AI-enabled cyber threats emerged as the leading perceived risk over the next 12 months: RBI survey
3 min read
The report warned that rapid AI progress can amplify the complexity, velocity, and magnitude of cyber incidents.
| Photo Credit:
istock.com
According to RBI’s latest Financial Stability Report, banks and NBFCs must keep investing in technology and cybersecurity to cope with the shifting cyber threat environment.
The report identified AI‑driven cyber threats as the top perceived risk for the coming year.
FSR pointed out that India still faces significant cyber‑attack exposure, ranking third globally in attack volume behind only Russia and Ukraine among emerging markets.
The report noted that rising geopolitical tensions can exacerbate cyber‑risk worries and demand greater vigilance. Accordingly, 42 % of the surveyed institutions said geopolitical uncertainty has raised the chance of cyberattacks.
These observations arise as cyber risk turns into a central financial‑ a central financial‑stability issue in a more digital and linked‑up financial system.
“Cyber incidents can impair vital financial infrastructure via outages, data loss, and payment disruptions, and also undermine public confidence in the system.”
“The swift uptake of digital financial services lately has broadened the attack surface for bad actors, fueling a worldwide increase in cyberattacks since 2020,” according to RBI’s survey of 33 scheduled commercial banks and 10 upper‑layer NBFCs.
AI-enabled threat preparedness
The report warned that fast‑moving AI progress can boost the complexity, speed, and scale of cyber incidents. Survey responses show that preparedness for AI‑enabled threats differs widely, with institutions at various stages of formalising and implementing measures inside their current cyber‑risk frameworks.
The majority placed themselves in the ‘Developing’ or ‘Intermediate’ categories, with only a minority claiming ‘Mature’ status. The report noted that, given AI‑driven cyber threats remain an evolving risk, ongoing, risk‑based enhancements to preparedness are anticipated, building on each entity’s existing security controls.
Therefore, ongoing improvements in threat monitoring, detection, response, staff awareness, incident readiness, and resilience—guided by regulators—will stay vital. In this context, aligning regulations across the financial sector becomes essential.
Third party dependency
Third‑party reliance and supply‑chain risk came in as the survey’s second‑top cyber concern. About 93 % of respondents said they are partly or heavily dependent on external vendors for cybersecurity tasks like SOC monitoring, cloud security, incident response, threat intelligence, and vulnerability assessments.
Furthermore, three‑quarters of the respondents reported moderate to very high operational dependence on third‑party tech providers for critical applications.
The report stressed that growing outsourcing amplifies supply‑chain risk, particularly when a few providers serve many banks at once. A significant cyber breach at one such provider could spread quickly across regulated firms, magnifying disruptions and threatening financial stability.
The report added that technology obsolescence and patch‑management challenges are closely tied to third‑party risks.
Survey data show that Indian financial institutions are actively managing technology‑lifecycle risks. Across critical categories—unsupported or end‑of‑life systems, those awaiting major upgrades, and those unable to get vendor patches—93 % of respondents said they have little or no exposure in essential services and applications.
This points to a solid base for operational resilience, yet ongoing vigilance is still needed because new vulnerabilities keep appearing fast.
IT expenditure
According to the survey, 81 % of respondents said their IT spending was under 5 % of revenue in FY 2025‑26. The IT‑to‑revenue ratios can differ among firms due to factors such as business model, group‑level tech setups, sourcing or outsourcing approaches, and the timing of major technology investments.
Nevertheless, indicators of improving cyber readiness are evident, shown by growing investments in people and security infrastructure. Between March 2025 and March 2026, roughly 67 % of respondents said they had increased IT and cybersecurity staff,” the survey noted.
Moreover, the share of cybersecurity spending within total IT budgets rose for 71 % of respondents over the past three fiscal years.
Published on July 1, 2026