Sebi chairman says cyber defence must move from IT issue to boardroom priority

Sebi Chairman Tuhin Kanta Pandey said cybersecurity must evolve into board-level cyber resilience, requiring continuous vulnerability management, tested recovery plans and risk-based patching. He also urged financial institutions to begin migratin...

Agencies

Sebi’s Tuhin Kanta Pandey urged financial institutions to strengthen cyber resilience through continuous risk management, tested recovery plans and post-quantum security preparedness.

Sebi Chairman Tuhin Kanta Pandey on Monday said cybersecurity can no longer be treated as only an IT issue and must be seen as a board-level, business-continuity and market-integrity concern. Speaking at Sebi Symposium on Cyber Defence on August 17, Pandey said the financial market ecosystem has become deeply connected, and a weakness in one institution can spread through vendors, technology platforms, third parties or other connected entities.

"The question is no longer simply: Is my organisation secure? The more important question is: Is the ecosystem resilient?" Pandey said.

The symposium brought together domestic participants and international delegates from 15 jurisdictions within IOSCO. Pandey said cyber resilience now depends on a wider ecosystem, including regulators, financial institutions, academia, technology institutions, market infrastructure institutions and regulated entities.


He said the cyber threat landscape is changing faster than ever, with attacks becoming more interconnected and sophisticated. Because of this, the focus has to move from cybersecurity alone to cyber resilience.

According to Pandey, organisations should assume that cyber incidents can happen and prepare for how quickly they can detect, contain and recover from them. He said every institution should have a clear incident response and recovery plan that has been tested, not one that exists only on paper.

Such plans must answer practical questions, including who takes decisions during an incident, who isolates affected systems, who communicates with regulators and stakeholders, and how critical operations are restored safely and quickly.
ADVERTISEMENT

Pandey said vulnerability management also needs a change in approach. The old model of conducting vulnerability assessment and penetration testing, fixing issues and repeating the exercise after months or a year is no longer enough.

“Today, vulnerabilities, software, cloud configurations, APIs and third-party dependencies are changing continuously,” he said.

He said vulnerability management must become continuous, dynamic and risk-driven instead of being treated as a periodic compliance exercise. The cycle should be to discover, assess, prioritise, remediate, validate and repeat.

Patch management was another key area flagged by the Sebi chairman. He said knowing about a vulnerability is not enough if it remains unpatched for weeks or months. Institutions need risk-based and increasingly automated patch management, especially for critical vulnerabilities, along with verification that remediation has worked.
ADVERTISEMENT

Pandey also said Sebi has embedded quantum resilience as a core pillar of its cybersecurity and cyber resilience strategy, in line with India’s National Quantum Mission.

He said quantum computing may challenge some of the cryptographic assumptions on which today’s digital systems are built. The concern, he said, is not only about a future powerful quantum computer, but also about data that can be captured today and decrypted later.
ADVERTISEMENT

“That is why post-quantum cryptography cannot remain a research topic for tomorrow. It has to become a migration programme for today,” Pandey said.

He said financial-sector organisations need to identify where they use quantum-vulnerable cryptography, which systems and vendors depend on it, and whether they have crypto-agility, or the ability to change cryptographic algorithms without redesigning the entire system.
ADVERTISEMENT
READ MORE

READ MORE:

LOGIN & CLAIM

50 TIMESPOINTS

More from our Partners

Loading next story
Business News › Markets › Stocks › News › Sebi chairman says cyber defence must move from IT issue to boardroom priority
Text Size:AAA
Success
This article has been saved

*

+