Discuss the significance of public-private partnerships in strengthening India's cybersecurity architecture for critical financial infrastructure, with reference to the Digital Threat Report on the BFSI sector.

Q. Discuss the significance of public-private partnerships in strengthening India's cybersecurity architecture for critical financial infrastructure, with reference to the Digital Threat Report on the BFSI sector. (15 marks, 250-350 words)

CERT-In, the national nodal cyber agency under Section 70B of the IT Act, 2000, cannot secure the BFSI ecosystem alone, since most banking, insurance and payment systems are built and run by private entities. The Digital Threat Report 2025-26 (2nd edition), released by MeitY with CERT-In, CSIRT-Fin and the private firm SISA, shows partnership becoming the operating principle of financial cyber-defence [1].

Why partnership has become indispensable - The report's central finding of "AI asymmetry" — attackers adopting AI faster than defenders for phishing, deepfakes, credential theft and supply-chain compromise — outpaces any single regulator's capacity [1]. - 6 of 7 predictions of the 2024 edition materialised, as the gap between threat emergence and exploitation shrank from years to weeks [1].

Significance demonstrated by the Report - Intelligence fusion: SISA's forensic investigation data, CERT-In's oversight and CSIRT-Fin's sectoral incident response combine into one threat picture no partner could produce alone [2]. - Actionable frameworks: the "Anatomy of Cyber Failure" 4-layer gap archetype and an 18-month roadmap translate intelligence into board-level controls [1]. - Capacity multiplication: CERT-In's empanelled private auditors enabled over 9,700 audits of critical sectors in 2024-25, the largest share in BFSI [3]. - Institutional replicability: the CSIRT-Fin model offers a template for sector-specific response teams in power, health and transport.

Limitations to address - Findings are advisory, not binding, unlike RBI's cyber-security framework for banks. - Firms under-report incidents fearing reputational loss, weakening shared intelligence. - Dependence on proprietary vendor data raises questions of neutrality and continuity.

Public-private partnership thus converts cybersecurity from periodic compliance into continuous, intelligence-led resilience. Institutionalising such collaboration through regular disclosure, wider empanelment and alignment with RBI and NCIIPC mandates would let India protect the trust that underpins its UPI-led digital economy — securing the digital public infrastructure on which inclusive growth now rests.

(~320 words)

Sources: 1. MeitY releases 2nd edition of the Digital Threat Report 2025-26 for India's BFSI Sector in Collaboration with SISA, PIB — AI asymmetry, 6 of 7 predictions realised, "Anatomy of Cyber Failure" framework, 18-month roadmap, partner institutions 2. India launches first Digital Threat Report 2024 to support cybersecurity in the BFSI sector, PIB — integration of SISA forensic data, CERT-In oversight and CSIRT-Fin incident response 3. Government Strengthens Cybersecurity Across Critical Sectors; Over 9,700 CERT-In Audits Conducted in 2024–25, PIB — audit volume and BFSI share via empanelled auditors