Skip to main content
SEBI Cyber Security Framework

SEBI Cyber Security &
Cyber Resilience Framework

Protecting Market Infrastructure Institutions (MIIs) and intermediaries through stringent controls, mandatory cyber audits, and robust incident response capabilities to ensure market continuity.

Asset ClassificationAccess ControlNetwork SecurityLog MonitoringMandatory Cyber Audits
24x7
Continuous monitoring & incident response mandate

MIIs & Intermediaries Coverage
Mandatory Cyber Audits (Bi-annual)
Market Continuity Assurance

Safeguarding India's Capital Markets

The SEBI Cyber Security and Cyber Resilience Framework applies to stock exchanges, depositories, clearing corporations, and market intermediaries. It establishes stringent controls to protect market infrastructure institutions (MIIs) and ensure the integrity, availability, and resilience of critical market systems.

iGlobus SEBI Framework consulting helps capital market entities establish, operationalize, and demonstrate compliance with SEBI's comprehensive cybersecurity requirements. Our engagement covers asset classification, access control, network security, log monitoring, vulnerability assessments, mandatory cyber audits, and incident response capabilities to ensure market continuity.

Applicable to: Recognized Stock Exchanges, Clearing Corporations, Depositories, and all SEBI-registered intermediaries including brokers, investment advisors, research analysts, and portfolio managers.

Core SEBI Framework Pillars

Key requirements under SEBI Cyber Security & Cyber Resilience Framework:

Asset Classification & Inventory
Critical asset identification, classification, and protection
Access Control & Identity Management
Privileged access management, role-based controls
Network Security & Segmentation
Perimeter security, micro-segmentation, DMZ controls
Log Management & Monitoring
Centralized logging, SIEM, retention policies
Mandatory Cyber Audits
Bi-annual audits by CERT-IN empaneled auditors

SEBI Framework Implementation Roadmap

iGlobus provides end-to-end SEBI Cyber Security and Cyber Resilience compliance enablement for capital market entities.

Asset Classification & Inventory

Identify and classify critical assets based on business impact, data sensitivity, and regulatory requirements.

  • Critical asset identification
  • Classification framework design
  • Asset inventory management

Access Control & IAM

Implement robust identity and access management controls, privileged access management, and segregation of duties.

  • Privileged Access Management
  • Role-based access controls
  • Periodic access reviews

Network Security & Segmentation

Design and implement network security controls, segmentation, and perimeter protection for market infrastructure.

  • Firewall & IPS/IDS management
  • Network micro-segmentation
  • DMZ & secure zones

Log Monitoring & SIEM

Establish centralized logging, real-time monitoring, and SIEM capabilities for threat detection.

  • Centralized log aggregation
  • Log retention & analysis
  • Security event correlation

Vulnerability Assessment & Pen Testing

Conduct comprehensive vulnerability assessments and penetration testing to identify and remediate security gaps.

  • Internal & external VAPT
  • Application security testing
  • Remediation tracking

Mandatory Cyber Audits

Facilitate bi-annual cyber audits by CERT-IN empaneled auditors and ensure remediation of audit findings.

  • Audit facilitation & coordination
  • Audit evidence preparation
  • Remediation roadmap

SEBI Framework Control Requirements

Comprehensive control categories mandated under the SEBI Cyber Security and Cyber Resilience Framework.

Asset Classification
Access Control
Network Security
Log Monitoring
Vulnerability Assessment
Cyber Audits
Incident Response
Backup & Recovery

Market Infrastructure Protection

Safeguard critical market systems and data

Market Continuity

Ensure uninterrupted market operations

Investor Trust

Strengthen confidence in capital markets

Audit Readiness

Bi-annual cyber audit preparedness

Capital Markets Cybersecurity

Capital Markets Cybersecurity Experts

iGlobus combines deep expertise in SEBI regulatory frameworks with practical cybersecurity implementation experience. Our consultants have extensive knowledge of market infrastructure operations, SEBI circulars, and integration with broader governance initiatives for capital market entities.

SEBI circulars & master directions expertise
MII & intermediary compliance programs
CERT-IN empaneled audit facilitation
Incident response & recovery planning
VAPT & red team exercises
Market continuity assurance
Secure Your Market Operations

SEBI Framework FAQs

Essential answers about SEBI cybersecurity compliance for capital market entities.

The SEBI Cyber Security and Cyber Resilience Framework applies to all Market Infrastructure Institutions (MIIs) including recognized Stock Exchanges, Clearing Corporations, and Depositories. Additionally, it applies to all SEBI-registered intermediaries such as Stock Brokers, Investment Advisors, Research Analysts, Portfolio Managers, Alternative Investment Funds (AIFs), and Mutual Funds. The framework mandates varying levels of compliance based on organizational size, complexity, and market role.

SEBI mandates that MIIs and specified intermediaries undergo comprehensive cyber audits at least twice a year (bi-annually). These audits must be conducted by CERT-IN empaneled information security auditors. The audit scope includes assessment of IT infrastructure, network security, access controls, log management, incident response capabilities, and compliance with SEBI cybersecurity circulars. Audit findings must be reported to SEBI within the stipulated timeline with remediation plans.

SEBI mandates immediate reporting of cybersecurity incidents to the designated authority. Critical incidents affecting market integrity or customer data must be reported within 6 hours of detection. All cybersecurity incidents, including phishing attempts, malware infections, unauthorized access attempts, and DDoS attacks, must be reported through SEBI's incident reporting portal. MIIs are also required to maintain incident registers and conduct post-incident analysis with root cause identification and preventive measures.

SEBI mandates comprehensive asset classification where all IT assets (hardware, software, data, and network components) must be inventoried and classified based on criticality to business operations. Assets are typically categorized as Critical, Important, or General. Critical assets require enhanced security controls, stricter access management, more frequent vulnerability assessments, and must be included in business continuity and disaster recovery planning. The asset inventory must be maintained and updated regularly.

The SEBI framework mandates robust Business Continuity Planning (BCP) and Disaster Recovery (DR) capabilities for MIIs and intermediaries. Key requirements include: geographically redundant infrastructure, Recovery Time Objective (RTO) and Recovery Point Objective (RPO) defined for critical systems, regular DR drills (at least quarterly), backup verification, and incident response teams capable of restoring market operations within mandated timelines. The framework also requires testing of crisis communication protocols and coordination with other market participants during disruptions.

Ready for SEBI Cyber Security & Cyber Resilience Compliance?

Strengthen your capital market entity's cyber resilience. Let's build a robust, audit-ready cybersecurity posture aligned with SEBI mandates.

Schedule a Cybersecurity Consultation

Start Your SEBI Framework Journey

Ready to establish a comprehensive cybersecurity posture compliant with SEBI mandates for capital market entities? Our financial sector cybersecurity experts are here to guide your organization through every stage of implementation.

Hyderabad HQ (PAN India presence)
4th & 5th Floor, Techno Enclave, Beside Cloud9 Hospitals, Madhapur, Hitech City, Hyderabad – 500081
+91 89785 55525

Request More Information