Bank of Baroda Appoints KM Salam as Deputy CISO in Major Cyber Push
Former Union Bank SOC head and NaBFID security chief assumes operational defense command in December 2026.
New Delhi: Bank of Baroda has selected K. M. Salam as its new Deputy Chief Information Security Officer. Salam currently leads cybersecurity at NaBFID. As the incoming Bank of Baroda Deputy CISO, he takes charge of day-to-day cyber defense at India's second-largest state-owned bank. The position puts him in direct control of network monitoring, threat response, and access governance across all digital banking units.
ETBFSI first reported the development on September 20, 2026. Salam is currently serving out his notice period at NaBFID. He will join Bank of Baroda in the second week of December 2026. The move comes as public sector lenders face stricter oversight from the Reserve Bank of India.
Optimo Capital Appoints Ex-RBI CGM Shrimohan Yadav Amid 179% AUM Surge
Official Confirmation Record: BoB Final Result Notice Dated August 28
Bank of Baroda started hunting for a top cyber leader earlier this year. The bank published recruitment notices for several senior contract posts throughout 2026.
An audit of the bank's careers website confirms the key milestones of this process:
- Official Entry: "Notification dated 28.08.2026 – Declaration of Final Result for the position Deputy CISO."
- Recruitment Scope: Senior contractual specialist roles across technology, risk, and audit streams.
- Verification Status: The bank’s public portal confirms the post was filled on August 28. However, the online list does not show the candidate's name.
Because the public notice leaves out individual names, Salam's identity as the chosen executive rests on ETBFSI's verified reporting. The bank had not issued a separate public statement regarding his contract at the time of publication.
18 Years at Union Bank, 3 Years at NaBFID: Salam's Career Track
Why did Bank of Baroda choose Salam? His career combines front-line technical defense with high-level boardroom planning.
Salam spent 18 continuous years at Union Bank of India. He worked across core networks, server security, and software systems. His final assignment at Union Bank was Head of the Security Operations Centre (SOC).
A bank SOC processes billions of daily event logs. It requires fast choices under real pressure. Salam brings both hands-on incident command and policy-level leadership to his new post.
In 2023, Salam joined NaBFID as its Chief Information and Security Officer. There, he built enterprise security frameworks from scratch. He also designed cloud compliance roadmaps. That role gave him deep strategic insight.
By bringing him in as Bank of Baroda Deputy CISO, the bank adds a seasoned leader. He knows how attackers target Indian banking infrastructure from the inside out.
1 TB Data Leak vs Finacle Safety: The July 2026 Cyber Incident
Why does this hiring matter right now? Context is critical.
On July 27, 2026, Bank of Baroda reported a data security incident. Attackers compromised an internal employee email account. The incident led to intense public scrutiny of public sector cybersecurity.
Anatomy of the July 2026 Data Breach
- Attack Vector: Business Email Compromise (BEC) using stolen employee credentials.
- Core Banking State: Finacle transactional systems were never breached and stayed secure.
- Internal Movement: Hackers leveraged broad folder rights to access central storage drives.
- Exfiltrated Volume: Exactly 1 Terabyte of data containing 92,000 files across 9,783 directories.
- Threat Syndicate: The leaked records were uploaded to the dark web by "TripleX".
The attackers did not breach core bank ledgers. Yet, they stole terabytes of operational files. How did that happen? Internal permission policies were simply too broad.
This reveals a key truth about modern banking: firewalls protect outer borders, but loose internal permissions compromise data. Stopping this type of lateral spread is the main challenge facing the incoming Bank of Baroda Deputy CISO.
CISO vs Deputy CISO: Division of Security Responsibilities
How do large banks split security leadership? In India's top lenders, information defense divides into two clear operational tracks:
| Functional Area | Chief Information Security Officer | Deputy CISO (Operations) |
|---|---|---|
| Core Mission | Strategic cyber policy and board reporting. | Tactical SOC defense and threat hunting. |
| Regulatory Role | Liaises with RBI, CERT-In, and audit boards. | Executes technical security controls. |
| Breach Protocol | Legal disclosures and executive response. | Live endpoint isolation and forensics. |
| Identity Access | Designs enterprise Zero Trust architecture. | Enforces hardware MFA and privilege limits. |
The Reserve Bank of India demands tight controls over digital payment architectures. The central bank closely tracks liquidity tools like aggressive VRRR reverse repo auctions, and its IT examiners take an equally strict approach to data security compliance.
News4Bharat Perspective: Moving Beyond the External Firewall
For years, public sector banks treated cybersecurity like an annual compliance audit. That approach no longer works. Modern cyber syndicates target human identities rather than attempting direct breaches of core databases.
Bank of Baroda's move highlights three vital industry shifts:
- Deep Technical Leadership: The bank selected an executive with 18 years of direct SOC command rather than a general administrative officer.
- Mandatory Zero Trust: Internal email accounts cannot maintain open access to network drives. Limiting internal lateral spread is now an urgent task.
- Faster Containment: Indian lenders must isolate intrusions in minutes, not days. That demands leaders who have run live cyber watch floors.
Salam’s onboarding gives Bank of Baroda specialized leadership right when it needs it most. His main challenge will be enforcing tight identity controls across thousands of bank branches nationwide.
Frequently Asked Questions
Clear, verified answers regarding Bank of Baroda's cybersecurity leadership update.
Who is the new Bank of Baroda Deputy CISO?
K. M. Salam, current CISO at NaBFID and former SOC head at Union Bank of India, has been selected for the role. He assumes charge in mid-December 2026.
Did the July 2026 incident compromise core banking?
No. The bank confirmed its Finacle core transactional platform remained secure. The breach was confined to employee email and internal network storage.
What are the key duties of a Deputy CISO?
The Deputy CISO directs tactical defense, oversees Security Operations Centre (SOC) workflows, monitors live threats, and manages identity access policies.
Has Bank of Baroda officially named Salam on its website?
The bank published a final selection notice dated August 28, 2026, without naming the candidate. Salam was identified through verified reporting by ETBFSI.

