Advertisement
X

Sebi Standardises Cyber Reporting As Market Entities Face Rising Threats

Sebi has aligned its cyber incident reporting portal with the global FIRE format. Existing reporting deadlines remain unchanged, while entities can now submit reports in stages

Market entities are required to report a cyber incident to Sebi within six hours of detecting the incident Photo: Canva, Sebi
Summary
  • Sebi brings global FIRE format to cyber incident reporting

  • Existing six-hour and 24-hour reporting deadlines stay unchanged

  • Meanwhile, Sebi also introduced the Cyber Suraksha Portal

Advertisement

The Securities and Exchange Board of India (Sebi) has aligned its Cyber Incident Reporting Portal with the Financial Stability Board’s (FSB) global FIRE format for reporting cyber incidents.

The move covers a wide range of regulated entities, including stock brokers, stock exchanges, depositories, mutual funds, alternative investment funds (AIFs), credit rating agencies, portfolio managers, investment advisers, custodians and registrar and transfer agents (RTAs).

FIRE, or Format for Incident Reporting Exchange, provides a common set of fields and definitions for reporting cyber incidents. “FIRE enables structured incident reporting by defining common information fields, standardised definitions, and consistent classification of incident attributes, promoting harmonisation across sectors or jurisdictions,” according to Sebi.

Sebi said the new format will help improve the classification of incidents and provide greater clarity on the origin of a cyberattack and the jurisdictions affected.

“With the rapid pace of technological developments in the securities market, the frequency and sophistication of cyber incidents are also on the rise. To proactively address these evolving threats and ensure the security of the securities market ecosystem, prompt reporting of these incidents is crucial to contain the attack, implement mitigation measures and strengthen defences,” said the regulator in its circular dated August 24, 2026.

Advertisement

Reporting Timelines Remain Unchanged

The regulator has not changed the existing reporting timelines under its Cyber Security and Cyber Resilience Framework.

Market entities are required to report a cyber incident to Sebi within six hours of detecting the incident. They are also required to submit the details through the Cyber Incident Reporting Portal within 24 hours, as prescribed under Annexure-O of the framework.

Sebi’s New Cyber Incident Reporting Format

The key change is the way these incidents will now be reported.

Sebi's portal will allow entities to submit information in stages, starting with an initial report, followed by updates as more details become available and a final closure report. This is aimed at addressing situations where the full impact or scope of a cyber incident may not be known when it is first detected.

Where To Report Cyber Incidents

Regulated entities can access the reporting portal at siportal.sebi.gov.in. Sebi has also asked them to make changes to their bye-laws, rules or regulations wherever required to comply with the new reporting format.

Advertisement

Sebi Launches Cyber Suraksha Portal

Meanwhile, Sebi has also introduced the Cyber Suraksha Portal as part of its broader Cyber Security Initiative. The portal can be accessed at cybersuraksha-ai.sebi.gov.in.

“This platform provides a comprehensive, centralized hub for the securities market to share crucial knowledge and disseminate information regarding cybersecurity. Through this portal, market participants can directly access the latest cybersecurity circulars, vulnerability warnings and incident insights,” the regulator said in a press release.

Show comments
Published At: