Sebi Implements Two-Pronged Cyber Defence Strategy

The CSR Journal Magazine

The Securities and Exchange Board of India (Sebi) has introduced two new portals to improve the reporting and management of cyber threats in the financial sector. The Incident Reporting Portal and the Cyber Suraksha Portal were launched on 18 August 2026. These initiatives aim to address the escalating complexity of cyberattacks that not only impact individual organisations but also the broader financial ecosystem.

Sebi chairman Tuhin Kanta Pandey emphasised that the approach must transition from merely assessing an organisation’s security measures to ensuring the resilience of the entire financial framework against cyber incidents. This strategic shift is crucial as the threat landscape continues to evolve.

Incident Reporting Portal Streamlines Processes

The newly established Incident Reporting Portal is designed to facilitate a more structured mechanism for market intermediaries to report cybersecurity incidents. It is aligned with the reporting format endorsed by the Financial Stability Board, thereby ensuring consistency and timeliness in cyber incident reporting across the securities market.

Prompt reporting is essential, as a cyberattack on one entity has the potential to affect multiple others through shared vendors, technology platforms, and interconnected systems. This portal aims to mitigate the risks stemming from such interdependencies.

By enabling faster reporting, the Incident Reporting Portal seeks to enhance the overall responsiveness of the financial sector to potential cyber threats, establishing a more proactive rather than reactive posture.

Cyber Suraksha Portal Fosters Information Sharing

The second initiative, the Cyber Suraksha Portal, functions as a centralised hub for sharing essential cybersecurity information across the securities market. It intends to collate data on vulnerability alerts, cybersecurity practices, policy measures, and insights from prior incidents.

This platform is geared towards equipping market participants with the necessary information to pre-emptively tackle emerging threats. By learning from past experiences, entities can adopt preventive measures instead of merely reacting to cyberattacks post-event.

Pandey noted that cybersecurity cannot be treated as a one-time compliance task. With the rapid evolution of software and systems, organisations must continuously identify and address vulnerabilities, making proactive risk management a core component of their cybersecurity practices.

Emphasis on Cyber Resilience Across Ecosystem

Pandey pointed out that financial institutions should operate under the premise that cyber incidents are inevitable. The key challenge now lies in the speed and effectiveness with which an organisation can detect, contain, and recover from such incidents.

Every institution is encouraged to maintain a clear incident response and recovery strategy that is routinely tested. This includes designating decision-makers during an attack, isolating affected systems, communicating with regulators, and ensuring the safe restoration of essential services.

He further highlighted that achieving cyber resilience requires a collaborative effort from all stakeholders involved in the financial ecosystem. Regulators, technology companies, and market infrastructure institutions must work together, as vulnerabilities in one area can pose risks to others.

Long or Short, get news the way you like. No ads. No redirections. Download Newspin and Stay Alert, The CSR Journal Mobile app, for fast, crisp, clean updates!

App Store –  https://apps.apple.com/in/app/newspin/id6746449540 

Google Play Store – https://play.google.com/store/apps/details?id=com.inventifweb.newspin&pcampaignid=web_share

Latest News

Popular Videos