FORENSIC ACCOUNTING • CYBERSECURITY & BANKING RISK DEFENSE The Chartered Accountant • October 2022 • Vol. 71 • pp. 38–45 (Journal pp. 386–393)

Defensive Solutions against Cyber Threats in Indian Banking Ecosystem

AK
Ankur Khairwal
Executive Officer, The Institute of Chartered Accountants of India (ICAI) • eboard@icai.in
HB
Dr. Haresh Barot
Associate Dean, School of Management Studies (SMS), NFSU • eboard@icai.in

The Threat Landscape: Digitization as a Double-Edged Sword

In the current tech era, one of the most destructive crimes is cyber fraud. With time, they are growing rapidly, and the banking sector is most prone and always remains top on the hit list. Improved digitization in the banking sector has given a fillip to cyber frauds globally. Fraudsters targeting the financial sector have grown very rapidly in past years.

Bank frauds such as unauthorized access to credit/debit card details, phishing, identity theft, vishing and smishing followed by QR code/UPI scams are growing rapidly. Considering possible approaches in thought, this paper explores concrete channels and defensive prevention strategies against such cyber threats.

1. Escalating Crisis: The 24-Month Detection Lag & Value Surges

Fraud, committed with either a small or big amount, puts the banks’ reputation at stake. Fraud detection is a set of tasks and activities undertaken to prevent/safeguard money or property from being obtained illegally and by false means. In this situation, early detection of fraud can save the bank, its reputation, the trust of common people and the economy to a better extent. For this, the bank authorities should be trained in this area.

159% Surge Fraud Value Growth in FY 2020

In financial year 2020, fraud percentage by value increased by 159% compared to FY 2019.[1]

~24 Months Average Lag to Detection

The average lag between cyber fraud execution and detection is about 24 months, severely compromising recovery.[1]

Zero Borders Globalized Offender Reach

Fraudsters sitting across sovereign borders commit remote attacks; undetected getaways make extradition and tracing exceedingly complex.

Early detection of fraud will help maximize the recovery amount. It will further warn the fraudulent indirectly about the robustness and high security of the banking system. Governing bodies have warned banks about following proper norms and compliance. Increasing cyber awareness and fraud awareness in staff and training them regularly will help in early fraud detection. The weak implementation of Early Warning Signals (EWS) is the key challenge in early fraud detection. If challenges are overcome, and a monitoring system is made, robust fraud detection can be easier and earlier. Lately, it shatters the banking system’s security and eventually affects the economy.

Timely inspection, monitoring and its reporting play a vital role. Focus should be on proper compliance with KYC, norms for releasing funds, ensuring the safety of customers’ funds. There should be a proper monitoring system and robust appraisal cycle, which monitors the release and proper recovery of the amount from time to time. For the auditing authority to report and identify the frauds, proper incentives should be announced. Sometimes when the fraudulent getaway is undetected, it becomes difficult for agencies to track and bring them back. Due to this, the case is prolonged and recovery is delayed. It is high time that we should use all safe technology advancements in the banking sector to detect suspicious activities going on with bank systems and accounts. [1,2]

2. Defensive Approach: RBI Cybersecurity Framework & Core Prevention Strategies

RBI Guidelines on Cybersecurity Framework

The RBI Guidelines on Cybersecurity Framework allow banks to establish and implement a comprehensive cyber-security policy as well as a cyber-crisis management strategy. The necessity to exchange information about cybersecurity events with the RBI aids significantly in proactive threat detection and systemic mitigation.[3]

Five Strategic Pillars to Mitigate Fraudulent Activities:

1. Anti-Fraud Environment

Establishment of an anti-fraud mindset as a way of life by bank administration, making integrity the organizational bedrock.

2. Historic Fraud Assessment

Operating an efficient risk incident response plan that integrates lessons learned from past fraud incidents to fine-tune control architecture.

3. Proactive Fraud Risk Evaluation

Cornerstone of risk mitigation: periodic evaluation of fraud scenarios and stress-testing organizational readiness against complex attack vectors.

4. Continuous Monitoring

Deploying automated tools and methodologies for real-time and near-real-time surveillance of network traffic and transaction patterns.

5. Whistleblowing Architecture

Implementing airtight non-retribution policies, safe reporting structures, unattended grievance mailboxes, and responsive escalation channels.

Core Analytical Assessment Methodologies Deployed by Banks:

  • Rule-Based Assessment: Applies historical data to match known signatures and patterns of fraudulent behavior.
  • Anomaly-Based Assessment: Flags statistical outliers and abnormal behaviors that deviate from baseline user activity.
  • Advanced Predictive Analytics: Determines the propensity of specific entities, geographic nodes, or operational channels to engage in fraud based on historical crime correlations.
  • Linkage Assessment: Synthesizes relationships across disparate data points (identities, IP addresses, emails, credit card tokens, employment histories) for rapid network discovery.
  • Textual Assessment: Natural language processing (NLP) analysis of transaction narratives, emails, and documentation to detect fraud terminology and suspicious syntax.[3,4]

3. Institutional Awareness Training & High-Profile Cyber Intrusion Case Studies

With the proliferation of sophisticated threats, education across customers, staff, and boards of directors is mandatory. Training must cover definition of cyber fraud, advanced attack vectors (phishing, ransomware, malware, Advanced Persistent Threats [APT], social engineering), understanding fraudster motives, identifying Red Flag Accounts (RFA) involving abnormal transfers or suspicious loans, establishing clear reporting lines, and exercising incident response drills.

Figure 1.1: Spreading Awareness Through Integrated Communication Channels

Newsletters for Employees ➔ SMS Broadcasts ➔ Employee Awareness Training (Quarterly) ➔ Brochures for Customers ➔ Automated Phone Calls for Customers

Case 1: The Cosmos Bank Cyber-Heist

ATM Switch Hack

Hackers breached the bank’s core ATM switch infrastructure, cloned card details, and coordinated simultaneous cash withdrawals across 28 countries. The syndicates executed immediate withdrawals totaling ₹13.92 crore via malicious SWIFT transfers before defensive countermeasures could be triggered.

Figure 1.2 Overview: Central Switch Compromise ➔ Card Cloning ➔ Multi-Country Cashout (28 Countries) ➔ ₹13.92 Cr SWIFT Exfiltration.

Case 2: UIDAI Software Compromise

Data Breach

By compromising Aadhaar software interfaces, threat actors gained unauthorized access to sensitive financial records including PAN numbers, bank account numbers, IFSC codes, and confidential personally identifiable information (PII), exposing banking systems to widespread identity impersonation.

4. Implementing Risk Management Service (RMS) & ISO Global Standards

Risk Management is the process of analyzing, assessing, identifying and planning to prevent frauds and losses. If a bank advances credit or issues loans, it exposes itself to immediate credit and cyber risk. A comprehensive Risk Management Model (RMS) detects fraud at the first instance, responds instantly, and structures punitive and recovery actions.

The International Organization for Standardization (ISO) establishes global frameworks that all banks must adhere to. An effective banking RMS model integrates five primary domains:

1. Analytics Tools: Technology & data analytics tools
2. ISMS: Information Security Management Systems
3. People & Culture: People, culture & organizational interest
4. Strategy: Planning, strategy & governance
5. Compliance: Process compliance & controls strategy

Table 1.1: Internal Control for Fraud Risk Management Activities

Control Mechanism Fraud Risk Management Activities
Fraud Risk Management • Establishing a structured cyber fraud risk assessment process.
• Involving appropriate personnel in the information security fraud risk assessment workflow.
• Performing an overall enterprise fraud risk assessment on a regular, institutionalized basis.
System Monitoring • Continuous network and server performance and traffic monitoring.
• Continuous IT infrastructure surveillance.
• Providing periodic evaluation of operational anti-fraud controls.
• Utilizing independent evaluation in banks through internal audit programs.
• Implementing advanced technology tools in continuous monitoring programs.
Anti-Fraud Control Activities • Defining and documenting mitigating controls and directly linking them to identified fraud risks.
• Modifying existing controls, designing and deploying new preventive controls, and enforcing prevention strategies.
Information and Communication • Promoting the strategic importance of fraud risk management programs through corporate communication channels.
• Designing and rolling out information security awareness training programs across all business tiers.

5. Fraud Response Architecture: Figure 1.3 Suspicious Transaction Lifecycle

Fraud risk management is not a one-time event; as an institution grows, threat vectors evolve. Managing suspicious transactions requires a continuous, closed-loop lifecycle as illustrated in Figure 1.3:

Step 01 Baseline Delineation:

Set baselines for controlling fraud risk by clearly delineating operational roles, access limits, and administrative duties.

Step 02 Active Monitoring & Mining:

Continuous surveillance gathering transaction data across multiple systems, mining it for anomalies, inconsistencies, and strange trends.[10]

Step 03 Employee Red Flag Training:

Ethical problem workshops teaching staff to recognize red flags in core banking systems, directing them to counsel, and showing leadership commitment.

Step 04 Whistleblower & Grievance Mailbox:

Establishing a formal whistleblower policy encouraging employees to report violations freely without fear of retribution, including unattended grievance mailboxes.

Step 05 Safe & Anonymous Reporting:

Providing secure, encrypted channels that guarantee whistleblower anonymity and accelerate forensic investigation while reducing false positives.

6. Appropriate IT-Audits, Regulatory Compliance & Insider Threat Detection

With data distributed across cloud ecosystems, branch servers, and portable devices, bank networks face massive attack surfaces.[5] Internal IT auditors must identify the hallmarks of fraud, evaluate procedures, and enforce three foundational pillars illustrated in Figure 1.4 (Audit Functions):

Audit Function 1: Risk Management and Governance
Audit Function 2: Review of Compliance with Laws & Regulations
Audit Function 3: Monitoring of Internal Control

Insider Threat Detection & Employee Monitoring Checklist:

  • Irregular Account Access: Repeated log-ins for no valid business reason; accessing accounts from IP addresses outside the bank’s authorized geographic region.
  • Target Evaluation & Return Visits: Repeated browsing of high-balance or vulnerable accounts; insider fraudsters returning post-fraud to verify if unauthorized transactions were spotted.[6]
  • Off-Hour Activity: Transacting outside office hours or hours after a client branch visitation.
  • Unusual General Ledger (GL) Postings: GL entries transferring funds directly to an employee’s personal bank account.[8,9]
  • Vulnerable Account Exploitation: Irregular transfers originating from dormant accounts, senior citizen accounts, or affluent high-net-worth accounts.
  • Non-Overruleable Rules: System controls must be engineered so that authorization rules cannot be overruled without cryptographic multi-party authorization.[11]

7. Advanced Vigilance Tools: Machine Learning & Leading AI Platforms

Machine learning-based fraud detection allows banks to instrument surveillance across multiple data channels simultaneously, learning to identify complex fraud across diverse payment instruments and customer programs at the exact moment of occurrence.

Figure 1.5: Best Practices for AI-Driven Fraud Detection
1. AI & Advanced Technologies ➔ 2. AML & Suspicious Activity Reporting ➔ 3. Data-Driven Fraud Risk Profiles ➔ 4. Profiling Fraudster Attributes ➔ 5. Continuous Auditing & Monitoring
Table 1.2: Core Use Cases of Advanced Vigilance Tools in Financial Institutions
• Risk Management • Anti-Money Laundering (AML) • Fraud Detection • Real-Time Monitoring • Financial Fraud Prevention • Regulatory Reporting • Early Identification

Comparative Benchmark of Advanced Fraud Prevention Platforms:

1. ClearSale

A complete fraud protection system integrating artificial intelligence, complex statistical methodologies, and specialized human fraud analysts to deliver zero false-positive precision.

2. Signifyd

Employs AI and machine learning across massive commerce networks to expose actionable risk insights and automate checkout trust verification.

3. Sift

A holistic digital trust and safety suite utilizing real-time ML to defend transactions, account integrity, and customer interactions while driving growth.

4. Riskified

An e-commerce and banking fraud solution that prevents fraud seamlessly from the algorithmic logic to checkout execution while maximizing legitimate conversion rates.

8. Conclusion: Multi-Layered Defense & The Primacy of Robust IT Audits

Fraud has far-reaching consequences that go beyond monetary loss, directly impacting individuals, businesses, organizations, and the broader economic environment. Whether perpetrated by opportunistic individuals or organized crime syndicates, cyber fraud demands dynamic, interdependent security ecosystems.

Combining comprehensive risk assessments, aggressive fraud reporting, and multi-layered defense architectures is indispensable. The key solution is a robust, continuous IT audit. Keeping software continually patched and updated is an foundational requirement. Post-fraud, rapid capture and forensic inspection must be initiated immediately. Dedicated teamwork across technical, operational, and audit teams is essential to safeguard the integrity of India’s banking ecosystem. ■■■