Cyber resilience in banking sector

sfg-2026
ForumIAS LATEST
    1. Ethics Redbook 3rd Edition: A Textbook That Teaches You How to Think Ethically Click Here to Read More →
    2. 21 Sept. | Forum Residential Coaching (FRC) for UPSC preparation Click Here to know more →
    3. 21 Sept. | GS Advance Program (GSAP) for UPSC 2027 Mains starts from 10th Oct. Click Here to Read More →

Source: The post “Cyber resilience in banking sector” has been created based on “Cyber resilience in banking sector” published in “Business Line” on 24th September 2026.

UPSC Syllabus: GS-3- Economy 

Context: India’s banking sector is increasingly dependent on digital infrastructure, fintechs, technology providers and third-party service providers. The emergence of AI-enabled and agentic cyberattacks has increased the scale, speed and sophistication of cyber threats, requiring a shift from merely preventing attacks to building sector-wide cyber resilience.

Emerging challenges

  1. AI-enabled attacks: Agentic AI models can autonomously identify vulnerabilities, reducing the time, cost and technical expertise required by attackers.
  2. Expanded attack surface: Banks are interconnected with fintechs, NBFCs, technology providers and other third parties, creating vulnerabilities beyond individual institutions.
  3. Systemic impact: The 2024 ransomware attack on C Edge Technologies, a core technology provider, temporarily disrupted payment services across about 300 cooperative and rural banks, affecting ATM withdrawals and UPI transactions.
  4. Asymmetric cyber risk: An attacker needs to exploit only one vulnerability, whereas financial institutions must protect numerous interconnected systems.
  5. Weak AI-risk preparedness: The RBI’s FREE AI Committee Report found that only one-fourth of respondents had formal processes for AI-related incidents or failures. Among 127 entities using AI, only 14% conducted regular audits, 18% maintained audit logs and 14% conducted real-time performance monitoring.
  6. Uneven technological capacity: Banks, NBFCs and microfinance institutions differ significantly in their technological maturity, operational capacity and financial resources.

Measures to strengthen cyber resilience

  1. Real-time information sharing: The RBI should operationalise real-time sharing of cyberattack, near-miss and third-party incident information among financial institutions through CSIRT-Fin.
  2. Non-punitive reporting: Confidential and non-punitive incident reporting can encourage institutions to report vulnerabilities and near-misses, similar to practices in aviation safety.
  3. Create an AI cyber-risk catalogue: Collective intelligence should be used to develop a common database of AI-enabled cyberattack scenarios, attack vectors, potential impacts and mitigation strategies.
  4. Common resilience standards: Establish minimum, non-negotiable cybersecurity standards across banking, securities, pensions and insurance, irrespective of institutional size.
  5. Strengthen regulatory frameworks: The RBI’s Model Risk Management guidance and Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 should be implemented effectively, with lessons from incidents, tests and drills continuously incorporated.
  6. Improve basic cyber hygiene: Strong authentication, access controls, audit logs, continuous monitoring, employee awareness and regular stress testing should remain the foundation of cyber resilience.

Conclusion: AI is changing cyber risk from an institution-specific problem into a sector-wide systemic risk. Therefore, India needs an ecosystem-based approach centred on real-time information sharing, collective intelligence, common resilience standards and continuous learning. The RBI can thereby ensure that financial institutions are not merely prepared to prevent attacks but are capable of withstanding, containing and recovering from them.

Question: Artificial Intelligence (AI)-enabled cyberattacks are creating new vulnerabilities for India’s banking and financial sector. Discuss the challenges posed by such attacks and suggest measures to strengthen cyber resilience in the financial sector. 

Source: Business Line

Print Friendly and PDF
Blog
Academy
Community