Why in the News
The Securities and Exchange Board of India (SEBI) has introduced an IT Resilience Index for Market Infrastructure Institutions, converting cyber preparedness into a periodically computed score rather than a one time compliance certificate. The same circular aligns the regulator’s cyber incident reporting portal for regulated entities with a standardised Format for Incident Reporting Exchange (FIRE), a common template that lets an incident be reported in stages as it unfolds. This follows the Reserve Bank of India (RBI) framework for banks and financial institutions issued last month, which mandates board level oversight, a dedicated information technology risk committee and a six hour window to report a cyber incident. Both regulators are responding to artificial intelligence lowering the cost of committing fraud at scale, including deepfake voices used to bypass Know Your Customer (KYC) verification. The tension is that resilience is now scored by the institution being scored, on a six monthly cycle, against threats that move in hours.
What is the IT Resilience Index?
- What it covers: It quantifies the information technology readiness of Market Infrastructure Institutions, meaning the stock exchanges, clearing corporations and depositories through which trading and settlement actually happen.
- The nine parameters: Availability and security carry a weight of 20 per cent each, and integrity, governance, reliability and monitoring, modularity and flexibility, and business continuity carry 10 per cent each. Scalability and a residual “others” parameter carry 5 per cent each.
- The reporting cycle: Each institution computes the index half yearly and files it within 60 days of the end of each half year. The filing carries a comparative analysis of two consecutive half years on a rolling basis together with the corrective action taken.
- When it applies: The framework takes effect from early 2027 and carries an early warning system with continuous monitoring to flag risks before they mature.
Why is cyber readiness being converted into a score?
- The stated risk: Disruption, degraded performance or compromise of these systems can hit critical market operations and damage trust in the securities market itself.
- A score reaches the board: Resilience expressed as a number can be measured and benchmarked, which moves it from the technology function into boardroom accountability.
- Direction matters more than a snapshot: A comparative filing across two consecutive half years shows whether an institution is improving or slipping, which a point in time audit cannot establish.
How is incident reporting being standardised?
- One template across regulated entities: The reporting portal now follows the FIRE format, so incidents arrive in a comparable structure rather than in each entity’s own narrative.
- Reporting follows the incident life cycle: The format carries initial reporting, intermediate updates and a final closure, and it accepts that some information will not be available at the first report.
- Two regulators, two clocks: The banking regulator fixes a hard outer deadline for reporting by banks, and the market regulator fixes a staged format for its own regulated entities.
How is artificial intelligence changing both the threat and the response?
- Fraud now scales cheaply: Synthetic voice is being used to defeat customer verification, and complex scams are being run against critical financial services institutions rather than only against individuals.
- Breaches have already landed: Cybersecurity threats infiltrated a number of banks during 2026.
- Guidelines are pending: The market regulator has said it will shortly issue guidelines for the responsible use of artificial intelligence and machine learning.
- The regulator is also a user: Artificial intelligence models already flag suspicious trading patterns, and a team has been constituted to build models covering corporate investigations, extending surveillance from trade data to filed quarterly results.
Why is the response shifting into the account holder’s own hands?
- The killswitch idea: The banking regulator has flagged a mechanism allowing a user to freeze all financial transactions in their accounts during an ongoing fraud.
- The securities market is examining the same tool: The market regulator is evaluating a comparable mechanism as part of its artificial intelligence guidelines.
- Compensation was widened first: In June the banking regulator revised its fraud compensation mechanism, enlarging the set of victims who can claim and bringing newer digital scams into the definition of fraud.
Challenges to the IT Resilience Index
- The score is self computed: An institution scores its own controls and files the result, so a weak control can be scored generously without an independent check. Eg. Lapses in access and system controls at a Market Infrastructure Institution surfaced in the co-location proceedings against the National Stock Exchange, not through its own reporting. Fix. Require third party assurance of the score before it is filed, in the same way financial statements are audited.
- A half yearly cadence cannot track a live intrusion: An index computed twice a year describes a posture, not an event that unfolds within a trading session. Eg. The National Stock Exchange outage of February 2021 halted cash and derivatives trading for close to four hours. Fix. Pair the half yearly score with a continuous telemetry feed to the regulator’s monitoring desk.
- The riskiest dependencies sit outside the perimeter: Cloud providers, data centres and software vendors are shared across institutions, and their failure is not captured by any single institution’s score. Eg. The CrowdStrike update failure of July 2024 disabled Windows systems at banks and airlines across several countries at once. Fix. Score vendor and cloud concentration explicitly, and require a tested failover to an alternative provider.
- Disclosure competes with reputation: An institution’s first instinct in a breach is containment, and a reporting clock runs against that instinct. Eg. The 2016 malware compromise of a payment switch led to about 32 lakh debit cards being recalled, and it surfaced weeks after the breach began. Fix. Make timeliness and completeness of incident reporting a scored parameter, so silence costs the institution its index.
Conclusion
Financial sector cyber regulation has moved from prescribing controls to scoring them, on the reasoning that a number travels to a board in a way an audit finding does not. The unresolved question is whether a score computed by the entity being scored will change behaviour or only documentation. Two markers settle it: the first comparative filings once the index takes effect, and the content of the artificial intelligence guidelines the market regulator has said are coming.
“[2022, GS3, 10 marks] What are the different elements of cyber security? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy.”

