Red Teaming Under the RBI's 2026 Directions
The 2026 Directions mention red teaming, and the word they use is "may". What that means in practice, and why an honest reading matters more than a convenient one.
Whether an Indian regulator requires a red team is the question most vendors answer badly, in the direction that suits them.
The honest answer for the RBI's 2026 cyber security Directions is that red teaming appears as something a regulated entity may undertake, not something it shall. That single word is the whole subject, and softening it into an obligation is the most common misrepresentation in this market.
What is actually mandatory, and what is not
The Directions are prescriptive about the two halves of routine testing and permissive about adversarial exercises. Vulnerability assessment and penetration testing carry defined intervals — six months and twelve months respectively, which is itself a distinction many organisations miss, since "we run an annual VAPT" does not satisfy a six-month VA requirement.
Red teaming sits in different language. It is contemplated, it is encouraged for entities whose risk profile warrants it, and it is not given a mandatory cadence in the way VA and PT are.
Security Brigade maintains the paragraph-level reading, including which entity types the Directions bind and where the intervals apply: red teaming requirements and the RBI Directions, 2026.
Why "may" still matters
A permissive provision is not an irrelevant one. Three practical consequences:
Supervisory expectation is not the same as the text. What a regulator expects of a large, systemically important entity is not what the minimum wording requires of everyone. A bank of a certain size explaining that it has never tested detection because the Directions said "may" is making a textual argument, not a risk one.
The mandatory testing has a ceiling. VA and PT establish what is broken. Neither establishes whether anyone would notice an intruder who got past them, and that is a question the intervals do not reach however diligently they are met.
It shapes what to buy first. Because it is permissive, a red team is a risk decision rather than a compliance one — which means it should be bought when it will change something, not to satisfy an auditor. If your penetration tests still surface unpatched hosts, that is where the money belongs. The sequencing argument is in purple team: when it beats a red team.
Where an adversarial exercise is named more firmly
Threat-led penetration testing is the term to watch. In several jurisdictions it is a defined, supervised programme rather than a service a firm sells, with prescribed threat intelligence, prescribed scoping and regulator involvement. Anyone comparing "we do TLPT" claims should establish which framework is meant, because the phrase is used both ways.
Reading a vendor's compliance claim
Two questions settle most of it:
- Which instrument, and which paragraph? A claim that cannot be pinned to a citation is marketing. The Directions are public.
- Does the claim say "shall" where the instrument says "may"? If a proposal tells you red teaming is mandatory under the 2026 Directions, that is a statement you can check, and it is wrong.
The same discipline applies to who may perform the work. CERT-In empanelment governs a large class of Indian audit requirements, and whether it applies to a given engagement is a question of the instrument that binds you rather than of a vendor's preference.
Continue reading
All articles →Choosing a Red Team Provider
Every firm answers yes to every capability question. Six that are harder to answer generically, and what a real answer sounds like.
Red Teaming and SEBI CSCRF
What the Cyber Security and Cyber Resilience Framework asks of regulated entities, where adversarial testing sits within it, and how the tiering decides how much applies to you.
Social Engineering Assessments and the Consent They Require
Testing people is not testing systems. What can be assessed, what must be agreed first, and why individual results should almost never leave the room.