SEBI turns exchange technology resilience into a measurable score: ITRI and FIRE change the cyber-control playbook
SEBI has moved from broad technology-resilience obligations toward measurable, system-driven monitoring for exchanges, clearing corporations and depositories, while aligning cyber incident reporting to the FSB FIRE format.
What changed
SEBI issued two Aug 24 circulars: an IT Resilience Index for MIIs and a FIRE-aligned cyber incident reporting framework.
Why it matters
The framework makes resilience comparable and reportable instead of leaving technology robustness as an abstract control objective.
Who is affected
Stock exchanges, clearing corporations, depositories, brokers, regulated intermediaries, CISOs, operational-risk teams and investors
Action required
MIIs should map the nine ITRI parameters, automation/data sources and implementation milestones; regulated entities should update cyber incident reporting workflows to the staged FIRE format.
Executive takeaway
SEBI’s 24 August technology circulars are important because they change the supervisory question from **“Do you have resilient systems?”** to **“Can resilience be measured consistently, generated from systems and compared over time?”**
The first circular introduces an **IT Resilience Index (ITRI)** for market infrastructure institutions—stock exchanges, clearing corporations and depositories. The second aligns SEBI’s cyber-incident reporting portal with the Financial Stability Board’s **Format for Incident Reporting Exchange (FIRE)**.
Together they create two complementary control layers:
- **ITRI:** preventive/ongoing measurement of infrastructure resilience.
- **FIRE:** structured reporting once a cyber incident occurs.
For investors, these may look like back-office rules. In reality, market plumbing is part of financial stability. A trading or clearing outage can interrupt price discovery, settlement, collateral movement and risk management across the market.
What the IT Resilience Index is trying to solve
Market infrastructure institutions already monitor systems, applications, capacity and service availability. The problem with a large collection of individual metrics is that supervisory attention can become fragmented. An index creates a compact signal that can be tracked across time and, subject to consistent measurement, across MIIs.
SEBI’s framework uses a uniform set of **nine parameters**, with specified weightages. Contemporary reporting of the circular says security and availability each receive 20% weight, while governance, business continuity, modularity/flexibility and integrity are among the other pillars.
The key design principle is that computation should be **system-driven rather than manually curated**. That matters because a resilience score loses value if institutions can massage inputs after an incident or use inconsistent human judgments.
Why real-time visibility matters
The circular also pushes MIIs toward consolidated dashboards that provide continuous visibility into system and application performance, service delivery and anomalies. This is more useful than waiting for an outage report because many failures have leading indicators: rising latency, resource saturation, queue build-ups, abnormal error rates or degraded dependencies.
A mature control environment should therefore connect three levels:
**component health → user/service experience → business continuity impact.**
An exchange server can be technically “up” while order acknowledgements are too slow for a functioning market. Resilience monitoring has to look beyond device uptime.
FIRE changes the incident-reporting language
The FSB’s FIRE framework is designed to standardise the information fields, definitions and classification used when financial institutions report operational or cyber incidents. SEBI’s alignment matters because cyber incidents evolve. At the first alert, the entity may not know root cause, affected systems or full customer impact.
A staged reporting model recognises that reality:
1. **Initial report:** what is known quickly.
2. **Intermediate updates:** new facts, scope and mitigation as investigation progresses.
3. **Closure:** root cause, final impact, remediation and lessons.
That is superior to forcing an early “complete” report that is either delayed or filled with speculation.
Who sits inside the reporting perimeter
SEBI’s FIRE circular applies across a broad regulated ecosystem, not just exchanges. The cyber incident portal is relevant to intermediaries including brokers, mutual funds/AMCs, portfolio managers, investment advisers, research analysts, credit rating agencies, custodians, depositories, clearing corporations and other regulated entities identified by the framework.
The practical implication is that firms need a **regulatory incident workflow**, not merely an IT incident ticket. The CISO, technology team, compliance officer, business owner, legal team and senior management need agreed responsibilities for escalation and regulator reporting.
What “resilience” should mean in practice
Finin2min would split resilience into five questions:
- **Can the institution prevent common failure modes?** Capacity, patching, architecture and security.
- **Can it detect degradation before users do?** Observability and anomaly detection.
- **Can it continue critical services when a component fails?** Redundancy and failover.
- **Can it recover cleanly?** Backups, disaster recovery and data integrity.
- **Can it learn from incidents?** Root-cause remediation, testing and governance.
ITRI can improve oversight only if the score retains those operational meanings. A high index number should not become a compliance trophy that hides concentrated single points of failure.
Implementation risk: metric gaming
Any weighted index creates the possibility of optimisation toward the metric. Institutions may improve easier indicators while hard architectural problems remain. SEBI’s emphasis on system-generated data and standardised measurement criteria is therefore important.
Supervisors will also need to examine the **distribution beneath the composite score**. A strong overall score should not neutralise a critically weak cybersecurity or availability pillar.
What boards and audit committees should ask
The new framework elevates technology resilience from the CISO’s technical agenda to board-level operational risk. Useful questions include:
- Which systems feed each ITRI parameter?
- Are any inputs manually editable?
- What are the largest single points of failure?
- How often is failover actually tested under production-like load?
- Can incident data be reconciled between internal logs, client impact and the SEBI portal?
- How are third-party/cloud dependencies incorporated?
- Does the institution have enough evidence to reconstruct a timeline after an outage or attack?
Market impact is indirect but real
These circulars do not change brokerage fees, settlement cycles or company valuations tomorrow. Their value is in lowering tail risk. Stronger infrastructure can reduce the probability that a technical event becomes a market-wide confidence event.
That makes ITRI conceptually similar to other financial-resilience metrics: the number is not the objective; **continuity under stress is**.
Finin2min bottom line
SEBI is building a measurable technology-supervision layer for the infrastructure on which India’s securities markets depend. ITRI measures whether the system is resilient before failure; FIRE standardises what happens when failure occurs.
For regulated entities, the work is operational: data mapping, dashboards, automated calculation, incident taxonomy, escalation and evidence. For investors, the message is simpler: **market infrastructure risk is financial risk, even when it starts in a server or a cyber alert.**
View official source →
FinNews is educational and professional reference material, not financial, tax or legal advice. Confirm the current official position from the primary source before acting on any figure, rate, provision or deadline mentioned here.