1 week ago
Indian Regulators Tighten Financial Cybersecurity Amid Rising AI Threats
Indian financial regulators are trying to protect banks, exchanges and other important money systems from cyberattacks.
Artificial intelligence can help criminals create convincing scams, fake voices and fake identities.
SEBI has created a scorecard to measure how well major market institutions can withstand computer problems and attacks.
These institutions will have to check their score twice a year and fix weaknesses.
SEBI also plans to monitor cyber incidents from the first report until they are closed.
The RBI has created new cybersecurity rules for banks and financial institutions.
These rules make senior boards responsible for cyber risks and require serious incidents to be reported within six hours.
The RBI and SEBI are also considering a kill switch that could stop transactions during suspected fraud.
Experts say regulators must keep updating the rules because AI-powered attacks can change very quickly.
SEBI introduced an IT Resilience Index to measure cybersecurity readiness at market infrastructure institutions.
The index assesses nine areas, including availability, security, integrity, governance, monitoring and business continuity.
SEBI’s framework will begin in early 2027 and require half-yearly calculations, comparisons and corrective action.
The RBI issued a cybersecurity framework requiring board-level oversight, dedicated IT-risk committees and six-hour incident reporting.
Both regulators are considering financial “kill switches” as AI enables deepfakes, identity fraud and faster cyberattacks.
- Who
- The Reserve Bank of India (RBI), the Securities and Exchange Board of India (SEBI), financial institutions and market infrastructure institutions.
- What
- Indian regulators are strengthening cybersecurity oversight and developing tools to measure resilience, report incidents and respond to fraud.
- Where
- India’s banking and securities-market infrastructure.
- When
- SEBI’s IT Resilience Index is scheduled to take effect in early 2027; the RBI issued its cybersecurity framework late last month, while other measures were announced on Monday and in June.
- Why
- Artificial intelligence is increasing the speed, scale and sophistication of cyber threats, including deepfakes, identity fraud and automated attacks.
More Prescriptive, AI-Specific Controls
Flexible, Technology-Neutral Accountability
How rules should address AI threats
More Prescriptive, AI-Specific Controls
Himanshu Bagai said regulators should focus on AI-specific threat modeling, continuous testing, cloud and third-party risks, model and data integrity, deepfakes and human accountability.
Flexible, Technology-Neutral Accountability
Tushar Kumar argued that the preferred response is not an excessively prescriptive code that technology could quickly outpace, but technology-neutral accountability supported by technology-specific safeguards.
How quickly systems should respond
More Prescriptive, AI-Specific Controls
Bagai said regulators should test whether institutions can detect and contain machine-speed attacks in real time, including with AI-enabled defensive systems.
Flexible, Technology-Neutral Accountability
Kumar emphasized surveillance architecture capable of addressing AI-enabled fraud and market abuse while avoiding rules tied too closely to rapidly changing technologies.
Key facts
- SEBI resilience index
- The IT Resilience Index applies to market infrastructure institutions such as exchanges and clearing corporations.
- Index parameters
- The index has nine parameters, with availability and security weighted at 20% each; several other areas carry 10% and scalability and miscellaneous requirements carry 5% each.
- Implementation
- The index framework will come into effect from early 2027.
- Reporting frequency
- Market infrastructure institutions must calculate the index half-yearly within 60 days of each half-year’s end.
- RBI incident reporting
- The RBI’s framework requires cyber incidents to be reported within six hours.
- Kill switch
- The RBI and SEBI are considering mechanisms that could stop financial transactions during suspected fraud.
- SEBI AI plans
- SEBI said it would shortly issue guidelines for responsible use of artificial intelligence and machine learning in markets.
Quotes
Securities and Exchange Board of India
India’s securities-market regulator
“Any disruption, degrading in performance or compromise of these (IT) systems may adversely impact critical market operations and pose risks to the trust in the securities market.”
indianexpress.com
Himanshu Bagai
Partner at Saikrishna & Associates
“SEBI’s IT Resilience Index is significant in that respect because resilience becomes something that can be measured, benchmarked and ultimately brought into boardroom accountability”
indianexpress.com
Kamlesh Chandra Varshney
SEBI whole-time member
“Now a team has already been constituted. Like we have a system for trading data, can we have a system for quarterly results that are filed?”
indianexpress.com









