loader image
DPDPA HUB
DPDPA Compliance Deadline: 230 Days Left until 13 May 2027 GET ASSESSED →

SEBI IT Resilience Index 2026: A Complete Guide to Cybersecurity, AI Risk and Investor Protection

India’s financial markets are becoming increasingly dependent on technology. Stock exchanges, clearing corporations and depositories operate critical IT infrastructure that supports trading, clearing, settlement, market data and other essential services.

But as technology becomes more central to financial markets, IT failures and cyberattacks can create risks far beyond an individual organisation.

To strengthen the resilience of this critical infrastructure, the Securities and Exchange Board of India (SEBI) has introduced the IT Resilience Index (ITRI) framework for Market Infrastructure Institutions (MIIs) through its circular dated August 24, 2026.

The framework provides a structured and system-driven method to measure the robustness of critical IT systems and introduces mechanisms such as an Early Warning System (EWS) and real-time monitoring of service delivery.

This article explains the SEBI IT Resilience Index, its parameters, cybersecurity implications, AI-related risks, implementation timeline and importance for investors.

What Is SEBI’s IT Resilience Index(ITRI)?

The SEBI IT Resilience Index (ITRI) is a structured, system-driven framework for measuring the robustness and resilience of critical IT systems operated by Market Infrastructure Institutions.

The framework applies to:

  • Stock Exchanges
  • Clearing Corporations
  • Depositories

SEBI states that IT systems are fundamental to the smooth and uninterrupted functioning of the securities market. A disruption, degradation in performance or compromise of these systems could affect critical market operations and investor confidence.

The ITRI therefore moves beyond traditional cybersecurity compliance. It looks at whether an institution’s technology environment can remain available, secure, reliable, recoverable, scalable and operationally resilient.

Why Did SEBI Introduce the ITRI Framework?

Technology systems are the backbone of modern securities markets. A serious disruption could affect trading, clearing, settlement, market access and investor confidence.

SEBI’s framework aims to create a standardised, measurable and system-driven approach to IT resilience.

The initiative is particularly significant because modern financial infrastructure faces multiple technology risks, including:

– Cyberattacks and ransomware

– System outages

– Software and configuration failures

– Data-integrity issues

– Third-party technology dependencies

– Cloud-related risks

– Capacity and scalability problems

– Automated-system failures

– Increasingly sophisticated cyber threats

The ITRI therefore shifts the focus from simply asking whether security controls exist to asking whether critical systems are genuinely resilient.

SEBI IT Resilience Index: 9 Parameters and Their Weightage

The ITRI uses nine parameters with a total weight of 100%. Availability and Security carry the highest individual weight at 20% each.

ParameterWeightage
Availability20%
Security20%
Integrity10%
Governance10%
Reliability and Monitoring10%
Business Continuity10%
Modularity and Flexibility10%
Scalability5%
Other, including Incident Handling5%
Total100%

Availability- 20%

Availability measures whether critical IT systems and services remain operational and accessible when required. For financial markets, availability is particularly important because even a temporary disruption can affect trading, settlement and market participants.

Security- 20%

Security is another major component of the ITRI. It relates to protecting critical systems from cyber threats, unauthorised access, vulnerabilities and other security risks. The 20% weighting demonstrates the importance of cybersecurity within overall IT resilience.

Integrity- 10%

A resilient financial system must maintain the accuracy, consistency and trustworthiness of its information. Compromised data, unauthorised changes or system errors can create serious consequences even when systems remain technically available.

Governance – 10%

Technology resilience requires accountability at the management and governance level. Strong governance ensures that technology risks are identified, monitored, escalated and addressed appropriately.

Reliability and Monitoring – 10%

Continuous monitoring helps identify abnormal behaviour, performance degradation, system failures and potential technology issues before they become larger incidents.

Business Continuity – 10%

Business continuity focuses on maintaining critical operations and recovering services when systems experience disruption. Cyber resilience is incomplete if an organisation can prevent some attacks but cannot recover effectively when an incident occurs.

Modularity and Flexibility – 10%

Modern financial systems need to adapt to changing technology, market volumes and business requirements. Modular and flexible architectures can help organisations manage change while reducing technology risk.

Scalability – 5%

Financial-market infrastructure must be capable of handling changing transaction volumes and increasing technology demands. Scalability helps ensure that systems do not become unstable when demand increases.

Other Factors and Incident Handling – 5%

The final category includes other relevant resilience factors, including incident handling. This connects the ITRI with an organization’s ability to manage and respond to technology incidents.

How SEBI’s ITRI Strengthens Cybersecurity

The ITRI is important from a cybersecurity perspective because it treats cybersecurity as part of broader operational resilience. Traditional cybersecurity often focuses heavily on prevention and protection.

Resilience asks a wider set of questions:

  • Can the organisation detect an attack?
  • Can it contain the incident?
  • Can critical services continue?
  • Can systems recover quickly?
  • Can the organisation learn from the incident?

This approach is particularly relevant to financial institutions because a cyber incident affecting critical market infrastructure could have consequences beyond a single organization.

SEBI ITRI and Artificial Intelligence Risk

AI is becoming increasingly important across financial services, but it also introduces new technology risks. Importantly, AI is not a separate weighted parameter in the nine-parameter ITRI framework.

However, AI-related risks can intersect with several ITRI categories, including security, integrity, governance, reliability and monitoring.

Key AI Risks Relevant to IT Resilience

Financial organizations using AI and automation should consider risks such as :

  • AI model failure
  • Incorrect automated decisions
  • Poor-quality training data
  • Model manipulation
  • Data leakage
  • Third-party AI dependency
  • Model drift
  • Lack of explainability
  • Security vulnerabilities in AI infrastructure
  • Excessive reliance on automated decisions

This means AI governance increasingly needs to become part of broader technology-risk and resilience programs.

SEBI’s Early Warning System for IT Risks

One of the important elements of the framework is the Early Warning System (EWS).

MIIs are required to establish mechanisms that can identify deterioration in ITRI parameters and enable corrective action before problems become major disruptions.

Potential warning signals could include:

  • Increasing system latency
  • Performance degradation
  • Repeated application failures
  • Abnormal resource utilization
  • Security-control deterioration
  • Increasing incidents
  • Service interruptions
  • Unusual system behavior

The underlying principle is simple:

Detect → Investigate → Correct → Prevent escalation

Real-Time Monitoring of Market Service Delivery

SEBI’s framework also requires MIIs to build systems providing continuous visibility into service delivery to market participants.

These systems are expected to include consolidated dashboards for monitoring system and application performance, continuous service delivery, deviations and anomalies. MIIs must also establish SOPs to monitor system availability and continuity of service delivery and flag disruptions or deviations.

This is important because cybersecurity monitoring should ultimately connect with the availability and reliability of the services that investors depend upon.

Why the SEBI IT Resilience Index Matters for Investors

The ITRI is not an investment rating, and it does not guarantee that an exchange, clearing corporation or depository will never experience an outage or cyberattack.

However, stronger IT resilience can indirectly support investors through:

– More reliable trading infrastructure

– Better continuity of critical market services

– Faster detection of technology problems

– Improved incident preparedness

– Better protection of financial data

– Stronger operational resilience

– Greater confidence in digital market infrastructure

For investors, cybersecurity is increasingly becoming a component of market stability and operational reliability.

SEBI IT Resilience Index Implementation Timeline 2026–2027

SEBI’s final circular establishes a specific implementation roadmap. MIIs have already implemented a beta version of the ITRI framework.

November 30, 2026 – Finalisation of Sub-Parameters

The Industry Standards Forum (ISF) is required to finalise the detailed sub-parameters and measurement criteria for the ITRI parameters by November 30, 2026.

January 31, 2027 – Submission of SOPs

Detailed Standard Operating Procedures are to be submitted to SEBI after review by the Standing Committee on Technology (SCOT) of MIIs by January 31, 2027.

February 28, 2027 – Operationalisation

MIIs must operationalise the ITRI framework, including the Early Warning System and real-time monitoring of service delivery, by February 28, 2027.

March 31, 2027 – First ITRI Submission

The first ITRI computation under the framework will cover the half-year ending March 31, 2027.

How Frequently Will SEBI’s ITRI Be Calculated?

MIIs are required to calculate the ITRI on a half-yearly basis, within 60 days from the end of each half-year.

The framework also requires comparative analysis of two consecutive half-year periods along with observations and corrective actions. This allows technology resilience to be tracked over time rather than treated as a one-time compliance exercise.

Will ITRI Calculation Be Manual?

A key feature of SEBI’s framework is that ITRI computation is intended to be system-driven and automatic, using data from IT systems or data extracted from those systems.

The objective is to reduce manual intervention and make the measurement more consistent and objective. Where manual data retrieval is necessary, the framework provides for limited exceptions subject to discussion with the Standing Committee on Technology.

What Does SEBI ITRI Mean for CISOs and Cybersecurity Teams?

The framework has implications beyond compliance teams.

CISOs, CIOs, SOC teams, risk managers and technology committees will increasingly need to connect cybersecurity metrics with broader operational-resilience objectives.

Important areas include:

– Security monitoring

– Vulnerability management

– Incident response

– Business continuity

– Disaster recovery

– Data integrity

– Third-party risk

– System availability

– Continuous monitoring

– Technology governance

The ITRI effectively encourages organisations to measure whether their security investments are contributing to the resilience of critical services.

SEBI IT Resilience Index vs Traditional Cybersecurity

Traditional cybersecurity primarily focuses on protecting systems against threats.

IT resilience takes a broader approach.

Cybersecurity Focuses on Prevention

Cybersecurity aims to prevent unauthorised access, attacks, data breaches and compromise.

Resilience Focuses on the Full Incident Lifecycle

Resilience considers:

Prevent → Detect → Respond → Recover → Learn

This distinction is important because no security system can guarantee that every attack will be prevented.

The ability to continue and recover critical services is therefore just as important as prevention.

Why SEBI’s ITRI Is Important for India’s Financial Markets

The significance of the ITRI extends beyond individual IT departments.

Stock exchanges, clearing corporations and depositories form critical components of India’s securities-market infrastructure.

A resilient technology environment can help reduce the risk that technology disruptions develop into broader market problems.

SEBI’s approach therefore connects:

Cybersecurity + IT Operations + Business Continuity + Governance + Market Stability

That is one of the most important aspects of the new framework.

SEBI IT Resilience Index 2026 and the Future of Financial Cybersecurity

SEBI’s IT Resilience Index 2026 represents an important step in strengthening technology resilience across India’s Market Infrastructure Institutions.

The framework does not focus on cybersecurity alone. It combines availability, security, integrity, governance, monitoring, business continuity, flexibility, scalability and incident handling into a structured resilience measurement system.

Its system-driven measurement model, Early Warning System and real-time service-delivery monitoring requirements signal a shift toward continuous and proactive technology-risk management.

For cybersecurity professionals, the message is clear:

Cybersecurity is no longer only about protecting systems from attacks. It is also about keeping critical financial services available, reliable and recoverable when technology risks become reality.

For investors, stronger technology resilience can contribute to more dependable market infrastructure and greater confidence in India’s increasingly digital financial ecosystem.

Secure systems protect data. Resilient systems protect markets.

Home » SEBI IT Resilience Index 2026: A Complete Guide to Cybersecurity, AI Risk and Investor Protection

Zorixx Assistant