Digital Threat Report 2025-26: Critical BFSI Cyber Risks

Aditya Pandey
10 Min Read

The Ministry of Electronics and Information Technology, working alongside CERT-In, CSIRT-Fin and SISA, has put out the second edition of the Digital Threat Report 2025-26 for the Banking, Financial Services and Insurance (BFSI) and payments space. The report is meant to give financial institutions, regulators and cybersecurity leaders a clear-eyed read on how threats to banking, finance, insurance and digital payments are evolving.

Speaking at the launch, MeitY Secretary S. Krishnan said, “As cyber threats become increasingly sophisticated, trusted partnerships between public institutions and industry are essential to strengthening digital trust. The Digital Threat Report represents a meaningful collaboration among CERT-In, CSIRT-Fin and SISA. This partnership demonstrates how expertise developed in India can contribute both to our national cyber resilience and to advancing cybersecurity knowledge globally.”

Threats are moving faster

The report leans on deep digital forensics and incident response work, analysis that lines up with what CERT-In and CSIRT-Fin have observed directly, and dedicated research into adversarial AI. Its headline finding is striking: six of the seven forward-looking predictions from last year’s edition have already played out in full. That’s a sign of just how fast the gap between a threat appearing and it actually being exploited is closing, often down to months, sometimes just weeks, where it used to take years.

Attack methods that used to be treated as rare or emerging, things like social engineering, credential theft, supply-chain compromise and cloud exploitation, are now standard playbook items. That’s changed what the most damaging attacks actually look like. Increasingly, they don’t look like intrusions at all. They show up as legitimate-seeming sessions, payments that get approved normally, workflows that have been quietly manipulated, or user behaviour that seems completely ordinary right up until the damage is done.

Why trust is the real thing at stake

Dharshan Shanthamurthy, Founder and CEO of SISA, framed the shift this way: “The distance between innovation and exploitation has narrowed dramatically, and that single shift changes everything about how our industry must defend itself. The BFSI industry is built on trust – trust that a transaction is genuine, that the systems processing it are acting as intended, that money will move securely and irreversibly through a network of institutions that depend on one another.

When that trust is weakened, the impact is never contained to a single breach or a single firm; it ripples across customers, partners, markets, and entire economies. This is why cybersecurity can no longer sit at the edge of the business as a technical control function. It has to become central to how institutions grow, innovate, and lead. Our work in forensics has taught us a simple truth: every breach leaves behind a lesson, and if we are willing to learn fast enough, those lessons can turn disruption into foresight.”

AI is handing attackers a shortcut

One of the risks the report singles out is what it calls AI asymmetry. Work that used to demand specialist teams, real budgets and weeks of grinding effort can now be done at machine speed by attackers with comparatively little in the way of resources. That’s letting offensive capability outpace the defensive and regulatory systems meant to keep it in check.

Dr. Sanjay Bahl, Director General of CERT-In, spoke to why this matters at a systemic level: “We are pleased to collaborate with SISA for the second consecutive year on the Digital Threat Report for the BFSI Industry. As India’s financial ecosystem becomes more interconnected, real-time and technology-driven, cyber resilience must be treated as a shared responsibility across institutions, regulators and the wider digital supply chain.

The report highlights the need to move beyond periodic security interventions towards continuous risk assessment, coordinated response and stronger information sharing. By translating emerging threat patterns into actionable guidance, it aims to help financial institutions anticipate systemic risks, strengthen operational resilience and protect trust in the country’s digital financial infrastructure.”

A New Framework

Rather than just cataloguing incidents, this edition tries to explain why controls that look solid on paper still fail once they’re under real pressure. The standout addition here is a 4-Layer Gap Archetype Framework the report calls the Anatomy of Cyber Failure, which walks through, step by step, how a modern breach actually plays out from start to finish.

The framework’s central point is that breaches are almost never one isolated mistake. They’re usually a chain of smaller weaknesses stacking on top of each other, and seeing them that way helps organisations spot recurring patterns, figure out which systemic risks matter most, and put money where it’ll actually reduce risk.

From diagnosis to an 18-month roadmap

The report doesn’t stop at describing the problem. It lays out the shifts likely to reshape the sector going forward and sets an 18-month roadmap that starts with shoring up basic controls, moves on to building continuous security capabilities, and ends with more resilient security architectures overall.

About CERT-In

CERT-In is India’s national nodal agency for responding to computer security incidents. Under the Information Technology Amendment Act 2008, it’s tasked with:

  • Collecting, analysing and sharing information on cyber incidents
  • Forecasting and issuing alerts on cyber security incidents
  • Coordinating emergency measures when incidents occur
  • Coordinating cyber incident response activities more broadly
  • Issuing guidelines, advisories, vulnerability notes and whitepapers on information security practices, procedures, prevention, response and reporting

Any other functions relating to cyber security as prescribed.

About CSIRT-Fin

CSIRT-Fin is the nodal sectoral CSIRT for India’s financial sector, providing incident prevention, response and security quality management services to financial entities. It manages cyber incidents and coordinates responses across banking, securities market infrastructure, insurance and pension funds. Its roles include:

  • Collecting, analysing and disseminating information on cyber incidents
  • Forecasting and alerting on cyber security incidents
  • Taking emergency measures on cyber security incidents
  • Coordinating cyber incident response activities
  • Issuing guidelines, advisories, vulnerability notes and white papers on information security
  • Monitoring sectoral efforts toward a dynamic, modern cyber security architecture and building awareness among regulated entities and the public

Any other functions relating to financial sector cyber security as prescribed.

About SISA

SISA is a global cybersecurity company focused on the payment ecosystem, working at the crossover point of AI, cybersecurity and payments. It’s trusted by major brands and financial institutions in more than 40 countries and secures over 1,000 organisations, helping them anticipate threats, build resilience and protect critical payment infrastructure. Its work is powered by real-world breach intelligence. SISA can be followed on LinkedIn for updates on cybersecurity, payment security innovation and emerging technologies.

Key Takeaway: The second edition of the Digital Threat Report 2025–26 highlights the rapidly evolving cyber threat landscape facing India’s Banking, Financial Services and Insurance (BFSI) sector, where sophisticated attacks driven by artificial intelligence, social engineering, credential theft and supply-chain vulnerabilities are increasingly targeting digital trust rather than merely exploiting technical weaknesses.

Developed through collaboration between MeitY, CERT-In, CSIRT-Fin and SISA, the report emphasises continuous risk assessment, coordinated incident response, stronger information sharing and resilient cybersecurity architectures, while introducing a framework to understand the systemic causes of cyber breaches. As India’s financial ecosystem becomes more interconnected and technology-driven, the report underscores the need for robust cyber resilience to safeguard critical financial infrastructure, maintain public trust and support the secure growth of the country’s digital economy.

M.C.Q.

Question 1: CERT-In, India’s national nodal agency for responding to cyber security incidents, functions under which Ministry?

  • A. Ministry of Home Affairs
  • B. Ministry of Electronics and Information Technology (MeitY)
  • C. Ministry of Communications
  • D. Ministry of Finance

Question 2: In the context of India’s financial sector, the acronym BFSI stands for:

  • A. Banking, Financial Services and Insurance
  • B. Banking, Foreign Services and Investments
  • C. Business Finance and Securities Institution
  • D. Banking and Fiscal Security Initiative

Read More: Varanasi’s New Elevated Corridor: A Remarkable Project

Share This Article