'AI Asymmetry' is emerging as a defining cybersecurity risk in the financial sector. Examine the challenges this poses to regulators and suggest measures for building resilience.

Q. 'AI Asymmetry' is emerging as a defining cybersecurity risk in the financial sector. Examine the challenges this poses to regulators and suggest measures for building resilience. (15 marks, 250-350 words)

'AI Asymmetry' — the central theme of the MeitY–CERT-In–CSIRT-Fin Digital Threat Report 2025-26 for the BFSI sector — describes how AI enables low-skill attackers to achieve outcomes once requiring specialist teams, compressing exploitation timelines from years to weeks [1]. For a UPI-driven financial system, this shifts cyber risk from an IT concern to a systemic stability challenge.

Challenges for regulators

Measures for resilience

Cybersecurity in finance is now an arms race in which defenders must match adversaries' velocity, not merely their tools. Institutionalising continuous, intelligence-led supervision — with sectoral CSIRTs, regulatory sandboxes for defensive AI and skilled personnel — can convert asymmetry into advantage, safeguarding the trust on which India's digital public infrastructure and financial inclusion ultimately rest.

(~330 words)

Sources: 1. MeitY releases 2nd edition of the Digital Threat Report 2025-26 for India's BFSI Sector in Collaboration with SISA, PIB — AI Asymmetry, 6 of 7 predictions materialised, threat vectors, 4-layer framework, 18-month roadmap, CSIRT-Fin's role 2. India launches first Digital Threat Report 2024 for the BFSI sector, PIB — public-private partnership model of CERT-In, CSIRT-Fin and SISA 3. Government Strengthens Cybersecurity Across Critical Sectors; Over 9,700 CERT-In Audits Conducted in 2024–25, PIB — audit volume and sectoral CSIRTs 4. CERT-In & SISA Launch First-of-its-kind ANAB-Accredited AI Security Certification (CSPAI) Program, PIB — AI security skilling initiative