In Feb 2021, a technical outage brought India’s largest stock exchange to a standstill for several hours. Trading froze and investor confidence took a hit. That single event pushed India’s securities regulator to rethink how ready market participants really are for a crisis.
That incident shaped the Securities and Exchange Board of India (SEBI) CSCRF, issued on Aug 20, 2024. One requirement inside it that sometimes gets treated as a checkbox is the cyber crisis drill.
A SEBI CSCRF cyber crisis drill is a structured simulation that checks if your incident response plan actually works under pressure. This guide walks you through how to conduct a SEBI CSCRF cyber crisis drill step by step, from scoping the scenario to reporting the outcome to your board.
What is a SEBI CSCRF cyber crisis drill?
SEBI’s CSCRF builds its resilience goals directly from the Cyber Crisis Management Plan (CCMP) published by CERT-In. These goals are Anticipate, Withstand, Contain, Recover and Evolve.
A cyber crisis drill puts these five goals to the test. Your incident response team, IT leadership and, in many cases, your board work through a simulated attack in real time. No actual breach happens. The drill checks decision-making, escalation and communication.
Every SEBI regulated entity (RE) above the Self-Certification tier needs a documented, board-approved CCMP. The cyber crisis drills help validate whether the CCMP is practical and effective.
Why your organisation needs a cyber crisis drill
This kind of drill protects more than just your compliance score. It builds real muscle memory for the day an incident actually hits.
- Regulatory timelines are tight: SEBI requires incident reporting to its portal and to CERT-In within 6 hours of detection. A drill tells you if your team can move that fast.
- Board accountability is real: SEBI CSCRF makes cybersecurity a board-level responsibility. A drill gives your board direct visibility into gaps.
- Third-party risk is common: Vendors, cloud providers and SOC partners all should be considered in your drill, since most incidents today touch a third party.
- Recovery objectives need testing: Your Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs) only mean something once tested under pressure.
Steps to conduct a SEBI CSCRF cyber crisis drill
Running an effective drill comes down to six steps. Skip any one of them, and the drill can turn into a difficult exercise:
- Define the scope and objective: Decide which business function, system or scenario the drill will test. A ransomware event, a data leak and a trading system outage each need a different playbook.
- Build a realistic scenario: Base it on your actual infrastructure, threat landscape and past incidents, not a generic template.
- Assign roles across functions: Bring in IT, legal, compliance, communications and senior leadership. A crisis is never an IT-only event.
- Run the simulation: Walk the team through the scenario in phases, from detection to containment to recovery, and observe real decisions being made.
- Capture gaps as they happen: Note where escalation stalled, where roles were unclear or where the CCMP did not match reality.
- Report findings and remediate: Share results with the board, close every gap with an owner and a deadline, then feed lessons into the next drill.
Common mistakes to avoid during a cyber crisis drill
Most crisis drills fail for the same reasons:
- Treating it as formality: A drill run once a year with no real pressure teaches your team nothing.
- Leaving out leadership: If your CISO or board never joins, the drill misses the governance test SEBI is looking for.
- Reusing old scenarios: Threats change every year. A ransomware scenario from three years ago will not test today’s gaps.
- Skipping the remediation loop: A drill without documented fixes is just a rehearsal with no payoff.
Conclusion
A SEBI CSCRF cyber crisis drill is the difference between a plan that looks good on paper and a team that knows exactly what to do when an incident hits. Define the scope, build a realistic scenario, involve the right people and close every gap you find.
CyberNX provides advanced and reliable SEBI CSCRF consulting services that can help you develop a compliance roadmap and measure effectiveness. If you need help planning or running your next SEBI CSCRF cyber crisis drill, connect with our experts for SEBI CSCRF framework consulting and get your cyber crisis management plan audit-ready.
How to Conduct a SEBI CSCRF Cyber Crisis Drill FAQs
What is the difference between a cyber crisis drill and a tabletop exercise?
A cyber crisis drill is the broader term for any simulated incident response exercise. A tabletop exercise is one format of it, run as a discussion-based walkthrough rather than a live technical simulation.
Who should attend a SEBI CSCRF cyber crisis drill?
Your incident response team, IT and security leadership, legal, compliance, communications and, for major scenarios, board or senior management representation.
Is a cyber crisis drill mandatory under SEBI CSCRF?
SEBI CSCRF requires every RE to maintain a board-approved Cyber Crisis Management Plan and regular drills to validate it, in line with CERT-In’s crisis management guidance.
How long does a typical cyber crisis drill take?
Most drills run between 2 and 4 hours, depending on scenario complexity and the number of teams involved.





