Digital Threat Report 2025-26
The Ministry of Electronics and Information Technology (MeitY), along with CERT‑In, CSIRT‑Fin, and SISA, releases the 2nd edition of the Digital Threat Report 2025‑26. The report provides a threat overview for India’s banking, insurance, and digital payments ecosystems, highlighting AI asymmetry and emerging cyber trends affecting BFSI and payments.
Digital Threat Report 2025-26 (2nd Edition):
| Dimension | Key Details |
|---|---|
| Release authorities | The 2nd edition is released by MeitY, CERT‑In, CSIRT‑Fin, and SISA. |
| Coverage sectors | The report covers threats affecting banking, insurance, and digital payments, including India’s BFSI and payments ecosystems. |
| Threat evolution | Six of seven predictions from last year’s report have already materialised, and the gap between threat emergence and exploitation shrinks from years to months or weeks. |
| Established attack methods | Attack methods now mainstream comprise social engineering, credential theft, supply‑chain compromise, and cloud exploitation. |
| Nature of attacks | Breaches often appear as legitimate sessions, approved payments, manipulated workflows, or ordinary user behaviour, making detection harder. |
| Cyber resilience risk | India’s financial system is highly connected, so one breach can spread across markets and economies. |
| Risk management approach | The report calls for ongoing risk checks, real‑time responses, and information sharing instead of occasional audits. |
| AI asymmetry | Low‑resource attackers can use AI to perform activities at machine speed, outpacing defensive and regulatory mechanisms. |
| Cyber failure framework | The report introduces a 4‑Layer Gap Archetype Framework to analyse how modern breaches escalate, and it states that major cyber failure is caused by a chain of small gaps. |
| Roadmap timeline | The report sets an 18‑month plan to guide financial institutions from basic security controls to continuous, resilient security systems. |
| CERT-In status and legal basis | Indian Computer Emergency Response Team (CERT‑In) is the national nodal agency under the IT Amendment Act 2008 for responding to computer security incidents. |
| CSIRT-Fin role | CSIRT‑Fin is a nodal sectoral CSIRT for India’s financial sector that provides incident prevention, response, and security quality management services. |
| SISA profile | SISA is a global cybersecurity leader for the payments ecosystem that secures 1,000+ organisations across 40+ countries using breach intelligence and AI‑driven solutions. |