Edition #45 cybersecurity

Attestation is not assurance: decoding the SISA Digital Threat Report for BFSI boards

The SISA Digital Threat Report 2025-26 documents control environments that cleared attestation and were breached soon after. Six of seven forward-looking threat predictions reached full-scale realization within a year. An AI-orchestrated state campaign executed 80-90% of operations autonomously. For BFSI boards, a passed audit is no longer a security finding.

sisacybersecurityattestationbfsicert-inmodel-risknon-human-identityai-governancerbi

Originally published on linkedin

FinSaAIstra Intelligence | BFSI Cyber Resilience Series | August 2026

AI has compressed the time between a passed audit and a real breach, and most institutions are still measuring their security by the audit.

Executive Signal

A passed audit is not proof of a secure institution. It is proof that a control existed on the day someone checked. The Digital Threat Report 2025-26, produced by SISA with CERT-In and CSIRT-Fin, documents control environments that cleared attestation and were breached soon after, not because the framework failed, but because attestation was never designed to survive an adversary. That gap, not any single attack technique, is this year’s most consequential finding for BFSI boards.

Attestation Half-Life (FinSaAIstra Definition): The shrinking interval during which a passed compliance attestation remains a reliable proxy for an institution’s actual security posture, now compressed by AI-accelerated attack tooling from a multi-year assessment cycle toward a matter of weeks.

Verified Market Signals

Signal 1: Six of the seven forward-looking threat predictions made in the previous edition of the report have already reached full-scale realization within a single year.

Source: SISA, CERT-In, CSIRT-Fin, Digital Threat Report 2025-26.

Threat maturity curves that once ran from research to experimentation to exploitation over years are now collapsing directly into operational impact, which means board risk committees calibrated to annual or biannual review cycles are structurally out of step with the threat they are meant to govern.

Signal 2: In November 2025, Anthropic disclosed GTG-1002, a state-linked cyber espionage campaign in which an AI model executed 80 to 90 percent of the operation independently against roughly 30 global targets, including financial institutions, firing thousands of requests per second.

Source: Anthropic disclosure, cited in SISA Digital Threat Report 2025-26.

The attacker headcount required to sustain a multi-target campaign against financial institutions has collapsed, meaning attack volume against any single institution is no longer bounded by how many people an adversary can staff.

Signal 3: Frontier AI models have produced working attacks against 207 of 405 historical smart contract exploits, totalling $550 million in simulated stolen funds, and a frontier model disclosed in April 2026 identified more than 23,000 potential vulnerabilities, over 1,000 rated high or critical severity.

Source: SISA Digital Threat Report 2025-26, citing frontier model disclosures.

Vulnerability discovery that once required specialist teams working over weeks is now executed at machine speed, directly compressing the assessment-to-exploitation window that compliance attestation implicitly assumes stays open.

Signal 4: India-focused BFSI institutions recorded cyberattack volumes running 1.6 times the global average, with incidents rising from 1.4 million in 2021 to 2.9 million in 2025, more than doubling in four years.

Source: Data Security Council of India and BCG, “Cybersecurity in the Age of AI: Building a Synchronous BFSI,” May 2026, cited in SISA Digital Threat Report 2025-26.

The compliance-security gap this edition describes is not a theoretical concern. It is compounding fastest in the market where CERT-In and CSIRT-Fin coordination is already the operational front line.

Structural Shift: Point-in-Time Attestation to Continuous Adversarial Assurance

Compliance frameworks ask whether a control existed during the assessment window. Adversarial reality asks whether that control holds when identity, runtime, cloud, and application layers are actively abused. The report is explicit that these are different questions with different answers: the same control environments that complete attestation cycles successfully are, in a meaningful number of cases, the same environments that subsequently require forensic investigation.

Attestation proves a control’s existence at a point in time. It does not prove the control’s survivability under pressure, and AI has now made the gap between those two things exploitable at speed.

Systemic Implications

The assumption that a control passing its assessment window remains representative until the next cycle no longer holds. The report names three recurring patterns behind this failure:

Implementation Drift is when the control exists but real-world operations have moved away from its intent: machine and AI identities carrying excessive privilege, secrets scattered across code and CI/CD pipelines, sensitive payment data persisting in runtime memory.

Scope Boundary Failure is when the control works exactly as designed but the attacker operates outside its design boundary entirely: multi-factor authentication validating access while doing nothing to stop session replay or hijack.

Framework Evolution Lag is when technology moves faster than the frameworks governing it: AI model abuse, dependency poisoning, and tampered model weights sitting outside what most current control requirements were built to catch.

Non-human identity is the most exposed function. Service accounts, API keys, and AI agents now carry administrator-equivalent privilege in a meaningful share of the incidents SISA investigated, yet they sit outside most institutions’ identity review cycles entirely. The report’s own flagship case is direct: an AI-orchestrated campaign did not need to breach the network, because it used valid entitlements it already held from within the perimeter.

CXO Action Layer

Board-Level: Add resilience metrics, Mean Time to Contain and adversarial validation pass rates on high-criticality controls, to board risk reporting at the same cadence currently reserved for compliance attestation. A clean audit finding should no longer be presented to the board as a security finding on its own.

Procurement Reality: Require vendors, QSAs, and AI model providers to demonstrate control survivability under adversarial testing, not attestation completion alone. Treat AI model weights, training data, and machine-learning dependencies as regulated software supply chain components subject to the same due diligence as any other third party.

Architecture Implication: Fund quarterly post-attestation adversarial validation on the three highest-criticality controls as a standing operational discipline, not a one-time project. Extend identity governance, rotation, attestation, and behavioral monitoring to AI agents and non-human identities on the same perimeter as human accounts.

This finding sits inside a broader regulatory direction already visible in India. The RBI’s draft Guidance on Regulatory Principles for Model Risk Management, circulated for comment through July 2026, moves in the same direction as this report’s core recommendation: mandatory human oversight, board-approved AI governance, and third-party AI accountability. Institutions that build toward that standard now, rather than waiting for it to finalize, will face materially less rework.


FinSaAIstra Law: Attestation vs Assurance. A control that has never been tested against an adversary has only been tested against a checklist; boards that treat the two as equivalent are pricing risk on the wrong curve.