Indian private bank — RBI CSF gap closure across 11 control domains.
Closed 96 RBI CSF gaps, refreshed the cyber-crisis playbook and integrated SOC alerts into board reporting.
- RBI gaps closed
- 96
- Tabletop exercises
- 4
- RBI inspection rating
- Improved

GRC, cybersecurity and audit services aligned to RBI, SEBI, IRDAI, CERT-In and DPDP Act.
MAST helps Indian banks, NBFCs, insurers, capital-market participants, fintechs and healthcare providers meet RBI, SEBI, IRDAI, CERT-In and DPDP Act 2023 obligations — alongside global standards such as ISO 27001, PCI DSS and SOC 2.
Reserve Bank of India — Cyber Security Framework for banks, NBFCs and PSOs.
SEBI Cybersecurity & Cyber Resilience Framework for regulated entities.
Information & Cyber Security guidelines for insurers.
Directions on incident reporting, log retention and SBOM.
Digital Personal Data Protection Act compliance programmes.
Ministry of Electronics and IT advisories and intermediary rules.
UPI, IMPS and RuPay security circulars for ecosystem participants.
Each engagement is led by a senior consultant with sector experience in your jurisdiction.
ISMS programmes for banks, NBFCs, GICs and IT services exporters.
Learn moreReadiness and Type II observation for Indian SaaS and IT services firms.
Learn moreRBI-tokenisation and UPI-aware PCI programmes.
Learn moreContinuous compliance against RBI, SEBI, IRDAI and DPDP.
Learn moreCo-sourced IT internal audit aligned to IIA standards.
Learn moreCERT-In empanelled-equivalent testing methodology with attestation.
Learn moreAnonymised snapshots of MAST delivery in your jurisdiction. Every engagement is sponsored by a named Lead Auditor.
Closed 96 RBI CSF gaps, refreshed the cyber-crisis playbook and integrated SOC alerts into board reporting.
Mapped 230+ CSCRF controls, deployed a continuous-monitoring dashboard and submitted CSCRF compliance evidence.
Refreshed the ISMS, third-party risk programme and incident response procedures aligned to IRDAI ICS guidelines.
Delivered notice & consent re-design, DPO function, data principal rights workflow and cross-border transfer assessments.
Built control inventory and evidence automation across AWS, Okta and GitHub for a 6-month observation window.
Implemented 6-hour incident reporting, 180-day log retention and SBOM workflows across product and IT estate.
Yes. We deliver RBI-aligned programmes for SCBs, SFBs, NBFCs, PSOs, payment aggregators and account aggregators.
Yes. Our DPDP programmes cover notice and consent, data principal rights, DPO appointment, cross-border transfers and breach response.
Yes — including 6-hour incident reporting, 180-day log retention, SBOM and ICT product compliance.
Tell us about your India programme — a senior consultant from MAST responds within one business day.