惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Apple Machine Learning Research
Apple Machine Learning Research
爱范儿
爱范儿
博客园_首页
博客园 - 【当耐特】
V
Visual Studio Blog
博客园 - 叶小钗
月光博客
月光博客
美团技术团队
J
Java Code Geeks
小众软件
小众软件
Y
Y Combinator Blog
博客园 - Franky
Martin Fowler
Martin Fowler
博客园 - 聂微东
Microsoft Azure Blog
Microsoft Azure Blog
IT之家
IT之家
MyScale Blog
MyScale Blog
人人都是产品经理
人人都是产品经理
Microsoft Security Blog
Microsoft Security Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
阮一峰的网络日志
阮一峰的网络日志
酷 壳 – CoolShell
酷 壳 – CoolShell
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
云风的 BLOG
云风的 BLOG

MEDIANAMA

India in talks with US, Anthropic for Mythos access; no Indian firms in Project Glasswing yet Including OTTs in TRAI’s spam protection draft rules a ‘regulatory overreach’: IAMAI Eternal Q4FY26: All Users Pay Higher Platform Fee, Only Some Get Discounts Amazon, Meta to challenge PhonePe-Google Pay dominance as UPI cap delayed since 2020 Meta failed to protect the safety of under-13s: European Commission If markets and regulators are ready for network slicing, we are ready: JIO Why defining ‘news’ won’t fix the free speech problems of draft IT Rules? #NAMA Eternal Q4FY26: Goyal Dismisses AI Disruption Risk as Zomato Quietly Builds Agentic Commerce Infrastructure Karnataka files appeal challenging the bike taxi ban lift in the Supreme Court How did WhatsApp turn 17 govt. flags into 9,400 digital arrest scam bans? Google Wallet integrates Aadhaar as digital ID, expands India’s mobile identity ecosystem Kerala HC issues notice on MediaOne’s Facebook page block in India MeitY warns VPN providers against enabling access to blocked betting platforms Shreya Singhal targeted private censorship. Today’s threat is the State #NAMA Amazon scales its quick delivery service ‘Amazon Now’ in 100 cities Can MeitY issue binding rules via advisories? Experts raise alarm over draft IT Rules #NAMA How 2019 election code of ethics became India’s three-hour content takedown mandate #NAMA Australia proposes new levy on big tech to fund news, opens draft law for consultation ‘judge, jury, executioner’: experts warn of Inter-Departmental Committee (IDC) overreach under New draft IT Rules Lowdown: TRAI flags low deployment under PM-WANI in public Wi-Fi consultation paper Why the NBFC licence matters for MobiKwik China blocks Meta-Manus deal, asserts origin-country jurisdiction: what this means for India ‘No transparency’: experts warn of expanding powers to block online speech in India #NAMA X launches standalone iOS messaging app XChat with encryption in India How India’s content takedown framework was built and where It has gone wrong #NAMA Claude Mythos puts India on alert: CERT-In, telcos, banks assess unprecedented cyber risks Explained: why did the RBI cancel Paytm’s banking licence? Meta now instantly blocks content in India Govt. asks ZEE5 to halt ‘Lawrence of Punjab’ web series release Online Gaming Rules notified, to be in effect from May 1, what are the major changes?
Lowdown: Insurers have to comply with DPDP as IRDAI updat...
Prabhanu Kumar Das · 2026-04-17 · via MEDIANAMA

Issued on April 6, 2026, the Insurance Regulatory and Development Authority of India (IRDAI) updated its Information and Cyber Security Guidelines, which apply to regulated entities (REs), including insurers, Foreign Reinsurance Branches (FRBs), and intermediaries such as brokers, corporate agents, web aggregators, and third-party administrators (TPAs). Compliance is mandated from the current financial year, replacing the 2023 guidelines.

Changes from the previous guidelines

  • The Information Security Risk Management Committee (ISRMC) must now meet at least quarterly, up from twice a year.
  • The Chief Information Security Officer (CISO) must not have a direct reporting relationship with the Head of IT and must not be given business targets.
  • Exception approvals are now tiered by duration: up to three months require CISO approval; three months to one year require ISRMC approval; beyond one year require Board approval. All exceptions exceeding 12 months must undergo reassessment and re-approval, and all exceptions must formally document the associated risk.
  • Insurance intermediaries must submit their audit compliance report from a CERT-In empanelled auditor within 30 days of completion of the audit.
  • REs must now take appropriate technical and organisational measures to comply with the Digital Personal Data Protection Act (DPDP Act).
  • External penetration testing must now be grey-box or white-box testing, and conducted at least once every six months by a CERT-In empanelled auditor.
  • Organisations must maintain an up-to-date inventory of cryptographic assets to prepare for the transition to post-quantum cryptographic environments.
  • REs must contractually require service providers to obtain prior written permission before any further sub-outsourcing.
  • Cloud service providers (CSPs) must be empanelled by the Ministry of Electronics and Information Technology (MeitY) and hold a valid Standardisation Testing and Quality Certification (STQC) audit status. Organisations must sign non-disclosure agreements (NDAs) with CSPs covering privacy, confidentiality, security, and business continuity. They must contractually require CSPs to eliminate all data from disks and backups upon contract termination.
  • Immutable backup and resilient components must be available for critical hardware.

Data Protection

  • All information assets must be classified into one of four tiers: Public, Internal, Restricted, or Confidential, with security controls calibrated to each level.
  • Dual-tag any Personally Identifiable Information (PII): classified under the standard four-tier system and separately flagged as PII.
  • Encrypt confidential information when transmitting it outside the organisation’s network, including over the internet, and when stored on mobile or removable media.
  • Review classification labels at least every two years.
  • Sensitive data that is not regularly accessed must be removed from the network and either operated as a standalone system or fully virtualised and powered off until needed.

Strengthening Cybersecurity Measures

  • Access to all systems must follow the principles of least privilege, need-to-know, segregation of duties, and individual accountability.
  • Users must change passwords every 45 days; previously used passwords must be blocked from reuse.
  • Privileged access must be limited to those with documented business justification, comprehensively logged, and reviewed at regular intervals. Vendors and contractors must not gain privileged access without close supervision and monitoring.
  • Organisations must deploy perimeter security, including firewalls and intrusion detection systems, segment networks based on data classification, implement micro-segmentation to counter lateral movement, and deploy WAFs for all web-facing applications.
  • All connections to high-severity systems from outside the organisation’s network require two-factor authentication.
  • Organisations must implement DMARC, SPF, and DKIM standards to reduce the prevalence of spoofed emails, use DNS filtering to block malicious domains, and deploy sandboxing to analyse and block malicious email attachments.
  • Cryptographic controls must be applied based on data classification. Organisations must define a key management lifecycle, protect keys from modification and loss, and not transmit keys over networks unless through secure channels.
  • Risk assessments must be conducted at least annually and ahead of major technology changes, new outsourcing arrangements, or granting external access to critical systems

Audits and Compliance

  • An independent assurance team must carry out an annual audit and present the audit plan and findings to the Audit Committee, RMC, or Board, as applicable.
  • The independent assurance auditor must be rotated every three years.
  • Insurers must submit their audit report to IRDAI within 90 days of the end of the financial year or within 30 days of audit completion, whichever is earlier.
  • All cyber incidents must be reported to CERT-In within six hours of detection, with copies to IRDAI and other relevant regulators.
  • Business Continuity Planning (BCP) and Disaster Recovery (DR) plans must be tested at least annually, with results reported to the ISRMC. Tests must cover real disaster scenarios, not only planned shutdowns.

Other Key Clauses

  • FRBs must comply with these guidelines on a comply-or-explain basis, subject to a reasonably justifiable explanation.
  • Insurance agents, micro-insurance agents, point-of-sale persons, and individual surveyors fall outside the guidelines’ direct scope; however, insurers must ensure that these entities follow a minimum security framework defined under the insurer’s Board-approved policy.
  • The CISO may engage externally certified forensic experts for investigations as and when required.
  • Organisations must participate in national and sectoral cybersecurity exercises and drills, such as CERT-In’s Cyber Security Exercises Programme.
  • All third-party vendor contracts must include right-to-audit clauses. If a vendor holds a valid ISO 27001 certification covering the scope of the services provided, the organisation may waive periodic audits, subject to the vendor’s self-certification and submission of valid certification copies.
  • For remote work, organisations must provision VPN, endpoint protection, data encryption, and data loss prevention (DLP) mechanisms on all user systems, and must conduct hardening checks on systems returned to the office.

Also read

Post navigation

Under the Commission’s proposal, Google would have to share a set of anonymised data including user queries, clicks, rankings and search result pages, with rivals in the European Economic Area

Amnesty urges withdrawal of Draft IT Amendment Rules 2026, citing censorship and surveillance risks.