Skip to Main Content
COM1MN106 • Foundations of Modern Banking
Module 4
Calicut University • B.Com • Semester 1

Foundations of Modern Banking — Module 4

Course Code: COM1MN106 • Lecture Notes

  1. Cyber: Security in Banking: Threat Vectors & Attack Typologies As banking operations transition into cloud-native architectures, API ecosystems, and instant retail payment networks, the threat landscape expands exponentially. Cybersecurity in modern banking is not merely an IT support function; it is a critical pillar of institutional solvency, systemic stability, and customer trust. 1.1 Master Taxonomy of Cyber Threats Facing Commercial Banks Threat Category Operational Mechanism & Attack Vector Direct Impact on Banking Systems
  2. Social: Engineering (Phishing, Vishing, Smishing) Deceptive emails, fake calls (vishing), or SMS links (smishing) mimicking legitimate bank communications to harvest user passwords,

MPINs, and OTPs. Unauthorized account takeovers, fraudulent funds transfer, and credential compromise.

  1. Ransomware &: Advanced Malware Malicious payloads (e.g., WannaCry, LockBit) encrypting mission-critical bank servers, databases, or backup vaults, demanding ransom in cryptocurrency.

Catastrophic operational outage, business interruption, and extortion threats.

  1. Distributed: Denial of Service (DDoS) Botnets overwhelming bank web servers, Core Banking Solution (CBS) gateways, or mobile banking APIs with billions of spoofed requests.

Complete paralysis of customerfacing online banking portals and digital payment rails.

  1. Man-in-theMiddle (MitM) &: Session Hijacking Interception of unencrypted or weakly encrypted communication channels between a user's browser/app and the bank's transaction server.

Eavesdropping on financial transactions, tampering with payment instructions in transit.

  1. SIM: Swap & Mobile Banking Fraud Fraudsters obtain a duplicate SIM card from telecom operators using forged identity proofs, hijacking the victim's mobile number.

Interception of two-factor authentication (2FA) SMS OTPs, executing rapid drain of bank balances.

  1. ATM: Jackpoting & Skimming Physical or malware-based exploitation (e.g.,

Ploutus malware) connecting external hardware to ATM cash dispensers or reading magnetic stripe data via skimmers.

Uncontrolled physical dispensing of cash notes and mass cloning of debit cards. 1.2 The Cyber Kill Chain in Banking Exploits

1. Stages 1 to 3: Infiltration

  • Reconnaissance: Scanning bank IP ranges, identifying unpatched firewall vulnerabilities.
  • Weaponization: Crafting banking malware laced inside weaponized PDF attachments.
  • Delivery: Spear-phishing targeted bank treasury or IT employees.

2. Stages 4 to 7: Execution & Exfiltration

  • Exploitation & Installation: Gaining internal domain administrator credentials.

Command & Control (C2): Establishing encrypted backdoors.

  • Actions on Objectives: Manipulating SWIFT messaging systems or exfiltrating customer financial records. 1.3 Emerging Retail Payment Frauds: UPI & QR Exploits
  1. Fake UPI: Collect Requests & QR Phishing (Quishing) Fraudsters send fraudulent "Collect / Pay" requests or paste counterfeit QR codes on merchant counters. Victims enter their UPI MPIN under the false impression of receiving cashback, inadvertently transferring money out of their accounts. (Golden Rule: Entering MPIN is required only for sending money, never for receiving money).
  2. Screen-Sharing: App Exploits Trick victims into downloading remote screensharing tools (AnyDesk, TeamViewer) under the guise of customer service, capturing banking credentials and SMS OTPs live on screen. 1.4 The SWIFT Interbank Cyber Threat Vector & SWIFT CSP SWIFT Attack Vector Historical Anatomy Mandatory SWIFT Customer Security Programme (CSP) Control
  3. Compromised: Local User Terminals Attackers use keyloggers to steal local operator credentials connected to SWIFT Alliance Access.

Mandatory Multi-Factor Authentication (MFA) and dedicated physical network isolation for SWIFT terminals.

  1. Fraudulent: Payment Message Injection Generating unauthorized MT103 / MT202 fund transfer messages to offshore laundering accounts.

Four-eye verification principle; independent secondary authorization for high-value cross-border wires.

  1. Tampering with: Confirmation Statements Modifying daily MT950 PDF bank statements to delay discovery of unauthorized debit transfers.

Automated, out-of-band immutable confirmation reconciliation engines.

  1. Emerging: Cyber Defense Architectures & Cryptographic Frameworks To defend against sophisticated state-sponsored cyber syndicates and automated botnets, modern banks deploy layered defence-in-depth frameworks. 2.1 Cryptographic Standards in Electronic Banking Cryptographic Technology Technical Architecture Banking Implementation Area
  2. Symmetric: Encryption (AES-256) Single secret key used for both encryption and decryption; ultra-fast processing.

Encrypting stored databases (Data-atRest), Core Banking customer records, and ATM PIN blocks.

  1. Asymmetric: Encryption (RSA-4096 / ECC) Public-private key pair architecture; mathematically linked but computationally irreversible.

Digital Signatures, Public Key Infrastructure (PKI), and secure session key exchanges.

  1. Transport: Layer Security (TLS 1.3) Cryptographic handshake ensuring endto-end encryption (E2EE) between client apps and bank servers.

Securing online banking web traffic, mobile banking API gateways, and interbank SWIFT / NEFT networks.

  1. Hash: Functions (SHA-256 / SHA-3) One-way deterministic mathematical algorithms producing a unique fixedlength digest.

Password hashing, transaction integrity verification, and blockchain ledger validation. 2.2 Zero Trust Architecture (ZTA) & Security Operations Center (SOC)

  1. Zero: Trust Architecture ("Never Trust, Always Verify") Assumes that threats exist both outside and inside the bank's internal network perimeter:
  • Micro-Segmentation: Isolating Core Banking servers from ordinary branch office workstations.
  • Least Privilege Access (RBAC): Granting employees minimum necessary access strictly on a need-to-know basis.
  • Continuous Verification: Re-authenticating sessions dynamically based on device health and geolocation. 2. 24/7 Security Operations Center (SOC) & SIEM The nerve center of cyber defense:

SIEM (Security Information and Event

  • Management): Ingests billions of log events from firewalls, servers, and ATMs, correlating suspicious patterns.

SOAR (Security Orchestration, Automation and Response): Automatically isolates compromised endpoints in milliseconds to prevent lateral movement. 2.3 Blockchain & Distributed Ledger Technology (DLT) in Banking

  1. Trade: Finance & Letters of Credit (LC) Replacing multi-day paper-based LC processing with real-time smart contracts on permissioned blockchain consortia, eliminating document forgery and duplicate invoice financing.
  2. Immutable: Audit Trails & Cross-Border Settlements Provides tamper-proof cryptographic transaction logs, enabling instant interbank reconciliation, realtime cross-border settlements, and fraud elimination. 2.4 Authentication Paradigms: Multi-Factor Authentication (MFA) & FIDO2 Authentication Dimension Authentication Factor Category Banking Implementation Example Factor 1: Knowledge Factor "Something You Know" Customer Password, ATM PIN, UPI MPIN, Security Questions.

Factor 2: Possession Factor "Something You Have" SMS OTP, Time-Based OTP (TOTP Authenticator), EMV Smart Chip Card, Hardware Token.

Factor 3: Inherence Factor "Something You Are" Biometric Fingerprint (AePS), Facial Recognition (Video KYC), Iris Scan, Voice Biometrics.

Factor 4: Behavioral / Contextual "Something You Do / Location" Typing cadence, habitual transaction geolocations, IP address reputation scoring.

  1. Regulatory: Guidelines: RBI Cyber Security Framework & IT Act The Reserve Bank of India enforces some of the world's most rigorous regulatory cybersecurity mandates to ensure operational resilience across the financial sector. 3.1 The RBI Cyber Security Framework for Banks (2016) Framework Pillar Regulatory Requirement Operational Implementation Mandate
  2. Board-Level: Governance Mandatory constitution of an IT Strategy Committee and a Board-level Cyber Security Committee (BCSC) headed by the Chief Information Security Officer (CISO).

Quarterly review of cyber risk posture, vulnerability assessments, and penetration testing (VAPT) audits.

  1. Cyber: Crisis Management Plan (CCMP) Formulation of an executable CCMP addressing cyber attack containment, system recovery, business continuity (BCP), and disaster recovery (DR).

Periodic mock cyber drill simulations testing ransomware recovery and failover to secondary DR data centers.

  1. Mandatory: Cyber Incident Reporting Statutory mandate to report all security incidents, data breaches, and ransomware attacks to RBI CSITE and CERT-In.

Must submit preliminary report within 2 to 6 hours of incident detection; detailed root-cause analysis within 21 days.

  1. Customer: Protection & Zero Liability RBI Circular on Limiting Liability of Customers in Unauthorised Electronic Banking Transactions.
  • Zero Liability: If fraud is reported by customer within 3 working days or arises from bank negligence.
  • Limited Liability: Capped at ₹5,000 to ₹25,000 if reported within 4 to 7 days. 3.2 Statutory Cyber Law Provisions under Information Technology Act, 2000

1. Section 43A: Compensation for Failure to Protect Data Mandates that banking corporations possessing sensitive personal data must maintain reasonable security practices; failure leading to wrongful loss attracts unlimited civil compensation liabilities.

2. Section 66C & 66D: Identity Theft & Impersonation Punishes identity theft (stealing MPINs, digital signatures) and cheating by personation over computer systems with imprisonment up to 3 years and fine up to ₹1 Lakh. 3.3 The Gopalakrishna Working Group Recommendations (2011) The landmark Gopalakrishna Committee Report (2011) laid the foundational blueprint for IT governance, cyber fraud management, and electronic banking security in India:

  1. Chief: Information Security Officer (CISO): Mandated an independent CISO reporting directly to the Risk Management Committee / Board, separate from IT operations.
  2. Dual-Factor: Authentication: Statutory requirement of mandatory 2FA for all online and mobile cardnot-present (CNP) financial transactions.
  3. IT Governance: Architecture: Defined comprehensive standards for Information Security Audits,

Vendor Risk Management, and Cyber Forensics. 3.4 Vulnerability Assessment & Penetration Testing (VAPT) and Cyber Insurance

  1. VAPT: Security Audits Mandatory semi-annual security testing conducted by CERT-In empaneled ethical security auditors, evaluating external attack surfaces, API endpoints, and mobile app code.
  2. Cyber: Risk Insurance Policies Comprehensive institutional insurance covering forensic investigation costs, legal defense liabilities, ransom extortion defense, and customer identity theft compensation.
  3. Role of: Data Analytics in Modern Banking: Value Maximization & Predictive Risk In data-rich banking environments, Big Data Analytics transforms raw transactional streams into actionable strategic foresight, driving customer personalization, credit risk optimization, and operational efficiency. 4.1 The Four Tiers of Banking Data Analytics Analytics Tier Core Question Answered Key Banking Applications
  4. Descriptive: Analytics "What happened in our banking operations?" Daily branch deposit inflows, ATM cash replenishment tracking, monthly NPA portfolio aging reports.
  5. Diagnostic: Analytics "Why did it happen?" Root-cause analysis of sudden spikes in retail credit card defaults in specific regions; analyzing ATM downtime causes.
  6. Predictive: Analytics "What is likely to happen next?" Customer churn prediction, loan default probability modeling, credit card cross-sell propensity scoring.
  7. Prescriptive: Analytics "What specific action should the bank take?" Automated loan pricing optimization, dynamic risk-weighted capital allocation, personalized investment recommendations. 4.2 Customer Intelligence & Customer Lifetime Value (CLV) Banks deploy advanced machine learning algorithms to build a Customer 360-Degree View, consolidating savings, credit cards, mortgages, and mutual fund holdings to calculate Customer Lifetime Value (CLV).
  • MATHEMATICAL FORMULA: CUSTOMER LIFETIME VALUE (CLV) Predictive Retail Analytics CLV = ∑ [ (Annual Rev enue per Custo mer × P ro f it Margin) ÷ (1 + D isc o unt Rate)^t ] × Retentio n Rate^t Where: $t$ = Customer Tenure (Years); Discount Rate = Cost of Capital; Retention Rate = Probability of customer remaining with bank. ∑ Worked Illustration: Customer Lifetime Value (CLV) Computation Customer Segment Parameters (Affluent HNI Retail Banking):
  • Average Annual Fee & Net Interest Revenue ($AR$) = ₹40,000 | Profit Margin ($m$) = 25% → Net Annual Margin = ₹10,000.
  • Average Customer Relationship Horizon ($N$) = 5 Years | Retention Rate ($r$) = 90% (0.90) | Bank Cost of Capital ($d$) = 10% (0.10).

1. Year 1 Present Value = ₹10,000 × (0.90 / 1.10) = ₹8,181.82.

2. Year 2 PV = ₹10,000 × (0.90 / 1.10)^2 = ₹6,694.21 | Year 3 PV = ₹5,477.08 | Year 4 PV = ₹4,481.25 | Year 5 PV = ₹3,666.48.

TOTAL CUSTOMER LIFETIME VALUE (CLV) = ₹8,181.82 + ₹6,694.21 + ₹5,477.08 + ₹4,481.25 + ₹3,666.48 = ₹28,500.84 per HNI Client. (Justifies customer acquisition costs up to ₹8,000). 4.3 Credit Risk Analytics & Expected Loss (EL) Modeling (Basel III)

  • MATHEMATICAL FORMULA: EXPECTED CREDIT LOSS (ECL) Basel III Prudential Analytics E xpec ted Lo ss (E L) = P ro bability o f D ef ault (P D ) × Lo ss Giv en D ef ault (LGD ) × E xpo sure at D ef ault (E AD ) Where:

PD: Likelihood of borrower defaulting over 1-year horizon.

  • LGD: Percentage of exposure lost after liquidating collateral (1 − Recovery Rate).
  • EAD: Total gross credit exposure outstanding at the time of default. ∑ Worked Illustration: Basel III Expected Credit Loss Computation Commercial Corporate Loan Portfolio Parameters: Total Outstanding Loan ($EAD$) = ₹100.00 Crore.
  • Internal Credit Rating Probability of Default ($PD$) = 2.5% (0.025).
  • Collateral Security Realization = 60% → Loss Given Default ($LGD$) = 100% − 60% = 40% (0.40).
  1. Expected: Loss Calculation = 0.025 × 0.40 × ₹100.00 Crore = ₹1.00 Crore.
  • PROVISIONING MANDATE: Bank must maintain ₹1.00 Crore statistical impairment provisions from annual operating profits to absorb expected credit default losses.
  1. Real-Time: Fraud Analytics, Early Warning Systems & Incident Response To thwart sophisticated cyber attacks before balance sheet damage occurs, banks integrate real-time anomaly detection engines and robust incident response protocols. 5.1 Early Warning Signals (EWS) for Stressed Asset Management To detect potential loan default before an account degrades into a 90-day Non-Performing Asset (NPA), banks deploy Early Warning Systems (EWS) tracking algorithmic red flags:
  • Operational Red Flags: Continuous high utilization of Cash Credit limits (> 95%), sudden frequent cheque returns, and substantial decline in sales turnover credited to the account.
  • Special Mention Accounts (SMA Hierarchy): SMA-0: Principal or interest overdue for 1 to 30 days.

SMA-1: Principal or interest overdue for 31 to 60 days.

SMA-2: Principal or interest overdue for 61 to 90 days (High default risk; trigger immediate resolution plan). 5.2 Real-Time Graph Analytics & Money Muling Detection

  1. Graph: Theory & Network Analytics Maps complex multi-tiered transaction networks as nodes (accounts) and edges (transfers) to instantly detect circular fund routing, synthetic identities, and coordinated money mule rings in real time.
  2. Incident: Containment & Disaster Recovery
  • Containment: Immediate network isolation of infected subnetworks.
  • Eradication: Patching zero-day vulnerabilities and wiping malware implants.
  • Recovery: Safe restoration of Core Banking database from immutable air-gapped backups. ∑ Worked Illustration: Cyber Risk Exposure & Maximum Tolerable Downtime (MTD)
  • Bank Core Banking Outage Scenario: Scheduled Commercial Bank processing ₹500 Cr digital transactions per hour.
  • Recovery Time Objective (RTO): Target restoration within 2.0 Hours | Recovery Point Objective (RPO) = Zero Data Loss (Synchronous Mirroring).
  • Direct Cost of Outage: Transaction fees lost (₹5 Lakh/hr) + NPCI compensation penalties (₹25 Lakh/hr) + Overtime IT staffing (₹10 Lakh/hr) = ₹40 Lakh per Hour.

Total Operational Outage Loss for 2 Hours = 2 × ₹40,000,000 = ₹80.00 Lakhs.

  • DISASTER RECOVERY CONCLUSION: Achieving a 2-hour RTO successfully limits systemic disruption below the bank's Maximum Tolerable Downtime (MTD) of 4.0 Hours, preventing regulatory sanctions. 5.3 Business Continuity Management (BCM) & Red-Teaming Cyber Simulations Resilience Pillar Operational Framework Regulatory Benchmark Mandate
  1. Hot: Disaster Recovery (DR) Site Geographically distant secondary data center (in a different seismic zone) with real-time synchronous data replication.

RTO ≤ 2 Hours; live failover simulation conducted twice every financial year.

  1. Red-Teaming (Ethical: Adversary Simulation) Independent certified ethical hackers simulating sophisticated APT cyber heists against the bank's live defenses.

Mandatory annual red-teaming audit submitted to the Board Cyber Security Committee.

  1. Immutable: AirGapped Vaults Offline, write-once-read-many (WORM) golden backups completely isolated from the bank's network routing.

Guarantees 100% data recovery even during catastrophic enterprise-wide ransomware attacks.

COM1MN106Foundations of Modern Banking

Download Module 4 Notes (PDF)

Calicut University • FYUGP 2024 Syllabus

Download PDF

Finished this module?

Continue reading the next module or return to the subject overview.