The Securities and Exchange Board of India has proposed extending its cyber security framework to encompass subsidiaries of Market Infrastructure Institutions that share data and technical infrastructure with exchanges. The regulatory move aims to fortify the securities market against evolving digital threats.
The Securities and Exchange Board of India moves to extend strict information technology and cyber security frameworks to subsidiaries of market infrastructure institutions.
The Securities and Exchange Board of India (SEBI) has proposed extending its comprehensive cyber security and cyber resilience mandates to specific subsidiaries of Market Infrastructure Institutions (MIIs). Announced through regulatory consultation channels in September 2026, the framework addresses potential vulnerabilities arising from data sharing and technological infrastructure linkages between stock exchanges, clearing corporations, depositories, and their auxiliary entities. The initiative is designed to plug operational gaps where auxiliary service providers handle critical market data without being subject to the same stringent digital defense audits as parent bourses.
Securing Interconnected Market Infrastructure
Modern financial architecture increasingly relies on subsidiary entities to execute specialized data processing, software development, and administrative support functions. According to regulatory documents reviewed by SEBI, vulnerabilities originating in loosely regulated auxiliary firms can expose primary trading platforms to sophisticated cyber threats.
The proposed expansion mandates that any subsidiary sharing infrastructure, databases, or network access with an MII must comply with rigorous protocols. These include real-time threat monitoring via a Security Operations Centre (SOC), mandatory vulnerability assessments, penetration testing (VAPT), and strict data localization standards. Market participants and technology risk specialists have been invited to review the compliance metrics and provide formal feedback.
Impact on Institutional Compliance and Market Integrity
For institutional investors, listed entities, and retail market participants, closing digital blind spots across auxiliary exchange operations strengthens overall market stability. Ensuring uniform cyber resilience prevents malicious actors from exploiting weaker peripheral nodes to compromise core settlement and trading systems.
According to official regulatory releases and enforcement updates published by the Securities and Exchange Board of India (SEBI) and major bourses like the National Stock Exchange of India (NSE) and the Bombay Stock Exchange (BSE), public consultations on the framework remain open.
"According to officials, extending robust information technology and cyber security standards to MII subsidiaries is vital to safeguard the digital backbone of the national securities market."
Key Facts at a Glance
Regulatory Authority: Securities and Exchange Board of India (SEBI).
Core Proposal: Extending cyber security frameworks to subsidiaries of Market Infrastructure Institutions (MIIs) that handle shared data and infrastructure.
Target Entities: Auxiliary technology, data processing, and administrative arms of stock exchanges and depositories.
Key Mandates: Real-time threat monitoring, rigorous VAPT, and unified compliance reporting.
Frequently Asked Questions
Why is SEBI proposing cyber rules for MII subsidiaries? To eliminate security vulnerabilities in auxiliary firms that share data and technical infrastructure with primary stock exchanges and depositories.
What entities qualify as Market Infrastructure Institutions? MIIs include stock exchanges, clearing corporations, and depositories registered under SEBI.
Where can stakeholders access the official consultation papers? Regulatory updates and discussion documents are hosted on the Securities and Exchange Board of India Official Portal.
How does this framework protect market participants? By ensuring that every connected subsidiary maintains strict digital defense standards, reducing the risk of systemic technical outages or data breaches.
Source: Securities and Exchange Board of India (SEBI), National Stock Exchange of India (NSE), Bombay Stock Exchange (BSE)