Kaspersky BFSI workshop examines AI security in banking

DQChannels Bureau
DQChannels Bureau
Kaspersky BFSI workshop examines AI security in banking

The Kaspersky BFSI workshop in Mumbai brought together policymakers, bankers, technologists and AI practitioners from close to 40 organisations to examine how India’s financial sector can prepare for AI-driven cyber risks. The discussion focused on the RBI’s draft Data Governance Directions and draft Model Risk Management framework, along with the wider questions of accountability, AI adoption and operational resilience.

The underlying message was simple: AI is moving faster than the governance structures built around it.

AI cyber risks are moving faster than rules

Heng Lee, Director, Government Affairs and Public Policy for APAC at Kaspersky, described frontier AI as a “known unknown”, with organisations still relying heavily on benchmarks and vendor disclosures. He also pointed to the shrinking gap between vulnerability discovery and exploitation as AI becomes capable of identifying and weaponising weaknesses.

For India’s BFSI sector, the regulatory focus is therefore becoming increasingly important. CERT-In’s incident-reporting rules and the RBI’s draft guidance were highlighted as key markers for organisations assessing their AI readiness.

Shadow AI puts sensitive data in play

The Kaspersky BFSI workshop also highlighted risks that can emerge inside organisations. Brijesh Singh, Principal Secretary, Information and Public Relations, Government of Maharashtra, raised concerns around “shadow AI”, where employees may feed confidential information into consumer AI tools without organisational visibility.

Deepfakes were another concern, particularly for KYC and identity verification. The discussion suggested that financial institutions face a higher responsibility when deploying AI because they manage both customer money and sensitive information.

Why AI security must go beyond the model

Kaspersky’s Vladislav Tushkanov argued that AI models should be treated as an “untrusted core” because their outputs can be unpredictable. That means security testing cannot stop at the model itself.

It also needs to cover RAG systems, agent harnesses, databases, access controls, integrations and tool-calling infrastructure. This creates a wider AI-powered cyber risks India challenge, where securing the surrounding systems becomes just as important as evaluating the AI model.

India BFSI sector needs stronger basics

A recurring point at the Kaspersky BFSI workshop was that the response does not necessarily require complicated new layers. Stronger data governance, identity and access controls, monitoring, model validation and board-level accountability were identified as practical foundations.

The conversation also showed why cybersecurity and AI governance can no longer be treated as separate areas. As banks and financial institutions adopt AI, security decisions increasingly need to sit alongside governance and risk decisions.

Financial cybersecurity shifts toward resilience

Closing the workshop, Jaydeep Singh, General Manager, India, Kaspersky, connected technological sovereignty with AI-enabled cybersecurity and layered defence. He acknowledged that complete technological sovereignty is not realistic for most organisations, pointing instead to diversification and resilience.

Read More: 

Orient Technologies makes a USD 5 million cybersecurity expansion move

Siemens and Redington expand industrial software access across Africa

CloudTV thunderOS takes aim at India’s TV OS gap

Commvault Active Directory Pre Recover targets identity downtime

Latest Stories