IRDAI 2023 Cyber Security Guidelines: SOC, VAPT & Reporting
18 July 2026 · 3 min read · Cloud Armor Security Team
- IRDAI
- Compliance
- Insurance
- Managed SOC
- Ayati One
TL;DR — IRDAI's Information and Cyber Security Guidelines, 2023 superseded the 2017/2022 advisories with a unified, governance-driven model for insurers and intermediaries. The operational core: run a SOC / end-to-end monitoring, conduct VAPT at least twice a year (critical findings fixed within 30 days), retain ICT/application logs for 180 days, and report cyber incidents to IRDAI and CERT-In within 6 hours. An annual audit by a CERT-In-empanelled auditor is required.
For an insurer, the IRDAI guidelines — not a global SIEM vendor's datasheet — are what an audit measures. And unlike much compliance writing, these guidelines are refreshingly concrete about monitoring, testing cadence and timelines, which makes them straightforward to operationalise if you build to them deliberately.
The operational mandates
- SOC / continuous monitoring with end-to-end log visibility
- Log retention of 180 days (rolling) for ICT and application logs
- VAPT at least twice yearly, critical findings remediated within 30 days
- 6-hour incident reporting to IRDAI and CERT-In
- Annual cybersecurity audit via a CERT-In-empanelled auditor
- Board-approved policy, CISO, and a cyber-crisis management plan
The 180-day log retention detail
The 180-day rolling retention requirement is specific and testable. It means your monitoring platform must retain searchable ICT and application logs for six months — a policy question that gets expensive fast on per-GB SIEM pricing, and a residency question under the DPDP framework.
Mapping the guidelines to controls
| IRDAI requirement | Operational need | Ayati One |
|---|---|---|
| SOC / end-to-end monitoring | 24×7 detection + triage | Managed SIEM + AI-SOC |
| 180-day log retention | Searchable 6-month logs | Per-asset, no ingestion meter |
| VAPT twice yearly, 30-day fix | Continuous + periodic testing | Continuous VA + VAPT |
| 6-hour incident reporting | Real-time detect-to-report | Analyst triage 24×7 |
| CERT-In-empanelled audit | Auditable evidence | Full case history + reporting |
Frequently asked questions
Does IRDAI apply to intermediaries, not just insurers?
Yes — the 2023 guidelines extend to insurers and licensed intermediaries. Scope varies with size and role; we'll map it to your registration.
Can continuous VA replace the twice-yearly VAPT?
No — they're complementary. Continuous VA keeps exposure visible day-to-day; the formal twice-yearly VAPT is a distinct, deeper assessment IRDAI requires. Ayati One provides the first; our VAPT practice delivers the second.
How does IRDAI relate to the DPDP Act for insurers?
They stack. IRDAI governs your sectoral obligations; the DPDP Act & Rules 2025 govern personal data and breach notification across all sectors.
Meeting IRDAI's 2023 guidelines? Talk to our SOC engineers about a managed SOC with 180-day retention and the 6-hour clock covered, at flat per-asset pricing.
Blog timeline
Explore the full series
27 July 2026 · 4 min read
Wazuh vs Commercial SIEM: The Real Enterprise Trade-off
27 July 2026 · 3 min read
Managed SOC & SIEM With Data Residency in India
26 July 2026 · 3 min read
Choosing an MSSP in Hyderabad, Dubai & the GCC
26 July 2026 · 8 min read
IBM QRadar Alternatives: Ayati One as a Managed SIEM + AI-SOC
25 July 2026 · 3 min read
An Arctic Wolf Alternative for India: Pricing & Residency
24 July 2026 · 2 min read
A Rapid7 InsightIDR Alternative: Managed, In-Region SIEM
23 July 2026 · 3 min read
A Microsoft Sentinel Cost Alternative: Beyond Per-GB Pricing
22 July 2026 · 3 min read
IBM QRadar Migration: A Practical Path Off QRadar
21 July 2026 · 3 min read
RBI Cybersecurity Framework: SOC Monitoring & 6-Hour Reporting
20 July 2026 · 3 min read
SEBI CSCRF Compliance: SIEM, SOC & the M-SOC Option
19 July 2026 · 3 min read
UAE NESA/SIA & Dubai ISR: Security Monitoring for Compliance
18 July 2026 · Currently reading
IRDAI 2023 Cyber Security Guidelines: SOC, VAPT & Reporting
18 July 2026 · 3 min read
The Enterprise DLP Implementation Checklist: What Most Rollouts Miss
17 July 2026 · 3 min read
DPDP Act & Rules 2025: Breach Detection & 72-Hour Notification
15 July 2026 · 4 min read
Data Loss Prevention for BFSI in India: The RBI, IRDAI and DPDP Act Compliance Guide
12 July 2026 · 3 min read
Forcepoint vs Safetica: How to Choose Between Enterprise DLP and Cloud-Native SaaS DLP
10 July 2026 · 3 min read
IAM vs SSO: What's the Difference, and What Does Your Enterprise Actually Need?
8 July 2026 · 3 min read
Business Email Compromise in BFSI and Pharma: A Layered Defence Playbook
5 July 2026 · 3 min read
Pharma Cybersecurity: Protecting Drug IP, Clinical Trial Data and GxP Systems
Put this into practice.
Our engineers deliver what these guides describe — from assessment to a running control. Bring us your environment.