📷 Image: Wikimedia Commons / Brajesh Ohdar
Business
SEBI mandates uniform cyber‑incident reporting for market participants
✍️ Outlook Money
🗓 26 Aug 2026, 07:19 AM
👁 5
The Securities and Exchange Board of India has introduced a standardized framework for reporting cyber incidents, aiming to strengthen resilience across stock exchanges and intermediaries.
SEBI announced new guidelines that require listed companies, brokers, depositories and other market participants to follow a uniform protocol for reporting cyber incidents. The regulator said the framework will help create a consolidated view of threats across the securities market.
The directive comes as cyber attacks on financial institutions have risen sharply, exposing weaknesses in trading platforms and data infrastructures. Recent breaches have underscored the need for quicker disclosure and coordinated response.
Under the new rules, entities must inform SEBI within a prescribed time‑frame after detecting a breach, submit detailed technical information and cooperate fully with investigations. Failure to comply could attract regulatory penalties.
SEBI also urged market players to bolster their cybersecurity posture by conducting regular risk assessments, maintaining dedicated incident‑response teams and adopting best‑practice safeguards.
The regulator believes that standardized reporting will enable better monitoring, faster remedial action and collective learning, thereby reducing the overall cyber risk to India’s capital markets.
The directive comes as cyber attacks on financial institutions have risen sharply, exposing weaknesses in trading platforms and data infrastructures. Recent breaches have underscored the need for quicker disclosure and coordinated response.
Under the new rules, entities must inform SEBI within a prescribed time‑frame after detecting a breach, submit detailed technical information and cooperate fully with investigations. Failure to comply could attract regulatory penalties.
SEBI also urged market players to bolster their cybersecurity posture by conducting regular risk assessments, maintaining dedicated incident‑response teams and adopting best‑practice safeguards.
The regulator believes that standardized reporting will enable better monitoring, faster remedial action and collective learning, thereby reducing the overall cyber risk to India’s capital markets.