The Insurance Regulatory and Development Authority of India (IRDAI) updated its Information and Cyber Security Guidelines in April 2026. The guidelines apply to regulated entities, including insurers, Foreign Reinsurance Branches, and intermediaries such as brokers, corporate agents, web aggregators, and third-party administrators. The guidelines mandate periodic vulnerability assessments, penetration testing and audits to identify and address potential weaknesses in the organisation's IT systems.