Breaking News

SEBI FIRE Cyber Reporting Framework Explained: What Changes?

SEBI’s alignment with the FSB FIRE framework shifts cyber reporting from one-time alerts to a lifecycle process. Discover what changes for brokers, AMCs, and RTAs.

SEBI FIRE cyber reporting framework infographic showing cybersecurity incident reporting lifecycle, FIRE standards, SEBI compliance requirements, 6-hour CERT-In alert, 24-hour reporting timeline, and
Infographic explaining SEBI’s FIRE-aligned cyber incident reporting framework, highlighting lifecycle-based reporting, CERT-In and SEBI timelines, and compliance requirements for brokers, AMCs, RTAs, portfolio managers, AIFs, and other market intermediariSource: Illustration generated and designed by ChatGPT based on publicly available information about SEBI’s FIRE cyber reporting framework and cybersecurity compliance requirements.

SEBI’s latest cybersecurity reporting reform is not about giving market intermediaries more time to report cyber incidents. It is about fundamentally changing how those incidents are recorded, classified, and tracked from the moment of detection through to final resolution.

On August 24, 2026, the Securities and Exchange Board of India (SEBI) aligned its Cyber Incident Reporting Portal with the Financial Stability Board’s Format for Incident Reporting Exchange, globally known as FIRE. This transition brings a highly standardised, internationally structure

.SEBI's latest cybersecurity reporting reform fundamentally shifts how market intermediaries handle cyber incidents. Introduced on August 24, 2026, through Circular No. HO/(449)2026-ITD-5_DIV1/I/19448/2026, the Securities and Exchange Board of India aligned its Cyber Incident Reporting Portal with the Financial Stability Board Format for Incident Reporting Exchange, commonly known as FIRE.

This alignment integrates a standardized international reporting structure into India's securities market. For regulated entities like stock brokers, depository participants, asset management companies, registrars and transfer agents, portfolio managers, and alternative investment funds, this means cyber incident reporting is no longer a one-and-done notification. It is now a dynamic, lifecycle-based process.

Understanding the FSB FIRE Framework and SEBI Integration

The FIRE framework was developed by the Financial Stability Board and finalized in April 2025 to solve a global financial sector problem: fragmented incident reporting. Previously, institutions reported similar incidents to different authorities using conflicting terminology, making it difficult to assess systemic risks. FIRE introduces common data elements and standardized terminology to streamline this process.

It is crucial to understand that SEBI adoption of FIRE does not replace its existing Cyber Security and Cyber Resilience Framework (CSCRF). The CSCRF remains the overarching regulatory framework governing cybersecurity. Annexure-O of the CSCRF continues to dictate what constitutes a reportable cyber incident. The FIRE framework simply upgrades the structural mechanism through which these incidents are reported to SEBI portal. Purely administrative failures or non-cyber physical disruptions do not become reportable cyber incidents just because SEBI adopted FIRE.

Reporting Deadlines: SEBI versus CERT-In

A major compliance misconception is that the FIRE alignment alters existing regulatory deadlines. It does not. SEBI existing timeline requirements, including the 24-hour reporting window under the portal framework, remain active.

Furthermore, CERT-In April 2022 Cyber Security Directions independently mandate that covered entities report specified cyber incidents within six hours of detection. SEBI CSCRF aligns with this for severe incidents. Regulated entities must evaluate an incident against both Annexure-O and CERT-In directions, recognizing that reporting to SEBI does not automatically satisfy CERT-In obligations, nor does one filing cover obligations to stock exchanges, depositories, or the NCIIPC. Firms must manage parallel notifications based on the specific incident severity.

The practical takeaway is that an entity must not delay an initial regulatory notification simply because its internal forensic investigation is incomplete.

The Incident Reporting Lifecycle

The most significant operational change introduced by the FIRE-aligned portal is lifecycle reporting. An organization is no longer expected to have all the answers at the time of the initial breach notification. The reporting process now develops along a logical curve: Detection, Initial Report, Investigation, Updates, Resolution, and Closure.

sebi-fire-cyber-reporting-framework-brokers-amcs-market-intermediaries-2026

The Initial Report

When a breach is detected, the initial report should capture immediately available facts. This includes the time of detection, suspected affected systems, the preliminary nature of the incident, immediate containment measures taken, and whether third parties or customers might be impacted. Uncertainty regarding the exact attack vector or total data exposed should not delay this initial filing.

Intermediate Updates

Cyber investigations are rarely linear. An incident initially classified as a minor system outage might escalate into a major data exfiltration event. The FIRE portal allows intermediaries to submit intermediate updates as forensic teams uncover new facts regarding compromised accounts, attack techniques, financial impact, and remediation efforts. This ensures the regulatory record evolves alongside the ground reality.

Closure

The final closure report represents the organization mature understanding of the event. It documents the confirmed root cause, total affected services, final financial and operational impact, successful recovery actions, and the patching of exploited vulnerabilities. This creates a comprehensive, auditable record from start to finish.

Impact on Market Intermediaries

Because India securities market relies on highly interconnected digital infrastructure, a single vulnerability can cascade across multiple institutions. The FIRE framework impacts different intermediaries in specific ways.

Stock Brokers and Depository Participants

Brokerage systems connect trading platforms, APIs, payment gateways, and order management systems. If API credentials are compromised, a broker initial report might only state that suspicious activity was detected and blocked. Subsequent lifecycle updates will clarify which client accounts were accessed and if unauthorized trades were attempted. Brokers and DPs must also integrate their applicable stock exchange and depository reporting obligations into this response chain, ensuring escalation reaches all relevant market infrastructure institutions promptly.

SEBI FIRE cyber reporting framework infographic showing reporting deadlines, incident lifecycle and impact on brokers, AMCs, RTAs and market intermediaries

Asset Management Companies (AMCs) and RTAs

AMCs operate within a complex ecosystem reliant on third-party vendors, making vendor risk management critical. If a Registrar and Transfer Agent experiences a breach affecting investor records, the RTA, as a SEBI-regulated entity, has its own independent obligation to report the incident. However, the AMC cannot simply rely on the RTA filing. The AMC must assess how the breach impacts its own operations and investors, fulfilling its own parallel reporting obligations. AMC vendor contracts must mandate rapid notification timelines so the AMC can meet its regulatory deadlines.

Portfolio Managers, AIFs and Smaller Entities

For smaller intermediaries, the primary challenge is governance rather than complex technology. These firms must establish a clear internal escalation matrix dictating exactly who authorizes a report, who contacts SEBI and CERT-In, and who manages the lifecycle updates on the portal. Ambiguity in these roles leads to critical delays.

Actionable Steps for Compliance and Security Teams

To adapt to the FIRE-aligned CSCRF portal, organizations should immediately overhaul their incident response protocols.

First, incident response plans must integrate compliance teams from the moment of detection. Technical teams and compliance officers must work from a single, centralized incident timeline to prevent contradictory regulatory submissions.

Second, organizations should conduct tabletop exercises simulating a breach outside normal working hours. This tests the firm ability to detect, classify, and issue a preliminary six-hour notification while information is still scarce.

Finally, compliance officers must review all critical third-party vendor contracts. Vendor notification Service Level Agreements must be strict enough to allow the regulated entity sufficient time to process the information and meet its own SEBI and CERT-In reporting deadlines.

The adoption of the FIRE framework does not change the rules of cybersecurity, but it strictly changes the communication standard. Regulated entities must stop viewing regulatory reporting as a static paperwork exercise and start managing it as a dynamic, evolving intelligence lifecycle.

Related Topics

Harsh Nath Jha

About the Author

Harsh Nath Jha

Section Editor

Harsh Nath Jha is a media student, writer, and the founder of Sahityashala.in. A graduate in Physics from the University of Delhi currently pursuing Radio & TV Journalism at IIMC Delhi, his work rests at the quiet intersection of empirical logic and creative expression. Driven by a genuine curiosity about people and culture, he approaches socio-political reporting and sports writing with thoughtful humility, steady precision, and a deep respect for the craft.

© Copyright 2026 News4Bharat - All Rights Reserved.