Digital Threat Report 2025-26

  • 16 Jul 2026

In News:

The Ministry of Electronics and Information Technology (MeitY), in collaboration with CERT-In, CSIRT-Fin and SISA, has released the second edition of the Digital Threat Report 2025–26 for India's Banking, Financial Services & Insurance (BFSI) and digital payments ecosystem. The report assesses emerging cyber threats and provides a roadmap to strengthen the resilience of India's financial sector.

About the Digital Threat Report 2025–26

The report is based on Digital Forensics and Incident Response (DFIR) investigations, threat intelligence, observations from CERT-In and CSIRT-Fin, and research on adversarial Artificial Intelligence (AI).

A key finding is that six of the seven cyber threat predictions made in the previous edition have already materialised, indicating that the gap between the emergence of a cyber threat and its exploitation has reduced dramatically—from years to months or even weeks.

Key Findings

The report notes that cyberattacks have evolved beyond conventional hacking methods. Increasingly, attacks appear as legitimate user sessions, authorised transactions, manipulated workflows and normal user behaviour, making them difficult to detect until significant damage has occurred.

One of the most significant concerns identified is AI asymmetry, where malicious actors are leveraging AI to launch sophisticated attacks at machine speed, while defensive and regulatory systems struggle to keep pace.

The report also highlights that threats such as:

  • Social engineering
  • Credential theft
  • Supply-chain attacks
  • Cloud exploitation

have now become mainstream attack vectors for the financial sector.

4-Layer Gap Archetype Framework

A major feature of this edition is the "Anatomy of Cyber Failure" – 4-Layer Gap Archetype Framework, which explains how cyber breaches typically result from a series of interconnected weaknesses rather than a single security lapse.

The framework enables organisations to:

  • Identify systemic vulnerabilities.
  • Prioritise high-risk security gaps.
  • Invest in long-term cyber resilience instead of isolated security controls.

Recommendations

The report recommends shifting from periodic cybersecurity measures to continuous risk assessment and proactive cyber resilience.

It proposes:

  • Continuous monitoring of cyber risks.
  • Greater information sharing among financial institutions.
  • Coordinated incident response mechanisms.
  • Building resilient security architectures.
  • An 18-month roadmap to strengthen foundational controls and develop long-term cybersecurity capabilities.

Key Institutions

CERT-In

The Indian Computer Emergency Response Team (CERT-In) is India's national nodal agency for responding to cybersecurity incidents. It is responsible for:

  • Collecting and analysing cyber incident information.
  • Issuing alerts, advisories and vulnerability notes.
  • Coordinating national cyber incident response.
  • Publishing cybersecurity guidelines and best practices.

CSIRT-Fin

The Computer Security Incident Response Team in Finance (CSIRT-Fin) is the sectoral cyber incident response agency for India's financial sector. It coordinates cybersecurity across:

  • Banking
  • Insurance
  • Securities market infrastructure
  • Pension funds

It also issues sector-specific advisories, coordinates incident response and promotes cyber resilience across financial institutions.