Released jointly by CERT-In, CSIRT-Fin and SISA, it provides an executive assessment of the threats reshaping the Banking, Financial Services, and Insurance (BFSI) and payments sector.
Key Highlights of Report
- Rising Threats: Cyberattacks on India’s BFSI sector rose from 1.4 million (2021) to 2.9 million (2025).
- AI Asymmetry: Offensive AI capabilities are scaling faster than the defensive and regulatory frameworks meant to contain them.
- Three Emerging Clusters of Cyber Risk:
- AI & Human Deception: Social Engineering, Phishing, Credential Theft, Deepfake, Adversarial LLMs etc.
- Software and Systems: API abuse, Application Race Conditions, Supply Chain / Third Party, LLM Prompt Hacking, AI-Driven Attacks etc.
- Infrastructure & Economy: UPI Fraud, Ransomware, Cryptographic / Quantum, Crypto Incidents etc.
- 4-Layered Cyber Security Gap Framework:
- Design Gaps: Systems are not prepared for adversarial reality, allowing malicious activities to appear legitimate.
- Enforcement Gaps: e.g. Multi-factor authentication secures login, but lack of continuous verification allows attackers to hijack active sessions.
- Signal Gaps: Failure to detect or interpret security signals correctly.
- Response Gaps: e.g. Phishing, fraudulent onboarding, and account takeovers were detected only after complaints or external alerts.
Way ahead
- Public-Private Partnerships: For coordinated incident response.
- Identity as the Primary Control Plane: Enable cross-database identity verification, Extend identity governance to non-human identities like Agentic AI.
- Supply Chain Visibility: Track vendors and their partners to reduce systemic cyber risks.
About Computer Emergency Response Team (CERT-In), MeitY
About Computer Security Incident Response Team in Finance sector (CSIRT-Fin)
|