur at least every six months and cover a full working day, while recovery planning must target minimal recovery time and a near-zero recovery point for critical systems. Foreign banks operating through Indian branches may use a comply-or-explain approach for specified governance, risk, audit and operational provisions, subject to the Reserve Bank of India accepting the justification through supervision.