
Incident Response under SEBI CSCRF: A Practical Guide for Regulated Entities
CERT-In gives regulated entities six hours to report a cyber incident once it is detected. For SEBI-regulated firms, that clock
Explore blogs on SEBI’s Cybersecurity & Cyber Resilience Framework (CSCRF). Stay informed on compliance, best practices and regulatory updates.

CERT-In gives regulated entities six hours to report a cyber incident once it is detected. For SEBI-regulated firms, that clock

A clean SEBI CSCRF audit report confirms that controls exist, governance is documented and you have met regulatory obligation for

In April 2024, the RBI’s Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices came into effect for

SEBI CSCRF audit cycle for the FY 2025-26 is live. SEBI’s supervisory teams are reviewing submissions. This is an execution

The penalty structure under CSCRF operates across multiple dimensions. It includes daily exchange fines for report non-submission, per-vulnerability charges for

SEBI auditors do not evaluate intent. They evaluate a cybersecurity policy approved last year, an asset inventory last updated six

SEBI CSCRF defines six security functions: Governance, Identify, Protect, Detect, Respond and Recover. Listing governance as first is deliberate. That’s

The Securities and Exchange Board of India’s Cyber Security and Cyber Resilience Framework (CSCRF) hold regulated entities to a higher

It is clear to see that India’s BFSI sector is undergoing digital evolution. Financial institutions are now utilizing Gen AI,
WhatsApp us