Asia Dialogues
Digital Trust at Scale: Cybersecurity and the Future of India's Financial Ecosystem
Nineteen senior leaders from banking, financial services, insurance and technology met in Mumbai for a closed-door dialogue on how India's BFSI sector can accelerate innovation while safeguarding institutions, customers and the integrity of the financial system.
The question facing India's financial institutions is no longer whether they will face a cyberattack. It is whether they are truly prepared to withstand one. That was the premise of the Digital Trust at Scale edition of the SpeakIn Asia Dialogues Forum 2026, a 90-minute dialogue moderated by Suresh Mahalingam, Chairperson of the Board at Aviva India, bringing together board chairs, CISOs, national security experts and academic leaders.
The stakes are considerable. According to the Economic Survey 2025, one in five cyberattacks in India in 2024 targeted the BFSI sector, and IBM puts the average global cost of a data breach at around USD 4.4 million. Participants agreed that the traditional model, in which cybersecurity sits in the back office as a compliance burden, is broken.
Giles Castelino of LSEG made the point vividly. The infrastructure his organisation operates carries the majority of India's dollar-rupee foreign exchange trading, and a five-minute outage would create systemic risk for the country. Cybersecurity there has moved from a tick-the-box agenda item to a top-two board priority. Amisha Vora of PL Capital Group went further, arguing that boards must own cybersecurity strategy rather than simply receive quarterly briefings. Shraddha Thacker of UnionPay International called for a new standard of personal accountability as more technically literate independent directors join boards.
Several leaders described how security is moving earlier in the product lifecycle. Vishweshwaran Ramakrishnan of Unity Small Finance Bank explained that security teams are now brought into the design stage rather than summoned for final approval, a secure-by-design philosophy also championed by Anand Kumar Sinha of Tata Technologies, who framed trust around people, process and technology. Most institutions, participants admitted, are strong on technology but underinvest in people and process. Dr. Padmakumar Nair of Thapar Institute offered an evolutionary explanation: the human brain evolved to respond to immediate physical threats, not abstract digital ones, so resilient systems must be designed to withstand human error rather than depend on vigilance.
The tension between innovation and risk ran through the discussion. R. Kalyanaraman of BlinkX by JM Financial described 25 years of digitisation and the shift of household savings into financial instruments, which has made seamless, real-time experiences the baseline expectation. Ajay Thakur of TGI SME Capital Advisors reminded the room that trust precedes every transaction, and that the resilience of market infrastructure under continuous attack is the product of relentless investment, not luck.
Third-party risk emerged as the sector's most under-governed vulnerability. Vora described attacks in late 2024 and early 2025 that began at a single shared operations vendor and cascaded across several brokerage and mutual fund firms. Atul Garg of SIDBI captured the dilemma: every technology introduced for innovation also expands the risk surface.
The threat itself is evolving at machine speed. Amit Dubey, a national security and cyber intelligence expert, described criminal networks using AI-driven bots to build trust with victims over weeks before striking. Ranjan Bhattacharya of HSBC India warned of deepfake attacks that replicate a CEO's face and voice on live video calls, and proposed a model built on prevention, real-time response and recovery. Arnab Biswas of Axis Direct shared a case in which malware lay undetected for 18 months on a forgotten test server before reaching production, and urged boards to ask how many serious incidents they have avoided rather than how much they have spent. Hina Kamra of Neo Wealth and Asset Management summarised the mood: with ransomware sold as a service, organisations are either already breached or about to be.
Regulation is tightening. India's Digital Personal Data Protection Rules 2025, notified in November 2025, phase in full obligations by May 2027, with penalties of up to Rs 250 crore for failing to maintain reasonable security safeguards. Castelino pointed to the EU's Digital Operational Resilience Act as a model worth studying. Yet Mahalingam cautioned that compliance alone is not enough: an institution can pass every audit and remain operationally vulnerable if it has never tested its incident response or stress-tested its vendors. Dr. Mukesh Mehta argued for detailed playbooks that remove discretion at the moments when human judgement is least reliable.
The forum's call to action was clear. Cybersecurity should be a standing board agenda measured by effectiveness rather than compliance. Secure-by-design and zero-trust principles should be the default. Vendor risk must be governed as strategic risk, AI-powered defence must keep pace with automated attacks, and cyber risk should be translated into the financial language boards understand. Digital trust, participants concluded, is not a compliance checkbox. It is the foundation on which every future financial transaction will rest.
Read the White Paper
Flip through the Asia Dialogues Forum 2026 Mumbai white paper right here, or download the PDF to read later.
Digital Trust at Scale: Mumbai White Paper
Preparing the white paper…
The page-turning reader couldn’t load in this browser. You can still open or download the full white paper.
Open the white paper in a new tabDrag a page corner, click the arrows, or use ← → keys to turn pages.
Our Partners
Leading brands who have partnered with us.
Latest News
Latest updates, insights, and highlights from our leadership community