Small Urban Co-operative Banks Face Outsized Cybersecurity Risks, RBI Warns

The420.in Staff
4 Min Read

Small urban co-operative banks face cybersecurity risks that can be disproportionately large compared with their size, Reserve Bank of India Deputy Governor Swaminathan J has cautioned, calling for stronger technology governance, better oversight of service providers and greater preparedness against cyber threats.

Speaking at the Mission SAHASRA programme for Directors, Managing Directors and CEOs of Urban Co-operative Banks in Telangana, Swaminathan said the growing use of technology in banking has changed the nature of risks faced by smaller institutions. He stressed that technology must be treated as a core governance issue rather than merely an operational matter.

FCRF Launches Flagship Certified Cyber Security Auditor (CCSA) Program for Next-Generation Cyber Auditors

Technology Risks Demand Greater Board Attention

Swaminathan said urban co-operative banks should ensure that technology-related risks receive adequate attention at the board level. While the size of a UCB may be limited, he said, the risks it faces may become magnified because of dependence on technology, particularly where infrastructure is shared.

He pointed to the growing reliance on service providers and shared technology arrangements, which can create vulnerabilities extending beyond an individual institution. A cyberattack or technology failure affecting shared systems could have consequences for multiple banks.

The Deputy Governor also emphasised that banks need to understand the risks arising from their technology arrangements and ensure appropriate safeguards are in place. As banking services increasingly depend on digital channels, technology governance has become closely linked with operational resilience and customer protection.

Smaller Banks Need Stronger Cyber Preparedness

Swaminathan said smaller UCBs may not have the same resources and specialised manpower available to larger commercial banks to deal with complex cyber threats, digital fraud and technology failures.

This makes it important for such banks to strengthen their preparedness and ensure that technology-related responsibilities are clearly understood. The remarks underline the need for boards and senior management to remain engaged with cyber risks rather than treating them solely as technical matters.

He also referred to the need for effective oversight of service providers. As banks increasingly rely on outside technology partners, weaknesses in third-party systems can create operational and security risks for financial institutions and their customers.

The Deputy Governor’s remarks come as banking services continue to shift towards digital platforms, increasing the importance of secure systems, resilient infrastructure and effective management of technology-related risks.

Mission SAHASRA Focuses on UCB Governance

Swaminathan also highlighted Mission SAHASRA, a Reserve Bank initiative launched in April this year to build capabilities among urban co-operative banks.

The programme aims to cover about 1,400 participants and has separate learning programmes for board members, senior management and assurance function heads. The initiative focuses on strengthening governance and improving the ability of UCB leadership to deal with emerging challenges.

His remarks placed cybersecurity within the wider responsibility of bank leadership, stressing that boards and senior executives must understand technology risks and ensure that appropriate safeguards and oversight mechanisms are in place.

As UCBs expand their use of digital services, the message from the RBI Deputy Governor was that their relatively small size does not necessarily translate into smaller technology risks. Dependence on shared infrastructure, external service providers and digital systems can expose these institutions to threats capable of causing wider disruption.

Stay Connected