Digital Threat Report 2025-26: BFSI Cyber Risk Findings
Why in the news
MeitY brought out the second edition of a cyber threat assessment aimed at banks, financial firms, insurers and payment players, to improve preparedness against new digital threats.
Key facts
- Coverage: Banking, Financial Services and Insurance plus payments.
- Evidence base: DFIR cases, CERT-In and CSIRT-Fin inputs, adversarial AI research.
- Partners named: MeitY, CERT-In, CSIRT-Fin and SISA Information Security.
- Aim: stronger cyber resilience and proactive defence in India’s digital finance.
Main findings
| Theme | Message |
|---|---|
| AI asymmetry | Attackers need fewer resources, narrowing defenders’ edge |
| Faster cycles | Threats change in weeks or months; 6 of 7 earlier predictions came true |
| Stealthy attacks | They imitate genuine sessions, approved transactions and routine activity |
| Gap framework | Four organisational layers examined |
| Roadmap | 18 months: tighter controls, ongoing risk monitoring, better information sharing, resilient architecture |
Major threats listed
Listed risks: insider threats, social engineering, stolen credentials, supply-chain compromise, cloud exploitation and AI-driven attacks.
About CERT-In and CSIRT-Fin
- CERT-In: national agency for cyber incidents under MeitY, set up under the IT Act, 2000 (amended 2008); handles response, alerts, vulnerability assessment, emergency coordination and guidelines.
- CSIRT-Fin: sector team for finance, coordinating cybersecurity for banks, insurers, securities market infrastructure and pension funds.
Exam angle
- Edition and ministry: second edition, MeitY.
- Expand DFIR, CERT-In and CSIRT-Fin.
- Framework name: Anatomy of Cyber Failure; roadmap length: 18 months.