·The Hindu·15 marks·250–350 words

Examine the risks posed by increasing technological dependence of India's securities markets and the regulatory responses evolved by SEBI since 2015.

In this answer
  1. Risks from deepening technological dependence
  2. SEBI's regulatory response since 2015

India's securities markets are now almost wholly electronic — order matching, clearing, settlement and securities holding run on IT systems. Recognising exchanges, clearing corporations and depositories as systemically important Market Infrastructure Institutions (MIIs), SEBI has since 2015 moved from cyber hygiene norms towards measurable technology resilience [1].

Risks from deepening technological dependence

  • Systemic concentration risk: trading, clearing and depository functions rest on a handful of MIIs; an outage at one halts price discovery market-wide, affecting crores of investors [6].
  • Cyber-attack surface: ransomware, data breaches and supply-chain intrusions threaten investor data and settlement integrity, prompting a dedicated Cyber Security Operations Centre for intermediaries [2].
  • Speed-related vulnerabilities: algorithmic and high-frequency trading plus shorter settlement cycles compress the tolerable downtime to minutes.
  • Retail exposure: mass participation through online broking apps transmits any technical failure directly to small investors, whose grievance redress is weakest.
  • Scalability shocks: sudden volume spikes on volatile days test capacity, while third-party cloud and vendor dependence diffuses accountability.

SEBI's regulatory response since 2015

  • 2015: first Cyber Security and Cyber Resilience Framework for exchanges, clearing corporations and depositories, aligned to CPMI-IOSCO Principle 17 on operational risk [1].
  • 2018: strengthened framework for MIIs, extended to stock brokers and depository participants, widening the regulated perimeter [3].
  • 2023: coverage extended to portfolio managers, closing intermediary-level gaps [4].
  • 2024: the consolidated Cybersecurity and Cyber Resilience Framework (CSCRF) for all SEBI-regulated entities introduced the Cyber Capability Index for periodic self-assessment [5].
  • 2026: after a consultation paper (March), SEBI notified the IT Resilience Index (ITRI) for MIIs (August), scoring availability, integrity, business continuity and scalability [6][7].

The trajectory marks a welcome shift from checklist compliance to outcome-based, quantifiable regulation. Its success will depend on credible third-party audits, disclosure of resilience scores, and coordination with CERT-In and the FSDC, so that technological trust keeps pace with the market's digital deepening.

Sources

  1. 1SEBI — Cyber Security and Cyber Resilience framework of Stock Exchanges, Clearing Corporation and Depositories (July 2015)MIIs as systemically important; CPMI-IOSCO Principle 17 basis
  2. 2SEBI — Cyber Security Operations Center for SEBI registered intermediaries (December 2018)institutional response to cyber-attack risk
  3. 3SEBI — Cyber Security & Cyber Resilience framework for Stock Brokers / Depository Participants (December 2018)extension to brokers and DPs
  4. 4SEBI — Cyber Security and Cyber Resilience framework for Portfolio Managers (March 2023)extension to portfolio managers
  5. 5SEBI — Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (August 2024)consolidated framework and Cyber Capability Index
  6. 6SEBI — IT Resilience Index for Market Infrastructure Institutions (Circular, 24 August 2026)ITRI notified for MIIs; systemic criticality of MII systems
  7. 7SEBI — Consultation Paper on Framework of IT Resilience Index for MIIs (25 March 2026)draft framework and parameters

More from this note