In a fireside chat session moderated by Dr. Deepak Kumar Sahu, Editor-in-Chief of VARINDIA, Dr. Sourabh Khemani, Founder Chairman of CyberCorp Ltd., delved into the rapidly evolving cybersecurity landscape and the growing threat of cybercrime.
CYBERCORP'S PATH TO INNOVATION
Dr. Khemani began by sharing the journey of CyberCorp, which was established in late 2022, amid the challenges of the COVID-19 pandemic. The company’s mission is to help startups scale in the cybersecurity and digital transformation sectors. By acquiring startups and nurturing talent, CyberCorp aims to bridge the gaps in technology, economic barriers, and growth potential, enabling companies to expand 10x to 20x in the next few years.
DEFENSIVE STRATEGIES FOR CYBERSECURITY
He emphasized that the scale of cybercrime losses is expected to reach $10 trillion by 2025, with predictions of it growing to $12 trillion by 2026. Dr. Khemani underscored the importance of shifting the focus from cybersecurity to "cyber defence." As cybercrime continues to increase, businesses must adopt a defensive strategy to protect against attacks. He stressed that a zero-trust architecture, AI-driven threat detection, and global intelligence sharing are critical in combating these threats.
KEY ATTACK VECTORS FUELLING CYBER LOSSES
According to Dr. Khemani, sectors such as banking, financial services, insurance (BFSI), healthcare, critical infrastructure, and retail/e-commerce are the most vulnerable to cybercrime. The primary attack vectors driving these losses include ransomware, phishing, business email compromise, supply chain attacks, and insider threats.
AI IN CYBERSECURITY
Addressing how businesses are responding to the rising financial losses caused by cybercrime, Dr. Khemani emphasized the need for proactive threat hunting, security automation, continuous monitoring, and investment in talent. He also discussed the role of AI in cybersecurity, warning that while AI can be a powerful tool for defence, it can also be a dangerous weapon if misused.
UNIFIED APPROACH TO CYBERCRIME
For businesses to protect themselves, Dr. Khemani recommended employee awareness training, endpoint detection and response, multi-factor authentication, regular security audits, and having a robust incident response plan. He concluded by highlighting the importance of collaboration over competition, encouraging businesses to partner and strengthen their collective defences against cyber threats.
At the end of the session, Dr. Khemani called for a unified effort in tackling cybercrime, stressing that cybersecurity is no longer just essential but a critical enabler of growth in the digital age.
Q&A: Banking, Cybersecurity, and KYC in the Spotlight
COOPERATIVE BANK CHALLENGES
The Q&A session comprised several key topics regarding the banking sector and cybersecurity brought up by the audience. The first question addressed the failure of cooperative banks, particularly citing the PMC Bank case, where 23,000 fictitious accounts were opened. The panellist, Bhaskar Rao, explained that cooperative banks face unique challenges, including inadequate KYC (Know Your Customer) procedures, which have contributed to several high-profile incidents. However, he stressed that these issues are not exclusive to cooperative banks. Even larger banks in the public and private sectors have experienced similar challenges. For example, some KYC data was linked to hundreds of accounts in other banks, causing significant damage. Despite the flaws, cooperative banks play an important role in serving underserved communities, providing support to individuals who might not have access to larger public or private banks. Rao concluded that while there is room for improvement in KYC processes across the entire banking sector, it is essential to understand the broader context of these issues.
PSYCHOLOGY OF SCAMS
The second question was directed to advocate Dr. Prashant Mali regarding the persistent stock market scams despite widespread media coverage of such incidents. The question inquired why individuals continue to invest in these scams despite knowing the risks. Dr. Mali responded by emphasizing the psychological nature of modern cybercrimes. He pointed out that fraudsters have evolved their tactics by using artificial intelligence (AI) and sophisticated psychological manipulation to target individuals. For instance, even an experienced stockbroker fell victim to a scam due to convincing fake websites, apps, and logos created by cybercriminals. This highlights how cybercrime has transitioned from being merely technical to deeply psychological, making it more difficult for victims to recognize fraudulent schemes.
KYC AND BIOMETRICS
The final question concerned the banks’ role in preventing such fraud and how policies can be improved. The panellists agreed that it was crucial for banks to reassess their policies and strengthen their security measures, particularly in KYC processes. They discussed the use of biometric methods like retina scanning and video verification, which could offer better protection against deepfakes, identity theft, and fraudulent account openings. The session concluded with a call for the banking industry to stay ahead of emerging threats by implementing more robust digital security protocols, continuous monitoring, and investing in advanced AI-driven fraud detection tools.
Tech Experts Solve Five Case Studies
- Stock Market App Frauds
- Privacy by Design is Essential for Organizations
- Rapid growth of Digital Services and increasing Concerns
- The Rise of Mule Accounts in Banking and Effective Countermeasures
- Incident Response Readiness in a Financial Institution
WIITF featured an engaging panel discussion session, expertly curated and moderated by Dr. Deepak Kumar Sahu, Editor-in-chief-VARINDIA. The panelists who joined the session were Advocate Dr. Prashant Mali - Practicing Lawyer Bombay High Court; Dr. Pawan Chawla, CISO & DPPO -TATA AIA LIFE Insurance; Samir Shah, Partner -Consulting- Ernst & Young LLP; Bhaskar Rao, CISO- Bharat Co-operative Bank; Ritesh Bhatia, Founder- V4 WEB Cybersecurity.
Changing the format of the discussion a little bit this time, the five panelists who are subject matter experts representing different industries - Banking, Insurance, Tech Consulting, Legal, and Cybersecurity respectively, were asked to analyze five critical real-world case studies.
Talking about stock market app frauds, Advocate Dr. Prashant Mali stated that solving the problem of stock market is similar to solving the problem of greed. It is there. “It will always be there till the human being exists. So stock market app fraud is at present a big reality. The people who are the most affected are the senior citizens. So senior citizens in India are supposed to be the richest across the world. They have a lot of corpus retirement money, investment money, pension money. So that money is usually targeted using sophisticated AI techniques and they are lured in through WhatsApp or Instagram texts. The problem comes when the money's gone, and there is no way to get that money back. Going to the police becomes another issue once the money is lost. So the solution is to always remember that no one is able to give you so easily an investment which increases more than the market standard. The moment you realize that the money is lost, Report to 1930.”
On why ‘Privacy by Design’ is essential for organizations, Dr. Pawan Chawla said that it is not a new concept and it is something which was introduced in the 1990s by Ann Cavoukian and organizations have started adopting it since then. “Privacy by Design starts with the principle of privacy that it has to come as a thought in the organization and the customer interest has to be kept in mind first. Because once you have that concept in mind, only then you can design privacy. Second, you need to be very transparent and bring in Visibility. You need to tell your customers that for what purposes the data has been collected and for what purpose it will be used. The other principle is end-to-end security. When you are building an application, you have to ensure that the encryption is there. Apple is one classic example; they have privacy by design implemented in the product and in the product cycle itself.”
Samir Shah spoke on rapid growth of digital services and increasing concerns, and said that while talking of digital services one needs to talk about growth in data as well. “The DPDP 2023 draft rules specifically says that you cannot hold back the data after the specified purpose is met. Also, you should have proper consent for the data that you possess. Because if you do not have the consent for that data and still continue processing it, then that is equivalent to data breach. We want to obviously continue the way we are using data, but the concern here is compliance risk, reputational risk, financial risk and then there could be the risk of using customer trust and confidence.”
On the rise of mule accounts in banking, Bhaskar Rao said that there are two layers - one is the operational side and the other is the security side. “Today the kind of digital transactions that are taking place, India is contributing to 48.5% of all these transactions. And in that, UPI has become an important mode of payment for a lot of customers today. Even for a small amount, we are just scanning a given code and making the payment. It also contains a lot of data. So this has become a lucrative area for hackers to steal not only money but also data. After stealing the money, they would need some place to deploy it. So they open fake accounts, or mule accounts with data stolen from another individual. Or even in the case of legitimate accounts, they will try to take over it and use that account to transfer the funds.”
On Incident Response readiness in a financial institution, Ritesh Bhatia said that it is not a matter of ‘if you will be hacked’, rather it is about ‘when will you be hacked’. “When any organization, individual is hacked, the incident response mechanism appears to be the most pathetic and it is true for every entity. It is part of the incident response process to negotiate with the hacker and there are two options available – either you pay the ransom or you don’t pay the ransom. Now an organization has agreed to pay the money since they do not have the back-up, and I see this happening with most of the organizations today. We keep on talking about modernizing our infrastructure, but we fail considerably when it comes to keeping a back-up of the most crucial servers.”
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.
