Kaspersky Highlights AI-Powered Cyber Risks for India’s Financial Sector at BFSI Workshop

The workshop examined how India’s banks and financial institutions can build AI-ready cyber resilience, with a core focus on the Reserve Bank of India’s (RBI) draft Data Governance Directions and draft Model Risk Management framework, and their implications for cybersecurity, AI adoption, accountability and operational resilience.
Kaspersky Highlights AI-Powered Cyber Risks for India’s Financial Sector at BFSI Workshop
Published on
3 min read

Kaspersky convened a workshop on “Cybersecurity and AI in India’s BFSI Sector,” together with Safer Internet India in Mumbai, India. The workshop examined how India’s banks and financial institutions can build AI-ready cyber resilience, with a core focus on the Reserve Bank of India’s (RBI) draft Data Governance Directions and draft Model Risk Management framework, and their implications for cybersecurity, AI adoption, accountability and operational resilience.

Policymakers, bankers, technologists and AI practitioners from close to 40 organisations took part, hailing from global and Indian banks, NBFCs and fintechs, market infrastructure bodies, advisory firms, and academic institutions, alongside knowledge partner Airtel. 

Heng Lee, Director, Government Affairs and Public Policy for APAC at Kaspersky, opened the session by describing frontier AI as a “known unknown” that something regulators and companies are largely assessing through benchmarks and vendor disclosures rather than hands-on testing. He walked through how Singapore and Australia are approaching AI-enabled cyber risk, and pointed out that the window between a vulnerability being found and being exploited has shrunk from months to hours, since AI can now identify and weaponise weaknesses. Turning to India, he referenced CERT-In’s incident-reporting rules and the RBI’s draft Model Risk Management and Data Governance guidance as the key regulatory markers to watch.

Brijesh Singh, Principal Secretary, Information and Public Relations, Government of Maharashtra, was a special guest at the event. He described the phenomenon of “AI-agentified” cyber kill chain attacks, where AI agents now automate and coordinate stages that once required specialised human actors. Deepfakes came up as a particular worry for KYC and identity verification, and he spent some time on “shadow AI”: employees quietly feeding confidential data into consumer AI tools the organisation has no visibility into. His broader point was that financial institutions owe their customers a higher standard of care than most other sectors when it comes to deploying AI, because they hold people’s money and data.

A panel moderated by Vivan Sharan, Co-Convenor of Safer Internet India, explored how far boards actually understand the AI risks they are signing off on, and what an organisation does in practice about shadow AI. Kaspersky's Vladislav Tushkanov, R&D Group Manager, argued that AI models should be treated as an “untrusted core” – not because they are malicious, but because their outputs are inherently unpredictable, which means security testing can't stop at the model. It has to cover the RAG systems, agent harnesses, databases, access controls, integrations and tool-calling infrastructure around it too.

Tushkanov observed that “the regulatory framework is starting to catch up with the fact that companies are going to use AI because of all the benefits and all the transformative power that this technology has”.

A recurring thread throughout the session was that AI is moving faster than the governance structures meant to keep pace with it. Speakers posited that the fix has more to do with getting the basics right: data governance, identity and access controls, monitoring, model validation, and board-level accountability. Cybersecurity and AI governance, several noted, are no longer really separate conversations. This is a challenge that requires regulators, banks, technology providers, cybersecurity firms and industry bodies pulling in the same direction.

Closing the workshop, Jaydeep Singh, General Manager, India, Kaspersky, tied the threads together technological sovereignty, AI-enabled cybersecurity, layered defence and was candid that full technological sovereignty was not realistically achievable for most organisations; diversification and resilience are the more realistic goals. He pointed to Kaspersky’s own use of AI and machine learning to catch new malware at scale, as well as its investment in an AI Centre of Excellence.

𝐒𝐭𝐚𝐲 𝐢𝐧𝐟𝐨𝐫𝐦𝐞𝐝 𝐰𝐢𝐭𝐡 𝐨𝐮𝐫 𝐥𝐚𝐭𝐞𝐬𝐭 𝐮𝐩𝐝𝐚𝐭𝐞𝐬 𝐛𝐲 𝐣𝐨𝐢𝐧𝐢𝐧𝐠 𝐭𝐡𝐞 WhatsApp Channel now! 👈📲

𝑭𝒐𝒍𝒍𝒐𝒘 𝑶𝒖𝒓 𝑺𝒐𝒄𝒊𝒂𝒍 𝑴𝒆𝒅𝒊𝒂 𝑷𝒂𝒈𝒆𝐬 👉 FacebookLinkedInTwitterInstagram

logo
DIGITAL TERMINAL
digitalterminal.in