SEBI Chairman Urges Board-Level Cyber Resilience for Indian Markets
SEBI Chairman Tuhin Kanta Pandey has called for a fundamental reorientation of cybersecurity strategies within India’s financial sector, advocating that cyber resilience become a primary focus for corporate boards rather than a technical departmental responsibility.
SEBI Chairman’s Call for Cyber Resilience
During the opening session of SEBI’s five-day Symposium on Cyber Defence in Mumbai, the regulator highlighted the urgent need for executive leadership to address evolving cyber threats. The statement underscores that the critical question for financial institutions is no longer whether a cyberattack will occur, but how swiftly they can identify, contain, and recover from such incidents.
Board-Level Accountability and Risk Management
The regulatory emphasis on board-level accountability follows a period of heightened scrutiny on financial infrastructure, as rapid digitization has expanded vulnerabilities across stock exchanges, depositories, and asset management firms. Recent enforcement actions by regulators have demonstrated a growing expectation for systemic institutions to address operational weaknesses and delayed response mechanisms.
Key Directives for Financial Institutions
Under the new framework, corporate boards are required to move beyond passive compliance reviews and instead actively manage risk-based patching schedules, continuous vulnerability assessments, and validated disaster recovery systems. Directors must now evaluate cyber risks with the same level of scrutiny applied to financial stability, capital planning, and business expansion strategies.
Centralized Digital Platforms for Threat Intelligence
SEBI introduced two centralized digital platforms to enhance threat intelligence sharing and incident response coordination. The SEBI Incident Reporting Portal establishes standardized reporting protocols aligned with global formats, streamlining cross-border collaboration and reducing delays in incident communication. The Cyber Suraksha Portal serves as a centralized hub for distributing real-time vulnerability alerts, threat analyses, and regulatory guidelines.
Addressing Information Silos
These tools are designed to dismantle information silos that have historically allowed cybercriminals to exploit multiple entities within the financial ecosystem. Smaller market participants, often lacking dedicated threat intelligence resources, will gain access to real-time advisories generated by centralized monitoring systems.
Addressing Quantum Computing Threats
SEBI also addressed long-term technological challenges, particularly the threat posed by quantum computing to existing cryptographic systems. As quantum processing capabilities advance, conventional encryption methods used to secure financial transactions and investor data may become obsolete. Financial institutions were advised to initiate planning for post-quantum cryptographic solutions to mitigate future risks.
Cyber Range Simulations and Global Collaboration
The symposium, which included participation from domestic market players and international representatives across 15 jurisdictions, featured live simulations on a Cyber Range platform to test organizational preparedness under realistic attack scenarios. By integrating board-level oversight with standardized reporting mechanisms and forward-looking encryption standards, SEBI aims to strengthen India’s financial markets against systemic cyber threats.
Conclusion
As digital transaction volumes and online onboarding grow, the resilience of the nation’s capital markets will increasingly depend on the ability of corporate boards to transform cybersecurity into a proactive operational priority.
