New Delhi, Sept. 21 -- Cyber resilience has evolved from protecting a business's own systems to protecting the ecosystem in which it operates, panellists at the VCCircle Finserv Investment Summit 2026 in Mumbai on Friday said.

Aditya Singh, co-founder and CEO of Tapfin and co-founder of GoGreen Capital, and Ajit Kumar, chief operating officer at FatakPay, discussed the growing importance financial institutions place on cyber resilience and how the approach to it is changing during a panel titled "Unified Front: Cross-sector Cyber Resilience for Banks, NBFCs and Fintech".

"No (business) conversation is complete without discussing cybersecurity (or cyber resilience)," Tapfin and GoGreen Capital's Singh said, listing some changes in how the industry approaches the issue now.

"One is that the focus has shifted from cybersecurity to cyber resilience. It is not only about protection but also about your ability to recover," he said.

"The other is that it is not just about protecting your own walls, it is about (safeguarding) your entire ecosystem (which includes vendors and partners). There is awareness that any risk within your own walls has the ability to become a large contagion... Thirdly, this is not treated just as a technical issue any more," Singh added.

FatakPay's Kumar said recovery has become a key concern for businesses today. However, recovery and protection are equally important, he said.

"Earlier, a lot of policies (towards cybersecurity and resilience) were there, but they were more about ticking a checklist," he said. "Today, there is more thought about having a drill when there is an attack. We can get the tools or have a system to prevent attacks, but what if it (the risk) is already in the system? That thinking has gained in popularity," Kumar added.

Averting a contagion

Tapfin, which helps EV fleet operators with financing, insuring, demand aggregation and OEM selection, launched non-banking financial company (NBFC) GoGreen Capital to cater to EV financing in India.

Elaborating on how an entity's cyber hygiene can affect the entire ecosystem, Singh said, "Tapfin, the parent entity, is a data company that takes telemetry data from EV devices and contextualises it for lenders to build underwriting models. The source of truth in this is multiple IoT and ODMs (original device manufacturers)."

"So my own infrastructure could be safe, but if my source of truth is compromised and one or two of these (IoT or ODM devices) send the wrong signals and this data is used to build underwriting models and do risk assessments of the portfolio, the risk is built into the entire ecosystem," Singh explained. "This is a great example of how your own systems could be fine, but the information you rely on is essentially introducing this (risk) to the ecosystem. So cyber resilience is more than tracking the volume of attacks.. It is also considering how the data is coming into your system," he added.

According to Kumar, just as businesses were earlier told to know their customers, they now need to know their vendors and their vendors' vendors. Businesses have to rely on vendors and must continuously monitor their systems to ensure that risks are not building up unnoticed along any of these nodes, he said.

Hence, vendor data needs to be enriched on a continuous basis, Singh noted.

Cross-sector collaboration

The speakers also discussed the importance of cross-sector collaboration. While there is collaboration over business leads, more needs to be done regarding collaboration on cyber risks, Singh said. There should be information flow both upwards (industry to regulators) and downwards (from regulators to industry). Such flow should also involve information on fintechs, and not just lenders, he added.

"There is a system to report cyber frauds upwards, but we need to share it with the larger ecosystem," Singh said, adding that entities should also share learnings from managing adverse events.

Industry players and regulators must collaborate on this, particularly since bad actors appear to be collaborating widely, Kumar said. added that i

Published by HT Digital Content Services with permission from VC Circle.