SEBI Aligns Cyber Incident Reporting Portal with FIRE Format

CCl- Compliance Calendar LLP

Volume

1

Rate

1

Pitch

1

The Securities and Exchange Board of India (SEBI) has introduced an important change in the manner in which cyber incidents are reported by entities operating in the securities market. Through Circular No. HO/(449)2026-ITD-5_DIV1/I/19448/2026 dated August 24, 2026, SEBI has aligned its Cyber Incident Reporting Portal with the Format for Incident Reporting Exchange (FIRE) developed by the Financial Stability Board (FSB). The objective of this alignment is to make cyber incident reporting more structured, consistent and effective.

Rather than treating cyber incident reporting as a one-time compliance requirement, the revised framework enables Regulated Entities, commonly referred to as REs, to report an incident throughout its entire life cycle. This means an entity can first submit an initial report based on the information available at the time of detection, provide intermediate updates as the investigation progresses and ultimately submit a final closure report after the incident has been resolved and analysed. Regulated Entities are required to use SEBI's Cyber Incident Reporting Portal, which can be accessed through https://siportal.sebi.gov.in, for reporting cyber incidents in accordance with the applicable SEBI cybersecurity.

Background: Why SEBI Strengthened Cyber Incident Reporting

Technology has become an integral part of almost every activity in the securities market. Stock exchanges, stock brokers, depositories, mutual funds, portfolio managers, research analysts, investment advisers and several other market intermediaries depend heavily on digital platforms for trading, client onboarding, settlement, payments, record maintenance and regulatory reporting. This increasing dependence on technology has also increased exposure to cyber threats. Market participants may face ransomware attacks, malware infections, phishing attempts, unauthorised access, credential theft, data breaches, denial-of-service attacks and vulnerabilities originating from third-party service providers.

A cyber incident affecting a major securities market participant can have consequences beyond the entity itself. It may affect investors, market operations, transaction processing, confidential information and interconnected financial infrastructure. SEBI has therefore emphasised the need for prompt reporting so that cyber incidents can be identified, assessed and appropriately addressed before they create wider systemic consequences. The alignment with FIRE is intended to improve the quality and consistency of information received by SEBI while recognising that complete information about an incident is often unavailable immediately after it is discovered.

What Is the FIRE Structure?

FIRE stands for Format for Incident Reporting Exchange. It was developed by the Financial Stability Board to improve consistency in the manner in which financial institutions report cyber and operational incidents to regulatory authorities. Historically, different regulators, jurisdictions and financial institutions have followed different formats for reporting cyber incidents. Some regulators may require detailed technical information while others focus more heavily on operational disruption, customer impact or financial losses. This lack of uniformity can create duplication, inconsistent terminology and difficulty in comparing incidents across organisations.

The FIRE structure seeks to solve this problem by providing common information fields, standard definitions and consistent classifications for incident reporting. It creates a structured approach through which regulators can obtain comparable information while allowing entities to report details progressively as their understanding of an incident develops. By aligning its Cyber Incident Reporting Portal with FIRE, SEBI is moving towards a globally recognised and standardised approach to cyber incident reporting within the Indian securities market.

What Has Changed Under SEBI's August 24, 2026 Circular?

The most significant change introduced by the circular is the adoption of a life-cycle-based approach to cyber incident reporting. Previously, an entity could view incident reporting primarily as a regulatory submission that had to be completed once an incident occurred. Under the revised approach, reporting is treated as a continuing process. An incident can therefore be reported initially when it is identified, updated when new facts emerge and finally closed once the investigation and remediation process has been completed.

This approach reflects the practical reality of cybersecurity incidents. At the moment an attack is detected, the organisation may know only that certain systems have become inaccessible or unusual activity has occurred. It may not immediately know the precise cause of the incident, whether confidential information has been compromised, how many investors have been affected or what financial impact the incident will ultimately have. Instead of waiting until every detail has been confirmed, the RE can report the available information and supplement it later through intermediate updates.

Stage One: Initial Cyber Incident Report

The initial incident report represents the first formal notification of the cyber incident to SEBI through the prescribed reporting mechanism. At this stage, an organisation is expected to report the information reasonably available to it. The initial report may include basic details regarding the nature of the incident, when it was detected, which systems or services appear to be affected and the preliminary actions being taken to contain the situation.

Importantly, SEBI recognises that the organisation may not possess complete information at the time of initial reporting. A cyber incident investigation may require forensic examination of servers, access logs, user accounts, network traffic and other digital evidence. Consequently, regulated entities should not unnecessarily delay reporting merely because some aspects of the incident remain under investigation.

For example, if suspicious activity is detected in an organisation's trading infrastructure, the entity may initially know that certain services have been disrupted but may not yet know whether the incident resulted from ransomware, unauthorised access or a technical vulnerability. The available facts can be reported initially and subsequently updated when the cause is established.

Stage Two: Intermediate Updates During Investigation

Intermediate reporting allows a Regulated Entity to provide additional information as its understanding of the incident improves. Cyber incidents are dynamic events. During the first few hours of an investigation, the organisation may discover additional affected systems, identify compromised credentials, determine that investor information was exposed or establish that the incident originated through a third-party technology provider. Intermediate updates enable these developments to be communicated to SEBI without waiting until the entire investigation has concluded.

For example, an RE may initially report that certain servers are unavailable. During investigation, the cybersecurity team may determine that the disruption was caused by ransomware and that specific databases were affected. Later, forensic analysis may reveal that the attacker obtained access through credentials associated with an outsourced technology provider. Each significant development can be reflected through intermediate reporting so that SEBI receives an increasingly accurate picture of the incident. This approach improves regulatory visibility while allowing the entity to conduct a proper technical investigation without treating preliminary assumptions as final conclusions.

Stage Three: Final Incident Closure

The final stage of the reporting process is the closure of the cyber incident. By this stage, the organisation should normally have a clearer understanding of what happened, why it happened, what systems or information were affected and what corrective measures have been taken. The final closure report can therefore contain information relating to the root cause of the incident, the final impact assessment, recovery activities, remedial measures and steps implemented to reduce the possibility of a similar incident occurring again.

The closure stage is particularly important because cybersecurity regulation is not concerned only with restoring affected systems. Regulators also need to understand whether the organisation has identified and corrected the weakness that enabled the incident. For instance, if an incident occurred because administrator credentials were compromised, the entity may need to explain not only how the affected systems were restored but also what additional authentication controls, monitoring systems or access restrictions have subsequently been implemented.

Information That May Form Part of Cyber Incident Reporting

The FIRE structure broadly organises incident information around reporting details, incident characteristics, impact assessment and incident closure. Reporting details generally concern the identity of the organisation submitting the report, relevant contact persons and basic information concerning the notification. This helps the regulator understand who is responsible for reporting and whom it can contact for additional information. Incident details focus on understanding what actually happened. This may include the nature of the attack, date and time of detection, affected systems, current status and available information regarding the source or method of attack.

Impact assessment focuses on the consequences of the incident. Depending upon the nature of the event, this could include disruption to services, number of clients affected, financial losses, exposure of confidential information, interruption of critical market functions or dependence on affected third-party infrastructure. Incident closure focuses on the final findings of the investigation. It may include root-cause analysis, lessons learned, corrective actions, security improvements and supporting documentation regarding the remediation undertaken. The exact information required in a particular case will depend upon the fields available on SEBI's Cyber Incident Reporting Portal and the requirements prescribed under the applicable SEBI cybersecurity.

Existing Cyber Incident Reporting Timelines Continue to Matter

The new FIRE-aligned portal should be understood together with SEBI's existing Cybersecurity and Cyber Resilience Framework (CSCRF). Under the existing framework referred to by SEBI, regulated entities are required to report specified cyber incidents within prescribed timelines. SEBI's circular refers to the requirement for reporting a cyber incident through email at mkt_incidents@sebi.gov.in within six hours and through SEBI's Incident Reporting Portal within 24 hours, in accordance with the applicable framework.

The introduction of staged reporting does not mean that an organisation can wait until the entire investigation is completed before notifying SEBI. The purpose of the new system is precisely the opposite. The entity should submit the initial information within the applicable reporting timeline and subsequently improve or supplement the information through intermediate reports and final closure reporting. Therefore, regulated entities need to manage two compliance objectives simultaneously: timely reporting and accurate reporting.

Who Is Covered by the Circular?

The circular applies broadly across entities regulated by SEBI and participants in the securities market ecosystem. Its coverage extends to several categories of intermediaries and regulated institutions, including stock exchanges, clearing corporations, depositories, depository participants, stock brokers, mutual funds, asset management companies, Alternative Investment Funds, portfolio managers, merchant bankers, credit rating agencies, custodians, debenture trustees, registrars and share transfer agents, investment advisers and research analysts, among other entities governed by the applicable SEBI.

The wide scope of the circular reflects the interconnected nature of India's securities market. A cybersecurity weakness in one intermediary may potentially have consequences for investors, other intermediaries and market infrastructure institutions. Uniform reporting therefore enables SEBI to obtain a more complete view of cyber risks occurring throughout the market.

Importance of Accurate Incident Timelines

Maintaining an accurate timeline is one of the most important elements of cyber incident management. A single cyber incident may involve several different timestamps. These can include the time when the attacker first obtained access, the time when malicious activity actually started, the time when the organisation detected suspicious activity, the time when the cybersecurity team confirmed the incident and the time when the matter was reported to SEBI. These times should not automatically be treated as identical.

For example, forensic analysis may later reveal that an attacker entered the network two days before the organisation detected the breach. The initial report may therefore contain one detection time, while the final report may contain additional information regarding the estimated beginning of the compromise. Regulated entities should maintain properly synchronised system logs, incident records and internal escalation documentation so that they can demonstrate when the incident was detected and how quickly regulatory reporting and containment measures were initiated.

Role of IT, Compliance and Senior Management

Cyber incident reporting should not be treated exclusively as the responsibility of the IT department. The technical team may be responsible for detecting and investigating an incident, but regulatory reporting often requires coordination between cybersecurity professionals, compliance officers, legal teams, risk management personnel, business operations and senior management.

An organisation should clearly define who has authority to classify an incident, determine whether SEBI reporting is required, submit the initial report, approve intermediate updates and provide the final closure information. Backup personnel should also be appointed so that reporting is not delayed merely because a particular employee is unavailable. This responsibility matrix should form part of the organisation's overall Cyber Incident Response Plan.

Third-Party and Vendor-Related Cyber Incidents

Regulated Entities increasingly depend on external technology providers such as cloud service providers, data centres, software companies, cybersecurity firms, managed service providers and outsourced technology platforms. A cyber incident affecting one of these third parties may directly affect the regulated entity even though the attack does not originate within its own IT infrastructure. For example, if a software service provider used by a securities intermediary suffers a ransomware attack and the intermediary's customer platform becomes unavailable, the event may still have regulatory implications for the RE.

Entities should therefore review their vendor agreements and outsourcing arrangements to ensure that service providers are required to communicate cyber incidents promptly. A vendor that takes several days to inform the regulated entity about a breach may make it extremely difficult for the RE to comply with SEBI's reporting timeline. Contracts with important technology service providers should therefore contain appropriate cyber incident notification, cooperation and information-sharing provisions.

Maintaining Consistency Across Regulatory Reports

A significant cyber incident may potentially trigger reporting requirements under more than one legal or regulatory. Depending on the circumstances, an entity may have reporting obligations towards SEBI as well as other relevant authorities. Information submitted to different authorities should therefore be consistent. If the organisation initially reports that 500 clients may have been affected but later forensic analysis determines that only 200 clients were actually impacted, the revised information should be properly documented and explained in subsequent regulatory updates.

A central incident register can help ensure consistency between reports submitted to different regulators, internal management reports, forensic assessments and final remediation records. The FIRE-based staged reporting structure supports this process because it allows preliminary information to be refined as the investigation progresses.

Internal Cybersecurity Policies Should Be Updated

Regulated Entities should review their existing cybersecurity and incident response policies following SEBI's circular. An internal policy that merely states that a cyber incident must be "reported to SEBI" may no longer be sufficient. The policy should clearly recognise the different phases of incident reporting, including initial notification, intermediate updates and final closure.

The policy should also specify responsibility for accessing SEBI's portal, preparing regulatory submissions, reviewing technical information and approving final reports. Organisations should maintain updated credentials for the Cyber Incident Reporting Portal and ensure that authorised personnel know how to access the system. Regular simulation exercises can also help determine whether the organisation can actually identify, escalate and report an incident within the prescribed regulatory timelines.

Importance of Root-Cause Analysis

Root-cause analysis is an important part of the final stage of cyber incident management. Merely restoring affected systems does not necessarily address the vulnerability that caused the incident. For example, systems may be restored after ransomware using backups, but if the organisation does not identify how the attacker obtained access, the same vulnerability may remain available for another attack.

The entity should therefore investigate the underlying technical and organisational causes of significant incidents. The root cause may involve weak passwords, excessive user privileges, outdated software, unpatched vulnerabilities, inadequate network segmentation, misconfigured cloud infrastructure, insufficient monitoring or security weaknesses at an outsourced service provider. Once the cause has been identified, the organisation should document the corrective steps taken to address it.

Remedial Actions and Lessons Learned

The closure of an incident should be followed by an evaluation of the lessons learned. If weaknesses were identified during the incident, the entity should determine whether additional security controls, employee training, technology upgrades or policy changes are necessary. For instance, a phishing-related breach may demonstrate the need for stronger employee awareness programmes and multi-factor authentication. A vulnerability-related breach may demonstrate the need for faster patch management.

A third-party incident may show that existing vendor-monitoring arrangements are inadequate. By documenting lessons learned and remedial actions, the entity can demonstrate that the incident has resulted in meaningful improvements to its cybersecurity framework rather than being treated merely as a closed operational event.

Role of the Board and Senior Management

Cybersecurity is increasingly a governance issue rather than merely an IT issue. A serious cyber incident can result in financial losses, investor complaints, reputational damage, regulatory consequences and disruption of important business operations. Senior management and the board should therefore have appropriate visibility over significant cybersecurity incidents.

Management should periodically review important incidents, analyse recurring vulnerabilities and assess whether adequate resources are being allocated to cybersecurity. For serious events, management should also monitor the completion of corrective actions and ensure that weaknesses identified during an incident are actually addressed. Such oversight strengthens accountability and demonstrates that cybersecurity forms part of the organisation's broader risk-management.

Practical Compliance Approach for Regulated Entities

Following SEBI's August 24, 2026 circular, every Regulated Entity should examine whether its existing incident-response mechanism can support staged regulatory reporting. The organisation should first ensure that authorised officials have working access to SEBI's Cyber Incident Reporting Portal and understand the existing reporting channels applicable under the CSCRF. The internal Cyber Incident Response Plan should clearly define how an incident will be detected, escalated, classified and reported. Responsibility should be assigned for preparing the first regulatory notification, coordinating technical information and submitting subsequent updates.

The entity should maintain detailed incident logs showing important events such as detection, internal escalation, regulatory notification, containment, restoration, forensic analysis and final remediation. Coordination between cybersecurity, legal, compliance and management teams should be established before an incident occurs rather than developed during an emergency. Vendor arrangements should also be reviewed so that important service providers are contractually required to disclose incidents quickly and cooperate in regulatory investigations. Finally, the organisation should regularly conduct cyber incident response drills to determine whether its reporting process can function effectively under real-world pressure.

How FIRE Alignment Can Benefit SEBI and the Securities Market

The alignment with FIRE can significantly improve SEBI's ability to understand cyber risks across the securities market. Standardised terminology makes it easier to compare similar incidents occurring across different intermediaries. If several regulated entities experience similar attacks or vulnerabilities, SEBI may be able to identify common patterns and issue appropriate guidance or mitigation measures.

Structured reporting can also improve data analysis. Instead of receiving incident descriptions written in completely different formats, SEBI can receive information through consistent fields and classifications. The staged approach also provides a balance between speed and completeness. SEBI can receive an early warning when an incident is detected while obtaining more comprehensive information later as the investigation progresses. This can ultimately contribute to stronger cyber resilience across India's financial and securities market ecosystem.

How the Supports Investor Protection

Although the reporting requirements apply primarily to regulated entities, the ultimate objective is closely connected with investor protection. Investors increasingly use digital systems to open accounts, execute transactions, access portfolio information, make payments and communicate with market intermediaries. A major cyber incident affecting such infrastructure can therefore have direct consequences for investors.

Prompt reporting allows SEBI to obtain early visibility into significant cyber events and evaluate whether wider regulatory intervention may be required. At the same time, final incident reporting encourages regulated entities to analyse causes and implement corrective measures so that similar incidents are less likely to occur again. Therefore, improved cyber incident reporting contributes not only to regulatory compliance but also to trust, stability and resilience within the securities market.

Legal Basis of the Circular

SEBI has issued the circular in exercise of its powers under Section 11(1) of the Securities and Exchange Board of India Act, 1992. The provision empowers SEBI to take appropriate measures to protect the interests of investors in securities and to promote the development and regulation of the securities market.

The cyber incident reporting requirements should therefore be viewed as part of SEBI's broader responsibility to ensure that market institutions maintain adequate technological resilience and that significant cybersecurity events are promptly brought to regulatory attention.

What Regulated Entities Should Do Now

Following the introduction of the FIRE-aligned reporting framework, Regulated Entities should immediately review whether their current cybersecurity systems and internal procedures are capable of supporting the revised reporting process. They should verify access to the Cyber Incident Reporting Portal, review the applicable reporting timelines under the CSCRF, designate responsible officials and ensure that the incident-response policy covers all three stages of regulatory reporting.

REs should also maintain adequate technical records, system logs and documentary evidence so that preliminary information submitted during an initial report can later be verified and supplemented. Internal communication between cybersecurity teams and compliance personnel should be strengthened because delayed communication within an organisation can ultimately lead to delayed regulatory reporting. Third-party service provider arrangements should also be examined so that the entity receives timely information about incidents occurring in outsourced systems. Most importantly, the organisation should treat cyber incident reporting as an ongoing compliance process rather than as a one-time regulatory form.

Conclusion

SEBI's Circular No. HO/(449)2026-ITD-5_DIV1/I/19448/2026 dated August 24, 2026, aligning the Cyber Incident Reporting Portal with the Format for Incident Reporting Exchange (FIRE), marks an important development in India's securities-market cybersecurity. The key feature of the revised mechanism is its recognition that a cyber incident develops over time. When an incident is first detected, an organisation may have only limited information. As the investigation progresses, additional details regarding the cause, affected systems, investor impact and remediation measures become available.

The FIRE-aligned system therefore allows the reporting process to follow this natural incident life cycle through an initial report, intermediate updates and final closure. For Regulated Entities, the change makes it essential to have a properly coordinated cyber incident management system involving technology, compliance, legal, risk management and senior management functions. Entities should not wait for a complete forensic investigation before initiating regulatory reporting where applicable. Instead, available information should be reported within the prescribed timelines, followed by accurate updates as additional facts emerge.

By adopting a more structured and internationally aligned reporting system, SEBI aims to improve regulatory visibility, standardise incident information, enhance cyber resilience and ultimately strengthen protection for investors and the securities market as a whole.

Frequently Asked Questions (FAQs)

Q1. What is SEBI’s August 24, 2026 circular on cyber incident reporting?

Ans. SEBI’s August 24, 2026 circular aligns its Cyber Incident Reporting Portal with the FIRE format developed by the Financial Stability Board. It introduces structured, staged reporting so regulated entities can submit initial details, intermediate updates, and final closure information efficiently.

Q2. What is the FIRE format?

Ans. FIRE means Format for Incident Reporting Exchange. Developed by the Financial Stability Board, it standardises cyber and operational incident reporting through common fields, definitions, and classifications, helping regulators receive consistent information and compare incidents effectively across regulated entities and jurisdictions.

Q3. Who is required to report cyber incidents to SEBI?

Ans. SEBI-regulated entities covered under the applicable cybersecurity framework must report relevant cyber incidents. This includes stock exchanges, brokers, depositories, mutual funds, asset managers, portfolio managers, investment advisers, research analysts, and other intermediaries subject to SEBI’s cybersecurity and reporting requirements nationwide.

Q4. Where should Regulated Entities report cyber incidents?

Ans. Cyber incidents should be reported through SEBI’s Cyber Incident Reporting Portal at siportal.sebi.gov.in. Regulated entities must also follow any additional reporting channels, timelines, and procedures prescribed under SEBI’s Cybersecurity and Cyber Resilience Framework and other applicable circulars or directions issued.

Q5. What are the main stages of cyber incident reporting?

Ans. The reporting process generally has three stages: initial reporting, intermediate updates, and final closure. The initial report gives available facts, intermediate reports provide new developments, and the final closure records confirmed findings, root cause, impact, remediation, and lessons learned comprehensively.

Q6. Is complete information required before submitting the initial report?

Ans. No. Complete information may not be available when an incident is first detected. Regulated entities should report available facts within the prescribed timeline and later provide additional or corrected information through intermediate updates as technical, forensic, and operational investigations continue.

Q7. What is an intermediate cyber incident report?

Ans. An intermediate report provides updated information after the initial notification. It may include newly identified affected systems, attack methods, user impact, containment actions, restoration progress, forensic findings, or other material developments discovered while the cyber incident investigation remains ongoing internally.

Q8. What information may be included in the final closure report?

Ans. The final closure report may include the confirmed cause, final impact assessment, affected systems, recovery measures, root-cause analysis, lessons learned, and corrective actions. It records how the incident was resolved and what steps were taken to prevent recurrence effectively thereafter.

Q9. What are the timelines for reporting cyber incidents to SEBI?

Ans. Under SEBI’s existing Cybersecurity and Cyber Resilience Framework, applicable cyber incidents are generally reported by email within six hours and through the incident reporting portal within twenty-four hours, subject to the latest SEBI directions and requirements applicable to each entity.

Q10. Does the FIRE-aligned portal replace SEBI’s existing cybersecurity framework?

Ans. No. The FIRE-aligned portal does not replace SEBI’s existing cybersecurity framework. It improves the structure of incident reporting and should be read together with the Cybersecurity and Cyber Resilience Framework, related circulars, reporting timelines, and any future SEBI regulatory updates.

You may also like