Introduction and About the Report

  • The Digital Threat Report 2024 is the first of its kind released by India, targeting the strengthening of cybersecurity in the Banking, Financial Services, and Insurance (BFSI) sector.
  • It is a combined initiative by SISA (Strategic Information Services Agreement), a worldwide cybersecurity firm, along with the Computer Emergency Response Team (CERT-In), and CSIRT-Fin.
  • The report offers a detailed analysis of growing cybersecurity risks in India's BFSI sector, guiding organisations to adopt stronger security measures, better compliance protocols, and advanced threat detection capabilities. 

 

Key Highlights of the Cyber Threat Report 2024

  • The report highlighted a surge in cyberattacks and data breaches costs in the BFSI sector, with global costs rising to USD 4.88 million and USD 2.18 million in India - a 10% increase from 2023. 
  • Notably, phishing attacks in India rose by 175% in June 2024 compared to the previous year. 
  • The crypto sector also faced serious threats, with cybercriminals targeting crypto exchanges and malware variants endangering crypto wallets.
  • The application of AI and deepfake technologies in cyberattacks is dramatically improving their sophistication and effectiveness. 

 

The role of AI in Phishing and Scams

  • AI technology has been weaponised to make phishing attacks more deceptive, creating emails that mimic the tone, style, and branding of trusted entities.
  • Additionally, AI-driven chatbot phishing scams have become interactive and proactive in extracting personal data.
  • Large language models (LLMs) are facilitating cybercriminals to generate more convincing phishing emails and potent malware. 

 

Cloud Security Weaknesses and Credential-related Threats

  • A major concern is cloud security weaknesses, primarily due to misconfigured cloud services and weak access controls, which have seen a 180% rise in exploitation attacks.
  • Hackers are increasingly using stolen login details and deploying malware that utilise techniques like session hijacking, brute-force attacks, deepfake technology, and BOLA vulnerabilities. 

 

Recommendations of the Report 

  • The report recommends adopting a human-centric, leadership-driven approach to cybersecurity, supplemented by ongoing employee training to combat emerging threats.
  • Organisations should carry out regular Automated Vulnerability Scans, share threat intelligence in real-time, and implement a multi-tiered “defence-in-depth” strategy consisting of firewalls, endpoint protection, and Zero Trust architecture.
  • Leveraging technology for timely patching (updates), AI-based threat detection, and use of MFA for controlling access are crucial.

 

India's Existing Framework for Cybersecurity

  • India already has legislative directives like the Information Technology Act, 2000, and the Digital Personal Data Protection Act, 2023.
  • It involves institutions including CERT-In, the National Critical Information Infrastructure Protection Centre (NCIIPC), the Indian Cyber Crime Coordination Centre (I4C), and Cyber Swachhta Kendra.
  • Strategic Initiatives like Bharat National Cybersecurity Exercise 2024 and National Cyber Security Policy, 2013, outline the vision and strategies for securing cyberspace.