PrahiX

RBI · IT Governance · CERT-In

RBI cyber security framework, operated, not documented.

The policy gets written. The committee meets. The CISO is appointed. Then the direction asks for round-the-clock threat monitoring, detection and incident response — and that is not a document, it is a rota, a platform and three years of evidence that both existed. PrahiX is the operating layer underneath the governance, producing that evidence continuously across your network, your security estate and your branches.

24/7

SOC coverage, which the IT governance direction expects

6-hour

CERT-In reporting clock, with the timeline already assembled

One

evidence trail across network, security and physical estate

Why the governance half is the easy half.

Board-approved policy, an IT Strategy Committee, an IT Steering Committee, a CISO independent of IT operations — all of it is achievable in a quarter with the right advice. What follows is the part that runs for years and costs real money.

The policy is written; the operation is not

A cyber security policy that commits you to continuous monitoring and defined response times is a commitment somebody has to keep at 3am on a Sunday. The document is reviewed annually. The obligation runs every hour in between.

Your obligations scale with your layer

The NBFC framework grades by layer and asset size, and an entity that crosses into the Middle or Upper layer inherits materially heavier expectations — often mid-year, and usually without a matching increase in the team that has to meet them.

Round-the-clock is a staffing problem

A 24/7 SOC needs three shifts plus relief, in a market where security staff churn constantly. Most institutions end up covering business hours, documenting an intent to do more, and hoping the gap is never the finding.

Reporting clocks do not wait for the morning

CERT-In's six-hour window runs in parallel with RBI's own incident reporting expectations. Meeting either means detection, triage and a defensible timeline already exist when the clock starts — which is an operations capability, not a procedure.

What the platform does for the IS audit.

The governance structure is yours. The operating controls underneath it — and the record proving they ran — is what this replaces.

24/7 SOC coverage, staffed by you or by us

The direction expects round-the-clock threat monitoring, detection and incident response. Run the platform with your own team, or take it as SOC as a Service and let us cover the shifts — the evidence an auditor sees is identical either way.

Detection and escalation against defined SLAs

Severity classification and escalation paths are agreed during onboarding rather than described in the abstract, so "which incidents were material, who was told, and how quickly" is a question with a timestamped answer.

Incident timelines built while the incident runs

The artefacts a statutory report needs are assembled by the platform as events unfold, not by an analyst reconstructing the night afterwards from four consoles and a memory.

Something for the committees to actually review

An IT Strategy Committee and an IT Steering Committee need current operational reality in front of them, not a quarterly slide restating the policy. Coverage, incidents, response times and change history are produced continuously and read as a report.

Network and branches, not just the security stack

Availability, configuration drift and multi-site monitoring across branches and data centres sit in the same platform as the security telemetry — which matters, because IT operations and cyber security are examined as one estate.

Retention configured to your classification

The frameworks specify a period of readily searchable logs plus a longer archive, and the figures differ by entity type and layer. We configure retention to the window you are actually held to — a settings decision, not an architecture one.

The operating half of IT governance.

RBI's framework treats IT operations, information security, business continuity and outsourcing as one subject, because from a supervisory standpoint they are. Answering it from four systems invites the question about the seams between them.

IT operations and cyber security in one record

Availability, capacity and change history sit alongside detection, escalation and response. An examiner asking whether a service was down and whether it was attacked is asking about the same estate on the same day.

Every branch monitored the same way

Head office, branches, data centres and disaster-recovery sites are covered identically, so evidence of continuous monitoring does not have a hole where the locations without local IT presence should be.

Physical security is part of the estate

Cameras and access control at branches and currency-handling areas are monitored alongside everything else, so a physical event and a systems event can be examined as one incident rather than by two teams months apart.

Data stays where you need it

Built in India, deployed where your board and your supervisor expect it to sit. For regulated financial institutions this is usually the first question asked, and the one that ends evaluations early when the answer is wrong.

The difference at the IS audit

Evidence assembled after the fact

  • The audit period is the last financial year; two tools were replaced within it.
  • Monitoring coverage is asserted in a policy and demonstrated nowhere.
  • Incident response times are reconstructed from email threads.
  • The observation is not that you were breached — it is that you cannot show you would have known.

PrahiX — evidence as you operate

  • The period is covered continuously, across tool changes and site additions.
  • Coverage is a dated inventory, not an assertion.
  • Detection and escalation timings are in the timeline as they happened.
  • The audit is a report, not a project.

How the platform maps to what is asked.

Four stages, running continuously. Each one produces an artefact your next IS audit or supervisory review will ask you for.

  1. Establish continuous monitoring

    Connect the estate — identity, perimeter, endpoints, servers, cloud, core network and branch infrastructure, and the physical layer where you run it. Because coverage is itself an audit question, the inventory of what is and is not monitored becomes part of the record immediately.

  2. Detect and classify against your SLAs

    Detections are mapped to MITRE ATT&CK and scored, and severity classification and escalation paths are agreed with you rather than assumed. What counts as material, and who must know within what period, is settled before it matters.

  3. Respond, and record while responding

    Containment playbooks run with their approval model attached, and every enrichment, decision and action is appended to the incident timeline as it happens. By the time a report is due, the material for it already exists.

  4. Report to the committee and the auditor

    Coverage, incidents and timings, actions taken, availability, asset inventory and change history export per period and per entity — for the IT Steering Committee monthly, the Strategy Committee quarterly, and the IS audit when it comes.

What this replaces.

Compliance spend in banking usually goes to the assessment rather than to the thing being assessed. That is backwards, and it is why the same observations reappear each cycle.

What this replaces.
CapabilityA consultant per auditPoint tools plus a spreadsheetPrahiX as the operating layer
EvidenceAssembled retroactively, from whatever survivedExported per tool and reconciled by handAccumulated continuously as the platform operates
24/7 SOC coverageOut of scope — that was never the engagementYour team, which in practice means business hoursOn the platform, staffed by you or run by us
Short-clock incident reportA scramble, every timePossible, if the right person happens to be awakeTimeline already assembled when the clock starts
Branch and multi-site coverageSampled during the auditWherever a collector was installedEvery site monitored the same way
Committee reportingA slide deck restating the policyManually compiled each quarterGenerated from what actually happened
Log retentionWhatever each tool happened to keepPer tool, with a different window on eachOne retention policy, set to your classification
Cost shapePer audit, indefinitelyLicences plus internal time each cycleOne operating subscription

What PrahiX is, and is not

PrahiX supplies the operational controls and the evidence an IS audit or supervisory review examines. It does not certify you, it does not replace your auditor, and it does not absolve the governance obligations the framework places on you — the board-approved policy, the IT Strategy and Steering Committees, the CISO appointment and the risk decisions stay exactly where the RBI put them. What changes is that the operating half runs continuously, and the evidence exists before anybody asks for it.

  • 24/7 SOC monitoring, detection and response
  • Incident timelines aligned to statutory reporting clocks
  • Retention configured to your entity type and layer
  • Continuous asset, availability and change records

Trusted by operations teams across India

Founder customer logos

Have Questions? We've Got Answers.

In outline: a board-approved IT and cyber security policy reviewed at least annually, a defined governance structure with a board-level IT Strategy Committee and a management IT Steering Committee, a CISO who does not also run IT operations, round-the-clock security monitoring and incident response, a VAPT programme, business continuity arrangements, and incident reporting within defined timelines. The detail scales by entity type, NBFC layer and asset size, so confirm what applies to you before budgeting against the strictest tier.

Round-the-clock threat monitoring, detection and incident response is what the IT governance direction expects, and a security operations centre is the usual way of delivering it. Whether you build that capability, share it, or buy it as a service is your decision — PrahiX can be the platform your own team runs, or you can take it as SOC as a Service and we cover the shifts.

No, and be wary of anyone who says their product does. Compliance here is substantially a governance obligation — the policy, the committees, the CISO appointment, the risk decisions and the assurance function — none of which a platform can hold on your behalf. What a platform can do is run the operational controls and produce the evidence that they ran, which is a large share of what an IS audit examines and the share that cannot be retrofitted.

It depends on your layer and your asset size. The IT framework for NBFCs scales obligations upward through the layers, and entities in the Middle and Upper layers carry materially more than those below. The awkward case is crossing a threshold mid-year and inheriting heavier expectations without a matching budget cycle — worth scoping deliberately rather than discovering at the next inspection.

CERT-In's directions require reporting of specified cyber incidents within six hours of noticing them, and that runs in parallel with RBI's own incident reporting expectations. The practical constraint is not the form — it is having detection, triage and a defensible timeline inside those hours. The platform assembles that timeline as the incident runs, so the report is written from a record rather than from recollection.

The frameworks specify a period of readily searchable logs plus a longer archival window, and the figures differ by entity type — so the honest answer is to confirm yours rather than take a number from a vendor page. Once you have, retention is a configuration decision on the platform rather than a redesign.

No. It is one estate, monitored once, with reporting scoped per entity and per period so each filing draws on the same underlying record — see the SEBI CSCRF page for that side. Groups holding both licences are the case this was built for; the alternative is two sets of tooling that will eventually disagree about the same infrastructure in front of two different auditors.

Yes, and the sensible way to scope one is around your last IS audit: pick the observation you found hardest to close, and we will show you the evidence for it being generated continuously instead. That is a more useful test than a feature demonstration, and it is effectively the one your auditor will run next time.

Keep reading

Your next IS audit is already collecting evidence.

Or it is not, and you will find out in a few months. Show us your estate and your entity classification, and we will scope what continuous monitoring and audit-ready reporting look like against the obligations you actually carry.