SEBI’s latest cybersecurity reporting reform is not about giving market intermediaries more time to report cyber incidents. It is about fundamentally changing how those incidents are recorded, classified, and tracked from the moment of detection through to final resolution.
On August 24, 2026, the Securities and Exchange Board of India (SEBI) aligned its Cyber Incident Reporting Portal with the Financial Stability Board’s Format for Incident Reporting Exchange, globally known as FIRE. This transition brings a highly standardised, internationally structure
.SEBI's latest cybersecurity reporting reform fundamentally shifts how market intermediaries handle cyber incidents. Introduced on August 24, 2026, through Circular No. HO/(449)2026-ITD-5_DIV1/I/19448/2026, the Securities and Exchange Board of India aligned its Cyber Incident Reporting Portal with the Financial Stability Board Format for Incident Reporting Exchange, commonly known as FIRE.
This alignment integrates a standardized international reporting structure into India's securities market. For regulated entities like stock brokers, depository participants, asset management companies, registrars and transfer agents, portfolio managers, and alternative investment funds, this means cyber incident reporting is no longer a one-and-done notification. It is now a dynamic, lifecycle-based process.
Understanding the FSB FIRE Framework and SEBI Integration
The FIRE framework was developed by the Financial Stability Board and finalized in April 2025 to solve a global financial sector problem: fragmented incident reporting. Previously, institutions reported similar incidents to different authorities using conflicting terminology, making it difficult to assess systemic risks. FIRE introduces common data elements and standardized terminology to streamline this process.
It is crucial to understand that SEBI adoption of FIRE does not replace its existing Cyber Security and Cyber Resilience Framework (CSCRF). The CSCRF remains the overarching regulatory framework governing cybersecurity. Annexure-O of the CSCRF continues to dictate what constitutes a reportable cyber incident. The FIRE framework simply upgrades the structural mechanism through which these incidents are reported to SEBI portal. Purely administrative failures or non-cyber physical disruptions do not become reportable cyber incidents just because SEBI adopted FIRE.
Reporting Deadlines: SEBI versus CERT-In
A major compliance misconception is that the FIRE alignment alters existing regulatory deadlines. It does not. SEBI existing timeline requirements, including the 24-hour reporting window under the portal framework, remain active.
Furthermore, CERT-In April 2022 Cyber Security Directions independently mandate that covered entities report specified cyber incidents within six hours of detection. SEBI CSCRF aligns with this for severe incidents. Regulated entities must evaluate an incident against both Annexure-O and CERT-In directions, recognizing that reporting to SEBI does not automatically satisfy CERT-In obligations, nor does one filing cover obligations to stock exchanges, depositories, or the NCIIPC. Firms must manage parallel notifications based on the specific incident severity.
The practical takeaway is that an entity must not delay an initial regulatory notification simply because its internal forensic investigation is incomplete.
The Incident Reporting Lifecycle
The most significant operational change introduced by the FIRE-aligned portal is lifecycle reporting. An organization is no longer expected to have all the answers at the time of the initial breach notification. The reporting process now develops along a logical curve: Detection, Initial Report, Investigation, Updates, Resolution, and Closure.

The Initial Report
When a breach is detected, the initial report should capture immediately available facts. This includes the time of detection, suspected affected systems, the preliminary nature of the incident, immediate containment measures taken, and whether third parties or customers might be impacted. Uncertainty regarding the exact attack vector or total data exposed should not delay this initial filing.
Intermediate Updates
Cyber investigations are rarely linear. An incident initially classified as a minor system outage might escalate into a major data exfiltration event. The FIRE portal allows intermediaries to submit intermediate updates as forensic teams uncover new facts regarding compromised accounts, attack techniques, financial impact, and remediation efforts. This ensures the regulatory record evolves alongside the ground reality.
Closure
The final closure report represents the organization mature understanding of the event. It documents the confirmed root cause, total affected services, final financial and operational impact, successful recovery actions, and the patching of exploited vulnerabilities. This creates a comprehensive, auditable record from start to finish.
Impact on Market Intermediaries
Because India securities market relies on highly interconnected digital infrastructure, a single vulnerability can cascade across multiple institutions. The FIRE framework impacts different intermediaries in specific ways.
Stock Brokers and Depository Participants
Brokerage systems connect trading platforms, APIs, payment gateways, and order management systems. If API credentials are compromised, a broker initial report might only state that suspicious activity was detected and blocked. Subsequent lifecycle updates will clarify which client accounts were accessed and if unauthorized trades were attempted. Brokers and DPs must also integrate their applicable stock exchange and depository reporting obligations into this response chain, ensuring escalation reaches all relevant market infrastructure institutions promptly.

Asset Management Companies (AMCs) and RTAs
AMCs operate within a complex ecosystem reliant on third-party vendors, making vendor risk management critical. If a Registrar and Transfer Agent experiences a breach affecting investor records, the RTA, as a SEBI-regulated entity, has its own independent obligation to report the incident. However, the AMC cannot simply rely on the RTA filing. The AMC must assess how the breach impacts its own operations and investors, fulfilling its own parallel reporting obligations. AMC vendor contracts must mandate rapid notification timelines so the AMC can meet its regulatory deadlines.
Portfolio Managers, AIFs and Smaller Entities
For smaller intermediaries, the primary challenge is governance rather than complex technology. These firms must establish a clear internal escalation matrix dictating exactly who authorizes a report, who contacts SEBI and CERT-In, and who manages the lifecycle updates on the portal. Ambiguity in these roles leads to critical delays.
Actionable Steps for Compliance and Security Teams
To adapt to the FIRE-aligned CSCRF portal, organizations should immediately overhaul their incident response protocols.
First, incident response plans must integrate compliance teams from the moment of detection. Technical teams and compliance officers must work from a single, centralized incident timeline to prevent contradictory regulatory submissions.
Second, organizations should conduct tabletop exercises simulating a breach outside normal working hours. This tests the firm ability to detect, classify, and issue a preliminary six-hour notification while information is still scarce.
Finally, compliance officers must review all critical third-party vendor contracts. Vendor notification Service Level Agreements must be strict enough to allow the regulated entity sufficient time to process the information and meet its own SEBI and CERT-In reporting deadlines.
The adoption of the FIRE framework does not change the rules of cybersecurity, but it strictly changes the communication standard. Regulated entities must stop viewing regulatory reporting as a static paperwork exercise and start managing it as a dynamic, evolving intelligence lifecycle.

