RBI Says Large Banks’ IT Systems Remain Robust
Reserve Bank of India Governor Sanjay Malhotra has said that the information technology systems of large Indian banks and other major regulated entities remain strong and robust, even as the financial sector faces increasingly sophisticated cyber threats.
The statement came days after a reported cyber breach at Bank of Baroda, where around 1 terabyte of customer and internal data was reportedly exposed following the compromise of an employee’s email account. The leaked information was reported to include branch audit reports, loan appraisal files, customer account-opening documents, vigilance records and other banking information.
Malhotra said large banks and regulated entities have established appropriate checks and balances to protect their systems. He emphasised that RBI’s oversight extends beyond issuing regulations and guidelines to include regular supervisory reviews of banks’ technology infrastructure and cyber-security preparedness.
According to the Governor, whenever supervisory assessments identify vulnerabilities or deficiencies, regulated entities are advised on corrective measures. RBI subsequently monitors implementation to ensure that weaknesses are addressed and systems remain secure on an ongoing basis.
Malhotra also acknowledged that new vulnerabilities continue to emerge as information technology evolves. Consequently, banks and other regulated entities need to continuously strengthen their cyber-security controls, operational resilience and technology risk-management frameworks.
Bank of Baroda had earlier stated that the cyber incident was not expected to have any material impact on its operations, financial performance or business continuity. The bank said its core business functions continued to operate normally and that a detailed assessment, along with remedial and preventive measures, was underway.
Cyber resilience has become an increasingly important supervisory priority for RBI. In April 2026, banks were asked to conduct a board-approved review of their cyber-security gaps and submit a time-bound plan for addressing vulnerabilities. Banks were also asked to formulate comprehensive artificial intelligence governance and security frameworks.
The scale of the challenge continues to grow. A June 2026 report cited by Mint stated that India recorded more than 493,000 cyberattacks and breaches targeting banks during calendar year 2025, more than twice the level recorded in 2022. The report estimated the average cost of a cyber breach at around $2.5 million, with an average resolution period of 263 days.

