Accounting & Finance for Bankers
Digital Banking & Cyber Security
1 / 2
Digital Banking & Cyber Security
Introduction
Digital banking and cybersecurity have become indispensable topics for banking professionals. With the rapid adoption of technology in financial services, understanding the digital banking ecosystem, associated risks, and cybersecurity measures is critical for the JAIIB exam. This topic covers electronic banking channels, digital payment systems, cybersecurity threats, and the regulatory framework for IT security in banks.
Evolution of Digital Banking
| Phase | Period | Features |
|---|---|---|
| Computerisation | 1980s-1990s | Standalone systems, back-office automation |
| Networking | Late 1990s | Branch connectivity, CBS implementation |
| Internet Banking | 2000s | Online transactions, fund transfers |
| Mobile Banking | 2010s | Smartphone apps, UPI |
| Open Banking | 2020s | API-based services, fintech collaboration |
Digital Banking Channels
Internet Banking
- Account management, fund transfers, bill payments
- Uses SSL/TLS encryption for secure communication
- Multi-factor authentication (password + OTP)
- Available 24x7 from any internet-connected device
Mobile Banking
- Banking through smartphone applications
- Uses encryption and device binding for security
- Supports IMPS, UPI, and NEFT transfers
- Biometric authentication (fingerprint, face recognition)
ATM (Automated Teller Machine)
- Cash withdrawal, deposit, balance enquiry, mini-statement
- White-label ATMs: Operated by non-bank entities (authorised by RBI)
- Brown-label ATMs: Hardware managed by third party, cash by sponsor bank
- Cash recyclers: Accept and dispense cash from the same machine
POS (Point of Sale)
- Card-based payments at merchant locations
- QR code-based payments (Bharat QR)
- Near Field Communication (NFC) for contactless payments
Digital Payment Systems in India
| System | Settlement | Managed By |
|---|---|---|
| NEFT | Half-hourly batches (24x7 from Dec 2019) | RBI |
| RTGS | Real-time, gross settlement (24x7 from Dec 2020) | RBI |
| UPI | Instant, 24x7 | NPCI |
| IMPS | Instant, 24x7 | NPCI |
| NACH | Batch processing | NPCI |
| Bharat Bill Payment | Real-time | NPCI |
| AePS | Aadhaar-based, real-time | NPCI |
Cybersecurity Threats in Banking
Common Threat Types
| Threat | Description |
|---|---|
| Phishing | Fraudulent emails/websites to steal credentials |
| Vishing | Voice-based phishing via phone calls |
| Smishing | SMS-based phishing with malicious links |
| Malware | Software designed to disrupt, damage, or gain unauthorised access |
| Ransomware | Encrypts data and demands payment for decryption |
| Man-in-the-Middle | Intercepting communication between two parties |
| DDoS | Overwhelming servers with traffic to disrupt services |
| Card Skimming | Copying card data using devices attached to ATMs/POS |
| SIM Swapping | Fraudulently getting a duplicate SIM to intercept OTPs |
| Social Engineering | Manipulating people to reveal confidential information |
Advanced Persistent Threats (APT)
- Sophisticated, prolonged attacks targeting specific organisations
- Often state-sponsored or by organised crime groups
- Can remain undetected for months or years
- Target SWIFT systems, core banking databases
Cybersecurity Framework for Banks
RBI Cybersecurity Framework (2016)
- Applicable to all scheduled commercial banks
- Banks must have a Board-approved Cyber Security Policy
- Mandatory appointment of a Chief Information Security Officer (CISO)
- Incident reporting to RBI within 2-6 hours of detection
- Regular cyber risk assessment and vulnerability testing
Key Components
- Governance: Board-level oversight, IT Strategy Committee
- Risk Assessment: Identify, assess, and mitigate cyber risks
- Prevention: Firewalls, intrusion detection/prevention systems (IDS/IPS)
- Detection: Security Operations Centre (SOC), real-time monitoring
- Response: Incident response plan, business continuity plan
- Recovery: Disaster recovery site, data backup and restoration
Authentication Methods
| Level | Method | Example |
|---|---|---|
| Single Factor | Something you know | Password, PIN |
| Two Factor (2FA) | Know + Have | Password + OTP |
| Multi-Factor (MFA) | Know + Have + Are | Password + OTP + Biometric |
Biometric Authentication
- Fingerprint recognition
- Iris scanning
- Facial recognition
- Voice recognition
Data Protection and Privacy
Key Regulations
- IT Act 2000 (amended 2008): Legal recognition for electronic transactions, cybercrime penalties
- Digital Personal Data Protection Act 2023: Data protection framework for India
- RBI Data Localisation: Payment system data must be stored only in India
- PCI DSS: Payment Card Industry Data Security Standard for card data protection
Data Classification
- Public: Annual reports, published data
- Internal: Operational data, internal communications
- Confidential: Customer data, financial records
- Restricted: Passwords, encryption keys, security configurations
Blockchain and Emerging Technologies
- Blockchain: Distributed ledger technology for secure, transparent transactions
- AI/ML in Security: Pattern detection for fraud, anomaly detection
- Cloud Banking: Scalable infrastructure with enhanced security controls
- Quantum Computing: Future threat to current encryption standards
Key Points to Remember
- NEFT operates in half-hourly batches; RTGS is real-time gross settlement — both are now 24x7
- Phishing (email), vishing (voice), and smishing (SMS) are the most common social engineering attacks
- RBI mandates a Board-approved Cyber Security Policy and appointment of a CISO
- Cyber incidents must be reported to RBI within 2-6 hours
- Two-factor authentication (2FA) combines something you know with something you have
- Payment data must be stored only in India per RBI's data localisation directive
- White-label ATMs are operated by non-bank entities
- The IT Act 2000 provides legal recognition for electronic transactions
- PCI DSS governs card data security standards
- Banks must have a Business Continuity Plan (BCP) and Disaster Recovery (DR) site
- Blockchain provides a distributed, tamper-proof ledger for transactions
- AePS (Aadhaar-enabled Payment System) enables biometric-based banking for financial inclusion
Topic Complete!
You covered 1 cards on Digital Banking & Cyber Security
Swipe to continue →