India ramps up defenses against AI-driven cyber threats in financial sector

India’s financial regulators are intensifying efforts to counter cyber threats powered by emerging technologies, with new training and testing initiatives aimed at preempting attacks in a rapidly evolving digital landscape.

India’s financial regulators are stepping up their defences against cyber threats as concerns grow over attacks powered by artificial intelligence and other emerging technologies. The Reserve Bank of India and the Securities and Exchange Board of India are widening training, testing and simulation exercises for regulated entities, with both saying the emphasis is now on preparedness, governance and spotting weaknesses before they trigger wider disruption.

According to reporting by Mint, RBI Governor Sanjay Malhotra has described cyber risk as a major issue for the economy and the banking system, alongside geopolitical tension and trade tariffs. A recent RBI survey found that banks and non-bank lenders view AI-enabled cyber threats as the biggest risk to their businesses over the coming year, underscoring how quickly the threat landscape is changing.

SEBI is also sharpening its focus on the market side of the financial system. The regulator has clarified that its Cybersecurity and Cyber Resilience Framework applies only to systems used for regulated activities, while accepting compliance that is equivalent to the RBI’s standards. It has said critical systems include both core operations and client-facing applications, and while zero-trust principles are encouraged, guidance on mobile applications remains advisory rather than mandatory.

The broader push reflects an older supervisory approach that has increasingly been extended to new risks. RBI rules for banks already require board-approved cybersecurity policies, continuous monitoring through security operations centres and regular testing and incident reporting, according to compliance guides citing the central bank’s framework. Newer industry commentary also points to growing attention on software supply-chain oversight, vendor assurances and cryptographic asset governance, suggesting regulators are now trying to cover not just direct attacks but the full digital ecosystem around financial firms. SEBI has likewise begun looking at quantum-era risks and technology roadmaps for market infrastructure institutions, while the RBI plans a micro-data analytics project for cyber risk assessment.

Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.