India’s securities regulator launches two new digital portals to streamline incident reporting and information sharing, reflecting a broader push to bolster market resilience against emerging cyber threats including AI and quantum computing.
India’s securities regulator has stepped up its cyber-defence push with two new digital portals meant to make incident reporting faster and information sharing more organised across the market system. Tuhin Kanta Pandey, chair of the Securities and Exchange Board of India, said the move reflects a broader recognition that attacks no longer stop at one firm’s firewall and can ripple through vendors, platforms and other connected institutions.
Pandey said cyber threats cross organisational, regulatory and national lines, and argued that lessons from one breach should help protect others. The new Incident Reporting Portal is intended to make disclosures of cyber events more structured, timely and useful, while the Cyber Suraksha Portal is designed as a central point for warnings, policy updates, vulnerability notices and lessons from incidents. The incident platform is aligned with the Financial Stability Board’s FIRE format, which aims to standardise reporting and ease cross-border coordination.
The SEBI chief also used the symposium to press firms to move away from a compliance-only approach to security. He said resilience means being able to anticipate, absorb, recover from and learn after an attack, and he called for tested response plans, clear responsibilities and continuous vulnerability management. That, he said, should include faster patching of critical flaws and stronger oversight of software, cloud set-ups, application programming interfaces and third-party dependencies, all of which can change quickly.
Pandey also flagged newer risks, including artificial intelligence and quantum computing. He said AI is accelerating both attacks and defences, but warned that any AI used for cybersecurity must be secure, governed and accountable. On quantum risk, he said post-quantum cryptography should already be treated as a migration effort, not just a research topic, and added that firms need to know where vulnerable encryption is in use, how dependent third parties are on it and whether they can switch algorithms without redesigning whole systems.
Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.





