Cybersecurity 2026

INDIA Law and Practice Contributed by: Anoop Narayanan, Priyanka Gupta and Harshita Sakarya, ANA Law Group

vices and data management. The board/partners/ proprietor of the Regulated Entity shall approve the list of critical systems. The CSCRF does not specify whether ICT services or cloud service providers will be considered as critical systems. 3.3 Key Operational Resilience Obligations The key objective of the CSCRF is to address evolving cyber threats, to align with the industry standards, to encourage efficient audits and to ensure compliance by SEBI Regulated Entities. The CSCRF also sets out standard formats for reporting by the Regulated Enti - ties. The CSCRF lays down that Regulated Entities are required to establish, communicate and enforce cybersecurity risk management roles, responsibili - ties and authorities to foster accountability and con - tinuous improvement. A comprehensive cybersecurity and cyber-resilience policy shall be documented and implemented with the approval of the board/partners/ proprietor. CSCRF mandates Market Infrastructure Institutions (MIIs), Qualified Regulated Entities and mid-size Reg - ulated Entities to prepare a cyber-risk management framework for identification and analysis, evaluation, prioritisation, response and monitoring of cyber risks on a continuous basis. MIIs and Qualified Regulated Entities must also prepare a Cyber Capability Index (CCI). MIIs shall conduct third-party assessment of their cyber-resilience using CCI on a half-yearly basis. Qualified Regulated Entities shall perform self-assess - ment of their cyber-resilience using CCI on a yearly basis. Risk assessment (including post-quantum risks) of Regulated Entities’ IT environment also must be done on a periodic basis. Regulated Entities shall establish appropriate security mechanisms through a Security Operations Centre for continuous monitoring of secu - rity events and timely detection of anomalous activi - ties. Regulated Entities shall be solely accountable for all aspects related to third-party services including (but not limited to) confidentiality, integrity, availability, non-repudiation, security of their data and logs, and

ensuring compliance with laws, regulations, circulars, etc, issued by SEBI/Indian government. Accordingly, Regulated Entities shall be responsible and account -

able for any violations of the same. Incident and Reporting Obligations

As per the CSCRF, the Regulated Entities are required to establish a comprehensive Incident Response Management Plan and corresponding SOPs, as well as formulate an up-to-date Cyber Crisis Management Plan. In the event of an incident, Root Cause Analysis (RCA) shall be conducted to identify the cause leading to the incident. Under the CSCRF, cyber-attacks, cybersecurity incidents and breaches experienced by Regulated Entities falling under CERT-In’s 2022 directive, must be notified to SEBI and CERT-In within six hours of noticing/detecting such incidents or being brought to notice about such incidents. This information also has to be shared to the SEBI Incident Reporting Portal within 24 hours. Stock brokers/depository participants shall also report the incident to stock exchanges/depositories as well as SEBI and CERT-In within six hours of noticing/ detecting such incidents or being brought to notice about such incidents. Any/all other cybersecurity inci - dents shall be reported to SEBI, CERT-In, and NCIIPC (as applicable) within 24 hours. During incident handling, some aspects must be cap - tured, such as whether the Regulated Entity has fol - lowed its organisation’s incident response plan, taken necessary (immediate) measures to contain the inci - dent impact and to control, mitigate and remediate the incident, whether the Regulated Entity has communi - cated about the incident to all relevant stakeholders, etc. The Regulated Entity shall undertake the necessary activities and submit the relevant reports within time - lines prescribed in the CSCRF. Thereafter, SEBI shall examine the incident on the basis of reports submit - ted. Further, the Regulated Entity shall classify the cybersecurity incident based on its severity and the same shall be reviewed and submitted to SEBI.

200 CHAMBERS.COM

Powered by