Banks Draw Vendors Into Fight Against AI-Led Cyber Risks: Report

A State Bank of India-led group is working on a common security framework as lenders examine weaknesses that may sit inside third-party software, cloud systems and AI-generated code.

Topics

  • Indian banks are preparing to work with 25 technology vendors to identify cybersecurity weaknesses linked to artificial intelligence, The Economic Times reported on Thursday, July 23.

    These companies already supply tools and applications used across the banking sector. Their involvement is meant to help lenders find vulnerabilities that may be embedded in licensed software or shared technology systems, rather than in infrastructure controlled directly by individual banks, ET said, citing people familiar with the matter.

    A separate working group led by the State Bank of India (SBI) is developing a broader framework for identifying such gaps and improving defenses against AI-enabled attacks.

    The group includes representatives from nine banks, the finance ministry, the Reserve Bank of India, the National Payments Corporation of India and the Indian Computer Emergency Response Team, ET reported.

    The banks and technology companies involved have not been named. SBI, the finance ministry and the RBI have also not publicly set out the scope or timetable of the exercise.

    The initiative reflects a problem that has become harder for banks to contain within their own walls. Much of their technology now depends on outside vendors, cloud services, open-source software and fintech integrations. A lender may have strong internal controls and still be exposed through a widely used third-party product.

    The primary concern is not that vendors can be breached but that the same software, code libraries or cloud services may be used by several banks at once.

    A working paper published by the National Institute of Bank Management (NIBM) said banks often have limited visibility into the open-source components, third-party libraries and AI-generated code built into products they license.

    A flaw in a commonly used component can spread well beyond one institution and AI-generated code may deepen the problem if the same vulnerable patterns are reused across several products without being detected.

    The paper pointed to earlier software supply-chain failures, including the difficulty organizations faced in tracing where the Log4j vulnerability appeared across their systems.

    For banks, this makes vendor oversight part of the security architecture. Technology suppliers may need to disclose software components more clearly, identify where AI is used and support coordinated testing when a weakness is found.

    The NIBM paper also said many banks still lack the technical capacity to test advanced AI systems properly. Frontier models can scan large codebases, identify weaknesses and connect separate flaws into a usable attack path. Security teams without equivalent tools or expertise may struggle to assess how exposed they are.

    It recommended shared testing infrastructure, stronger disclosure standards for vendors and closer coordination across the banking system.

    The banking-sector initiative follows a warning in the RBI’s June Financial Stability Report.

    In a survey of major banks and non-banking financial companies, AI-enabled cyberattacks emerged as the most serious cyber risk expected over the following 12 months. Third-party dependence and supply-chain exposure ranked close behind.

    Most institutions described their preparedness for AI-related threats as developing or intermediate rather than mature.

    The RBI also found that about 93% of the institutions surveyed relied partly or substantially on external providers for services such as security monitoring, cloud security, incident response and threat intelligence. Three-quarters reported moderate to very high dependence on third parties for critical applications.

    Indian banks are already required to assess vendors, monitor systems continuously, report cyber incidents and protect customer information handled by third parties. Boards are also expected to oversee major control gaps and the steps taken to close them.

    AI makes those obligations more demanding. Attackers can use models to speed up reconnaissance, write more convincing phishing messages, search for software flaws and automate parts of an intrusion.

    Banks are also turning to AI for defense. The same technology can help inspect code, link alerts and identify unusual activity more quickly.

    Topics

    More Like This

    You must to post a comment.

    First time here? : Comment on articles and get access to many more articles.