Monday, August 24


The Securities and Exchange Board of India (SEBI) has introduced two measures to strengthen the resilience of the securities market’s technology infrastructure, requiring market infrastructure institutions (MIIs) to adopt a system-driven IT Resilience Index (ITRI) and aligning its cyber incident reporting portal with the Financial Stability Board’s (FSB) Format for Incident Reporting Exchange (FIRE) framework.

The measures, issued through separate circulars on August 24, are aimed at improving early detection of technology risks, strengthening monitoring of critical systems and bringing greater standardisation to the reporting of cyber incidents across the securities market ecosystem.

IT Resilience Index for MIIs

Under the ITRI framework, stock exchanges, clearing corporations and depositories will be required to assess the resilience of their critical IT systems through a composite index covering nine parameters.

The index will assign the highest weightage to availability and security, at 20% each, followed by integrity, governance, reliability and monitoring, business continuity, and modularity and flexibility at 10% each. Scalability and other parameters, including incident handling, will carry 5% each.

SEBI said the index is intended to provide a mechanism for monitoring the resilience of MII IT systems, identifying emerging weaknesses at an early stage and initiating corrective measures. The framework covers critical systems as defined under SEBI’s existing master circulars, as well as other systems feeding into or related to those critical systems.

The Industry Standards Forum (ISF) of MIIs will finalise the sub-parameters and detailed measurement criteria for the nine parameters by November 30, 2026. It will also establish baseline parameters, acceptable threshold scores and a standard operating procedure for calculating the index, with the objective of enabling comparability across MIIs.

A key feature of the framework is that the ITRI calculation will have to be system-driven and automated, without manual intervention. Where a parameter cannot be automatically computed, manual data retrieval can be undertaken only after prior discussion with the MII’s Standing Committee on Technology.

MIIs will calculate the index every half-year, within 60 days of the end of each half-year, and submit a rolling comparison of two consecutive half-years along with corrective actions taken or proposed to their Standing Committee on Technology and governing board.

SEBI has also mandated MIIs to develop an Early Warning System based on the ITRI to identify deterioration in individual parameters that could lead to performance issues or system slowness.

The regulator is further requiring MIIs to build systems providing continuous visibility into service delivery to market participants. These systems are expected to include consolidated dashboards for monitoring system and application performance, service delivery and deviations or anomalies. MIIs will also have to formulate SOPs to monitor system availability and continuity of services and flag disruptions.

MIIs have already implemented a beta version of the ITRI framework. The full framework, including the Early Warning System and real-time monitoring of service delivery, is to be operationalised by February 28, 2027. The first ITRI submission will cover the half-year ending March 31, 2027.

Cyber incident reporting aligned with global FIRE framework

Separately, SEBI has aligned its Cyber Incident Reporting Portal with the FIRE framework developed by the FSB, introducing a more structured approach to reporting cyber incidents by regulated entities.

SEBI said the frequency and sophistication of cyber incidents have been increasing alongside technological development in the securities market, making prompt reporting critical for containing attacks, implementing mitigation measures and strengthening defences.

Existing SEBI requirements require regulated entities to report cyber incidents to SEBI through the prescribed email channel within six hours and through the Incident Reporting Portal within 24 hours.

The revised portal will use the FIRE format, which establishes common information fields, standardised definitions and consistent classification of incident attributes. According to SEBI, this is intended to promote harmonisation across sectors and jurisdictions and improve the quality and comparability of cyber incident data.

Importantly, reporting will now follow the life cycle of a cyber incident, rather than being limited to the initial disclosure. Regulated entities will provide an initial report when an incident is detected, followed by updates as the situation develops and a final report once the incident is closed.

The requirement applies across SEBI’s regulated ecosystem, including entities such as alternative investment funds, clearing corporations, mutual funds and asset management companies, custodians, depositories, merchant bankers, portfolio managers, stock brokers and stock exchanges.

  • Published On Aug 24, 2026 at 07:05 PM IST

Join the community of 2M+ industry professionals.

Subscribe to Newsletter to get latest insights & analysis in your inbox.

All about ETLegalWorld industry right on your smartphone!




Source link

Share.
Leave A Reply

Exit mobile version