India's Financial Sector Needs Coherent Data and Cybersecurity Frameworks
India's financial sector faces growing cybersecurity risks due to rapid AI and ML adoption. New regulations aim to enhance data governance and cybersecurity resilience across institutions.
India's financial sector is responding to the escalating cybersecurity threats posed by the rapid adoption of artificial intelligence (AI) and machine learning (ML). Financial institutions are becoming increasingly susceptible to cyberattacks as these technologies advance, making attacks more scalable and potent.
New regulatory developments, including the Draft Guidance on Regulatory Expectations for Data Governance and a consolidated Cybersecurity Framework, aim to harmonize and clarify requirements for data management and cybersecurity. These replace a patchwork of previous instructions with a more unified approach.
Regulators, such as the Reserve Bank of India (RBI), have begun to address these emerging risks. A high-level meeting in April assessed the implications of advanced AI models on banking sector cyber resilience. In June, the RBI mandated banks to conduct gap assessments and submit action plans for managing AI-related risks.
The consolidation of these frameworks is crucial, as data and cyber risks are often interconnected. For instance, a data breach like the one at Bank of Baroda, which resulted in customer data exposure, necessitated the activation of both cybersecurity and data governance protocols. Unified standard operating procedures are intended to prevent duplication and confusion during incident response.
The European Union has similarly harmonized ICT risk management practices for financial entities through its Digital Operational Resilience Act. India's initiative seeks to establish a comparable framework to ensure adequate data protection and cybersecurity across the entire financial ecosystem.