Learning Objectives:
-
Identify key cyber threats in digital banking.
-
Explain authentication and security protocols.
-
Understand data privacy and regulatory compliance.
6.1 Cyber Threats and Vulnerabilities
Digital banking faces a range of cyber threats . Common threats include:
-
Phishing: Deceptive emails or messages seeking sensitive information .
-
SIM Swap: Fraudulently porting a mobile number to gain access to banking apps .
-
UPI Frauds: Unauthorised UPI transactions through social engineering .
-
Malware and Ransomware: Malicious software designed to disrupt systems or demand payment .
-
Man-in-the-Middle (MITM) Attacks: Intercepting communication between the user and the bank .
6.2 Authentication and Security Protocols
Security measures include:
-
Multi-Factor Authentication (MFA): Requiring multiple forms of verification for system access .
-
Biometric Authentication: Using fingerprints, facial recognition, or other biometric data for identity verification .
-
AI-Based Fraud Detection: Using machine learning to identify suspicious transaction patterns .
-
Behavioural Biometrics: Analysing user behaviour (e.g., typing patterns, device usage) for anomaly detection .
-
Data Encryption: Protecting data both in transit and at rest .
6.3 Data Privacy and Regulatory Compliance
Data protection is governed by regulations such as the DPDP Act 2023 in India and GDPR in Europe . Compliance requirements include:
-
Data Localisation: Storing data within the country of origin .
-
Informed Consent: Ensuring customers explicitly consent to data collection and use .
-
Data Minimisation: Collecting only the data necessary for the service .
-
Regulatory Frameworks: RBI’s cyber security framework for banks and Master Directions on Digital Payment Security Controls .