Client Background

The client is a leading retail bank in India operating an expanding digital franchise across internet banking, mobile banking and assisted channels. Following a detailed IT examination by the national banking regulator, the bank faced a long list of action points, regulatory correspondence on the conduct of disaster recovery drills, and a run of service outages across its core and digital platforms. A recent supervisory action against a peer bank for persistent IT control failures had also raised the stakes for the board. Cedar was engaged to support the board's IT Strategy Committee with a consolidated, decision-ready view of information security, business continuity and IT risk.

Cedar’s Approach

Cedar applied a structured risk-review approach that linked regulatory findings, operational incidents and security telemetry to a single set of prioritised recommendations, each with a named owner function and a clear status for the committee to track.

Regulatory Compliance Review – Cedar consolidated the status of the IT examination action points and the cyber security assessment observations, reconciling the bank's own compliance view with the regulator's assessment, and analysed the regulator's concerns on disaster recovery drill duration and coverage for critical digital channels.

Peer Lessons and Repeat Observations – Using the supervisory action against a peer bank as a lens, Cedar traced recurring observations across successive inspection cycles in IT asset inventory, patch management, user access, vendor risk, data leak prevention and business continuity, and translated them into a tracked action plan covering a master asset register, end-of-life reporting, two-factor authentication for critical applications and audit validation.

Business Continuity and Downtime Risk – Cedar root-caused recent outages to process gaps in database maintenance, certificate management, DNS changes and monitoring coverage, and recommended completing business impact analysis for all critical and high-criticality applications, revisiting recovery time objectives for committee approval and moving towards near-zero data loss for critical systems.

Security Posture and Risk Indicators – Cedar reviewed privileged and vendor access practices, role-based access controls, obsolete infrastructure, certificate expiry, operating system licence compliance, SOC effectiveness, vulnerability closure, third-party risk assessments, cloud posture and brand monitoring, and presented them through a key risk indicator dashboard with clear thresholds.

Strategic Outcome and Way Forward

The IT Strategy Committee received a single, structured view of the bank's regulatory exposure, resilience gaps and security posture, with each issue linked to a recommendation, an accountable function and a follow-up mechanism. The review sharpened attention on the areas regulators had flagged repeatedly, and several actions were already under way, including a revised business continuity management policy placed for approval, monthly end-of-life reporting to senior risk and technology leaders, and tighter tracking of patch and asset inventory exceptions through the IT steering committee.

The agreed way forward prioritises completing business impact analysis and approving revised recovery objectives, curtailing default vendor administrative rights, establishing a master tracker and monitoring tool for certificates, and closing overdue vulnerability observations within policy timelines, with progress reported to the committee at each subsequent meeting.

Relevant Client Cases