The Securities and Exchange Board of India (SEBI) has constituted a dedicated task force, cyber-suraksha.ai, to examine cybersecurity risks arising from advanced artificial intelligence tools, particularly AI-driven vulnerability identification systems such as Claude Mythos. SEBI said such tools can accelerate the identification of system vulnerabilities and potentially increase the scale and speed at which weaknesses could be exploited.
The task force brings together representatives from market infrastructure institutions, qualified registrars and transfer agents, regulated entities and other stakeholders. Its mandate includes assessing AI-related cyber risks, developing common mitigation strategies, facilitating threat-intelligence sharing and ensuring priority reporting of critical cyber incidents.
The initiative reflects the interconnected nature of India’s securities-market infrastructure. A cyber incident affecting one participant could potentially have consequences for other connected entities, making coordinated monitoring and rapid information sharing important for preventing wider disruption.
Following discussions within the task force, SEBI has advised regulated entities to strengthen several areas of cybersecurity. These include prompt system patching, regular vulnerability assessments, vendor-risk management, change-management controls, API security and continuous Security Operations Centre monitoring. SEBI has also encouraged entities to onboard the Market-SOC platform for real-time threat detection.
The advisory also calls for periodic cyber-risk assessments, system hardening and updated inventories of critical assets and software components. Organisations are expected to consider vulnerabilities arising from third-party applications, services and technology dependencies as part of their wider cyber-risk assessments.
An important aspect of the initiative is that AI is being treated as both a cybersecurity capability and a potential source of cyber risk. AI can help organisations identify vulnerabilities and improve threat detection, but the same capabilities can potentially enable faster discovery and exploitation of weaknesses by malicious actors.
SEBI has therefore also called for longer-term planning around the secure integration of AI into cybersecurity operations, with associated risks subject to continuous reassessment.
For financial-market participants, the development reinforces the importance of integrating AI risk, cybersecurity, third-party risk and operational resilience rather than managing these areas independently.
The creation of cyber-suraksha.ai indicates a move towards a more coordinated approach to AI-related cyber threats across the securities ecosystem, with emphasis on faster vulnerability management, information sharing and continuous monitoring.
Want to deepen your expertise beyond today’s news?
Explore practical certification courses designed for banking, risk, insurance, compliance, ESG, AI, and emerging technologies professionals.
Learn from industry experts and earn certifications from RMAI and BFSI Sector Skill Council of India.
#Riskmanagementnews