SEBI launches two cybersecurity portals to strengthen securities market resilience
Synopsis
Key Takeaways
The Securities and Exchange Board of India (SEBI) on Monday, 17 August launched two new digital initiatives — a revamped Incident Reporting Portal and the Cyber Suraksha Portal — to fortify cybersecurity, incident reporting, and information sharing across India's securities market ecosystem. SEBI Chairman Tuhin Kanta Pandey made the announcement at the SEBI Symposium on Cyber Defence in New Delhi.
What the Two Portals Do
The revamped SEBI Incident Reporting Portal is designed to make cybersecurity incident reporting more structured, timely, and actionable. It is aligned with the Financial Stability Board's (FSB) Format for Incident Reporting Exchange (FIRE), a global standard that aims to bring consistency to incident reporting and reduce friction in cross-border disclosures.
The second initiative, the Cyber Suraksha Portal, will function as a centralised hub for sharing cybersecurity intelligence among market stakeholders. It will facilitate the exchange of vulnerability warnings, policy measures, knowledge resources, and lessons drawn from past cyber incidents across the financial ecosystem.
What SEBI Chairman Pandey Said
'Cyber threats do not respect organisational boundaries. They do not respect regulatory boundaries. And they certainly do not respect national borders,' Pandey said at the symposium. He emphasised that the portals are 'not merely technology platforms' — their real value, he argued, will depend on how effectively institutions use them to share information, learn from incidents, and respond promptly.
Pandey stressed that a cyberattack originating in one institution can cascade through vendors, technology platforms, and third-party networks, potentially affecting interconnected organisations across the financial system. Effective practices and lessons from one institution, he said, should serve as references for the wider ecosystem.
The Broader Case for Systemic Cyber Resilience
SEBI's move reflects a growing regulatory consensus that cybersecurity cannot be treated as an individual-institution problem. A breach at one node — a broker, a depository, or a technology vendor — can propagate risk across the entire market infrastructure. This is the first time SEBI has launched a dedicated information-sharing portal specifically for the securities sector, marking a structural upgrade in how the regulator approaches collective cyber defence.
Notably, the alignment with the FSB's FIRE framework also signals India's intent to harmonise its incident reporting standards with global norms, easing coordination with overseas regulators in the event of a cross-border cyber incident.
Redefining Resilience: Beyond Prevention
Pandey drew a clear distinction between cybersecurity as prevention and cyber resilience as a broader capability. 'Cyber resilience does not mean assuming that our systems can never be attacked. It means building the capability to anticipate, withstand, respond to, recover from and learn from an attack,' he said. This framing — anticipate, withstand, respond, recover, learn — represents a shift from a purely defensive posture to one that accepts breach as a possibility and prepares institutions accordingly.
What Comes Next
Both portals are now live, and SEBI is expected to issue detailed operational guidelines for regulated entities on reporting timelines and information-sharing protocols. Market participants — including brokers, depositories, stock exchanges, and asset managers — will be required to engage with the new infrastructure as part of their regulatory compliance obligations. How quickly institutions operationalise these tools will determine whether SEBI's cyber resilience push translates from policy intent to market-wide practice.