# Navigating the New Cyber Security Framework in GIFT IFSC Published: 12 Mar 2025 Author: Treelife Practice area: News Source: https://treelife.in/news/navigating-the-new-cyber-security-framework-in-gift-ifsc/ --- Blog Content Overview - [1 Key Implications](#Key_Implications) - [2 Important Due Dates](#Important_Due_Dates) - [3 Entities exempt from this guideline](#Entities_exempt_from_this_guideline) Cyber threats are evolving, and for entities operating in GIFT IFSC, staying ahead is not just strategic, rather it’s essential. As GIFT IFSC grows into a global financial powerhouse, the complexity of cyber risks also intensifies. Recognizing this, the International Financial Services Centres Authority (IFSCA) has introduced the β€œπΊπ‘’π‘–π‘‘π‘’π‘™π‘–π‘›π‘’π‘  π‘œπ‘› πΆπ‘¦π‘π‘’π‘Ÿ π‘†π‘’π‘π‘’π‘Ÿπ‘–π‘‘π‘¦ π‘Žπ‘›π‘‘ πΆπ‘¦π‘π‘’π‘Ÿ 𝑅𝑒𝑠𝑖𝑙𝑖𝑒𝑛𝑐𝑒” aimed at safeguarding data, operations, and reputations. ## **Key Implications** - Every entityΒ  registered with IFSCA (Regulated Entities / REs) must appoint a Designated Officer (like a CISO) to lead cyber risk management. - Entities need to develop and regularly update a Cyber Security and Cyber-Resilience Framework tailored to their operations. - Annual audits are now mandatory - Cyber incidents to be reported within 6 hours, followed by a root cause analysis within 30 days. ## **Important Due Dates** - The framework comes into effect April 1, 2025. - Annual audits to be completed and reported within 90 days of the financial year-end. ## **Entities exempt from this guideline** Certain entities, such as units with less than 10 employees, branches of regulated entities, and foreign universities, enjoy a 3-year exemption subject to specific conditions as under: - REs shall adopt the Cyber Security and Cyber Resilience framework and IS Policy of its parent entity. - The CISO of the parent entity shall act as the Designated Officer for the REs in IFSC. - The parent entity of REs, in India or overseas, shall be regulated by a financial sector regulator in its home jurisdiction. If you’re navigating these new regulations or setting up operations in GIFT IFSC, it’s crucial to align strategies early. Have questions or need guidance? Let’s connect at dhairya.c@treelife.in for a discussion. ### Related posts: - [Sovereign Green Bonds in the IFSC](https://treelife.in/news/sovereign-green-bonds-in-the-ifsc/) - [SEBI Extends Timelines for AIFs to Hold Investments in Dematerialised Form](https://treelife.in/news/sebi-extends-timelines-for-aifs-to-hold-investments-in-dematerialised-form/) - [From Fees to Tokenization: Key IFSCA Updates You Should Know](https://treelife.in/news/from-fees-to-tokenization-key-ifsca-updates/) - [FDI in ecommerce under ED ScrutinyΒ ](https://treelife.in/news/fdi-in-ecommerce-under-ed-scrutiny/) --- This is informational content from Treelife. For advice specific to your situation, contact support@treelife.in