S. Krishnan, Secretary in Ministry of Electronics and Information Technology, Government of India
| Photo Credit:
With the financial sector rapidly adopting emerging technologies like cloud computing, AI and real-time payment systems, cyberattacks are becoming faster, more sophisticated and increasingly systemic, the government said on Monday. To mitigate these evolving threats, the government emphasised the urgent need to develop robust domestic capabilities for these technologies.Releasing the second edition of ‘Digital Threat Report 2025-26’ for the Banking Financial Services and Insurance (BFSI) sector, S Krishnan, Secretary, Ministry of Electronics and Information Technology (MeitY) said these technologies have also dissolved traditional boundaries and expanded the threat surface into a distributed mesh across partners, platforms, models and infrastructure layers.“A critical area we need to act on is ensuring that in the AI space, what is the infrastructure and the capability we build as a country, both in terms of models, data, how we use this, how this infrastructure is something that we can support ourselves with, and the critical thing here is building domestic capacity,” he said.Prioritising cybersecurityKrishnan emphasised that cybersecurity is one of the most important concerns to be prioritised for preserving the benefits derived from digitisation.The Indian Computer Emergency Response Team (CERT-In) and Computer Security Incident Response Team - Finance Sector (iCSIRT-Fin) have noticed a clear acceleration in the pace and sophistication of cyberattacks targeting the financial industry, he noted.“Malicious actors are using advanced tactics, techniques and procedures to get beyond traditional defences. The landscape is changing with generative AI, large language models and machine-speed payment systems. Adversaries are exploiting gaps between systems, institutions and workflows. Notable findings also show that some firms struggle to translate compliance into real-world resilience, where controls that pass periodic assessment fail under adversarial pressure,” he explained.The report released by MeitY, along with CERT-In, CSIRT-Fin and SISA (leading global firm in cybersecurity for the payment ecosystem), draws on extensive digital forensics and incident response (DFIR) research, analysis aligned with CERT-In and CSIRT-Fin observations, and research into adversarial AI.Its central finding is that six of the seven forward-looking predictions made in last year’s edition have already reached full-scale realisation, demonstrating how the time between the emergence of a threat and its operational exploitation is shrinking, often from years to months or even weeks.Attack methodsThreats previously considered emerging or episodic - including social engineering, credential theft, supply-chain compromise and cloud exploitation - are now established attack methods. The consequence is a threat environment where the most damaging attacks no longer resemble traditional intrusions at all, the report highlighted.The report also identified AI asymmetry as one of the defining risks facing financial institutions. Activities that once required specialist teams, significant resources and weeks of effort can increasingly be performed at ‘machine speed’ by comparatively low-resource threat actors. This is placing offensive capabilities on a faster development curve than many of the defensive and regulatory mechanisms designed to contain them, it added.“As India’s financial ecosystem becomes more interconnected, real-time and technology-driven, cyber resilience must be treated as a shared responsibility across institutions, regulators and the wider digital supply chain,” Sanjay Bahl, Director General at CERT-In, said.Published on July 13, 2026












