SEBI launches two cybersecurity portals to strengthen securities market resilience

Share:
Audio Loading voice…
SEBI launches two cybersecurity portals to strengthen securities market resilience

Synopsis

SEBI has launched two dedicated cybersecurity platforms — a revamped Incident Reporting Portal aligned with global FSB standards, and a new Cyber Suraksha Portal for real-time threat intelligence sharing. It is the first time India's securities regulator has built a centralised information-sharing infrastructure for cyber defence, signalling a shift from individual compliance to ecosystem-wide resilience.

Key Takeaways

SEBI launched two cybersecurity portals on 17 August : a revamped Incident Reporting Portal and the new Cyber Suraksha Portal .
The Incident Reporting Portal is aligned with the Financial Stability Board's (FSB) FIRE framework, enabling consistent cross-border incident reporting.
The Cyber Suraksha Portal will serve as a central hub for sharing vulnerability warnings, policy insights, and lessons from cyber incidents across the securities ecosystem.
SEBI Chairman Tuhin Kanta Pandey stressed that cyber resilience means the ability to anticipate, withstand, respond to, recover from, and learn from attacks — not merely prevent them.
Both portals are now live; regulated entities including brokers, depositories, and exchanges are expected to engage with the platforms under compliance obligations.

The Securities and Exchange Board of India (SEBI) on Monday, 17 August launched two new digital initiatives — a revamped Incident Reporting Portal and the Cyber Suraksha Portal — to fortify cybersecurity, incident reporting, and information sharing across India's securities market ecosystem. SEBI Chairman Tuhin Kanta Pandey made the announcement at the SEBI Symposium on Cyber Defence in New Delhi.

What the Two Portals Do

The revamped SEBI Incident Reporting Portal is designed to make cybersecurity incident reporting more structured, timely, and actionable. It is aligned with the Financial Stability Board's (FSB) Format for Incident Reporting Exchange (FIRE), a global standard that aims to bring consistency to incident reporting and reduce friction in cross-border disclosures.

The second initiative, the Cyber Suraksha Portal, will function as a centralised hub for sharing cybersecurity intelligence among market stakeholders. It will facilitate the exchange of vulnerability warnings, policy measures, knowledge resources, and lessons drawn from past cyber incidents across the financial ecosystem.

What SEBI Chairman Pandey Said

'Cyber threats do not respect organisational boundaries. They do not respect regulatory boundaries. And they certainly do not respect national borders,' Pandey said at the symposium. He emphasised that the portals are 'not merely technology platforms' — their real value, he argued, will depend on how effectively institutions use them to share information, learn from incidents, and respond promptly.

Pandey stressed that a cyberattack originating in one institution can cascade through vendors, technology platforms, and third-party networks, potentially affecting interconnected organisations across the financial system. Effective practices and lessons from one institution, he said, should serve as references for the wider ecosystem.

The Broader Case for Systemic Cyber Resilience

SEBI's move reflects a growing regulatory consensus that cybersecurity cannot be treated as an individual-institution problem. A breach at one node — a broker, a depository, or a technology vendor — can propagate risk across the entire market infrastructure. This is the first time SEBI has launched a dedicated information-sharing portal specifically for the securities sector, marking a structural upgrade in how the regulator approaches collective cyber defence.

Notably, the alignment with the FSB's FIRE framework also signals India's intent to harmonise its incident reporting standards with global norms, easing coordination with overseas regulators in the event of a cross-border cyber incident.

Redefining Resilience: Beyond Prevention

Pandey drew a clear distinction between cybersecurity as prevention and cyber resilience as a broader capability. 'Cyber resilience does not mean assuming that our systems can never be attacked. It means building the capability to anticipate, withstand, respond to, recover from and learn from an attack,' he said. This framing — anticipate, withstand, respond, recover, learn — represents a shift from a purely defensive posture to one that accepts breach as a possibility and prepares institutions accordingly.

What Comes Next

Both portals are now live, and SEBI is expected to issue detailed operational guidelines for regulated entities on reporting timelines and information-sharing protocols. Market participants — including brokers, depositories, stock exchanges, and asset managers — will be required to engage with the new infrastructure as part of their regulatory compliance obligations. How quickly institutions operationalise these tools will determine whether SEBI's cyber resilience push translates from policy intent to market-wide practice.

Point of View

More third-party tech vendors, more cross-border flows — yet its cyber incident reporting infrastructure lagged well behind its market depth. Aligning with the FSB's FIRE framework is a smart move: it reduces the coordination cost when a breach crosses jurisdictions, which is increasingly how serious attacks unfold. The harder question is adoption. Regulators can build portals; they cannot force institutions to share embarrassing breach data candidly. SEBI will need credible enforcement teeth — and perhaps safe-harbour protections for early reporters — to make the Cyber Suraksha Portal a genuine intelligence-sharing network rather than a compliance checkbox.
NationPress
17 Aug 2026

Frequently Asked Questions

What are the two cybersecurity portals launched by SEBI?
SEBI launched a revamped Incident Reporting Portal and a new Cyber Suraksha Portal on 17 August. The Incident Reporting Portal streamlines breach disclosures in line with global FSB standards, while the Cyber Suraksha Portal acts as a centralised hub for sharing threat intelligence, vulnerability alerts, and policy insights across the securities market.
What is the FSB FIRE framework and why is it relevant?
The Financial Stability Board's Format for Incident Reporting Exchange (FIRE) is a global standard designed to bring consistency and reduce friction in cross-border cybersecurity incident reporting. SEBI's alignment with FIRE means Indian market participants can report incidents in a format recognised by international regulators, easing coordination during cross-border cyber events.
Who is required to use these new SEBI portals?
All regulated entities under SEBI — including stock exchanges, brokers, depositories, and asset managers — are expected to engage with the new portals as part of their compliance obligations. Detailed operational guidelines on reporting timelines and protocols are expected to follow.
What did SEBI Chairman Tuhin Kanta Pandey say about cyber resilience?
Pandey said cyber resilience is not about assuming systems will never be attacked, but about building the capability to anticipate, withstand, respond to, recover from, and learn from an attack. He also warned that a cyber incident in one institution can spread through vendors and third parties to affect the broader financial ecosystem.
Why does SEBI's cybersecurity initiative matter for the broader market?
India's securities market is deeply interconnected — a breach at one broker, depository, or technology vendor can cascade across the system. By creating shared reporting and intelligence infrastructure, SEBI is shifting cyber defence from an individual-institution responsibility to a collective, ecosystem-wide obligation, which is the approach regulators globally are converging on.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 2 months ago
  2. 3 months ago
  3. 3 months ago
  4. 3 months ago
  5. 9 months ago
  6. 10 months ago
  7. 1 year ago
  8. 1 year ago
Google Prefer NP
On Google