Blogs

SEBI's Cybersecurity Double Move: A FIRE-Aligned Reporting Portal and a New Cyber Suraksha Hub, Decoded

CS Archana Gupta   |   03 Sep 2026

(4.3)
8 Views

Quick Answer: On August 24, 2026, SEBI made two cybersecurity moves: it aligned its Cyber Incident Reporting Portal with the Financial Stability Board's Format for Incident Reporting Exchange (FIRE), and it launched the Cyber Suraksha Portal, a centralised hub for cybersecurity circulars, vulnerability warnings, and incident insights. The 6-hour email alert and 24-hour portal filing deadlines under the Cybersecurity and Cyber Resilience Framework (CSCRF) do not change- only the fields, classification, and staged-reporting structure do, following FIRE's common taxonomy. This applies to every SEBI-regulated entity covered by CSCRF's Annexure-O incident classification and handling framework.

Last updated: 3 September 2026

What Did SEBI Change on August 24, 2026?

  • Alignment with FIRE framework: SEBI vide Circular HO/(449)2026-ITD-5_DIV1/I/19448/2026 aligns the Cyber Incident Reporting Portal with "Format for Incident Reporting Exchange (FIRE)" Framework, replacing free-form reporting with a structured, internationally consistent taxonomy.
  • Introduction of staged reporting: Incidents are now reported in stages - an initial report, intermediate updates as facts emerge, and a final closure report, instead of one complete submission upfront.
  • Reporting deadlines: Email alert through mkt_incidents@sebi.gov.in within 6 hours and reporting through SEBI Incident Reporting Portal within 24 hours of cyber incident remain exactly as before.
  • Read together with CSCRF: This circular to be read with SEBI guidelines for reporting of cyber incidents under Annexure-O (B: Guidelines on Handling Cybersecurity Incidents) of Cybersecurity and Cyber Resilience (CSCRF) framework.
  • Cyber Suraksha Portal: SEBI vide Press Release No. 51/2026 dated August 24, 2026 launched the Cyber Suraksha Portal, a centralised hub for the securities market to share crucial knowledge and disseminate information regarding cyber security. Through this portal, market participants can directly access the latest cybersecurity circulars, vulnerability warnings and incident insights. Cyber Suraksha Portal can be accessed at cybersuraksha-ai.sebi.gov.in

Which Entities Must Comply?

  • Alternative Investment Funds (AIFs), Bankers to an Issue (BTI) and Self-Certified Syndicate Banks (SCSBs), Clearing Corporations, Collective Investment Schemes, Credit Rating Agencies, Custodians, Debenture Trustees, Depositories, Designated Depository Participants, Depository Participants through Depositories.
  • Investment Advisers, Research Analysts, KYC Registration Agencies, Merchant Bankers, Mutual Funds/ Asset Management Companies (AMCs), Portfolio Managers, Registrar to an Issue and Share Transfer Agents (RTAs).
  • Stock Brokers through Exchanges, Stock Exchanges, and Venture Capital Funds.
  • BSE Limited (Research Analysts Administration and supervisory body-RAASB)

How Are Cybersecurity Incidents Classified by Severity?

Severity Classification of cybersecurity incidents as per Annexure-O of Cybersecurity and Cyber Resilience (CSCRF) framework.

Severity Illustrative Triggers What It Typically Means
Low System probes/scans on external systems; threat intelligence about vulnerabilities and username password compromise; isolated malware caught by antivirus etc. No real operational impact; routine monitoring and hygiene response
Medium Recon/scans detected; attempted penetration or Denial of Service attacks with no impact on operations; known malwares handled by antivirus software; new malware not caught by antivirus software; phishing emails not recognized by employees and clicked by them; data corruption, modification and deletion etc. Contained but noteworthy; requires investigation and staff awareness follow-up
High Penetration or Denial of Service attacks with limited impact on operations; new malwares not handled by anti-virus software; unauthorized access to servers and network devices; unauthorized or unexpected configuration changes on network devices; impersonation of SEBI officials in email communications; data exfiltration; high count of phishing emails; outbound phishing emails; some risk of negative financial or public relations impact etc. and includes cyber incident resulting in disruption, stoppage or variance in the normal functions/operations of entity systems Real exposure with some operational or reputational risk; escalation warranted
Critical Successful penetration or Denial of Service attacks with significant impact on operations; ransomware attack; exfiltration of market-sensitive data; widespread data corruption affecting operations; significant risk of negative financial or public relations impact etc. and includes cyber incident resulting in disruption, stoppage or variance in the normal functions/operations of entity systems Severe impact on operations, investors, or market integrity; highest-priority response

What Are the Cyber Incident Reporting Deadlines?

Report / Activity Deadline from Date of Reporting
Email alert to SEBI (mkt_incidents@sebi.gov.in) and, where applicable, to CERT-In / Exchanges / Depositories Within 6 hours of noticing or being made aware of the incident
Filing on SEBI's Cyber Incident Reporting Portal (siportal.sebi.gov.in), now in FIRE-aligned fields Within 24 hours
Interim report (nature, time of occurrence, affected systems, severity, initial response steps) 3 days
Mitigation measures update 7 days
Root Cause Analysis (RCA) report 30 days (case-by-case extension possible)
Forensic audit report and closure report (where applicable) Up to 75 days (maximum)
Vulnerability Assessment and Penetration Testing (VAPT) report and closure report (where applicable) 45 days

What Are the Compliance Risks of Getting This Wrong?

  • Non-adherence to the reporting Standard Operating Procedure (SOP): Regulatory action under the extant framework applicable to the entity.
  • Every downstream report is independently tracked: Each has its own deadline and its own consequence for delay or inaccuracy - interim, mitigation, RCA, forensic, VAPT.

Failure to implement High Powered Steering Committee on Cyber Security (HPSC-CS)/SEBI recommendations on time: Regulatory action, independent of any penalty already levied for the original incident.

What Should Regulated Entities Do Now?

  • Map your category: Reconfirm your CSCRF entity category and applicable thresholds, to determine applicability of Annexure-O provisions and audit periodicity's.
  • Refresh your SOPs: Update your Cyber Crisis Management Plan and incident response SOP for FIRE-aligned portal fields and staged reporting.
  • Pre-build classification templates: Make sure your Chief Information Security Officer (CISO)/Information Technology (IT) team classify an incident against the Low/ Medium/ High/ Critical matrix within minutes of detection.
  • Centralise your reporting calendar: Track the 6-hour, 24-hour, 3-day, 7-day, 30-day, 45-day, and 75-day windows on incident becoming live.
  • Institutionalise internal review: No Root Cause Analysis, forensic, or Vulnerability Assessment and Penetration Testing (VAPT) report to reach SEBI without sign-off from IT Committee of Regulated Entity's.
  • Align third-party contracts: Vendor contracts to reflect the same reporting timelines and FIRE-aligned data fields in case of outsource of SOC or IT services.
  • Monitor the new intelligence channel: Monitor Cyber Suraksha Portal for vulnerability warnings relevant to the systems.

How Does LexComply's Global Compliance Tool Help?

  • Multi-jurisdiction, centralised due-date tracking: Reflects SEBI's 6-hour, 24-hour, 3-day, 7-day, 30-day, 45-day, and 75-day reporting windows automatically once an incident is logged, across India and other jurisdictions of operation.
  • Real-time managing of regulatory updates: Our regulatory research team tracks notifications like this FIRE-alignment circular and pushes updated requirements into the obligations register as soon as they are issued.
  • Automated alerts and escalations: Automated reminders to the right owner- CISO, compliance officer, IT Committee - before each deadline, with escalation if a task is at risk.
  • Entity, category, and incident-wise mapping: Every incident, its classification, and its downstream reports tracked, against the specific SEBI category and audit periodicity, applicable to the entity.
  • Audit-ready documentation: A time-stamped, audit-ready record of every submission and internal sign-off, ready for SEBI, CERT-In, or the Board of the entity.
  • Consolidated, group-wide reporting: Compliance status across SEBI, CERT-In, and other regulators rolled into a single dashboard for management visibility.

Frequently Asked Questions

Does the FIRE alignment change SEBI's 6-hour and 24-hour reporting deadlines?

No. The deadlines are unchanged - email alert within 6 hours, portal filing within 24 hours. What changes is the structure and fields used to report the incident, now aligned to FIRE's common taxonomy, and the introduction of staged reporting (initial, intermediate, closure).

What is the FIRE format?

FIRE - Format for Incident Reporting Exchange is a common reporting format finalised by the Financial Stability Board in April 2025. It standardises information fields, definitions, and classification for operational and cyber incident reporting so that regulators and firms across sectors and jurisdictions can exchange incident data consistently.

What is the Cyber Suraksha Portal, and how is it different from the Incident Reporting Portal?

The Cyber Suraksha Portal, launched on August 24, 2026, is a centralised hub for cybersecurity circulars, vulnerability warnings, and incident insights for the market to consume. The Cyber Incident Reporting Portal is the separate channel through which regulated entities report their own incidents to SEBI.

Which entities must use SEBI's Cyber Incident Reporting Portal?

All SEBI-regulated entities covered by the Cybersecurity and Cyber Resilience (CSCRF) Framework including AIFs, stock brokers, depositories, mutual funds, merchant bankers, investment advisers, research analysts, KYC Registration Agencies, and Market Infrastructure Institutions along with the administration and supervisory bodies for Investment Adviser (IAs) and Research Analyst (RAs).

What happens if a Root Cause Analysis report is late or inaccurate?

SEBI may treat it as deficient and grant up to 15 additional days for correction. If the entity still fails to submit an accurate and complete report, appropriate regulatory action may follow, over and above any action for the original incident.

Relevant Notifications and References

Final Word

  • Incident reporting now speaks the same structured language, regulators expect globally (FIRE).
  • Severity classification and cascading interim, RCA, forensic, and VAPT deadlines leave very little room for an ad hoc response.
  • Entities that build the classification and reporting workflow into their compliance calendar now will be the ones ready when the next incident- (not if), but when- (arrives).

To map SEBI's cascading incident-reporting windows against the entities that actually hold them, talk to the LexComply team.

Legal Disclaimer: This article is for general information and reflects the circulars and press release referred to as at 3 September 2026. It does not constitute legal advice. Confirm the obligations and timelines applicable to your organisation with a qualified adviser.