From threats to resilience: Sebi's new 2-pronged cyber defence strategy

From threats to resilience: Sebi's new 2-pronged cyber defence strategy

The regulator launched the Incident Reporting Portal and the Cyber Suraksha Portal on Monday. The move comes as cyberattacks become more complex and increasingly affect not just individual institutions but the wider financial ecosystem. The new framework safeguards the exit point for the shareholders with a reliance on market priceThe Securities and Exchange Board of India (Sebi) has stepped up its cyber defence efforts with two new portals aimed at helping financial market participants report and respond to cyber threats more effectively.The regulator launched the Incident Reporting Portal and the Cyber Suraksha Portal on Monday. The move comes as cyberattacks become more complex and increasingly affect not just individual institutions but the wider financial ecosystem.Speaking at Sebi’s Cyber Defence Symposium, Sebi chairman Tuhin Kanta Pandey said the focus now needs to shift from simply checking whether an organisation is secure to ensuring that the entire financial ecosystem can withstand and recover from cyber incidents.INCIDENT REPORTING PORTAL TO MAKE REPORTING FASTERThe new Incident Reporting Portal will provide market intermediaries with a more structured way to report cybersecurity incidents to Sebi. The reporting system is aligned with the format recommended by the Financial Stability Board. This is expected to make cyber incident reporting more consistent and timely across the securities market.The need for faster reporting has become more important as a cyberattack on one institution can potentially affect others through vendors, technology platforms, third-party service providers and interconnected systems.CYBER SURAKSHA PORTAL TO SHARE CYBER THREAT INFORMATION The second platform, called the Cyber Suraksha Portal, will serve as a central platform for sharing cybersecurity information across the securities market.It will bring together information such as vulnerability alerts, cybersecurity knowledge, policy measures and insights from previous incidents.The aim is to help market participants learn from emerging threats and take preventive action rather than responding only after an attack has happened.SEBI WANTS CONTINUOUS CHECKS FOR VULNERABILITIESPandey said cybersecurity cannot be treated as a periodic compliance exercise.Software, cloud systems, application programming interfaces (APIs) and third-party services are constantly changing. This means vulnerabilities can emerge even after an organisation has completed its regular security checks.He said organisations need to continuously identify vulnerabilities, assess the risks they pose, prioritise them, fix them and then check whether the fixes have worked.The growing use of artificial intelligence is making this even more important. AI can help organisations strengthen their cyber defences, but it can also make cyberattacks faster and more sophisticated.FOCUS SHIFTS FROM CYBERSECURITY TO CYBER RESILIENCEAccording to Pandey, financial institutions should work on the assumption that cyber incidents can happen.The bigger question, therefore, is how quickly an organisation can detect an attack, contain the damage and restore normal operations.He said every institution should have a clear incident response and recovery plan that is regularly tested, rather than simply keeping a plan on paper.Such plans should clearly spell out who will make decisions during an attack, who will isolate affected systems, who will communicate with regulators and other stakeholders, and how essential services will be restored safely.CYBER RESILIENCE NEEDS THE WHOLE FINANCIAL ECOSYSTEMThe Sebi chairman said cyber resilience cannot be achieved by regulators or individual financial institutions working alone.Pandey said regulators, financial institutions, technology companies, market infrastructure institutions, academia and other regulated entities all have a role to play.As financial systems become more connected, a weakness in one part of the ecosystem can quickly become a risk for others. Sebi’s new initiatives are aimed at building a stronger system that can not only prevent cyberattacks but also detect, contain and recover from them when they occur.- EndsPublished By: Jasmine anandPublished On: Aug 18, 2026 12:20 IST

Original Source

Read the full article at Indiatoday →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.