The Ministry of Electronics and Information Technology released the second edition of the Digital Threat Report 2025-26 on 13 July 2026, offering a comprehensive assessment of cyber threats facing India’s banking, financial services, insurance and digital payments ecosystem. Developed jointly with CERT-In, CSIRT-Fin and cybersecurity firm SISA, the report warns that artificial intelligence is fundamentally altering the threat landscape and shortening the gap between innovation and exploitation. It also introduces a new analytical framework and an 18-month roadmap to help financial institutions build stronger cyber defences.
Understanding the Digital Threat Report
The Digital Threat Report 2025-26 is the second edition of an annual publication focused specifically on the Banking, Financial Services and Insurance (BFSI) sector. The report draws on three primary sources: digital forensics and incident response (DFIR) research from SISA’s investigations, observations from CERT-In and CSIRT-Fin on real-world cyber incidents, and analysis of adversarial AI techniques targeting the financial ecosystem.
CERT-In, the Indian Computer Emergency Response Team, is the national nodal agency for responding to cybersecurity incidents. Established in 2004 and operating under MeitY, it was formally designated under Section 70B of the Information Technology (Amendment) Act, 2008 to handle functions such as collecting and disseminating information on cyber incidents, issuing alerts and coordinating response activities. CSIRT-Fin, the Computer Security Incident Response Team for the Finance sector, is a sectoral body that manages cyber incidents across banking, securities market infrastructure, insurance and pension fund entities, working closely with regulators including RBI, SEBI, IRDA and PFRDA.
SISA, a global forensics-driven cybersecurity company headquartered in Bengaluru, was founded in 2006 by Dharshan Shanthamurthy. The company specialises in payment ecosystem security and has operations across more than 40 countries, serving over 1,000 organisations.
The report is aimed at financial institutions, regulators and cybersecurity leaders. Its central finding is striking: six of the seven forward-looking predictions made in the 2024-25 edition have already reached full-scale realisation, demonstrating how rapidly cyber threats are evolving.
AI Asymmetry: The Defining Risk
The report identifies AI asymmetry as one of the most critical risks facing financial institutions. This term describes the widening gap between the speed and sophistication of AI-powered offensive capabilities and the relatively slower pace of defensive and regulatory mechanisms.
In the past, launching a sophisticated cyberattack required specialist teams, substantial computing resources and weeks of preparation. Today, the same tasks can be executed at machine speed by comparatively low-resource threat actors using generative AI, large language models and automated tools. AI-generated phishing emails, voice cloning, deepfake customer impersonation and automated malware generation have moved from theoretical possibilities to operational realities.
The consequence is a threat environment where attackers can innovate faster than defenders can adapt. Offensive AI capabilities are on a faster development curve than the regulatory frameworks and security controls designed to contain them. MeitY Secretary S. Krishnan emphasised that building domestic capacity in AI and cybersecurity is critical for India to secure its digital infrastructure.
Threat Acceleration and Evolving Attack Methods
A key theme of the report is the dramatic compression of the threat timeline. The time between the discovery of a vulnerability and its operational exploitation has shrunk from years to months, and in some cases, to just weeks. This acceleration makes traditional periodic security assessments, annual audits and compliance checks inadequate for the current threat environment.
Threats that were once considered emerging or episodic have now become mainstream attack methods:
| Attack Method | Description |
|---|---|
| Social Engineering | Manipulating individuals to divulge confidential information or perform actions that compromise security |
| Credential Theft | Stealing usernames, passwords and authentication tokens to gain unauthorised access |
| Supply-Chain Compromise | Targeting third-party vendors and service providers to breach primary institutions |
| Cloud Exploitation | Exploiting misconfigurations and vulnerabilities in cloud infrastructure |
The report notes that the most damaging attacks today no longer resemble traditional intrusions. They surface as legitimate user sessions, approved payment transactions, manipulated workflows or ordinary user behaviour that is indistinguishable from genuine activity until the damage is done. This makes detection extremely difficult and places enormous pressure on institutions to build real-time monitoring and response capabilities.
The Anatomy of Cyber Failure Framework
A standout feature of this edition is the Anatomy of Cyber Failure: A 4-Layer Gap Archetype Framework. The framework is designed to help organisations understand why well-established security controls still fail under real-world adversarial pressure.
The core insight of the framework is that a major cyber breach is rarely caused by a single technical lapse. Instead, it is the result of multiple gaps aligning across four interconnected layers:
| Layer | Gap Type | Description |
|---|---|---|
| Layer 1 | Design Gaps | Systems are built for correctness, not adversarial reality. Missing threat models and implicit trust assumptions create entry points |
| Layer 2 | Enforcement Gaps | Controls exist on paper but fail under real-world conditions. Control bypass paths and misaligned detection logic allow adversaries to slip through |
| Layer 3 | Signal Gaps | The system does not generate or interpret the right signals. Detection silos and behavioural baseline gaps mean threats go unnoticed |
| Layer 4 | Response Gaps | Even when signals exist, action fails. Detection-to-response latency and manual-only containment procedures delay intervention |
The framework is grounded in evidence from hundreds of SISA engagements, including security assessments, red team exercises, AI model testing under adversarial conditions, and forensic investigations following real breaches. It helps organisations identify recurring failure patterns, prioritise systemic risks and direct investments toward the gaps with the greatest potential impact.
CERT-In Director General Dr. Sanjay Bahl noted that as India’s financial ecosystem becomes more interconnected and real-time, cyber resilience must be treated as a shared responsibility across institutions, regulators and the wider digital supply chain. He called for moving beyond periodic security interventions towards continuous risk assessment, coordinated response and stronger information sharing.
The 18-Month Cyber Resilience Roadmap
The report converts its findings into actionable direction through an 18-month implementation roadmap structured across three horizons. The roadmap aims to guide financial institutions from foundational controls to resilient security architectures.
| Horizon | Timeline | Focus Area |
|---|---|---|
| Horizon 1 | Months 1-6 | Strengthen foundational controls: identity management, access control, endpoint protection, patch management |
| Horizon 2 | Months 7-12 | Build continuous capabilities: continuous monitoring, threat hunting, Security Operations Centre (SOC) maturity, incident response drills |
| Horizon 3 | Months 13-18 | Develop resilient architectures: Zero Trust Architecture, AI-enabled defence, cyber resilience frameworks |
The roadmap is mapped against six BFSI operating layers and is designed to help institutions transition from reactive, compliance-driven security to proactive, intelligence-led cyber resilience. It emphasises that compliance with regulatory frameworks, while necessary, is not sufficient. The report identifies a compliance-security translation gap, where controls that pass periodic assessments often fail under adversarial pressure.
Dharshan Shanthamurthy, Founder and CEO of SISA, described the narrowing distance between innovation and exploitation as a fundamental shift that changes how the industry must defend itself. He stressed that cybersecurity can no longer sit at the edge of the business as a technical control function but must become central to how institutions grow, innovate and lead.
Key Takeaways
- The Digital Threat Report 2025-26 was released by MeitY on 13 July 2026 in collaboration with CERT-In, CSIRT-Fin and SISA, focusing on India’s BFSI sector.
- The report identifies AI asymmetry as a defining risk, where AI-powered offensive capabilities are outpacing defensive and regulatory mechanisms.
- Six of seven predictions from the 2024-25 edition have already materialised, showing that the threat lifecycle has compressed from years to weeks.
- The Anatomy of Cyber Failure framework introduces four gap layers: Design, Enforcement, Signal and Response gaps that combine to enable breaches.
- The 18-month roadmap moves from foundational controls to continuous capabilities and resilient architectures across three horizons.
- CERT-In, established in 2004 under Section 70B of the IT (Amendment) Act, 2008, is the national nodal agency for cybersecurity incident response in India.