SEBI Aligns Cyber Incident Reporting with FIRE: What Entities Must Review

SEBI Aligns Cyber Incident Reporting with FIRE

On August 24, 2026, SEBI issued a circular aligning its Cyber Incident Reporting Portal with the Financial Stability Board’s Format for Incident Reporting Exchange, commonly referred to as FIRE. This follows closely on the launch of SEBI’s revamped Incident Reporting Portal and the new Cyber Suraksha Portal on August 17, and together these developments mark a deliberate move toward standardising how cyber incidents are reported, classified, and tracked across India’s securities market ecosystem.

For regulated entities, including stock exchanges, clearing corporations, depositories, intermediaries, and alternative investment funds, this is not simply a technical portal upgrade. It changes the structure, terminology, and staging of how cyber incidents must be reported, which means internal incident response and reporting workflows need to be reviewed and, in many cases, adjusted to align with the new format.

What the FIRE Alignment Actually Changes

SEBI’s circular introduces structured, staged reporting of cyber incidents while retaining the existing reporting timelines that entities are already familiar with.

  • Regulated entities continue to report cyber incidents by email within 6 hours of detection, and through SEBI’s Cyber Incident Reporting Portal within 24 hours, so the underlying speed of reporting is unchanged
  • The FIRE framework, developed by the Financial Stability Board, introduces common information fields, standardised definitions, and consistent incident classifications
  • This is designed to improve consistency in how cyber incidents are described and categorised, both within India’s securities market and in the broader context of cross border financial sector information exchange
  • The portal now supports multiple stages of the incident lifecycle, including initial reporting, intermediate updates, and final closure, rather than requiring a single, complete report upfront
  • Entities can file an initial report with the information available at the time, and supplement it with updates as investigation and remediation progress, closing with a final closure report once the incident is fully resolved

Why This Matters Beyond a Portal Update

Standardised, staged reporting reflects a broader shift in how financial regulators globally are thinking about cyber incident management.

  • A single point in time report, filed once and never revisited, tends to either delay initial reporting while an entity gathers complete information, or forces entities to submit incomplete or speculative details under time pressure
  • Neither outcome serves the regulator’s actual objective, which is timely awareness combined with an accurate, evolving picture of the incident as it unfolds
  • By aligning with FIRE’s common fields and classifications, SEBI is positioning its incident data to be more readily comparable with international frameworks
  • This supports better systemic risk monitoring and more effective coordination during incidents that may affect multiple institutions or cross into other jurisdictions, an increasingly common pattern given how interconnected financial market technology has become

Read Now: SEBI Cyber Suraksha AI Task Force 2026: Combating AI Driven Threats

What Regulated Entities Should Review

Institutions covered by this circular need to work through several practical areas of review rather than treating this as a routine notification to file away.

  • Incident classification taxonomy. Internal incident classification categories need to be checked against FIRE’s standardised definitions to confirm they map cleanly, since gaps or mismatches are better reconciled before the next incident occurs than discovered mid incident under time pressure
  • Data fields captured during detection and triage. Existing incident detection and triage processes need review to confirm they actually capture the specific data points FIRE requires, since filling in critical fields retroactively during a live incident adds unnecessary delay and risk of inaccuracy
  • Staged reporting workflow and ownership. With initial reporting, intermediate updates, and final closure now distinct stages, entities need clear internal ownership for each stage, including who files updates as new information becomes available and how responsibility is handed off across shifts or days
  • Existing 6 hour and 24 hour reporting discipline. While the format has changed, the underlying timelines have not, making this a natural trigger to verify that internal escalation processes reliably meet existing deadlines in practice
  • Bye-law, rule, and internal policy alignment. SEBI’s circular requires regulated entities to put systems in place to implement the changes and consider necessary amendments to applicable bye-laws, rules, or regulations where relevant
  • Cyber Suraksha Portal engagement. Entities should assign clear internal ownership for monitoring and acting on information shared through this portal, rather than treating it as a passive channel no one actively checks

The Broader Pattern This Reflects

This circular does not exist in isolation.

  • It sits alongside SEBI’s newly introduced IT Resilience Index for Market Infrastructure Institutions, also issued on August 24
  • It builds on the earlier CSCRF cybersecurity guidelines requiring offline, encrypted backups and regular resilience testing
  • Taken together, these developments show a regulator moving consistently toward measurable, standardised, and continuously monitored cyber resilience, rather than periodic, narrative based assurance
  • Entities that treat each development as a separate, isolated compliance task risk missing how closely connected they actually are, since incident reporting, resilience measurement, and information sharing are designed to work together as a single, coherent cyber governance framework

Read Now: RBI Cybersecurity Directions 2026: Board Level Cyber Risk Governance Training

Conclusion

SEBI’s alignment with the FIRE format changes the structure and staging of cyber incident reporting far more than it changes the underlying timelines, but that structural shift still requires real internal review. Entities that map their classification taxonomy, data capture processes, and staged reporting ownership now will be far better prepared than those that wait for the next incident to discover a mismatch.

Build This Capability with RMAI

The Online Course on Cyber Security and Technology Risk Management in Banking covers incident detection, classification, and response practices directly relevant to this framework. The Online Certificate Course on Governance, Risk and Compliance (GRC) helps compliance and governance professionals align internal policy with evolving regulatory formats.

ENROLL NOW

author avatar
RMA INDIA

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.