Context: The rapid spread of Artificial Intelligence (AI) is increasing the scale and sophistication of cyber fraud, prompting the Reserve Bank of India (RBI) and Securities and Exchange Board of India (SEBI) to strengthen cybersecurity oversight.
- Emerging threats include AI-generated deepfakes, voice impersonation, sophisticated digital scams and attacks on critical financial infrastructure.
- The regulatory focus is shifting from merely preventing cyber incidents to building measurable resilience, early-warning systems and rapid response mechanisms.
SEBI’s IT Resilience Index
- SEBI has introduced an IT Resilience Index (ITRI) for Market Infrastructure Institutions (MIIs) such as stock exchanges and clearing corporations.
- MIIs are critical to financial markets; disruption, degradation or compromise of their IT systems can affect trading and overall market stability.
- ITRI converts cybersecurity preparedness into a measurable and board-level accountable framework.
ITRI Parameters
- Availability and security: 20% each.
- Integrity, governance, reliability and monitoring, modularity and flexibility, and business continuity: 10% each.
- Scalability and other requirements: 5% each.
- MIIs must calculate the index every six months, within 60 days of the end of each half-year, and submit a comparative analysis of two consecutive half-years along with corrective measures.
Standardised Cyber-Incident Reporting
- SEBI has aligned its cyber-incident reporting portal with the standardised Format for Incident Reporting Exchange (FIRE).
- The format allows incidents to be reported progressively—from initial reporting to intermediate updates and final closure.
- This recognises that complete information may not be available when an incident is first detected and enables regulators to monitor the entire incident life cycle.
RBI’s Strengthened Cybersecurity Framework
- The RBI has introduced a comprehensive cybersecurity framework for banks and financial institutions, with greater emphasis on institutional accountability.
- Key requirements include board-level oversight, dedicated Information Technology (IT) risk committees and tighter cyber-incident reporting.
- Financial entities are required to report cyber incidents within a six-hour window, strengthening the speed of regulatory response.
- The RBI has also expanded its fraud-compensation framework to cover a wider range of victims and newer forms of digital fraud.
The “Kill Switch” Concept
- The RBI has considered a “kill switch” mechanism through which customers can rapidly freeze financial transactions when fraud is detected.
- Similar mechanisms are being examined in the securities market as part of SEBI’s emerging AI-related regulatory framework.
- Such mechanisms aim to limit losses by enabling rapid interruption of suspicious financial activity.
How AI Is Raising Cyber Risks
- AI allows fraudsters to automate and scale attacks that previously required significant time and expertise.
- Deepfake voices and other synthetic media can potentially be used to impersonate individuals and bypass identity or Know Your Customer (KYC) verification processes.
- AI can also make cyberattacks more adaptive by analysing patterns and exploiting vulnerabilities across financial institutions.
- As financial systems become increasingly technology-driven, cyber incidents can potentially have system-wide consequences rather than remaining isolated fraud events.
SEBI’s Emerging AI Oversight
- SEBI has been examining ways to strengthen surveillance of AI-driven risks and suspicious market activity.
- It has already deployed AI models to identify unusual trading patterns and is developing specialised teams for AI-related functions, including corporate investigations.
- The regulator has also indicated the need for continuous monitoring and early-warning systems as AI technology evolves.
Why Cyber Resilience Matters
- Cybersecurity focuses primarily on preventing unauthorised access, attacks and data compromise.
- Cyber resilience goes further by ensuring that critical systems can withstand disruption, continue essential operations, recover quickly and learn from incidents.
- The shift towards resilience is particularly important for financial markets because even temporary disruption to exchanges, clearing systems or banking infrastructure can undermine public confidence and financial stability.
Key Challenges
- Cyber threats are evolving rapidly alongside AI and other emerging technologies, making static regulatory frameworks inadequate.
- Regulators must balance strong oversight with technological innovation without creating excessive compliance burdens.
- Financial institutions need continuous investment in technology, skilled cybersecurity personnel, monitoring systems and incident-response capabilities.
- AI-based security tools themselves require careful oversight because poorly governed AI systems can introduce new risks, biases or vulnerabilities.
Way Forward
- Strengthen board-level accountability for cybersecurity and technology risks.
- Institutionalise continuous monitoring, early-warning mechanisms and regular resilience assessments.
- Develop rapid-response tools such as transaction freeze/kill-switch mechanisms for confirmed or suspected fraud.
- Ensure standardised and time-bound cyber-incident reporting across the financial ecosystem.
- Continuously update regulatory frameworks to address deepfakes, AI-enabled fraud and emerging cyber threats.
- Improve coordination among RBI, SEBI, financial institutions, cybersecurity agencies and technology providers.
Key Takeaway
- India’s financial-sector regulation is moving from a reactive cybersecurity approach to proactive cyber resilience.
- The growing use of AI means regulators must ensure that financial infrastructure is not only secure but also measurable in its resilience, capable of early detection and able to recover rapidly from sophisticated attacks.