India’s markets regulator SEBI is launching the IT Resilience Index (ITRI), a pioneering framework quantifying the robustness of trading, clearing, and settlement systems to modern cyber threats and operational shocks, setting a new benchmark for global financial resilience standards.
India’s markets watchdog has moved to put a numerical value on one of the most important questions in modern finance: how well the systems behind trading, clearing and settlement can withstand disruption. The Securities and Exchange Board of India has introduced an IT Resilience Index, or ITRI, for market infrastructure institutions, a group that includes stock exchanges, clearing corporations and depositories. The aim is to move beyond routine compliance checks and create a clearer picture of whether the technology underpinning the market can keep working through cyberattacks, system failures and sudden bursts of activity.
According to reports in Business Standard and The Economic Times, the framework will be built around nine parameters and scored out of 100, with availability and security carrying the heaviest weight at 20% each. Governance, reliability and monitoring, integrity, business continuity, modularity and flexibility will each account for 10%, while scalability and other factors, including incident handling, will make up the remaining 5% apiece. SEBI has said the index will be system-driven and comparable across institutions, with an Early Warning System designed to flag deterioration before it turns into an outage or broader operational problem.
The regulator’s push reflects how dependent Indian capital markets have become on digital infrastructure. Even brief interruptions can affect millions of investors and billions of rupees in transactions. The framework is also meant to strengthen continuous monitoring of service delivery, with MIIs expected to build dashboards that track system and application performance, continuity of service and anomalies in real time. Business Standard reported that the new framework is due to become operational by February 28, 2027, with the first half-yearly computation covering the period ending March 31, 2027.
SEBI’s approach stands out internationally because it tries to convert operational resilience into a measurable score. The Financial Conduct Authority and Prudential Regulation Authority in the UK use resilience rules that require firms to define important services and prove they can recover from severe shocks, while the European Union’s Digital Operational Resilience Act is a broader rulebook rather than a single index. SEBI is also aligning its incident reporting portal with the Financial Stability Board’s FIRE framework, which standardises cyber incident reporting across stages from initial notification to final closure. The broader test now is whether a high score on paper translates into faster recovery when Indian markets face a real technology shock.
Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.





