Cybersecurity in BFSI: Building Resilience in a Digitally Connected World
As India's BFSI sector embraces digital banking, UPI, AI, cloud adoption and open banking, the cybersecurity landscape is becoming increasingly complex. Organizations today must contend with sophisticated cyber threats, expanding digital ecosystems and evolving regulatory expectations.
In this exclusive interview, Karmendra Kohli, CEO & Director of SecurEyes, a cybersecurity consulting and advisory firm, discusses the key cybersecurity threats facing India's BFSI sector. He also talks about the growing role of AI, emerging risks and regulatory expectations and why a governance-led, risk-based approach is essential to building long-term cyber resilience.
Drawing from his two decades of experience in cybersecurity, governance, risk management and compliance, he advises organizations across sectors on building resilient and secure digital ecosystems.
For deeper insights on the cybersecurity in BFSI and building resilience, read the following interview.
Q: What are the biggest cybersecurity threats facing India's BFSI sector today?
A. The biggest concern today is not any one type of cyberattack. It is the combination of technology vulnerabilities, organized fraud and manipulation of customers or employees. Phishing, remote-access application frauds, fake investment schemes, fraudulent UPI collect requests, malicious QR codes, account takeover and identity theft continue to affect customers. At the institutional level, ransomware, data theft, API attacks, cloud misconfigurations, privileged-access misuse, supply-chain compromise and attacks on payment infrastructure are major concerns.
If I had to prioritize the current threat landscape, I would broadly prioritize four areas. The first is third-party and supply chain compromise. Earlier, attackers focused directly on banks. Today, they increasingly target vendors, fintech partners and service providers because compromising one trusted partner often provides an indirect route into the banking ecosystem.
The second is API (Application Programming Interface) related risks. As banks expand digital banking and open banking services, APIs have become the backbone of customer interactions. Every API exposed externally also becomes a potential entry point if it is not adequately secured and monitored.
The third is social engineering, particularly phishing attacks that target employees and customers. These attacks are becoming far more personalized than before, making them increasingly difficult to detect.
Finally, ransomware continues to pose a significant threat because financial institutions cannot afford prolonged service disruptions. Alongside these, we are also witnessing an increase in nation-state-sponsored attacks where financial infrastructure becomes a strategic target during periods of geopolitical tension. Cybersecurity today is therefore no longer confined to protecting banks alone it is about securing the entire financial ecosystem.
Q: How has the rise of digital banking, UPI, AI and open banking changed the Indian cybersecurity landscape?
A. The biggest change is that banks are no longer just banks. They have evolved into digital service platforms. Today, customers expect to make UPI payments, pay utility bills, recharge FASTag accounts, complete digital onboarding and access multiple financial services through a single institution. While this has significantly enhanced customer convenience, it has also expanded the attack surface.
Earlier, security teams primarily focused on internet banking and mobile banking. Today, they must secure multiple digital channels, APIs, cloud environments and third-party integrations simultaneously. Every additional service introduces another layer of complexity.
The growing reliance on external partners for material operational processes such as KYC and customer onboarding further extends the security perimeter beyond the organization itself. AI adds another dimension. While it is improving automation and operational efficiency, Organizations are still adapting to the ways that AI systems process data, make decisions and should be governed. AI privacy, transparency, explains ability, etc. are still areas of concerns that organizations are dabbling with. As digital services continue to grow, cybersecurity is becoming less about protecting individual systems and more about managing an increasingly interconnected ecosystem.
Q: Why do cyberattacks continue to succeed despite significant investments in cybersecurity?
A. A fundamental concept in cybersecurity is the attacker's advantage versus the defender's challenge. A security team has to protect every possible entry point, whereas an attacker only needs to identify one weakness. That imbalance will always exist.
The second challenge is complexity. Data is no longer confined within the bank. It is distributed across cloud platforms, vendors, partners, outsourced service providers and customer-facing applications.
Maintaining visibility across such a distributed environment is becoming increasingly difficult.
Another issue is that many Organizations invest heavily in technology but sometimes focus more on acquiring tools than on the outcomes those tools are expected to deliver. Buying security technology is important, but continuously validating whether it is reducing organizational risk is equally important.
Cybersecurity also tends to become compliance-driven rather than risk-driven. Passing an audit does not automatically mean every risk has been addressed. Sustainable cybersecurity requires mature Governance, continuous Risk management, ongoing Compliance monitoring along with leadership direction with commitment, rather than viewing security simply as another regulatory checklist.
Q: Which types of cyberattacks pose the greatest risk to banks, NBFCs and other financial institutions?
A. The attack vectors remain broadly the same, but their sophistication continues to increase. Third-party compromise is one of the biggest concerns because attackers increasingly exploit trusted relationships instead of attacking banks directly. As financial institutions depend more on vendors, partners and fintech companies, every connected organization effectively becomes part of the attack surface.
API attacks are another growing risk. APIs enable seamless digital services, but they also require continuous authentication, monitoring and protection. Even a small weakness can provide an attacker with an opportunity to gain access. Social engineering continues to be highly effective because it targets people rather than technology. Highly personalized phishing campaigns can deceive even well-informed users if Organizations do not continuously build awareness. Ransomware also remains a significant threat because financial institutions depend heavily on uninterrupted operations. What has changed is that attackers are no longer looking at individual Organizations in isolation instead they are targeting the broader financial ecosystem, including customers, vendors and service providers, making ecosystem-wide resilience increasingly important.
Also Read: Powering India's AI Revolution Through Domestic Infrastructure
Q: How is AI transforming cybersecurity in the BFSI sector?
A. AI is transforming cybersecurity from both a defensive and an offensive perspective. On the defensive side, AI is enabling faster threat detection, automated monitoring, prioritization of incidents and quicker response times. Security teams are increasingly using AI to analyze large volumes of data, identify anomalies and reduce the time taken to detect, investigate and respond to incidents.
However, attackers are also using AI. They are automating phishing campaigns, creating convincing deepfakes, adapting malware more quickly and carrying out increasingly personalized attacks. In many ways, AI is becoming a force multiplier for both defenders and adversaries. At the same time, financial institutions are embedding AI into their own business processes and customer services. That makes AI governance equally important. Organizations need to understand how AI systems use data, ensure appropriate controls are in place and adopt governance frameworks that balance innovation with security. AI should therefore be viewed not only as a cybersecurity tool but also as a technology that itself requires careful governance and oversight.
Q: Are Indian BFSI organizations adequately prepared to meet evolving cybersecurity and regulatory requirements?
A. Cybersecurity maturity is a journey and Organizations are at different stages of that journey. Large public and private sector banks have made significant progress. They are investing in stronger cybersecurity frameworks, adopting regulatory guidance from RBI and increasingly using AI-driven capabilities for monitoring and threat detection. Regular audits, vulnerability assessments and penetration testing are also becoming more structured.
RBI requirements now extend beyond basic information security and cover IT governance, risk management, assurance, digital payment security, fraud-risk management, outsourcing and operational resilience. CERT-In also requires specified cyber incidents to be reported and relevant logs to be preserved in accordance with its directions.
The challenge is greater for smaller institutions such as cooperative banks, NBFCs and many fintech companies. Business priorities often take precedence and cybersecurity tends to be viewed from a compliance perspective rather than as a strategic business risk. The regulatory landscape is evolving rapidly. The Digital Personal Data Protection (DPDP) Act, together with guidelines from RBI, SEBI and IRDAI, are steadily raising the bar. As expectations around accountability, resilience and data protection continue to increase, Organizations across the BFSI sector will have little choice but to strengthen their cybersecurity posture.
Q: How can financial institutions secure their cloud environments, fintech partnerships and third-party ecosystems?
A. The first step is a mindset shift. Every third-party vendor, a service provider should be viewed as an extension of the organization itself. Outsourcing a service does not mean that the financial institution has outsourced its risk and ownership. If they have access to systems or data, they also become part of the organization’s attack surface. Continuous monitoring, periodic security reviews and clearly defined security obligations within contracts are essential.
Before onboarding a cloud provider, fintech or technology partner, the institution should perform a detailed risk assessment covering data handling, security architecture, regulatory compliance, incident history, business continuity and subcontracting arrangements. Contracts should clearly define security requirements, breach-notification timelines, audit rights, data location, data return or deletion, recovery obligations and responsibility for subcontractors.
Cloud security also requires a clear understanding of the shared responsibility model. Moving workloads to a leading cloud platform does not automatically make them secure. The cloud provider is responsible for securing the infrastructure, but the organization remains responsible for securing its applications, configurations, identities and most importantly, its data. A risk-based approach that combines Zero Trust principles, strong authentication, encryption, secure API management and continuous monitoring helps Organizations build resilience across increasingly interconnected digital ecosystems.
Also Read: Strengthening India's AI Surveillance with Hardware-Level Security
Q: Why should cybersecurity be treated as a boardroom priority rather than just an IT function?
A. Cybersecurity is no longer just a technology issue rather it is a business resilience issue. The impact of a cyberattack extends far beyond financial losses. It can damage customer confidence, affect an organization’s reputation, disrupt operations and invite regulatory scrutiny. In many cases, rebuilding trust takes much longer than restoring systems.
That is why cybersecurity needs leadership from the top. The board defines the organization’s risk appetite, allocates resources and sets the tone for how seriously cybersecurity is taken across the business. When the board actively reviews cyber risks, resilience planning and security investments, the importance naturally cascades throughout the organization. Regulators have also made this expectation increasingly clear. Cyber resilience is now viewed as a governance responsibility rather than simply an IT responsibility. Technology teams may implement the controls, but building a resilient organization requires leadership, direction and sustained commitment from the highest level.
Institutions must maintain complete visibility of logs across data centres, cloud environments, applications, APIs, databases, endpoints and third parties
A. The threat landscape will continue to evolve alongside technology. AI-driven attacks are likely to become more sophisticated, with greater automation, faster adaptation and increasingly convincing phishing campaigns. Deepfake technology will make identity fraud more challenging, while AI-powered malware will continue to evolve to evade traditional detection methods.
Another important development is quantum computing. While the technology itself offers tremendous opportunities, its potential to break current encryption standards means Organizations must begin preparing for a future where existing cryptographic methods may no longer be sufficient.
Supply chain attacks will also become more sophisticated as financial ecosystems become more interconnected. At the same time, regulatory expectations will continue to tighten, with stronger accountability and more significant consequences for Organizations that fail to protect customer data adequately. The future challenge is therefore not just defending against new technologies, but preparing Organizations to adapt continuously as both threats and regulations evolve.
Also Read: Building Trust in Silicon: The Future of Cybersecurity & Semiconductor
Q: What are the top cybersecurity best practices every bank, NBFC, insurance company and fintech should adopt today?
A. Cybersecurity should always begin with governance. Technology is important, but it is most effective when supported by strong leadership, clearly defined processes and a culture of shared responsibility. Organizations should adopt a risk-driven approach rather than treating cybersecurity as a compliance exercise. Zero Trust principles, strong multi-factor authentication, encryption and continuous monitoring should become foundational security practices rather than optional controls.
Every financial institution should first identify its critical services, sensitive data, important systems and major external dependencies. Security efforts should then be prioritized around these areas. Regular vulnerability assessments, penetration testing, red-team exercises and well-tested incident response plans help Organizations remain prepared for evolving threats. Equally important is strengthening third-party risk management because the security of the ecosystem is only as strong as its weakest participant.
Strong multifactor authentication should be implemented for employees, administrators, vendors and high-risk customer activities. Privileged access should be tightly controlled, monitored and periodically reviewed. Systems should be patched on time, and internet-facing assets should be continuously checked for vulnerabilities and unauthorised exposure.
Institutions must maintain complete visibility of logs across data centres, cloud environments, applications, APIs, databases, endpoints and third parties. Alerts should be investigated based on business impact and not merely closed to meet timelines.
Sensitive information should be encrypted and protected through data-loss-prevention controls, proper access restrictions and secure key management.
Finally, people remain a critical line of defence. Continuous awareness programs, clearly defined accountability and leadership support are essential to building a security-conscious culture. NPCI specifically cautions users about fake cashback links, QR-code scams, unknown applications, social-media approaches and fake investment schemes.
When governance becomes a priority, capacity and capability of people is given high importance and technology supports clearly understood business risks, Organizations are far better positioned to build long-term cyber resilience.



