31 Aug 2026, 08:33 AM 2 min readtechDaily Pulse

India Tightens Cybersecurity Regulations for Banks and Power Infrastructure

New regulations mandate 24x7 security divisions and a 6-hour incident reporting timeline for critical infrastructure.

[New Regulatory Framework]:

India has significantly strengthened its cybersecurity landscape with new mandates targeting critical sectors. The Reserve Bank of India issued updated cybersecurity directions on July 31, 2026, for commercial banks, while the Central Electricity Authority has published the Cyber Security in Power Sector Regulations, 2026. These regulations impose strict obligations on power generation, transmission, and grid dispatch infrastructure, requiring the establishment of 24x7 Information Security Divisions and mandatory IT/OT isolation to prevent cross-system breaches.

[Compliance and Reporting]:

The new rules introduce rigorous operational requirements, including a strict 6-hour incident reporting timeline for power sector entities. Furthermore, the IT Rules 2026 have set stringent compliance timelines for digital platforms, requiring action on unlawful or harmful content within three hours. These measures are designed to enhance national resilience against cyber threats, ensuring that critical infrastructure and digital services can withstand and respond to sophisticated attacks in an increasingly digitized economy.

[Market Outlook]:

The regulatory push is accompanied by strong growth in IT spending. Gartner forecasts India's IT services spending to grow by 11.1% in 2026, driven by enterprise investments in infrastructure as a service and application modernization. Additionally, software spending is projected to reach $24.7 billion, a 17.6% increase, fueled by rising demand for AI-enabled software solutions. As companies invest in compliance and modernization, the Indian IT sector is poised for significant expansion, balancing regulatory adherence with technological innovation to support the country's digital growth.
Pulse Intelligence
Context & Impact
  • Cybersecurity has become a top priority for the Indian government due to the increasing frequency of digital attacks.
  • The power sector has been identified as a critical infrastructure target requiring specialized protection.
  • Previous IT rules were less stringent regarding content removal timelines.
  • Banks and power companies will need to increase their cybersecurity budgets to meet the new compliance standards.
  • IT services firms will likely see increased demand for consulting and security implementation services.
  • The 3-hour content removal rule will force digital platforms to invest heavily in automated moderation tools.

Increased compliance costs for banks and power firms may impact short-term margins, but the surge in IT spending is a major positive for the tech services sector.

The Indus Pulse is committed to accuracy and transparency.
Report a CorrectionEditorial Standards