Regulation & Compliance - June 17, 2026 - 9 min read
The Broker CISO's 2026 Workplan: Running the Audit, VAPT and Board-Reporting Side of IRDAI's Cyber Security Guidelines
IRDAI's revised cyber security guidelines hand a broking firm's Chief Information Security Officer a defined annual workplan: an independent reporting line free of business targets, a vulnerability-assessment and penetration-testing cadence, an annual third-party security audit with non-conformities closed on the clock, a tested incident-response lifecycle, and a board pack that turns all of it into decisions. This piece is written for the broker CISO and the board they answer to, setting out how to operationalise audit, VAPT and reporting rather than restating the rule text.
By Sarvada Editorial Team