Computer Vulnerabilities, User Failures and Bank Failures
Most frauds need two weak points: one on the customer's side and one on the bank's. Here is how to name and close each.
A vulnerability is a weak point that an attacker can use. RBI's 2026 cybersecurity directions define it as a weakness, susceptibility or flaw of an asset or control that can be exploited by one or more threats. It can sit in software, in a configuration, in a process, or in a person.
IIBF's Unit 4 splits the subject the way a fraud review does: failures on the user's side, failures on the bank's side, and the internet crime that exploits both. Most real frauds need one of each: a customer who shares an OTP, and a bank system that lets a new device and a new beneficiary through in the same ten minutes.
You save ₹300
- Full 120-question mocks
- Cyber law coverage
- Module-wise practice
One payment, no subscription · Valid for 2 months
Threat, Vulnerability, Risk, Exploit
Four words the exam treats as distinct. Mixing them up is the commonest error on this unit.
- Threat
- Something with the potential to cause harm by exploiting a weakness: a fraud gang, a worm, a disgruntled insider.
- Vulnerability
- The weakness itself: an unpatched server, a default password, a staff member who doesn't verify callers.
- Exploit
- The method or code that actually uses a vulnerability.
- Risk
- The chance that a threat exploits a vulnerability, combined with the damage if it does. Remove either the threat or the vulnerability and the risk falls.
- Zero-day
- A vulnerability the vendor does not yet know about or has not yet patched, so no fix exists when it is first used.
User Failures and Bank Failures
Typical weaknesses on each side, and the control that addresses each.
Sharing OTP, PIN or card details with a caller
Whose failure
Customer
Control
Awareness messaging; alerts that name the merchant; multi-factor authentication
Installing apps from links sent on WhatsApp or SMS
Whose failure
Customer
Control
Device binding, app-store-only advice, anti-malware
Same password reused on many sites
Whose failure
Customer or staff
Control
Strong password policy, MFA
Unpatched operating systems and servers
Whose failure
Bank
Control
Patch management tracking vendor and CERT-In advisories
Default or shared admin passwords
Whose failure
Bank
Control
Centralised identity management, MFA for privileged users
Logs collected but never reviewed
Whose failure
Bank
Control
Security operations centre, alert monitoring
Weak vendor or outsourced systems
Whose failure
Bank
Control
Third-party risk assessment, contract security clauses
| Weakness | Whose failure | Control |
|---|---|---|
| Sharing OTP, PIN or card details with a caller | Customer | Awareness messaging; alerts that name the merchant; multi-factor authentication |
| Installing apps from links sent on WhatsApp or SMS | Customer | Device binding, app-store-only advice, anti-malware |
| Same password reused on many sites | Customer or staff | Strong password policy, MFA |
| Unpatched operating systems and servers | Bank | Patch management tracking vendor and CERT-In advisories |
| Default or shared admin passwords | Bank | Centralised identity management, MFA for privileged users |
| Logs collected but never reviewed | Bank | Security operations centre, alert monitoring |
| Weak vendor or outsourced systems | Bank | Third-party risk assessment, contract security clauses |
What RBI Expects Banks to Do About Them
RBI's directions push banks to find weaknesses before attackers do. For critical systems and those in the DMZ (the network zone that faces the internet) with a customer interface, a vulnerability assessment must be done at least once every six months and a penetration test at least once every 12 months. Findings must be fixed in a time-bound way, with known flaws tracked against the public CVE (Common Vulnerabilities and Exposures) list and scored on a documented scale such as CVSS.
Patching is the other half. Banks must watch vendor releases and CERT-In advisories and apply security patches under a patch management policy. Privileged users of critical systems must use multi-factor authentication. And because many failures are human, banks must educate customers about the consequences of sharing login credentials, OTPs and PINs.
Quick practice on banking operations. No signup.
Courseware and Current Rules
The IIBF courseware is a 2025 edition, so it predates RBI's 31 July 2026 consolidation of its cybersecurity and IT instructions into entity-wise Directions, 2026. Your notes may cite the earlier circulars; the rules described above are as stated in the 2026 Directions. Sittings from September 2026 to February 2027 use a 30 June 2026 cut-off for regulatory updates, so expect questions framed on the earlier circulars.
How the IIBF Exam Tests This
- check_circleDefinition swaps: a question describes an unpatched server and offers 'threat' as an option. It is a vulnerability; the hacker is the threat.
- check_circleAttribution: 'a customer clicked a link and shared an OTP' is a user failure; 'the bank never reviewed its logs' is a bank failure. Expect both in one scenario.
- check_circleFrequency facts: VA and PT are different exercises with different minimum periodicity for critical systems.
- check_circleZero-day: the defining feature is that no patch exists yet, not that the attack is new to the victim.
FAQs
What is the difference between a threat and a vulnerability?expand_more
A vulnerability is the weakness, such as an unpatched server. A threat is whatever can exploit it, such as a hacker or a worm. Risk is the combination of the two with the likely damage.
How often must banks do VAPT?expand_more
Under RBI's 2026 directions, critical systems and DMZ systems with a customer interface need a vulnerability assessment at least every six months and a penetration test at least every 12 months. Other systems follow a risk-based schedule.
What are user failures in cyber security?expand_more
Mistakes on the customer or staff side that attackers rely on: sharing OTPs or PINs, reusing passwords, installing apps from links, and ignoring alerts.
What is a zero-day vulnerability?expand_more
A flaw that the software maker has not yet fixed, often because it was unknown until attackers used it. Layered controls and behavioural monitoring are the defence until a patch arrives.
Next steps
Take a full IIBF Cyber Crimes mock test120 questions, 2 hours, scored instantly.
