logo

IRDAI 2026 Cybersecurity Guidelines for Insurance Companies

ID: 310085fa-2ac6-5fdd-baca-96b43d63a67d

STIX ID: report--310085fa-2ac6-5fdd-baca-96b43d63a67d

Feed Name: Security Boulevard

Date Published: 2026-04-25

Date Updated: 2026-04-25

Author: Shikha Dhingra

...
...

The post summarizes IRDAI's 2026 cybersecurity guideline updates for insurers, marking a shift from static compliance to continuous cyber resilience. Key changes include expanded board and CISO responsibilities, separation of CISO from IT, introduction of an IT Steering Committee, removal/merging of certain roles and committees, mandatory external cybersecurity experts, an exception management framework, stricter audit and reporting timelines, and enhanced technical controls (regular penetration testing, infrastructure segregation, MeitY-empaneled cloud use, cryptographic inventory, immutable backups). The article concludes with a practical compliance checklist for insurers to align with the new requirements.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.