Business News
.png)
3 min read | Updated on August 17, 2026, 12:43 IST
SUMMARY
The SEBI chief warned that cyber incidents can spread through vendors, cloud platforms, third parties and interconnected institutions, making ecosystem-wide resilience more important than individual security.

SEBI chairman Tuhin Kanta Pandey was addressing SEBI’s Symposium on Cyber Defence.
Cyber attacks are no longer a question of "if" but "when", SEBI Chairman Tuhin Kanta Pandey said on Monday, calling for greater preparedness and collective resilience across the financial ecosystem.
Addressing SEBI's Symposium on Cyber Defence, Pandey said the cyber threat landscape was evolving rapidly, with attacks becoming more interconnected and sophisticated.
"So, the question before us is perhaps no longer whether a cyber-incident will happen. The more relevant question is: When it happens, how ready are we?" he said.
Pandey said financial institutions must focus on how quickly they can detect, contain and recover from a cyber attack, and how effectively they can share lessons from an incident to prevent other institutions from becoming victims.
He said cyber resilience should not be about assuming that systems can never be attacked, but about building the ability to anticipate, withstand, respond to, recover from and learn from an attack.
Every organisation should have a clear incident response and recovery plan that is regularly tested, he said.
“A plan in which people know their roles. A plan that answers very practical questions: Who takes the decision when an incident occurs? Who isolates the affected system? Who communicates with the regulators and other relevant stakeholders?” Pandey said.
The SEBI chief also stressed that cyber risks could spread beyond individual organisations because of the interconnected nature of financial markets.
"An incident may begin with one organisation, but the impact may travel through a vendor, a technology platform, a third party or a connected institution," he said.
"The question is no longer simply: Is my organisation secure? The more important question is: Is the ecosystem resilient?"
Pandey said vulnerability management also needed to move away from periodic compliance exercises towards continuous and risk-based processes.
Vulnerabilities in software, cloud configurations, APIs and third-party dependencies were changing continuously, while newer AI models were accelerating both cyber attacks and defence, he said.
"Vulnerability management too must become continuous, dynamic and risk-driven, rather than a periodic compliance exercise," he said.
Pandey called for intelligent and increasingly automated patch management, along with rapid deployment and verification that remediation had worked.
He also flagged the risks posed by quantum computing and said post-quantum cryptography should no longer be treated as a research topic for the future.
"The concern is also about data that can be captured today and potentially decrypted in the future. That is why post-quantum cryptography cannot remain a research topic for tomorrow. It has to become a migration programme for today," he said.
He also said artificial intelligence, agentic systems, automation and advanced analytics would change the way cyber defence is conducted.
"Cybersecurity is no longer only an IT issue. It is a board-level issue. It is a business-continuity issue. It is a market-integrity issue. It is an investor-confidence issue," Pandey said.
Pandey said cyber threats did not respect organisational, regulatory or national boundaries and called for greater cooperation among regulators, financial institutions, technology providers and other stakeholders.
"Cooperate. Prepare. Respond," he said, outlining the three principles that should guide cyber defence.
The symposium is being attended by international participants from 15 jurisdictions within the International Organization of Securities Commissions (IOSCO), besides domestic participants from the financial sector, technology and academia.
Pandey said the objective was to ensure that participants left with new ideas, capabilities and connections that would strengthen preparedness across the financial ecosystem.
About The Author
.png)
Next Story