SEBI Mandates Critical Cyber Reporting Alignment: Regulated Entities Must Adopt New FIRE Format

SEBI Mandates Critical Cyber Reporting Alignment: Regulated Entities Must Adopt New FIRE Format

SEBI Mandates Critical Cyber Reporting Alignment: Regulated Entities Must Adopt New FIRE Format​

Regulatory Overhaul: SEBI Aligns Incident Portal with Global FSB Standards​

The Securities and Exchange Board of India (SEBI) has introduced a critical regulatory mandate requiring all regulated entities to align their cyber incident reporting procedures with the 'Format for Incident Reporting Exchange' (FIRE) framework. This move is part of a proactive strategy by SEBI to fortify the resilience and security of the entire securities market ecosystem against escalating digital threats.

The initiative formalizes a highly structured method for reporting incidents, ensuring that all relevant data—from initial detection to final resolution—is captured consistently across different financial sectors. By adopting the FIRE standard, which was developed by the Financial Stability Board (FSB), SEBI is driving sector-wide harmonization in cybersecurity incident management.

Strict Reporting Deadlines and Mechanisms Detailed​

To address the increasing sophistication of cyber attacks, SEBI has reinforced existing guidelines under the CSCRF framework regarding incident reporting. All regulated entities must now report any detected cyber incidents through two specific channels within strict timelines.

The immediate response mechanism requires reporting to be submitted via email (mkt\_incidents@sebi.gov.in) within six hours of detection. Following this initial report, comprehensive information must then be lodged on the SEBI's dedicated Incident Reporting Portal within 24 hours.

Regulated Entities (REs), including Mutual Funds (MFs), Asset Management Companies (AMCs), Stock Brokers, and AIFs, are required to utilize the designated platform, accessible at https://siportal.sebi.gov.in. This dual-layer reporting mechanism ensures prompt containment efforts can be initiated across the industry.

Importance of FIRE Format for Market Resilience​

The shift to the FIRE format represents a significant enhancement in how cybersecurity incidents are managed and tracked within the Indian financial market. The new framework mandates standardized definitions, common information fields, and consistent classification of incident attributes.

This standardization means that regulatory bodies can gain clearer insights into the nature and geographical extent of cyber threats being faced by various entities. It facilitates structured reporting across different sectors or jurisdictions, allowing for better overall defense preparedness nationally.

The portal is designed to facilitate reporting in stages, accommodating the reality that not all information will be available at the precise moment an incident is first detected. Entities must continue sharing updates until the matter is fully resolved, reflecting the dynamic nature of cyber threats.

Compliance Mandate and Future Obligations​

All Regulated Entities are strongly advised to immediately implement the provisions set forth in this circular by making necessary amendments to their existing bye-laws, rules, and internal regulations. Failure to comply could impact regulatory standing across various categories, including Clearing Corporations, Custodians, and Portfolio Managers.

SEBI emphasizes that this circular must be read in conjunction with all other applicable SEBI guidelines concerning cybersecurity and cyber resilience. The mandate is a reflection of the board's commitment under Section 11 (1) of the Securities and Exchange Board of India Act, 1992, to protect investor interests and promote market development.
 

Disclaimer: Due care and diligence have been taken in compiling and presenting news and market-related content. However, errors or omissions may arise despite such efforts.

The information provided is for general informational purposes only and does not constitute investment advice, a recommendation, or an offer to buy or sell any securities. Readers are advised to rely on their own assessment and judgment and consult appropriate financial advisers, if required, before taking any investment-related decisions.

Any views, opinions, or statements expressed, where applicable, are those of the respective analysts or experts and do not reflect the views of this website. The website has no association with such viewpoints and does not assume any responsibility for them.

Last edited by a moderator:
Back
Top