Join a community of professionals and get:
on all CeFPro events.
unlock speaker decks and audience polls.
Full library access the moment you sign up.
Digital Content

- Unlimited access to peer-contribution articles and insights
- Global research and market intelligence reports
- Discover Connect Magazine, a monthly publication
- Panel discussion and presentation recordings
- Banks are
strengthening partnerships with major technology vendors to counter
AI-enabled cyber threats
- Indian lenders have
identified 25 key technology providers for enhanced cyber resilience
initiatives
- A multi-agency
working group is developing a framework to identify vulnerabilities and
strengthen sector-wide defences
- Regulators warn that
third-party software and AI-generated code can create hidden systemic
vulnerabilities
- Banks are deploying
defensive AI tools to reduce network attack surfaces and improve threat
detection
- Supervisors globally
are increasing scrutiny of AI governance, vendor oversight and operational
resilience
- Experts say effective
cyber resilience requires stronger governance and communication alongside
AI technology
- Financial
institutions are increasingly treating cybersecurity as an ecosystem-wide
risk management challenge
India's banking sector has emerged at
the forefront of the trend, identifying 25 original equipment manufacturers
whose software and applications are widely deployed across the industry for
closer collaboration on AI-related cyber risk.
The initiative follows warnings from
the Reserve Bank of India that AI-enabled cyberattacks represent one of the
most significant systemic threats facing the country's financial sector.
A working group led by the State Bank
of India, with participation from nine banks, the finance ministry, the Reserve
Bank of India, the National Payments Corporation of India and the Indian
Computer Emergency Response Team, is developing a broader framework to identify
vulnerabilities and strengthen sector-wide cyber defences.
According to industry participants,
banks are being encouraged to reduce their network attack surface by deploying
defensive AI agents capable of detecting vulnerabilities before they can be
exploited.
The framework also envisages regular
reviews of mitigation measures as institutions adapt to an environment in which
AI is increasingly being used by both defenders and attackers.
The initiative highlights a growing
concern that even banks with robust internal controls remain vulnerable through
weaknesses in third-party technology providers.
Researchers at the National Institute
of Banking Management recently warned that financial institutions often lack
visibility into the open-source software libraries, AI-generated code and
external components embedded within the products they license.
A single vulnerability introduced
through commonly used software could therefore spread across multiple
institutions before it is detected, echoing the widespread disruption caused by
previous software supply chain incidents.
The emphasis on vendor oversight
mirrors a broader regulatory trend.
Banking supervisors in several
jurisdictions are increasingly focusing on third-party risk management, data
governance and AI oversight as financial institutions accelerate deployment of
generative AI across customer service, fraud detection, software development
and operational processes.
U.S. regulators, including the Office
of the Comptroller of the Currency and the Federal Reserve, have expanded
supervisory discussions around AI governance, vendor management and contingency
planning, while continuing to rely on existing risk management frameworks
rather than introducing AI-specific rules.
Cybersecurity experts also warn that
adopting advanced AI tools alone will not be sufficient to strengthen
resilience.
Industry analysts argue that banks
must combine AI-enabled detection with clear governance, rapid incident
response and effective customer communication if they are to maintain trust
during cyber incidents.
As cyberattacks become faster and
increasingly automated, organisations will need operational processes capable
of matching the speed of AI-driven threats.
The wider economic implications are
also attracting attention from regulators. The Monetary Authority of Singapore
recently warned that rapid advances in artificial intelligence are increasing
cybersecurity risks alongside broader financial stability concerns.
The authority noted that AI-powered
phishing campaigns and increasingly sophisticated cyberattacks are becoming
more prevalent, prompting renewed investment in advanced defensive technologies
across the financial sector.