Cyber Security for Banks

By: CA  Anil K. Jain 
Chartered Accountant | Economist | Policy Researcher | Author
President – Ahimsa Foundation India
Email:
CAINDIA@HOTMAIL.COM

Chapter Synopsis

This chapter examines the comprehensive cyber security framework governing India's banking sector, where trust is the foundation of operations and cyber resilience is essential for financial stability. Banks face a hostile threat landscape including social engineering frauds (Jamtara vishing, phishing), ransomware and data breaches, Advanced Persistent Threats (state-sponsored groups like Red Echo), supply chain vulnerabilities, and insider threats.

The Reserve Bank of India has constructed one of the world's most demanding regulatory architectures. The Master Direction on Digital Payment Security Controls (2021) mandates multi-factor authentication, device binding, and real-time fraud monitoring. The Cyber Security Framework for Banks (2018/2021) requires board-approved policies, ISO 27001 alignment, annual VAPT, bi-annual red teaming, and a CISO reporting directly to the board. Following the Cosmos Bank heist, the RBI mandated SWIFT-CBS integration and isolated SWIFT environments.

Core technical controls include network segmentation (isolating SWIFT, ATM switch, and core banking zones), privileged access management, data encryption and tokenisation, 24/7 Security Operations Centres with SIEM, and immutable offline backups with defined RTO/RPO. The DPDP Act, 2023 imposes additional obligations on banks as Data Fiduciaries—reasonable security safeguards, breach notification to the Data Protection Board and customers, with penalties up to ₹250 crore.

Incident response requires the "golden hour" approach: immediate containment, regulatory reporting (CERT-In within six hours, RBI within two to six hours), forensic preservation, and customer communication. Board governance is paramount—directors face liability under the Companies Act and DPDP Act for gross negligence.

The chapter concludes that bank security is a public good requiring embedded cyber culture, not merely technical controls, with emerging threats including AI-driven attacks, cloud concentration risk, and quantum computing vulnerabilities.

1. Introduction

A bank is not merely a repository of money; it is a repository of trust. When a farmer deposits the proceeds of his harvest into a savings account, when a young professional transfers her monthly salary to her parents, when a business borrows capital to expand its factory, each transaction is an act of faith in the safety and soundness of the banking system. In the twenty-first century, that faith is sustained not only by prudential regulation and capital adequacy but by the invisible, relentless discipline of cyber security.

India’s banking sector has undergone a digital revolution. The Unified Payments Interface processes billions of transactions monthly. Mobile banking apps have made the branch visit a rarity. Cloud computing, artificial intelligence, and open banking APIs are reshaping the financial landscape. The Reserve Bank of India’s Digital Payments Index charts a steep upward curve. But every new digital channel, every API, every cloud instance expands the attack surface. The adversaries are not amateurs: they are organised syndicates operating ransomware-as-a-service, state-sponsored groups probing for systemic vulnerabilities, and insiders with legitimate access and malign intent. A successful attack on a major bank is not merely a loss to that institution and its customers; it is a threat to the financial stability of the entire nation.

The Reserve Bank of India, as the guardian of the financial system, has constructed one of the world’s most comprehensive and demanding cyber security regulatory architectures. It is backed by the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023, and the CERT-In Directions. Compliance is not optional; it is enforced through audits, penalties, and business restrictions. This chapter explores the cyber security framework applicable to banks in India, the practical measures required to achieve resilience, and the governance structures that must be in place from the boardroom to the server room.

Quotation:

“A bank’s balance sheet may show crores in capital, but its true capital is the trust of its depositors. A cyber breach erodes that trust faster than any market downturn. Cyber security is not a cost centre; it is the insurance of the bank’s very existence.” — Shaktikanta Das, Governor, Reserve Bank of India, in a 2023 address at the CAFRAL conference.

2. The Banking Cyber Threat Landscape

Banks face a uniquely hostile threat environment. The following are the most significant cyber threats to Indian banks.

A. Financial Fraud Enabled by Social Engineering: The Jamtara vishing gangs, the phishing emails impersonating banks, the fake UPI apps, and the business email compromise scams all target the bank’s customers, but the bank bears the operational, reputational, and often financial liability. Under the RBI’s zero liability circular, a customer bears no loss if an unauthorised transaction results from a bank’s system breach or third-party failure, provided the customer reports it promptly. The fraud monitoring systems of the bank are the front line of defence.

B. Ransomware and Data Breaches: Banks hold vast quantities of sensitive personal data—KYC documents, financial statements, transaction histories—that are gold for identity thieves. A ransomware attack that encrypts core banking systems can halt operations. The 2018 Cosmos Bank heist, where attackers simultaneously compromised the ATM switch and the SWIFT terminal, demonstrated the devastating potential of a coordinated multi-vector attack.

C. Advanced Persistent Threats (APTs): State-sponsored groups target Indian banks for intelligence gathering and to prepare the battlefield for potential financial disruption. The Red Echo APT group, attributed to China, was detected in 2021 conducting reconnaissance on Indian power and banking networks. Such groups are patient, well-resourced, and capable of remaining undetected for months.

D. Supply Chain and Third-Party Risk: Banks depend on a vast ecosystem of IT vendors, payment gateways, cloud providers, and fintech partners. A breach at a small, poorly-secured vendor can cascade into the bank. The RBI’s outsourcing guidelines mandate rigorous due diligence, but the enforcement is a continuing challenge.

E. Insider Threats: The bank employee with legitimate access to customer data and core systems is a perennial risk. The 2023 case of a wealth management clerk in a Mumbai private bank selling HNI customer data on Telegram for two years before detection illustrates the danger.

Quotation:

“The threat landscape for a bank is not static; it is a living, evolving adversary. The attacker learns. The bank must learn faster.” — Dr. Lopa Mudraa Basu, Global CISO, in a 2023 DSCI Summit address.

3. The RBI’s Regulatory Architecture for Banking Cyber Security

The RBI has built a comprehensive, multi-layered regulatory edifice that sets the gold standard for sectoral cyber security regulation in India. The key components are:

A.      Master Direction on Digital Payment Security Controls (2021): This mandates banks to implement robust governance, multi-factor authentication, device and SIM binding, real-time fraud monitoring, security operations centres (SOC), and cyber crisis management plans.

B.      Cyber Security Framework for Banks (2018, updated 2021): This is the foundational document. It requires banks to have a board-approved cyber security policy, a cyber security risk management framework aligned with ISO 27001, annual vulnerability assessments and penetration testing (VAPT), and bi-annual red teaming exercises conducted by CERT-In empanelled auditors. It mandates the appointment of a Chief Information Security Officer (CISO) who reports directly to the board or the risk management committee.

C.      Guidelines on Information Security, Electronic Banking, Technology Risk Management, and Cyber Frauds: These cover specific areas such as electronic banking channels, mobile banking, payment aggregators, and fraud risk management.

D.      SWIFT-CBS Integration (2018): After the Cosmos Bank heist, the RBI mandated that all banks integrate their SWIFT messaging environment with their Core Banking Solution (CBS) to enable real-time reconciliation of SWIFT transactions. It also required dedicated, isolated workstations for SWIFT, multi-factor authentication, and network segmentation.

E.      Outsourcing and Third-Party Risk Management Guidelines: Banks must conduct comprehensive due diligence, risk assessment, and continuous monitoring of all IT and business process outsourcing partners. Contracts must include security requirements, audit rights, and breach notification obligations.

F.       Digital Lending Guidelines (2022): These address the specific risks of the digital lending ecosystem, mandating that loan disbursals and repayments flow directly between the borrower and the regulated entity’s bank account, eliminating pass-through third-party apps that misuse data.

G.     CERT-In Directions (2022): All cyber incidents must be reported within six hours. Banks, as body corporates, must retain logs for 180 days, synchronise system clocks, and maintain an accurate ICT asset register.

These regulations are not merely advisory. The RBI conducts regular inspections, thematic reviews, and cyber security audits. Non-compliance can result in monetary penalties, restrictions on business activities, and—in cases of gross failure—licence cancellation.

Example: 

Following the City Union Bank SWIFT fraud (2018), the RBI imposed a monetary penalty for non-compliance with its cyber security framework and directed the bank’s board to overhaul its IT governance. The penalty served as a sector-wide warning.

Quotation:

“The RBI’s cyber security framework is not a suggestion; it is a binding obligation. Banks that treat compliance as a checkbox exercise will find themselves on the wrong side of the regulator and the wrong side of their customers’ trust.” — M. Rajeshwar Rao, Deputy Governor, RBI, in a 2023 address on operational resilience.

4. Key Technical and Organisational Controls

A resilient bank implements a layered, defence-in-depth architecture. The following controls are foundational.

A. Network Security and Segmentation:

         i.            The bank’s network must be segmented into security zones: the core banking zone, the payment systems zone, the SWIFT zone, the ATM switch zone, and the internet-facing zone. Traffic between zones is strictly controlled by next-generation firewalls.

       ii.            The SWIFT environment must be physically and logically isolated, with dedicated, whitelisted workstations.

     iii.            Intrusion detection and prevention systems (IDS/IPS) monitor all traffic for anomalous patterns.

B. Identity and Access Management (IAM):

         i.            Multi-factor authentication is mandatory for all privileged access, remote access, and customer-facing applications.

       ii.            The principle of least privilege is enforced: every user, from the teller to the system administrator, has only the access necessary for their role.

     iii.            Privileged access management (PAM) tools control, monitor, and record all administrative sessions.

     iv.            User access is reviewed and recertified at regular intervals, and access is revoked immediately upon employee separation. 

C. Data Protection and Encryption:

         i.            All sensitive customer data—KYC documents, transaction records, Aadhaar numbers—is encrypted both at rest and in transit.

       ii.            Card-on-file tokenisation, mandated by the RBI effective October 2022, ensures that merchants and payment gateways store only tokens, not actual card numbers.

     iii.            Data loss prevention (DLP) systems monitor outbound communication to prevent unauthorised exfiltration of sensitive data. 

D. Security Operations Centre (SOC) and Incident Response:

         i.            Every bank must operate a 24/7 SOC, staffed by trained analysts, equipped with a security information and event management (SIEM) system that aggregates and analyses logs from all critical systems.

       ii.            A formal incident response plan is documented, rehearsed, and tested through regular tabletop exercises and simulated attacks.

     iii.            Cyber incidents are reported to the RBI and CERT-In within the mandated timelines. The bank’s board is informed of significant incidents.  

E. Vulnerability Assessment, Penetration Testing, and Red Teaming:

         i.            The bank conducts quarterly vulnerability assessments and annual penetration tests covering its entire IT infrastructure, including web applications, mobile apps, and APIs.

       ii.            Bi-annual red teaming exercises simulate real-world, multi-vector attacks to test the effectiveness of detection and response capabilities. These exercises are conducted by CERT-In empanelled auditors.     

F. Third-Party and Cloud Security

         i.            Before engaging a cloud service provider or an IT vendor, the bank conducts a thorough risk assessment and due diligence.

       ii.            Contracts with vendors include security requirements, the right to audit, and mandatory breach notification within defined timeframes.

     iii.            Cloud deployments comply with the RBI’s guidelines on outsourcing and data localisation requirements, where applicable.        

G. Business Continuity and Disaster Recovery:

         i.            The bank maintains a documented and tested business continuity plan (BCP) and disaster recovery (DR) plan.

       ii.            Critical systems have defined recovery time objectives (RTO) and recovery point objectives (RPO). For core banking and payment systems, RTO is measured in minutes.

     iii.            The DR site is geographically separated from the primary site, and live drills are conducted periodically. Backups are maintained offline and are immutable.  

Quotation:

“A bank’s resilience is not measured by the strength of its perimeter alone, but by its ability to detect, respond, and recover when the perimeter is breached. Assume breach, and build accordingly.” — Rajshekhar Pullabhatla, CISO of a leading Indian telecom operator, in a 2023 NASSCOM report on banking security.

5. Data Protection and the DPDP Act

The Digital Personal Data Protection Act, 2023, imposes significant additional obligations on banks, which are quintessential Data Fiduciaries.

A.      Consent and Notice: The bank must provide clear notice to customers about the personal data collected and the purposes of processing, and obtain free, specific, informed, and unambiguous consent. The standard account opening form must be reviewed to ensure compliance.

B.      Reasonable Security Safeguards: The bank must implement “reasonable security safeguards” to prevent a personal data breach. Compliance with the RBI’s Cyber Security Framework and ISO 27001 certification will be strong evidence of reasonableness.

C.      Breach Notification: In the event of a personal data breach, the bank must notify the Data Protection Board and each affected Data Principal (customer) in the prescribed manner and time frame. This is in addition to the RBI and CERT-In reporting obligations.

D.      Penalties: Failure to implement reasonable security safeguards can attract a penalty of up to ₹250 crore. Failure to notify a breach can attract a penalty of up to ₹200 crore.

E.      Significant Data Fiduciaries: Most large banks will be classified as Significant Data Fiduciaries, requiring them to appoint a Data Protection Officer, conduct periodic Data Protection Impact Assessments, and undergo independent data audits.

Quotation:

“The DPDP Act has added a new dimension to banking risk: the regulatory penalty risk. A ₹250 crore fine for a data breach is not a remote possibility; it is a clear and present danger that every board must price into its risk management framework.” — N.S. Nappinai, Advocate, Supreme Court, in a 2023 article on banking and data protection.

6. Incident Response and Reporting: The Golden Hour

Speed is the essence of effective cyber incident response in banking. The first hour—the “golden hour”—is often the difference between a contained incident and a systemic crisis.

A.    Immediate Actions: Upon detection, the SOC isolates affected systems, blocks suspicious IP addresses, disables compromised accounts, and initiates the incident response plan.

B.     Regulatory Reporting:

        i.            To CERT-In: within six hours for all mandated incident categories.

      ii.            To the RBI: within the timeline specified in the Cyber Security Framework (typically two to six hours for significant incidents).

    iii.            To the Data Protection Board: in the event of a personal data breach, within the timeline to be prescribed under the DPDP Act. 

C.    Forensic Preservation: A forensic image of affected systems is created immediately, with hash values recorded. Logs are preserved.

D.    Customer Communication: Affected customers are notified promptly, with clear guidance on protective steps.

E.     Post-Incident Review: A blameless post-mortem is conducted, and lessons learned are integrated into the security architecture.

Example: 

When the AIIMS ransomware attack occurred in 2022, the Delhi Police and CERT-In coordinated the response. While AIIMS is not a bank, the incident demonstrated the criticality of rapid containment and public communication. Banks have applied these lessons to their own incident response protocols.

7. Governance: The Role of the Board and Senior Management

Cyber security is a governance issue, not merely an IT issue. The RBI’s framework explicitly places accountability on the board of directors.

A.      Board Responsibilities: The board must approve the cyber security policy, review it annually, ensure adequate resource allocation, receive regular reports on the threat landscape and incidents, and satisfy itself that the bank’s cyber resilience meets regulatory and business requirements.

B.      CISO Independence: The CISO must report directly to the board or a board-level risk management committee, not buried within the IT department.

C.      Audit Committee: The audit committee must oversee the effectiveness of cyber security controls, internal audits, and external audit findings.

D.      Director Liability: Under the Companies Act, 2013, and the DPDP Act, directors can face personal liability for gross negligence leading to a significant breach.

Quotation:

“If the board does not understand cyber risk, it cannot govern it. Every bank board in India must have the competence to ask the right questions and demand the right answers from management on cyber security.” — Dr. P.M. Nair, IPS (Retd.), in a 2023 corporate governance address.

8. Emerging Threats and Future Directions

A.      Artificial Intelligence: AI is a double-edged sword. Banks use AI for fraud detection and customer service. Attackers use AI for hyper-personalised phishing, deepfake voice cloning to mimic senior executives, and autonomous malware. Defending against adversarial AI requires continuous investment in AI-driven defence.

B.      Cloud Concentration Risk: As banks migrate core systems to the cloud, they become dependent on a small number of global cloud service providers. A major outage or breach at a provider could cascade. The RBI is developing a cloud security framework to address this.

C.      Quantum Computing: Large-scale quantum computers will break current public-key cryptography. Banks must begin transitioning to post-quantum cryptography, as mandated by the National Quantum Mission.

Conclusion

The security of a bank is a public good. It protects the savings of the farmer, the capital of the entrepreneur, and the stability of the financial system. The Indian banking sector has, under the stewardship of the RBI, built a formidable cyber security architecture. The Master Directions, the Cyber Security Framework, the SWIFT integration mandate, and the continuous supervisory scrutiny have raised the bar. But the adversary does not rest, and technology does not stand still. The bank of the future will be secure not because it has the strongest walls, but because it has the most resilient culture—a culture where every employee is a sensor, every incident is a lesson, and every board meeting asks not “are we secure?” but “how do we become more resilient?”.

Quotation:

“The bank that survives the next decade will not be the one with the most capital or the largest network. It will be the one that has embedded cyber security into its DNA, from the boardroom to the teller’s counter.” — Dr. Sanjay Bahl, Director General, CERT-In, in a 2024 address to the Indian Banks’ Association.

 

Chapter References

1.        Reserve Bank of India, Master Direction on Digital Payment Security Controls, 2021.

2.        RBI, Cyber Security Framework for Banks, 2018 (updated 2021).

3.        RBI, Circular on SWIFT-CBS Integration, 2018.

4.        RBI, Guidelines on Digital Lending, September 2022.

5.        RBI, Guidelines on Information Security, Electronic Banking, Technology Risk Management, and Cyber Frauds.

6.        CERT-In, Directions on Information Security Practices, April 2022.

7.        Digital Personal Data Protection Act, 2023, Sections 5, 6, 8, Schedule.

8.        Information Technology Act, 2000, Sections 43A, 66, 70B.

9.        ISO/IEC 27001:2022, Information Security Management Systems.

10.     Cosmos Bank Heist, CBI Investigation, 2019; City Union Bank SWIFT Fraud, 2018.

11.     NCRB, Crime in India 2022; CERT-In, India Cyber Threat Report 2023.

12.     National Quantum Mission, 2023.

 

 

No comments:

Post a Comment