Financial sector must build collective resilience to tackle cyber risks, says Sebi chief Pandey

/ 2 min read
AI Hub

According to Tuhin Kanta Pandey, the key question for financial-sector entities is no longer whether a cyber incident will occur, but how quickly they can detect, contain and recover from one. 

Tuhin Kanta Pandey, Chairman, Sebi.
Tuhin Kanta Pandey, Chairman, Sebi. | Credits: Nishikant Gamre

Securities and Exchange Board of India (Sebi) Chairman Tuhin Kanta Pandey on Monday called for greater cooperation among regulators, financial institutions, technology companies and other stakeholders to strengthen cyber resilience across the financial sector, warning that cyber threats are becoming increasingly interconnected and sophisticated. 

Speaking at the Sebi-promoted National Institute of Securities Markets (NISM), Pandey said the focus of cybersecurity must move beyond protecting individual organisations to building resilience across the wider financial ecosystem. “The question is no longer simply: Is my organisation secure? The more important question is: Is the ecosystem resilient?” Pandey said. 

He said that the interconnected nature of the financial system creates dependencies, meaning a cyber incident at one organisation can have consequences far beyond it through vendors, technology platforms, third-party service providers or other connected institutions. 

According to Pandey, the key question for financial-sector entities is no longer whether a cyber incident will occur, but how quickly they can detect, contain and recover from one. He also stressed the importance of sharing lessons from cyber incidents so that other institutions can strengthen their defences. 

Sebi pushes for continuous vulnerability management 

He said the traditional cycle of conducting vulnerability assessment and penetration testing, identifying vulnerabilities, remediating them and repeating the exercise months or a year later is increasingly outdated as software, cloud configurations, APIs and third-party dependencies change continuously. 

The growing use of artificial intelligence is also accelerating both cyberattacks and defence, making it necessary for organisations to continuously discover, assess, prioritise, remediate, and validate vulnerabilities. 

Recommended Stories

Pandey highlighted the need for risk-based and increasingly automated patch management, particularly for critical vulnerabilities, along with verification that remediation measures have actually worked. 

Sebi flags quantum computing risks 

Pandey said Sebi has made quantum resilience a core part of its cybersecurity and cyber-resilience strategy, aligned with the government's National Quantum Mission. 

While quantum computing could create significant opportunities across science, technology and finance, it could also challenge the cryptographic systems underpinning today's digital infrastructure, he said. 

The risk, Pandey stated, extends beyond the point when sufficiently powerful quantum computers become available. Data captured today could potentially be decrypted in the future using quantum capabilities. Hence, he called for post-quantum cryptography to be treated as a migration programme rather than a future research exercise. Financial-sector organisations, he said, need to identify systems dependent on quantum-vulnerable cryptography, assess their third-party dependencies and determine how quickly those systems can be replaced. 

Most Powerful Women In Business 2026
View Full List >

Pandey also highlighted the importance of “crypto-agility”—the ability to change cryptographic algorithms without having to redesign an entire system. 

AI can strengthen cyber defence, but creates new risks 

Pandey said emerging technologies such as AI, agentic systems, automation and advanced analytics could transform cyber defence by helping organisations identify anomalies, correlate intelligence, prioritise vulnerabilities and recommend defensive action. However, greater automation also brings new risks. AI systems used for cybersecurity themselves need to be secure, governed and accountable, he said. 

“Cybersecurity is no longer only an IT issue,” Pandey said, adding that it is also a board-level, business-continuity, market-integrity and investor-confidence issue. Sebi launches initiatives for faster incident reporting and information sharing 

Pandey also highlighted two initiatives launched by Sebi to strengthen collective cyber resilience across the securities-market ecosystem. The revamped Sebi Incident Reporting Portal is designed to make incident reporting more structured, timely and actionable, while aligning with the Financial Stability Board's Format for Incident Reporting Exchange (FIRE). The alignment is expected to improve uniformity and reduce friction in cross-border incident reporting.

NEXT STORY