Cloud Armor IT Consultancy logo

IRDAI 2023 Cyber Security Guidelines: SOC, VAPT & Reporting

18 July 2026 · 3 min read · Cloud Armor Security Team

  • IRDAI
  • Compliance
  • Insurance
  • Managed SOC
  • Ayati One

TL;DR — IRDAI's Information and Cyber Security Guidelines, 2023 superseded the 2017/2022 advisories with a unified, governance-driven model for insurers and intermediaries. The operational core: run a SOC / end-to-end monitoring, conduct VAPT at least twice a year (critical findings fixed within 30 days), retain ICT/application logs for 180 days, and report cyber incidents to IRDAI and CERT-In within 6 hours. An annual audit by a CERT-In-empanelled auditor is required.

For an insurer, the IRDAI guidelines — not a global SIEM vendor's datasheet — are what an audit measures. And unlike much compliance writing, these guidelines are refreshingly concrete about monitoring, testing cadence and timelines, which makes them straightforward to operationalise if you build to them deliberately.

The operational mandates

  • SOC / continuous monitoring with end-to-end log visibility
  • Log retention of 180 days (rolling) for ICT and application logs
  • VAPT at least twice yearly, critical findings remediated within 30 days
  • 6-hour incident reporting to IRDAI and CERT-In
  • Annual cybersecurity audit via a CERT-In-empanelled auditor
  • Board-approved policy, CISO, and a cyber-crisis management plan
The two cadence traps Insurers most often slip on the twice-yearly VAPT with a 30-day critical-fix SLA and the 6-hour reporting clock. A once-a-year pen test and a business-hours SOC will not satisfy either — both require an operating rhythm, not an annual project.

The 180-day log retention detail

The 180-day rolling retention requirement is specific and testable. It means your monitoring platform must retain searchable ICT and application logs for six months — a policy question that gets expensive fast on per-GB SIEM pricing, and a residency question under the DPDP framework.

How Ayati One fits IRDAI A 24×7 managed SOC for the monitoring and 6-hour-reporting requirement, continuous VA to sustain the twice-yearly testing cadence (paired with our VAPT practice for the formal assessments), and 180-day retention at flat per-asset pricing — no per-GB penalty for keeping logs — with data kept in India.

Mapping the guidelines to controls

IRDAI requirement Operational need Ayati One
SOC / end-to-end monitoring 24×7 detection + triage Managed SIEM + AI-SOC
180-day log retention Searchable 6-month logs Per-asset, no ingestion meter
VAPT twice yearly, 30-day fix Continuous + periodic testing Continuous VA + VAPT
6-hour incident reporting Real-time detect-to-report Analyst triage 24×7
CERT-In-empanelled audit Auditable evidence Full case history + reporting

Frequently asked questions

Does IRDAI apply to intermediaries, not just insurers?

Yes — the 2023 guidelines extend to insurers and licensed intermediaries. Scope varies with size and role; we'll map it to your registration.

Can continuous VA replace the twice-yearly VAPT?

No — they're complementary. Continuous VA keeps exposure visible day-to-day; the formal twice-yearly VAPT is a distinct, deeper assessment IRDAI requires. Ayati One provides the first; our VAPT practice delivers the second.

How does IRDAI relate to the DPDP Act for insurers?

They stack. IRDAI governs your sectoral obligations; the DPDP Act & Rules 2025 govern personal data and breach notification across all sectors.


Meeting IRDAI's 2023 guidelines? Talk to our SOC engineers about a managed SOC with 180-day retention and the 6-hour clock covered, at flat per-asset pricing.

Blog timeline

Explore the full series

  1. 27 July 2026 · 4 min read

    Wazuh vs Commercial SIEM: The Real Enterprise Trade-off

  2. 27 July 2026 · 3 min read

    Managed SOC & SIEM With Data Residency in India

  3. 26 July 2026 · 3 min read

    Choosing an MSSP in Hyderabad, Dubai & the GCC

  4. 26 July 2026 · 8 min read

    IBM QRadar Alternatives: Ayati One as a Managed SIEM + AI-SOC

  5. 25 July 2026 · 3 min read

    An Arctic Wolf Alternative for India: Pricing & Residency

  6. 24 July 2026 · 2 min read

    A Rapid7 InsightIDR Alternative: Managed, In-Region SIEM

  7. 23 July 2026 · 3 min read

    A Microsoft Sentinel Cost Alternative: Beyond Per-GB Pricing

  8. 22 July 2026 · 3 min read

    IBM QRadar Migration: A Practical Path Off QRadar

  9. 21 July 2026 · 3 min read

    RBI Cybersecurity Framework: SOC Monitoring & 6-Hour Reporting

  10. 20 July 2026 · 3 min read

    SEBI CSCRF Compliance: SIEM, SOC & the M-SOC Option

  11. 19 July 2026 · 3 min read

    UAE NESA/SIA & Dubai ISR: Security Monitoring for Compliance

  12. 18 July 2026 · Currently reading

    IRDAI 2023 Cyber Security Guidelines: SOC, VAPT & Reporting

  13. 18 July 2026 · 3 min read

    The Enterprise DLP Implementation Checklist: What Most Rollouts Miss

  14. 17 July 2026 · 3 min read

    DPDP Act & Rules 2025: Breach Detection & 72-Hour Notification

  15. 15 July 2026 · 4 min read

    Data Loss Prevention for BFSI in India: The RBI, IRDAI and DPDP Act Compliance Guide

  16. 12 July 2026 · 3 min read

    Forcepoint vs Safetica: How to Choose Between Enterprise DLP and Cloud-Native SaaS DLP

  17. 10 July 2026 · 3 min read

    IAM vs SSO: What's the Difference, and What Does Your Enterprise Actually Need?

  18. 8 July 2026 · 3 min read

    Business Email Compromise in BFSI and Pharma: A Layered Defence Playbook

  19. 5 July 2026 · 3 min read

    Pharma Cybersecurity: Protecting Drug IP, Clinical Trial Data and GxP Systems

Put this into practice.

Our engineers deliver what these guides describe — from assessment to a running control. Bring us your environment.