PFRDA circular PFRDA/2025/05/ICS/01 · 04 Sept 2025
Summary
Check the official recordThe Pension Fund Regulatory and Development Authority (PFRDA) has issued guidelines for the classification and prioritization of cybersecurity incidents for all intermediaries and regulated entities. Building upon the Information & Cyber Security Policy Guidelines of 2024, this circular mandates that entities must categorize incidents into four levels—Critical, High, Medium, and Low—based on business impact and recovery effort rather than a first-come, first-served approach. Any incident causing disruption, stoppage, or variance in normal operations that impacts service delivery must be classified as either High or Critical. Entities are required to implement these classification standards to ensure effective incident response and maintain operational resilience.
What you must do
पेंशन निधि विनियामक और विकास प्राधिकरण PENSION FUND REGULATORY AND DEVELOPMENT AUTHORITY
परिपत्र सं.:पीएफआरडीए/2025/05/आईसीएस/01 04.09.2025
परिपत्र
सेवा में सभी मध्यस्थ एवं विनियमित संस्थाएँ
विषय: साइबर सुरक्षा घटनाओं के वर्गीकरण संबंधी दिशा-निर्देश
कविता सिंगम जेवियर
महाप्रबंधक सूचना एवं साइबर सुरक्षा विभाग
Circular No.: PFRDA/2025/05/ICS/01 04.09.2025
CIRCULAR
To All Intermediaries & Regulated entities
Subject: Guidelines on Classification of Cybersecurity Incidents
Kavita Singam Xavier
General Manager Information & Cyber Security Department
Annexure I
Guidelines on Classification of Cybersecurity Incidents
| S. No. | Category | Parameters |
|---|---|---|
| 1 | Critical | Cyber incidents of critical nature (such as successful penetration or Denial of Service attacks detected with significant impact on operations; ransomware attack; exfiltration of sensitive data; widespread instances of data corruption causing impact on operations; significant risk of negative financial or public relations impact, etc.) on any part of IT infrastructure. |
| 2 | High | Penetration or Denial of Service attacks attempted with limited impact on operations; widespread instances of a new malwares not handled by anti-virus software; unauthorized access to servers and network devices; unauthorized or unexpected configuration changes on network devices detected; data exfiltration; unusually high count of phishing emails; instances of outbound phishing emails; some risk of negative financial or public relations impact, etc. |
| 3 | Medium | Target recon or scans detected; penetration or Denial of Service attacks attempted with no impact on operations; widespread instances of known malwares easily handled by antivirus software; isolated instances of a new malwares not handled by anti-virus software; instances of phishing emails that were not recognized by employees and were clicked by them; instances of data corruption, modification and deletion being reported, etc. |
| 4 | Low | System probes or scans detected on external systems; intelligence received concerning threats to which systems may be vulnerable; intelligence received regarding username password compromise; isolated instances of known malwares easily handled by antivirus software, etc. |
Key dates
Who is affected
Thresholds