Sebi Clarifies Cybersecurity Framework
Aug 28, 2025 19:18
Sebi clarifies cybersecurity & cyber resilience framework (CSCRF) applicability, audits, & compliance for regulated entities.
Photograph: Kind courtesy pixabay.com
New Delhi, Aug 28 (PTI) Markets regulator Sebi on Thursday clarified that the cybersecurity and cyber resilience framework (CSCRF) applies only to systems used exclusively for its regulated activities.
Shared infrastructure will also be audited if not already covered by the RBI or another regulator.
Further, if regulated entities (REs) comply with RBI (or other regulator) cybersecurity rules that are equivalent to Sebi's, such compliance will be accepted by the markets watchdog.
In its circular, Sebi also elaborated on the definition of critical systems, stating that it includes all systems that affect core operations, store or transmit regulatory data, client-facing applications, internet-facing systems, and other systems on the same network.
REs have been asked to adopt zero-trust principles such as network segmentation, high availability, and avoiding single points of failure with approval from their IT Committees.
The regulator said that guidelines relating to mobile applications are recommendatory, not mandatory, while for cyber crisis response, entities must act as per their Cyber Crisis Management Plan instead of issuing press releases.
The regulator further clarified that deploying tools like threat simulations, vulnerability management, and decoy systems is encouraged but not compulsory.
Entities are also required to assess third-party/vendor risks in consultation with their IT Committees.
On audit-related matters, Sebi said, "While receiving and handling cyber audit reports submitted by their members, stock exchanges and depositories shall ensure that adequate safeguards are in place to maintain the confidentiality and integrity of such reports".
In terms of disaster recovery, REs must be capable of resuming critical operations within two hours (RTO), maintain a 15-minute Recovery Point Objective (RPO), and plan for scenarios where timelines are not met, Sebi said.
The regulator has also revised the thresholds and categorisation of regulated entities under the CSCRF. For Portfolio Managers, those with Assets Under Management (AUM) of Rs 10,000 crore and above will be categorised as Qualified REs, while those managing between Rs 3,000 crore and Rs 10,000 crore will fall under the Mid-size RE category.
Portfolio managers with AUM of Rs 3,000 crore or below will be treated as Small-size REs, and those below the minimum threshold may be classified as Self-certification REs with simplified compliance requirements.
For Merchant Bankers (MBs), all active MB-- those undertaking merchant banking activities during the relevant period--will be classified as Small-size REs for compliance purposes, while inactive MBs will be exempt from CSCRF provisions.
DISCLAIMER - This article is from a syndicated feed. The original source is responsible for accuracy, views & content ownership. Views expressed may not reflect those of rediff.com India Limited.
You May Like To Read
MORE NEWS
Indian Bank Q4 Profit Up 5%, Dividend Declared
Indian Bank reports 5% rise in Q4 profit to Rs 3,103 cr, declares Rs 18.25/share...
Sensex, Nifty Rebound: FMCG, Auto Shares Lead
Sensex and Nifty rebound nearly 1% driven by FMCG, auto, and telecom stocks amid...
Vedanta Q4 Profit Zooms 89% on Metal Prices
Vedanta Ltd reports 89% jump in Q4 profit to Rs 9,352 cr, driven by higher metal prices...
Pinnacle Launches Global Centre in Bengaluru
Pinnacle Infotech launches Global Centre of Excellence in Bengaluru, signing MoUs with...
Maharashtra AI Policy: Rs 10,000 Cr Investment
Maharashtra approves AI Policy 2026, investing Rs 10,000 Cr, creating 1.5 lakh jobs,...
Skoda Auto India Partners with CSC Grameen eStore
Skoda Auto India partners with CSC Grameen eStore to expand reach in non-metro areas....
Rupee Falls to Near Record Low Amid Oil Price...
Rupee depreciates to 94.82 against USD amid rising crude oil prices, FII outflows, and...
Kissht IPO: Founders Invest Rs 40 Cr at Premium
Kissht founders invest Rs 40 crore at a premium ahead of IPO. IPO opens April 30....
Sterlite Technologies Posts Profit in Q4 FY26
Sterlite Technologies reports Rs 59 crore net profit in Q4 FY26, driven by order growth...
Vijay Anandh New MD of City Union Bank
Vijay Anandh appointed MD & CEO of City Union Bank (CUB) on May 1, succeeding Dr. N...
Read More »