The Reserve Bank of India has called on banks and financial institutions to treat technology and cyber risk as a central part of financial resilience, warning that failures in digital infrastructure can disrupt essential services, expose sensitive data and affect customers across an increasingly interconnected financial system.
RBI Deputy Governor Rohit Jain, speaking at the SBI Banking and Economic Conclave in Mumbai on September 24, said technology investment should also be viewed as an investment in risk management, while the expansion of digital payments must not come at the cost of trust and resilience.
He also stressed that artificial intelligence could fundamentally change financial services, but governance must come before large-scale adoption.
Why Is Technology Now a Banking Risk?
Technology has transformed Indian banking over the past two decades by expanding access, lowering transaction costs and allowing institutions to provide round-the-clock services.
Jain said the sector is now entering a different phase in which technology is not simply changing how banking services are delivered, but is shaping the architecture of banking itself.
A bank may have adequate capital, liquidity and a strong balance sheet, but customers can still lose access to essential financial services if a critical technology system becomes unavailable, a cyber incident disrupts operations or an important technology dependency fails.
This means financial resilience and technology resilience can no longer be considered separately. Technology architecture is becoming part of a bank’s overall risk architecture.
Jain said technology investment should therefore be treated as a risk investment because it supports continuity, confidence and financial stability.
How Big Has Digital Banking Become?
The scale of India’s digital transformation is particularly visible in payments. UPI processed 24.9 billion transactions worth approximately ₹30.15 lakh crore in August 2026, equivalent to nearly 79 crore transactions every day.
Over the past decade, UPI transaction volumes have increased nearly 13,000-fold. During FY 2025-26, the platform processed 24,162 crore transactions.
Other parts of India’s digital financial infrastructure, including Account Aggregator and the Unified Lending Interface, are also changing how financial information is accessed and how credit is originated.
However, Jain said scale creates responsibility. When a system handles millions or billions of transactions, a technology failure can have consequences beyond a single institution, potentially affecting customers, counterparties and the wider financial system.
What Have Past Cyber Incidents Taught Banks?
Past disruptions have shown that protecting only a bank’s core systems is not enough.
Jain referred to a 2018 cyberattack on a cooperative bank in India involving the compromise of its ATM switch and subsequent misuse of the SWIFT network. The incident showed how weaknesses at a payment interface could bypass conventional controls and enable fraud across jurisdictions.
The lesson, he said, was that payment switches, connected channels, authentication mechanisms and transaction-monitoring controls also need protection as part of an integrated security architecture.
He also referred to mobile and internet banking outages, which underline the need for capacity planning, modernisation of legacy systems, change management, disaster recovery and resilience among third-party providers.
A technology outage for a customer is not merely a technical problem. It can mean being unable to access money or complete an urgent financial transaction.
Jain also cited the 2017 Equifax data breach in the United States and the 2024 CrowdStrike outage as examples of wider technology risks. The latter was not a cyberattack and was not confined to the financial sector, but demonstrated how a faulty software update from a major technology provider could cause widespread disruption.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
Where Are New Cyber Threats Coming From?
The RBI Deputy Governor said cybersecurity can no longer be understood simply as protecting an institution’s external perimeter.
Modern banking environments include core banking platforms, payment applications, APIs, cloud infrastructure, data centres, cybersecurity tools, software and hardware providers, external technology service providers and increasingly AI models and services.
These systems are interconnected. A disruption or compromise at one point can affect other parts of the ecosystem.
Cyber threats are also combining technical vulnerabilities with human behaviour. Ransomware can interrupt critical systems, compromised credentials can provide access to sensitive applications, and APIs can create additional points of exposure even while improving efficiency.
Insider threats can misuse legitimate access, while social engineering can manipulate employees and customers without requiring a highly sophisticated technical breach.
Deepfakes, voice cloning and AI-enabled fraud add another layer of risk because malicious actors can use them to impersonate people, create convincing communications and personalise fraudulent interactions at scale.
Jain said attackers may not always try to defeat the strongest technical defence. Instead, they may target the weakest identity, process, interface or human decision within a connected ecosystem.
How Does AI Change the Risk?
Artificial intelligence can strengthen customer service, fraud detection, risk assessment and productivity while helping financial institutions analyse large volumes of information.
But the same speed and scale can amplify mistakes. This is particularly important in financial services because automated outputs can influence credit decisions, fraud alerts, customer access, pricing and service delivery.
Jain said AI use must therefore be supported by validation, monitoring, human oversight and clear accountability.
AI can also work on both sides of cybersecurity. Criminals can use it to scale phishing, impersonation, vulnerability exploitation and other attacks. Financial institutions, meanwhile, can deploy AI for continuous threat detection, behavioural anomaly analysis and automated incident response.
The banking ecosystem should move towards coordinated and responsible use of AI-enabled cybersecurity, including centralised threat intelligence and automated detection and response mechanisms, so emerging threats can be identified and contained across the ecosystem.
What Should Banks Do About Third-Party Risks?
Banks increasingly depend on outside providers for infrastructure, software and cybersecurity capabilities, but Jain stressed that outsourcing technology does not mean outsourcing accountability.
Institutions must understand risks linked to external dependencies, including access controls, concentration, recoverability, data protection and options for exiting an arrangement.
A vulnerability in a connected fintech, software provider, payment interface or common cloud environment can have consequences beyond the organisation where the weakness first appears.
A dependency that appears manageable for one institution could become a concentration risk when several banks and financial entities depend on the same provider.
The wider risk architecture must therefore be assessed across the interconnected financial ecosystem rather than only within individual institutions.
What Are RBI’s 10 Requirements for Technology and Cyber Risk Management?
RBI Deputy Governor Rohit Jain laid out ten key requirements that banks and financial institutions should focus on as technology becomes increasingly central to their operations.
1. Make Governance Deliver Results: Banks need strong governance arrangements and technology-risk frameworks, but the real test is whether those frameworks produce effective outcomes.
2. Maintain Visibility Across Technology Systems: Financial institutions need adequate visibility into their complex technology environments, including the assets and exposures that have to be monitored and managed.
3. Fix Vulnerabilities and Legacy Technology on Time: Identifying vulnerabilities is not enough. Banks need to address material weaknesses according to their severity and potential impact, while also dealing with risks created by older technology.
4. Strengthen Identity and Access Management: Strong authentication, appropriate access privileges and effective monitoring should remain fundamental to managing who can access critical systems and information.
5. Check Whether Security Controls Actually Work: Banks should not focus only on deploying cybersecurity controls. They must also determine whether those controls are operating effectively and delivering their intended results.
6. Keep Controls in Step With Technology: Risk-management and control processes need to evolve at the same speed at which new technology is developed, implemented and scaled.
7. Manage Third-Party Dependencies: Banks should understand their critical external dependencies, the risks they create and the resilience of those arrangements. Reliance on outside providers does not remove the institution’s accountability for technology risk.
8. Learn From Cyber and Technology Incidents: Post-incident reviews should go beyond identifying what happened. Their value lies in reducing the likelihood of similar incidents happening again and limiting their impact if they recur.
9. Regularly Test Recovery and Resilience: Recovery arrangements need regular and realistic testing so institutions can determine whether they will work during an actual disruption and improve their preparedness.
10. Address Architecture and Capacity Problems: Banks should identify and address underlying weaknesses in technology architecture and capacity because these can prevent sustained improvements in technology-risk management.
Jain’s broader message was that sound technology governance is not about eliminating every possibility of failure. Banks need the institutional capacity to identify vulnerabilities early, make informed decisions, contain disruptions, protect customers and restore critical services when problems occur.
The420 Takeaway: “Digital Banking Can Scale Only if Security Scales With It”
India’s banking system is becoming faster, more connected and increasingly dependent on technology, but that also expands the number of places where disruption can begin.
As banks adopt AI, cloud services, APIs and outside technology providers, cybersecurity and resilience can no longer remain only an IT responsibility. They have become central to keeping financial services available, secure and trusted.
About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics