The Securities and Exchange Board of India (SEBI) has launched the SEBI Incident Reporting and Cyber Suraksha web portals to improve cyber-incident reporting and information sharing across the securities market. The first is a redesigned reporting system, while the second creates a common space for vulnerability warnings, policy measures, and lessons from cyber incidents. Together, the portals shift cybersecurity from isolated compliance reporting towards faster, coordinated protection of the market ecosystem.
Why Securities Market Cybersecurity Matters
SEBI was first constituted as a non-statutory body on 12 April 1988. Parliament gave it statutory status through the Securities and Exchange Board of India Act, 1992, which came into force on 30 January 1992. The Act assigns SEBI three linked duties: protecting investors, promoting the development of the securities market, and regulating that market. Secure digital systems are now essential to all three duties because trading, settlement, investor records, and communication depend heavily on technology.
The term cyber resilience means an organisation’s ability to anticipate, withstand, contain, recover from, and learn from a cyberattack. A weakness in one market participant can affect others through vendors, cloud services, application programming interfaces (APIs), technology platforms, and other connected institutions. Cybersecurity is therefore not limited to protecting a single broker or exchange. It also requires timely intelligence and coordinated action across the wider ecosystem.
SEBI issued the Cybersecurity and Cyber Resilience Framework (CSCRF) for its regulated entities on 20 August 2024. The framework brought greater uniformity to cybersecurity controls and covers governance, asset classification, vulnerability testing, patch management, audits, threat intelligence, incident response, and recovery. It also requires regulated entities to maintain incident response arrangements, prepare a cyber crisis management plan, conduct root cause analysis, and undertake forensic investigation when the cause of an incident remains unclear or the incident is serious.
Two Portals With Different Functions
SEBI launched the two portals as complementary tools. The Incident Reporting portal deals with the formal flow of information from a regulated entity to the regulator. Cyber Suraksha deals with wider circulation of useful cybersecurity knowledge among participants in the securities market.
| Portal | Main purpose | Information handled |
|---|---|---|
| SEBI Incident Reporting | Structured reporting of cyber incidents | Incident details, impact, response actions, updates, and closure information |
| Cyber Suraksha | Centralised cybersecurity information sharing | Vulnerability warnings, cybersecurity circulars, policy measures, and incident insights |
The redesigned Incident Reporting portal replaces the earlier reporting arrangement with a more structured, timely, and actionable process. It is meant to help SEBI receive comparable information about incidents and act faster on risks that may affect other regulated entities. The portal is relevant to the broad SEBI-regulated ecosystem, including market infrastructure institutions and intermediaries such as stock exchanges, clearing corporations, depositories, stock brokers, mutual funds, custodians, merchant bankers, portfolio managers, and investment advisers.
Cyber Suraksha creates a common reference point for the market. A vulnerability warning can alert several institutions to the same weakness, while an incident insight can help them improve controls before a similar attack occurs. This approach treats cybersecurity information as a shared defensive resource rather than knowledge that remains confined to the organisation where an incident began.
Incident Reporting Aligned With the FIRE Format
On 24 August 2026, SEBI aligned its cyber-incident reporting portal with the Format for Incident Reporting Exchange (FIRE) developed by the Financial Stability Board (FSB). The FSB is an international body that monitors the global financial system and makes recommendations to strengthen financial stability. FIRE is a common format for reporting operational and cyber incidents, with standard information fields, definitions, and classifications.
The purpose of this alignment is to improve consistency within the securities market and make information easier to compare across sectors and jurisdictions. FIRE does not create one universal reporting deadline for every country. Instead, it provides a common information structure that authorities can adapt to their own legal and supervisory requirements.
Reporting Across the Incident Life Cycle
The updated portal supports reporting in stages. A regulated entity can submit an initial report when an incident is detected, provide intermediate updates as facts become clearer, and send a final report after the incident is resolved and remedial action is assessed.
| Reporting stage | What it communicates |
|---|---|
| Initial | The known facts and early assessment of the incident |
| Intermediate | New information, changing impact, and response actions |
| Final | Resolution status, root cause, lessons learned, and corrective measures |
This staged process recognises that an organisation may not know the full extent or cause of a cyberattack at the time of first reporting. It allows the regulator to receive an early warning without requiring every detail immediately, followed by a fuller picture as investigation and recovery progress.
Under SEBI’s existing CSCRF requirements, regulated entities must report cyber incidents through the prescribed email channel within six hours and through the Incident Reporting portal within 24 hours. The FIRE-aligned design improves the quality and continuity of this reporting, but it does not replace the need to meet SEBI’s prescribed timelines.
From Individual Security to Ecosystem Resilience
The two portals are significant because the securities market is highly interconnected. An attack on one institution can spread through a shared technology vendor, cloud service, API, or third-party provider. Quick information sharing can help other institutions identify the same threat, isolate affected systems, and apply defensive measures before the disruption becomes wider.
The initiative also supports a change in vulnerability management. Vulnerability management means finding, assessing, fixing, and checking weaknesses in digital systems. SEBI’s approach places emphasis on continuous, risk-based monitoring because software, cloud settings, APIs, and external dependencies change regularly. A system that was secure during a periodic audit may face a new weakness after a software update or a change in a connected service.
The regulator has also identified quantum resilience as a longer-term cybersecurity concern. Quantum computers could eventually weaken some encryption methods used to protect digital communication and data. The move towards post-quantum cryptography, which refers to encryption designed to resist quantum computing attacks, therefore requires planned migration of systems rather than waiting for the technology to mature fully.
For investors, stronger reporting and shared warnings can support the availability, integrity, and confidentiality of market services. They do not remove cyber risk. Their value will depend on whether regulated entities report promptly, study incident lessons, fix known weaknesses, and coordinate with SEBI and other relevant authorities.
The Way Forward
The immediate priority is effective adoption by every regulated entity. Institutions need clear internal reporting responsibilities, tested incident response plans, accurate inventories of critical systems, and arrangements for communicating with vendors and authorities during an attack. Regular exercises can reveal gaps before a real incident places pressure on decision-making.
SEBI’s broader framework provides the foundation for this work through cyber audits, threat intelligence, security operations, business continuity, and recovery controls. The new portals add two important operating links: one captures incidents in a consistent format, and the other helps distribute warnings and lessons across the market. Their combined impact will be strongest when reporting becomes a continuous process of detection, response, recovery, and learning.
Key Takeaways
- SEBI launched the SEBI Incident Reporting and Cyber Suraksha portals to strengthen cybersecurity across the securities market ecosystem.
- The Incident Reporting portal was aligned with the Financial Stability Board’s FIRE format on 24 August 2026.
- The FIRE format supports initial, intermediate, and final reporting across the life cycle of a cyber incident.
- Under SEBI’s existing requirements, regulated entities must report cyber incidents through the prescribed email channel within six hours and through the portal within 24 hours.
- SEBI issued the Cybersecurity and Cyber Resilience Framework for regulated entities on 20 August 2024.
- SEBI was constituted in 1988 and became a statutory body under the SEBI Act, 1992.