How MDIT Helped a Leading NBFC Achieve RBI Cybersecurity Framework Compliance

Case Study | BFSI / NBFC

How a ₹2,000 Cr NBFC Achieved Full RBI Cybersecurity Compliance in 6 Months

Industry: NBFC / Lending
Size: 800+ employees
Location: Delhi NCR
Timeline: 6 months

Client Background

Our client (name withheld for confidentiality) is a Delhi-based NBFC with an AUM of over ₹2,000 crore, operating across 12 states through a digital lending platform. With RBI's enhanced cybersecurity framework taking effect in 2024, the client faced an urgent regulatory mandate to demonstrate robust information security controls or risk operational restrictions.

The Challenge

The client came to MDIT Services with three critical problems:

  • No formal ISMS: Security controls were ad-hoc with no documented policies, risk register, or incident response plan.
  • Legacy infrastructure exposure: A network assessment had flagged 127 open vulnerabilities across their loan origination system and payment gateway integrations — 23 rated Critical or High.
  • RBI deadline pressure: The client had received an RBI advisory requiring a cybersecurity audit report and remediation roadmap within 90 days.

“We had 90 days to demonstrate compliance or face operational restrictions. MDIT was the only vendor who gave us a realistic roadmap — not just a sales pitch.”

— CTO, Client NBFC (name withheld)

MDIT's Approach

Phase 1 — Assessment (Weeks 1–4)

  • Comprehensive network & infrastructure VAPT across 340 IP addresses
  • Web application pentest of loan origination portal (OWASP Top 10 + business logic)
  • ISO 27001 gap assessment — scored 34% against Annex A controls
  • RBI Cybersecurity Framework gap mapping

Phase 2 — Remediation & ISMS Build (Weeks 5–16)

  • Critical vulnerability remediation: closed all 23 Critical/High CVEs within 30 days
  • ISO 27001 ISMS implementation: 47 policies, 12 procedures, risk register for 89 assets
  • Security incident response plan (SIRP) with CERT-In notification workflow
  • Employee security awareness training — 800 staff across 12 state offices

Phase 3 — Audit & Certification (Weeks 17–26)

  • Internal audit against ISO 27001:2022
  • Stage 1 & Stage 2 certification audit coordination with accredited CB
  • RBI cybersecurity audit report preparation and submission
  • 24/7 SOC monitoring setup with 4-hour incident SLA

Results

ISO 27001
Certified in 6 months
100%
Critical vulnerabilities remediated
RBI ✓
Cybersecurity audit cleared
₹0
Regulatory penalties incurred

Facing a Similar Compliance Challenge?

Our CERT-In empanelled team has helped 50+ BFSI companies achieve RBI, PCI DSS, and ISO 27001 compliance. Get a free scoping call today.

Schedule Free Consultation →

Related MDIT Services

Discuss a Similar RBI Compliance Engagement →

Free Consult