Centre Sets Up Inter-Ministerial Group To Form Financial Cybersecurity Strategy
India's central government has constituted an inter-ministerial group to draft a cybersecurity strategy for the financial sector, finance minister Nirmala Sitharaman told the Rajya Sabha, citing rising AI-enabled fraud and frontier-AI risks.
Intelligence analysis by Llama

Finance minister Nirmala Sitharaman announced an inter-ministerial group to build a financial-sector cybersecurity strategy, warning that frontier AI models could threaten the sector's stability. The move complements existing bodies like CERT-In's NCCC, an FSDC-level technical group, and the newly formed IDPIC fraud-intelligence entity.
India's government is putting together a special team of people from different departments to protect banks and money apps from computer bad guys. They're worried because sneaky AI programs can now fake voices and faces to steal money, so the team has to build a strong plan to keep everyone's savings safe.
Analysis
A Cabinet-Level Firewall for Digital Finance
India's financial system has become one of the most digitised in the world, anchored by UPI, Aadhaar-enabled payments and a fast-growing fintech stack. That scale, finance minister Nirmala Sitharaman argued in the Rajya Sabha, has also made the sector a high-value target. The IMG's creation signals that New Delhi is no longer content with piecemeal cybersecurity measures and wants a single strategy document spanning ministries, regulators and law-enforcement bodies. By placing the exercise at an inter-ministerial level rather than inside a single department, the government is acknowledging that financial cybersecurity now sits at the intersection of finance, electronics and IT, home affairs and the Reserve Bank of India.
The Architecture Already in Place
The IMG will not start from a blank slate. According to the finance minister, CERT-In's National Cyber Coordination Centre (NCCC) already monitors cyberspace at a metadata level and pushes threat intelligence to regulators and institutions. An Inter-Regulatory Technical Group under the Financial Stability and Development Council (FSDC) is meant to align regulators, and the Indian Banking Association runs a working group on emerging-technology risks. The newest piece, the India Digital Payment Intelligence Corporation (IDPIC), was incorporated in 2025 as a Section 8 company jointly owned by State Bank of India and Bank of Baroda, with former Canara Bank CEO K Satyanarayana Raj as its head. IDPIC's job is to use AI, machine learning and big-data analytics to detect and analyse fraud across digital payments in real time, sharing alerts with banks. The IMG's strategy will likely determine how aggressively these threads are woven together.
Frontier AI as the New Threat Vector
Sitharaman's most striking comment was the warning that frontier AI models could challenge the "growth, security and stability" of the financial sector. Her reference to deepfake-enabled impersonation, sophisticated phishing and automated fraud tracks a broader concern also flagged in connection with Anthropic's autonomous vulnerability-finding system, dubbed Mythos. For India, the IMG's recommendations will test whether the country can move from reactive fraud detection to a more anticipatory model, one that treats AI-generated attacks as a structural rather than tactical risk. The group's report, once ready, will be a key signal of how seriously New Delhi is preparing its financial system for the next generation of AI-driven crime.
Key points
- India has set up an Inter-Ministerial Group to draft a financial-sector cybersecurity strategy, finance minister Nirmala Sitharaman said in the Rajya Sabha.
- Sitharaman warned that frontier AI models could threaten the 'growth, security and stability' of the financial sector.
- The India Digital Payment Intelligence Corporation (IDPIC), incorporated in 2025 and owned by SBI and Bank of Baroda, will use AI, ML and big data to flag fraud in real time.
- Existing architecture includes CERT-In's NCCC, an FSDC-level Inter-Regulatory Technical Group, and an IBA working group on emerging-technology risks.
- The push comes amid growing AI-enabled threats such as deepfake impersonation, sophisticated phishing and automated financial fraud.
If the IMG's strategy is implemented swiftly, India could set a global benchmark for AI-era financial cybersecurity, with IDPIC's real-time fraud intelligence giving banks a faster, shared view of emerging threats. A coordinated approach across regulators, public-sector lenders and CERT-In could materially reduce successful phishing and deepfake-enabled fraud cases.
Inter-ministerial groups often produce slow, consensus-driven recommendations that lag the threat landscape, and the financial sector's dependence on legacy core banking systems may limit how quickly new safeguards can be deployed. If IDPIC and the IMG operate in silos, frontier-AI attacks could still outpace India's defensive architecture.



