SEBI tightens IT oversight of market infrastructure institutions with new resilience index

Prop traders lead India’s derivatives market as retail investors lose over ₹72,000 crore


Markets regulator SEBI has introduced a new framework to measure the resilience of technology systems at stock exchanges, depositories and clearing corporations, seeking to identify potential weaknesses before they translate into disruptions for market participants.

The IT Resilience Index (ITRI) will give market infrastructure institutions (MIIs) a standardised measure of the health of their technology systems. The index will be based on nine parameters, with availability and security carrying the highest weightage of 20% each.

Integrity, governance, reliability and monitoring, business continuity, and modularity and flexibility will each account for 10% of the score. The remaining 10% will be split between scalability and other aspects, including incident handling.

Alongside the index, MIIs will set up an Early Warning System (EWS) to track deterioration in individual parameters and flag signs of system slowness, performance issues or potential service disruptions.

The framework is currently in its beta phase. SEBI has directed MIIs to make the ITRI operational, along with the EWS and real-time monitoring of service delivery, by February 28, 2027.

The first assessment will cover the six months ended March 31, 2027. Thereafter, MIIs will calculate the index every half-year and submit the results within 60 days of the period-end. The submission will include a comparison with the previous half-year and details of corrective measures already taken or planned.

The index is intended to be largely automated, with SEBI seeking to make the scoring process objective and comparable across institutions. Any parameter that cannot be computed automatically will require the exception to be discussed with the MII’s Standing Committee on Technology before manual data is collected.

The Information Systems Framework will set the baseline parameters, acceptable thresholds and standard operating procedures for calculating the index.

In a separate move, SEBI has also aligned its cyber incident reporting portal with the Financial Stability Board’s Format for Incident Reporting Exchange (FIRE) framework.

The alignment will introduce a common structure for reporting cyber incidents, including standardised fields and classifications. Regulated entities will be able to update reports as an incident develops, from the initial notification through subsequent updates and final closure.

SEBI said the measures are intended to improve the monitoring of technology systems, strengthen service continuity and enable faster identification and resolution of emerging IT and cyber risks.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *