Indian Banks Raise Cybersecurity Spending as AI Threats Mature
India's Ministry of Electronics and Information Technology said on July 13 that six of seven cyber threats forecast for the banking and payments sector a year earlier had reached full-scale realization. Economic Times BFSI reported that banks are increasing defenses as attacks combine AI, stolen identities, and manipulated payment workflows, while Punjab National Bank allocated roughly Rs 7-8 billion to cybersecurity for FY27.
India's Ministry of Electronics and Information Technology said on July 13 that six of seven cyber threats forecast for the banking, financial services, insurance, and payments ecosystem a year earlier had reached full-scale realization. The finding comes from the second Digital Threat Report 2025-26, produced by CERT-In, CSIRT-Fin, and cybersecurity firm SISA.
The ministry said the interval between an emerging technique and operational exploitation is shrinking from years to months or weeks. Social engineering, credential theft, supply-chain compromise, and cloud exploitation have moved from emerging or episodic risks to established attack methods, according to the official release.
AI changes both the attack surface and the response
The report identifies AI asymmetry as a defining risk: vulnerability discovery, exploit generation, and attack orchestration that once required specialist teams and substantial resources can increasingly be performed faster by lower-resource actors. Economic Times BFSI reported that attacks are combining AI, stolen identities, and manipulated payment workflows to resemble legitimate customer activity.
The same reporting describes banks adopting AI-led fraud detection alongside zero-trust controls, micro-segmentation, identity management, cyber monitoring, cloud security, and vulnerability assessment. The official report calls for continuous risk assessment and coordinated response rather than relying only on periodic security checks.
Cybersecurity becomes a larger budget item
Economic Times BFSI reported that Punjab National Bank allocated about 20% of its FY27 technology budget, or roughly Rs 7-8 billion, to cybersecurity. The publication said that was more than 50% above the prior year and that the bank could increase the allocation if needed.
The Reserve Bank of India has also discussed AI, geopolitical risk, and expected-credit-loss implementation with bank chief executives, according to Economic Times BFSI. The publication reported that the central bank circulated a draft AI-governance framework for regulated entities.
For security and ML teams in financial services, the evidence points to a combined controls problem. Fraud models need identity and session telemetry, payment-workflow monitoring, access segmentation, and incident response around them. The official report's 18-month roadmap also emphasizes stronger authentication, machine-identity inventories, adversarial testing of payment workflows, cloud identity controls, and continuous assurance as the threat environment evolves.
Key Points
- 1India's Digital Threat Report 2025-26 says six of seven threats forecast for the BFSI and payments sector a year earlier have reached full-scale realization.
- 2Punjab National Bank allocated roughly Rs 7-8 billion, about 20% of its FY27 technology budget, to cybersecurity, according to Economic Times BFSI.
- 3The reported response combines AI-led fraud detection with identity, zero-trust, segmentation, payment-workflow, and continuous-assurance controls.
Scoring Rationale
The official report documents rapid operationalization of threats across India's financial ecosystem, while the PNB budget provides a concrete spending signal. The event is materially relevant to security and fraud teams but remains a sector trend rather than a binding rule or a single broadly deployable technology release.
Sources
Primary source and supporting public references used for this report.
Practice with real Banking data
90 SQL & Python problems · 15 industry datasets
250 free problems · No credit card
See all Banking problems
