Category: Technology & Innovation
The move comes as financial markets become increasingly dependent on interconnected digital systems, making cyber incidents capable of affecting not just individual organisations but also other market participants. SEBI’s latest initiatives seek to improve the speed and quality of incident reporting while creating a mechanism for sharing information on vulnerabilities, cyber threats and lessons from previous incidents.
The initiative is aimed at strengthening the cybersecurity framework of India’s securities market by improving coordination among SEBI-regulated entities and other stakeholders.
The revamped Incident Reporting Portal is intended to make the reporting of cybersecurity incidents more structured, timely and actionable. Standardised reporting can help the regulator understand the nature and extent of an incident, assess its potential impact on interconnected systems and determine appropriate response measures.
The portal is also aligned with the Financial Stability Board’s (FSB) Format for Incident Reporting Exchange (FIRE). The framework seeks to promote greater consistency in cyber-incident reporting and facilitate information exchange, including in situations involving cross-border financial institutions.
The second platform, the Cyber Suraksha Portal, is designed as a central knowledge-sharing platform. It will facilitate the dissemination of cybersecurity information, including vulnerability warnings, policy and regulatory measures, incident insights and other relevant cybersecurity guidance.
Together, the two platforms reflect a shift from treating cybersecurity solely as an internal technology function towards a more coordinated, ecosystem-wide approach.
The revamped Incident Reporting Portal will provide a more structured mechanism for SEBI-regulated entities to report cybersecurity incidents. The objective is to ensure that information reaches the regulator in a timely and usable form, enabling quicker assessment and response.
Cybersecurity incident reporting is already an established requirement under SEBI’s Cyber Security and Cyber Resilience Framework. SEBI’s framework provides time-bound reporting requirements for regulated entities, including reporting through the SEBI Incident Reporting Portal.
The Cyber Suraksha Portal will complement incident reporting by focusing on information sharing and cyber awareness across the securities-market ecosystem.
It will provide access to cybersecurity knowledge, vulnerability warnings, policy measures and insights derived from cyber incidents. By making relevant information available to market participants, the platform can help organisations identify emerging threats and strengthen their preventive and response capabilities.
The two initiatives could strengthen the overall cyber resilience of India’s securities market by improving the flow of information between regulated entities and the regulator. More consistent incident reporting can help SEBI identify common vulnerabilities, understand emerging patterns and respond to risks that may extend beyond a single organisation.
The Cyber Suraksha Portal can further support preventive cybersecurity by enabling market participants to learn from reported incidents and stay informed about vulnerabilities and regulatory developments.
The initiative is particularly relevant as stock exchanges, clearing corporations, depositories, brokers and other market intermediaries increasingly rely on interconnected digital infrastructure. The broader impact, therefore, is expected to be a more coordinated approach to cybersecurity, where timely reporting, information sharing, prevention and incident response operate as interconnected components of market resilience.
SEBI’s launch of the revamped Incident Reporting Portal and Cyber Suraksha Portal marks another step towards strengthening cybersecurity governance in India’s securities market. While the first platform focuses primarily on making incident reporting more structured and actionable, the second creates a mechanism for sharing cybersecurity knowledge, warnings and incident-related insights.
As financial markets become increasingly digital and interconnected, cybersecurity risks can have consequences beyond individual institutions. SEBI’s latest initiatives underline the importance of collective preparedness, faster information sharing and stronger cyber resilience across the financial ecosystem. The effectiveness of these platforms will ultimately depend on timely reporting, active participation by regulated entities and the ability to translate shared information into stronger cybersecurity practices.
1) India Today
https://www.indiatoday.in/business/story/from-threats-to-resilience-sebis-new-2-pronged-cyber-defence-strategy-2973803-2026-08-18
2) Live Mint
https://www.livemint.com/companies/people/our-cyber-defence-must-evolve-faster-sebi-chief-tuhin-kanta-pandey-launches-2-new-portals-for-digital-security-11786963774172.html