Case Study | BFSI / NBFC
How a ₹2,000 Cr NBFC Achieved Full RBI Cybersecurity Compliance in 6 Months
Size: 800+ employees
Location: Delhi NCR
Timeline: 6 months
Client Background
Our client (name withheld for confidentiality) is a Delhi-based NBFC with an AUM of over ₹2,000 crore, operating across 12 states through a digital lending platform. With RBI's enhanced cybersecurity framework taking effect in 2024, the client faced an urgent regulatory mandate to demonstrate robust information security controls or risk operational restrictions.
The Challenge
The client came to MDIT Services with three critical problems:
- No formal ISMS: Security controls were ad-hoc with no documented policies, risk register, or incident response plan.
- Legacy infrastructure exposure: A network assessment had flagged 127 open vulnerabilities across their loan origination system and payment gateway integrations — 23 rated Critical or High.
- RBI deadline pressure: The client had received an RBI advisory requiring a cybersecurity audit report and remediation roadmap within 90 days.
“We had 90 days to demonstrate compliance or face operational restrictions. MDIT was the only vendor who gave us a realistic roadmap — not just a sales pitch.”
— CTO, Client NBFC (name withheld)
MDIT's Approach
Phase 1 — Assessment (Weeks 1–4)
- Comprehensive network & infrastructure VAPT across 340 IP addresses
- Web application pentest of loan origination portal (OWASP Top 10 + business logic)
- ISO 27001 gap assessment — scored 34% against Annex A controls
- RBI Cybersecurity Framework gap mapping
Phase 2 — Remediation & ISMS Build (Weeks 5–16)
- Critical vulnerability remediation: closed all 23 Critical/High CVEs within 30 days
- ISO 27001 ISMS implementation: 47 policies, 12 procedures, risk register for 89 assets
- Security incident response plan (SIRP) with CERT-In notification workflow
- Employee security awareness training — 800 staff across 12 state offices
Phase 3 — Audit & Certification (Weeks 17–26)
- Internal audit against ISO 27001:2022
- Stage 1 & Stage 2 certification audit coordination with accredited CB
- RBI cybersecurity audit report preparation and submission
- 24/7 SOC monitoring setup with 4-hour incident SLA
Results
Facing a Similar Compliance Challenge?
Our CERT-In empanelled team has helped 50+ BFSI companies achieve RBI, PCI DSS, and ISO 27001 compliance. Get a free scoping call today.
Related MDIT Services
- RBI Cybersecurity Framework Compliance — Complete guide to meeting RBI cyber security requirements for NBFCs and banks
- SOC Services — 24×7 Security Operations Centre for continuous threat monitoring and incident response
- Vulnerability Assessment & Penetration Testing — Identify and remediate security gaps before attackers exploit them
