THE POLICY EDGE
Policy Bites

17 August 2026

SEBI Launches Cyber Reporting and Threat-Sharing Portals for Securities Market

SEBI has launched two platforms to improve cyber coordination across India’s securities market. The regulator is also signalling that regulated entities should move beyond periodic security audits towards continuous vulnerability management, tested recovery plans and preparation for quantum-era risks

Listen to the article
Policy Bites image

Key Details

In an address at the SEBI Symposium on Cyber Defence, Chairman Tuhin Kanta Pandey combined two immediate institutional initiatives with a broader statement of regulatory direction.

Area

Development

Incident reporting

The revamped SEBI Incident Reporting Portal is intended to make cyber reporting more structured, timely and actionable

International alignment

The reporting portal is aligned with the Financial Stability Board’s FIRE format

Threat intelligence

The new Cyber Suraksha Portal will share vulnerability warnings, incident insights, policy measures and cybersecurity knowledge

Vulnerability management

SEBI wants regulated entities to replace periodic checking with a continuous cycle of discovery, assessment, remediation and validation

Emerging risks

The regulator considers migration towards post-quantum cryptography a present preparedness requirement rather than a future research issue


Two Portals Address Different Cybersecurity Gaps

The revamped Incident Reporting Portal will standardise information submitted after cyber incidents, helping SEBI assess affected systems, wider market exposure and response requirements. Alignment with the Financial Stability Board’s (FSB) Format for Incident Reporting Exchange could also improve consistency with international reporting.

The Cyber Suraksha Portal instead serves as a knowledge-sharing hub covering:

  • vulnerability alerts;

  • lessons from cyber incidents;

  • regulatory and policy measures; and

  • cybersecurity guidance.

The speech does not specify portal access, changes to reporting requirements or detailed operating timelines.


Cybersecurity Moves Towards Continuous Resilience

SEBI is seeking a shift from periodic cybersecurity checks towards continuous identification and remediation of vulnerabilities.

The envisaged cycle is:

Discover → Assess → Prioritise → Remediate → Validate

This includes faster patching of critical vulnerabilities and verification that fixes have worked. Incident-response plans must also be tested in practice, with clear responsibility for isolating affected systems, regulatory reporting, stakeholder communication and service restoration.


Third-Party Risk Becomes a Market-Wide Concern

Securities-market institutions increasingly depend on shared technology providers and interconnected infrastructure. A vulnerability affecting one vendor or institution can therefore disrupt multiple market participants.

SEBI consequently treats cyber resilience as a market-integrity and business-continuity issue, requiring boards and senior management to understand critical dependencies and test recovery arrangements rather than leaving cybersecurity solely to technology teams.


Quantum Readiness Enters the Cybersecurity Agenda

SEBI has also identified quantum resilience as a strategic priority, aligned with the National Quantum Mission. One concern is that encrypted information stolen today could potentially be decrypted once sufficiently capable quantum computers become available.

Institutions are being encouraged to identify vulnerable cryptographic systems and third-party dependencies, estimate migration requirements and develop crypto-agility — the ability to change encryption methods without redesigning entire systems.

This establishes a preparedness direction, not a mandatory migration timetable.


What Is the FSB?

The Financial Stability Board (FSB) is an international body that coordinates financial-sector regulation and promotes global financial stability. Its members include central banks, finance ministries and financial regulators from major economies, including India.


Policy Relevance

  • Common reporting can improve systemic visibility. Standardised incident information should help SEBI assess whether an attack is confined to one entity or threatens connected market infrastructure.

  • Information-sharing must be timely and protected. The usefulness of the Cyber Suraksha Portal will depend on participation, data quality and safeguards for sensitive vulnerability information.

  • Smaller intermediaries may face capacity constraints. Continuous monitoring, automated patching and recovery testing require skills and investment that smaller regulated entities may find difficult to sustain.

  • Vendor oversight needs greater attention. Cyber requirements should extend beyond regulated entities’ own systems to cloud providers, software suppliers and other critical third parties.

  • Quantum migration requires an inventory before a deadline. Mapping cryptographic dependencies and replacement cycles would provide the foundation for future enforceable standards.


Relevant Question for Policy Stakeholders: How can SEBI convert faster incident reporting and shared threat intelligence into collective resilience without discouraging institutions from disclosing vulnerabilities promptly?


Follow the Full Address Here: The SEBI Chairman’s address at the Symposium on Cyber Defence

Rethinking Public Policy Through Insight | Inquiry | Impact

Opinion • Grassroots Voices • Policymakers Perspectives • Expert Analysis • Policy Briefs