·PIB·15 marks·250–350 words

'AI Asymmetry' is emerging as a defining cybersecurity risk in the financial sector. Examine the challenges this poses to regulators and suggest measures for building resilience.

In this answer
  1. Challenges for regulators
  2. Measures for resilience

'AI Asymmetry' — the central theme of the MeitY–CERT-In–CSIRT-Fin Digital Threat Report 2025-26 for the BFSI sector — describes how AI enables low-skill attackers to achieve outcomes once requiring specialist teams, compressing exploitation timelines from years to weeks [1]. For a UPI-driven financial system, this shifts cyber risk from an IT concern to a systemic stability challenge.

Challenges for regulators

  • Speed mismatch: attackers operate at machine speed while regulation moves through audit cycles; the report found 6 of 7 of its previous edition's threat predictions had already materialised [1].
  • Expanding attack surface: social engineering, credential theft, supply-chain compromise and cloud exploitation cut across entities, so supervising a single bank no longer secures the ecosystem [1].
  • Capacity deficit: despite over 9,700 CERT-In audits across critical sectors in 2024-25, periodic auditing struggles to keep pace with continuously evolving AI-enabled threats [3].
  • Attribution and accountability gaps: AI-generated deepfake and voice-cloning frauds blur liability between customer negligence and institutional failure.
  • Dual-use dilemma: restricting AI tools risks stifling legitimate fintech innovation, while permissiveness widens the asymmetry.

Measures for resilience

  • Adopt the report's remedies: the "Anatomy of Cyber Failure" 4-layer gap framework and its 18-month roadmap from foundational controls to resilient architecture offer a supervisory template [1].
  • Continuous assurance replacing point-in-time audits — real-time threat intelligence sharing through CSIRT-Fin, the finance-sector incident response team [1].
  • Deepen public-private partnership, the model underlying both editions of the report, pooling private forensic intelligence with CERT-In's statutory oversight under Section 70B, IT Act 2000 [2].
  • Build AI-security skills, as with the CERT-In–SISA CSPAI AI security certification [4]; strengthen customer awareness against AI-driven social engineering.

Cybersecurity in finance is now an arms race in which defenders must match adversaries' velocity, not merely their tools. Institutionalising continuous, intelligence-led supervision — with sectoral CSIRTs, regulatory sandboxes for defensive AI and skilled personnel — can convert asymmetry into advantage, safeguarding the trust on which India's digital public infrastructure and financial inclusion ultimately rest.

Sources

  1. 1MeitY releases 2nd edition of the Digital Threat Report 2025-26 for India's BFSI Sector in Collaboration with SISA, PIBAI Asymmetry, 6 of 7 predictions materialised, threat vectors, 4-layer framework, 18-month roadmap, CSIRT-Fin's role
  2. 2India launches first Digital Threat Report 2024 for the BFSI sector, PIBpublic-private partnership model of CERT-In, CSIRT-Fin and SISA
  3. 3Government Strengthens Cybersecurity Across Critical Sectors; Over 9,700 CERT-In Audits Conducted in 2024–25, PIBaudit volume and sectoral CSIRTs
  4. 4CERT-In & SISA Launch First-of-its-kind ANAB-Accredited AI Security Certification (CSPAI) Program, PIBAI security skilling initiative

More from this note