India's banking regulator (RBI) does not want the CISO Reporting to IT
The 2026 Directions put the CISO's reporting line in writing — outside IT, into risk, with no business targets. The RBI regulates over 9000 financial entities, ranking one of largest in the world.
Most cybersecurity regulation is about controls.
Encrypt this.
Log that.
Patch within X days.
Test annually.
The CISO section of the RBI (CBs – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 is about something harder to buy and impossible to fake in an audit: where the security function sits on the org chart.
Paragraph 27 opens with a sentence that most banks will read twice:
The CISO shall not have any direct reporting relationship with the Head of IT and shall not be given any business targets.
And paragraph 28(6) closes the loop:
The CISO shall directly report to the Executive Director or equivalent executive overseeing the risk management function.
That's not a control.
That's a governance verdict.
Why the reporting line is the control
Security teams already know the failure mode this is written against.
The CISO finds an unpatched internet-facing system, a privileged account nobody owns, a vendor with production access and no contract clause.
The finding goes up.
It lands on the desk of the Head of IT, who is measured on uptime, delivery dates, and the release calendar that the fix would break.
The risk gets "accepted."
The register gets updated.
Nothing changes.
When the CISO reports into IT, the second line of defence is being appraised by the first line.
Every escalation is a complaint about your own boss.
Every "no" is a career decision.
The independence exists on paper and evaporates in the performance review.
RBI's fix is structural rather than behavioural: move the reporting line to the executive who owns risk, not the executive who owns delivery.
The person the CISO answers to should be someone whose incentives improve when uncomfortable findings surface early.
This isn't new thinking, the same requirement appeared in RBI's Master Direction on IT Governance, Risk, Controls and Assurance Practices, which stated that the CISO should have no direct reporting relationship with the Head of IT and should not be given business targets.
What the 2026 Directions do is restate it inside a consolidated, bank-specific cybersecurity framework, alongside the staffing, budget and seniority clauses that make the reporting line actually mean something.
The clause everyone skips: "shall not be given any business targets"
Read that half-sentence again, because it closes the obvious workaround.
You can move the CISO out of IT and still neutralise the role by making them a revenue enabler, a security head with a slice of the digital-onboarding target, or a KPI tied to time-to-launch for new products.
Attach a number to a control function and you have converted it into a sales function with a certificate on the wall.
RBI's language removes that lever.
The CISO is not to be incentivised on outcomes that create pressure to approve.
Practically, this means banks should audit not just the org chart but the scorecard.
If the CISO's annual KRAs contain a digital adoption number, a launch count, or anything indexed to business volume, the reporting line has been fixed and the incentive has not.
Seniority, tenure and staffing, the clauses that give the role teeth
Independence without standing is just isolation.
The Directions address that too.
Rank. The CISO is to be a senior-level executive, preferably at General Manager grade or equivalent.
A CISO two rungs below the CTO can be independent in the org chart and irrelevant in the room.
A reasonable minimum term. This is the anti-churn clause, and it cuts both ways: it stops the role being a revolving door, and it makes the CISO harder to remove for being inconvenient.
Security programmes run in multi-year arcs; a CISO who expects to be reassigned within twelve months will optimise for the twelve months.
Staffing commensurate with the bank. The CISO's office must be adequately staffed with people who have real technical expertise, scaled to business volume, extent of technology adoption and complexity.
In other words: a bank running a heavy digital stack cannot staff security like a bank that isn't.
Budget set by the threat landscape. The budget for information security and cybersecurity is to be determined with the current and emerging threat landscape in view, not as a residual percentage of the IT budget after the IT roadmap has been funded.
That distinction is the difference between a security budget and a security leftover.
Standing, visibility and the SOC
Three more clauses shape how the CISO actually operates day to day:
- Permanent invitee to the IT Strategy Committee and the IT Steering Committee. Not "may be invited." The CISO is in the room where the technology bets are made, before they are made.
- The CISO's office manages and monitors the Security Operations Centre and drives cybersecurity projects, and is accountable for the effective functioning of the security solutions deployed. Note what this does to the neat three-lines-of-defence model: RBI has given the second-line CISO genuine operational ownership. The SOC is not an IT service that reports security news to the CISO, it is the CISO's.
- Board-level reporting. Paragraph 28(7) requires the CISO to place a review of the bank's cybersecurity risks, arrangements and preparedness before the Board or the Risk Management Committee. (Under the earlier IT Governance Master Direction, this presentation to the board or risk committee was set at a quarterly cadence; banks should check the frequency specified in the full 2026 text.)
The last one matters more than it looks.
Independence from IT is worth little if the only route to the Board runs through the executives whose decisions you are reporting on.
What banks will actually have to fix
Expect supervisors to look past the policy PDF and at the artefacts:
- The org chart, including dotted lines. A solid line to the ED-Risk with a dotted line to the CTO for "administrative purposes" is the compliance theatre this clause exists to catch.
- The appointment letter, does it specify a term?
- The KRA sheet, any business target, anywhere?
- The budget document, is there a distinct information security budget line, and can the bank show what threat assessment drove the number?
- The headcount, vacancy rates and skills in the CISO's office versus the size of the estate they are defending.
- Committee minutes, is the CISO recorded as present at ITSC and IT Steering Committee, consistently?
- Role separation, a CISO who also owns IT infrastructure or IT operations has not been separated from IT; they have been given two hats and a conflict.
What the Directions don't say
Worth stating plainly, because over-reading is its own risk:
- This is not a ban on the CISO working with IT. Security cannot be delivered without the people who run the systems. What's prohibited is the reporting relationship, not the working one.
- It does not mandate a direct line to the MD/CEO or the Board. The destination specified is the Executive Director, or equivalent, overseeing risk management.
- It does not relieve IT of security responsibility. Owning the SOC does not make the CISO the only person accountable for a hardened estate.
The takeaway for cyber leaders
Every mature security programme eventually discovers the same thing: the technical work is the easy part.
The hard part is whether an inconvenient "no" survives contact with a delivery deadline.
RBI has now written the answer into the org chart.
The CISO doesn't report to the person whose project they might have to stop, isn't paid on the outcome they might have to delay, holds a rank that makes the objection audible, and has a term long enough to see the consequences.
If your bank's response to this section is to redraw one box on a slide, you've read it as a compliance item.
It was written as an independence guarantee.
This piece is based on the CISO provisions (paragraphs 27–28) of the RBI (CBs – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026.