Economy
SEBI Chief Urges Collective Cyber Resilience as Financial Threats Become More Sophisticated

India’s financial sector needs to move away from relying mainly on periodic cybersecurity compliance checks and instead adopt a continuous, risk-based approach to cyber resilience, SEBI Chairman Tuhin Kanta Pandey said on Monday. Speaking at SEBI’s Symposium on Cyber Defence in Mumbai, which is being held from August 17 to 21, Pandey said the nature of cyber threats is changing rapidly, making it increasingly important for financial institutions to be prepared for attacks at any time. He said the focus should no longer simply be on preventing an attack, but on how quickly an organisation can identify a breach, contain its impact, restore operations and learn from the incident.
The symposium has brought together participants from India as well as international delegates representing 15 IOSCO jurisdictions. Financial regulators, market participants, technology institutions and academic experts are also taking part in the event. The programme includes classroom sessions, tabletop exercises involving simulated scenarios and real-time cyberattack simulations through a Cyber Range platform.
Pandey encouraged participants to use these exercises as an opportunity to test their preparedness under pressure and uncover weaknesses that may not become visible during routine assessments. He stressed that effective cyber resilience depends on cooperation across the broader financial ecosystem rather than the efforts of individual organisations alone.
“Cyber resilience that we see today is the outcome of efforts across a much wider ecosystem,” Pandey said, highlighting the contributions of regulators, financial institutions, technology organisations and academia. At the opening ceremony, SEBI introduced two new portals intended to improve cybersecurity coordination and information sharing across the securities market. The SEBI Incident Reporting Portal has been developed to make cyber-incident reporting more structured, timely and actionable. It also follows the CIFI format, which is intended to bring greater consistency to incident reporting and make cross-border coordination easier.
The regulator also launched the Cyber Suraksha Portal as a central platform for sharing cybersecurity information. It will provide access to knowledge resources, vulnerability alerts, policy developments and insights from cyber incidents, helping participants across the securities ecosystem stay informed about emerging risks.
Pandey also called for a rethink of conventional vulnerability and patch-management practices. With new weaknesses constantly emerging in software, cloud systems, APIs and third-party technology, he said periodic assessments are no longer sufficient. Instead, organisations need a continuous process of identifying vulnerabilities, assessing their risks, prioritising them, fixing them and verifying that the fixes have worked. Intelligent and increasingly automated patch-management systems could play an important role in this process.
The SEBI chairman further highlighted the cybersecurity risks that could emerge from advances in quantum computing. He said financial institutions should begin treating post-quantum cryptography as an immediate migration challenge rather than a distant research issue. Organisations need to identify systems that could eventually be exposed to quantum attacks, understand their technology dependencies and develop “crypto-agility”, allowing them to change encryption methods without having to rebuild their entire technology infrastructure.
Pandey also stressed that cybersecurity can no longer be viewed solely as an information technology issue. A serious cyber incident can affect business continuity, market stability and investor confidence, making cyber resilience an important responsibility for company boards and senior management. He concluded by outlining three principles for strengthening cyber defence: “Co-operate, Prepare, Respond.” His message underlined the need for financial institutions to continuously improve their capabilities, share information and develop a collective ability to withstand and recover from increasingly sophisticated cyber threats.



