'AI Asymmetry' is emerging as a defining cybersecurity risk in the financial sector. Examine the challenges this poses to regulators and suggest measures for building resilience.
Q. 'AI Asymmetry' is emerging as a defining cybersecurity risk in the financial sector. Examine the challenges this poses to regulators and suggest measures for building resilience. (15 marks, 250-350 words)
'AI Asymmetry' — the central theme of the MeitY–CERT-In–CSIRT-Fin Digital Threat Report 2025-26 for the BFSI sector — describes how AI enables low-skill attackers to achieve outcomes once requiring specialist teams, compressing exploitation timelines from years to weeks [1]. For a UPI-driven financial system, this shifts cyber risk from an IT concern to a systemic stability challenge.
Challenges for regulators
- Speed mismatch: attackers operate at machine speed while regulation moves through audit cycles; the report found 6 of 7 of its previous edition's threat predictions had already materialised [1].
- Expanding attack surface: social engineering, credential theft, supply-chain compromise and cloud exploitation cut across entities, so supervising a single bank no longer secures the ecosystem [1].
- Capacity deficit: despite over 9,700 CERT-In audits across critical sectors in 2024-25, periodic auditing struggles to keep pace with continuously evolving AI-enabled threats [3].
- Attribution and accountability gaps: AI-generated deepfake and voice-cloning frauds blur liability between customer negligence and institutional failure.
- Dual-use dilemma: restricting AI tools risks stifling legitimate fintech innovation, while permissiveness widens the asymmetry.
Measures for resilience
- Adopt the report's remedies: the "Anatomy of Cyber Failure" 4-layer gap framework and its 18-month roadmap from foundational controls to resilient architecture offer a supervisory template [1].
- Continuous assurance replacing point-in-time audits — real-time threat intelligence sharing through CSIRT-Fin, the finance-sector incident response team [1].
- Deepen public-private partnership, the model underlying both editions of the report, pooling private forensic intelligence with CERT-In's statutory oversight under Section 70B, IT Act 2000 [2].
- Build AI-security skills, as with the CERT-In–SISA CSPAI AI security certification [4]; strengthen customer awareness against AI-driven social engineering.
Cybersecurity in finance is now an arms race in which defenders must match adversaries' velocity, not merely their tools. Institutionalising continuous, intelligence-led supervision — with sectoral CSIRTs, regulatory sandboxes for defensive AI and skilled personnel — can convert asymmetry into advantage, safeguarding the trust on which India's digital public infrastructure and financial inclusion ultimately rest.
(~330 words)
Sources: 1. MeitY releases 2nd edition of the Digital Threat Report 2025-26 for India's BFSI Sector in Collaboration with SISA, PIB — AI Asymmetry, 6 of 7 predictions materialised, threat vectors, 4-layer framework, 18-month roadmap, CSIRT-Fin's role 2. India launches first Digital Threat Report 2024 for the BFSI sector, PIB — public-private partnership model of CERT-In, CSIRT-Fin and SISA 3. Government Strengthens Cybersecurity Across Critical Sectors; Over 9,700 CERT-In Audits Conducted in 2024–25, PIB — audit volume and sectoral CSIRTs 4. CERT-In & SISA Launch First-of-its-kind ANAB-Accredited AI Security Certification (CSPAI) Program, PIB — AI security skilling initiative