SEBI’s Cyber Defence Symposium Continues in Mumbai With Financial-Market Resilience in Focus

The Securities and Exchange Board of India’s five-day Symposium on Cyber Defence continued on August 18 with hands-on cybersecurity exercises aimed at strengthening the ability of financial-market institutions to detect, respond to and recover from cyber incidents. Running from August 17 to 21 at the National Institute of Securities Markets campus near Mumbai, the programme brings cybersecurity professionals together for practical simulations, red-team and blue-team exercises, incident-response training and discussions on emerging threats. The initiative reflects SEBI’s growing emphasis on treating cyber resilience as a core requirement for protecting market integrity and ensuring continuity across India’s increasingly technology-dependent securities ecosystem. (NISM)

SEBI Cyber Defence Symposium Enters Second Day

The August 18 programme shifts the symposium from its opening sessions into intensive practical cybersecurity exercises.

Hands-On Cybersecurity Exercises Dominate Day Two

SEBI has designated August 18 as the symposium’s hands-on cybersecurity exercise day.

The programme includes practical cyber exercises during the morning and afternoon, followed by red-team and blue-team activities and a Capture the Flag challenge.

These exercises are designed to move participants beyond theoretical cybersecurity discussions.

Financial institutions need teams capable of recognising an attack while it is unfolding, isolating affected systems and restoring services safely.

Simulation-based training allows cybersecurity professionals to practise those decisions in controlled environments without putting real financial infrastructure at risk.

The format reflects the reality that successful cyber defence depends not only on technology but also on how quickly people respond when systems are under pressure. (NISM)

Cyber Range Provides Realistic Training Environment

The symposium uses a Cyber Range platform to create simulated attack environments.

Cyber ranges allow security professionals to encounter realistic scenarios while protecting production systems from actual damage.

Participants can practise defensive techniques, incident investigation and recovery procedures.

SEBI is also incorporating classroom sessions and tabletop exercises during the broader programme.

Combining these formats can strengthen both technical and managerial preparedness.

Technical teams need to understand how to contain attacks, while senior decision-makers need to coordinate communications, business continuity and regulatory responses.

Cybersecurity Becomes Financial-Market Stability Issue

India’s securities ecosystem has become deeply dependent on interconnected digital systems.

Markets Depend on Continuous Technology Availability

Modern capital markets cannot operate effectively without technology.

Stock exchanges use sophisticated electronic trading platforms.

Depositories maintain digital records of securities ownership.

Clearing corporations process and settle enormous numbers of transactions.

Brokers provide mobile and online trading systems.

Mutual funds, portfolio managers and other intermediaries depend on digital platforms for customer transactions and regulatory processes.

This interdependence creates extraordinary efficiency.

It also means cyber incidents can have consequences extending far beyond a single affected company.

A disruption at an important technology provider or market intermediary can potentially affect connected organisations and investors.

Cyber Defence Is More Than an IT Function

SEBI Chairman Tuhin Kanta Pandey used the opening of the symposium to emphasise that cybersecurity should be viewed as a board-level concern connected with business continuity and market integrity, rather than simply as an operational IT matter. (The Economic Times)

This distinction has important governance implications.

Senior management cannot delegate the entire responsibility for cyber resilience to technology teams.

Boards need to understand critical systems, major vulnerabilities and recovery capabilities.

They also need to ensure sufficient financial resources are allocated to cybersecurity.

When financial infrastructure is digital, cyber resilience becomes part of the institution’s fundamental operating resilience.

Financial Ecosystem Creates Systemic Cyber Risk

The increasing connectivity of financial institutions means vulnerabilities can spread across organisational boundaries.

Third-Party Providers Expand Attack Surface

Financial companies increasingly depend on outside technology providers.

Cloud platforms host applications.

Software vendors provide business systems.

Cybersecurity companies monitor infrastructure.

Payment providers, data vendors and telecommunications companies support everyday operations.

Each connection creates potential operational dependencies.

A financial institution can maintain strong internal security but still experience disruption because an important vendor is compromised.

This makes third-party cyber risk an increasingly important concern for regulators.

Institutions need to understand not only their own security posture but also the resilience of companies supporting critical functions.

One Weak Link Can Affect Multiple Institutions

Cyber attackers frequently target the least protected part of a network rather than confronting the strongest security controls directly.

Compromising a vendor connected to numerous financial institutions can create access to several targets simultaneously.

Supply-chain attacks therefore present a particularly serious threat to financial markets.

Regulators increasingly expect institutions to conduct due diligence on service providers and maintain contingency plans for vendor outages.

The objective is to ensure that disruption affecting one participant does not escalate into broader market instability.

Incident Response Receives Strong Focus

Preventing every cyberattack is unrealistic, making response capability equally important.

Institutions Need Tested Incident Playbooks

SEBI’s symposium is designed to help participants create and operationalise incident-handling playbooks.

A playbook establishes predetermined actions for different types of cyber incidents.

If ransomware is detected, for example, teams need to know which systems should be isolated.

If customer data may have been compromised, legal and regulatory teams need defined escalation procedures.

If trading infrastructure fails, business-continuity processes need to activate rapidly.

Planning these steps before a crisis reduces uncertainty when an actual incident occurs.

Recovery Is Part of Cyber Resilience

Cyber defence does not end when an attack has been stopped.

Systems must be restored safely.

Data integrity needs to be verified.

Compromised credentials may need replacement.

Organisations also need to understand how attackers entered and whether additional vulnerabilities remain.

Recovery planning therefore becomes a central part of resilience.

SEBI’s programme specifically includes training on threat detection, incident-response workflows and recovery planning. (NISM)

Red Teaming Tests Security Defences

The symposium’s practical exercises include red-team and blue-team activities.

Red Teams Simulate Attackers

A red team attempts to breach systems using techniques similar to those employed by real attackers.

Its objective is not to cause damage but to discover weaknesses before criminals exploit them.

Red teams can test network security, employee behaviour and incident-response processes.

They can attempt phishing, privilege escalation and other simulated techniques under controlled conditions.

The exercise provides organisations with a realistic assessment of whether existing defences work when actively challenged.

Blue Teams Defend Systems

Blue teams operate on the defensive side.

They monitor networks, identify suspicious activity and attempt to prevent attackers from reaching critical systems.

Successful defence requires rapid detection.

An attacker who remains unnoticed inside a network can potentially access additional systems and collect information.

Blue-team exercises therefore help participants practise analysing alerts and responding under time pressure.

Combining red and blue teams creates a more realistic representation of the constantly changing relationship between cyber attackers and defenders.

Capture the Flag Builds Practical Skills

The August 18 programme also includes a Capture the Flag cybersecurity challenge.

Participants Solve Simulated Security Problems

Capture the Flag competitions present participants with technical security challenges.

Teams may need to discover vulnerabilities, analyse systems or obtain information hidden within simulated environments.

The objective is educational rather than malicious.

Participants learn how security weaknesses can be identified and exploited, improving their understanding of how real attackers operate.

This attacker perspective can help defenders design stronger controls.

Cybersecurity Skills Require Continuous Practice

Cyber threats evolve rapidly.

Techniques effective against yesterday’s attack may not be sufficient against tomorrow’s threat.

Security professionals therefore need continuous training.

Hands-on exercises provide experience that cannot be replicated through written policies alone.

The symposium’s practical format reflects this requirement by placing participants inside simulated cyber incidents rather than limiting the programme to presentations.

Artificial Intelligence Creates New Cyber Challenges

The symposium will move into sessions examining emerging technology risks on August 19.

AI Can Strengthen Cyberattacks

Artificial intelligence can make malicious activity more scalable.

Attackers can generate convincing phishing messages quickly.

Automated systems can search networks for vulnerabilities.

Synthetic voice and video technologies can support sophisticated impersonation attempts.

AI can also help attackers modify malware and social-engineering strategies.

Financial institutions therefore need security systems capable of responding to attacks that are increasingly automated and personalised.

AI Can Also Strengthen Defence

The technology is not exclusively beneficial to attackers.

Cybersecurity teams can use machine learning to identify unusual network behaviour.

Automated systems can prioritise alerts.

AI tools can help analysts investigate large volumes of security information.

SEBI’s symposium schedule includes a session on red teaming using AI tools and a panel discussion around emerging cyber challenges linked to disruptive technologies. (NISM)

The emerging security environment is therefore becoming a contest in which both attackers and defenders use increasingly sophisticated automation.

Quantum Resilience Enters Financial-Market Discussion

The programme also includes a dedicated session on quantum resilience.

Future Quantum Computers Could Challenge Encryption

Modern financial systems depend heavily on encryption.

Sensitive customer information, authentication systems and digital communications all use cryptographic protections.

Large-scale quantum computers could eventually undermine some conventional encryption techniques.

Commercially capable systems able to break widely used encryption are not yet generally available.

However, financial institutions operate technology and data systems that may remain in use for many years.

Preparing early can therefore reduce future transition risk.

Migration to New Cryptography Takes Time

Replacing cryptographic infrastructure across a major financial organisation is not a simple software update.

Institutions need to identify where encryption is used.

Applications and devices may require modification.

Third-party vendors also need compatible systems.

This is why regulators and cybersecurity professionals increasingly discuss post-quantum resilience well before quantum computing becomes an immediate operational threat.

SEBI including quantum resilience within the symposium demonstrates that financial-market cybersecurity planning is extending beyond current attacks toward longer-term technological risks. (NISM)

Blockchain Security Also Forms Part of Programme

Distributed-ledger technology creates another specialised security domain.

Blockchain Does Not Eliminate Cyber Risk

Blockchain systems are sometimes described as inherently secure because distributed ledgers can make historical records difficult to alter.

However, applications built around blockchain can still contain vulnerabilities.

Smart contracts can have coding errors.

Private keys can be stolen.

Interfaces connecting blockchain systems with conventional infrastructure can be attacked.

Financial organisations exploring distributed-ledger technology therefore still require strong cybersecurity governance.

Security Must Cover Entire Technology Stack

A secure core protocol cannot compensate for vulnerabilities elsewhere.

Users access digital systems through devices.

Applications communicate through APIs.

Data travels across networks.

Administrators hold credentials with elevated privileges.

Attackers can target any of these layers.

SEBI’s scheduled session on applied blockchain security reflects the need to evaluate emerging financial technologies as complete operational systems rather than relying on assumptions about individual technologies. (NISM)

Tabletop Exercises Test Leadership Response

The symposium will move into broader incident-response simulations on August 20.

Senior Teams Need Crisis Coordination Skills

Cyber incidents can quickly become organisational crises.

Technology teams may need to isolate systems.

Executives need to decide whether services should be temporarily suspended.

Legal teams assess disclosure obligations.

Communications teams respond to customers and media.

Regulators may require immediate reporting.

These decisions need coordination.

Tabletop exercises simulate a developing crisis and ask participants to make decisions as new information appears.

The objective is to reveal weaknesses in communication and responsibility before a real incident occurs.

CERT-In and IIT Bombay Participate in Simulation Track

The August 20 programme includes a market CISO tabletop exercise track involving a cyberattack AI simulation by IIT Bombay and a tabletop exercise flow involving CERT-In, according to the official programme. (NISM)

Collaboration between regulators, technical institutions and cybersecurity agencies can strengthen preparedness because major incidents often require coordinated responses across organisational boundaries.

Financial-market cyber resilience cannot be achieved by institutions operating entirely independently.

SEBI Cybersecurity Framework Raises Compliance Expectations

The symposium complements SEBI’s broader regulatory focus on cybersecurity and cyber resilience among regulated entities.

Financial Firms Need Structured Cyber Governance

Cybersecurity programmes need formal ownership, documentation and monitoring.

Institutions must identify critical assets.

They need access controls.

Systems should be patched and monitored.

Incident-response capabilities require periodic testing.

Backups need protection from attackers.

The objective is to build resilience throughout the technology lifecycle rather than adding security only after systems are deployed.

Smaller Entities Also Need Resilience

Large exchanges and financial institutions possess significant cybersecurity budgets.

Smaller intermediaries can have more limited resources.

Yet they remain connected to the wider securities ecosystem.

Attackers may deliberately target these organisations if they believe security is weaker.

Regulatory frameworks therefore need to accommodate differences in organisational scale while still maintaining minimum resilience standards.

The ecosystem is only as secure as the network of organisations supporting it.

Investor Protection Depends Increasingly on Cybersecurity

Cyber incidents can create direct financial and personal risks for investors.

Customer Data Is Valuable to Criminals

Brokerages and financial intermediaries hold substantial quantities of sensitive information.

Customer identities, account details, transaction histories and contact information can all be valuable to criminals.

Stolen information can support fraud or impersonation.

Protecting this data is therefore a fundamental component of investor protection.

Cybersecurity failures can undermine trust even when no securities or money are directly stolen.

Trading Accounts Can Become Targets

Attackers may attempt to compromise individual trading accounts.

Phishing messages can trick investors into revealing credentials.

Malicious applications can capture passwords.

Fraudsters can impersonate brokers or regulators.

Financial institutions therefore need both strong technical controls and investor education.

Multi-factor authentication, transaction alerts and monitoring can help reduce risks.

Stock Exchanges Require Exceptional Resilience

Market infrastructure institutions occupy a particularly important position within the securities ecosystem.

Trading Disruption Can Have Systemic Consequences

A temporary outage at an ordinary business affects its customers.

A major outage at a stock exchange can affect an entire market.

Investors may be unable to trade.

Brokers can face operational problems.

Price discovery can be disrupted.

This makes business-continuity planning essential.

Cybersecurity controls must therefore be supported by resilient backup systems and disaster-recovery capabilities.

Recovery Sites Need Regular Testing

Backup infrastructure is useful only when it works during an emergency.

Financial-market institutions need periodic tests demonstrating that systems can transition from primary infrastructure to recovery environments.

Cyberattacks can create a particularly difficult scenario because organisations must determine whether backup systems have also been compromised.

Recovery procedures need to preserve both availability and data integrity.

Cybersecurity Spending Is Becoming Strategic Investment

Financial firms increasingly need to view security expenditure as essential infrastructure.

Cost of Major Breach Can Exceed Prevention Spending

A serious cyberattack can generate multiple costs.

Operations may be interrupted.

Customers may need compensation.

Systems require forensic investigation and restoration.

Regulatory consequences can follow.

Reputational damage can drive customers toward competitors.

Investment in prevention and preparedness can therefore be economically rational even when the immediate financial return is difficult to measure.

Boards Need Cyber Expertise

Directors do not need to become cybersecurity engineers.

They do need enough understanding to evaluate management’s preparedness.

Boards should know which systems are most critical.

They should understand major dependencies and recovery capabilities.

Clear reporting can help directors monitor security risk similarly to credit, liquidity or operational risk.

The broader message emerging from SEBI’s symposium is that cyber defence is becoming part of financial governance rather than a specialised back-office responsibility.

India’s Digital Market Growth Raises Security Stakes

The expansion of online investing has increased the volume and importance of financial technology infrastructure.

Millions of Investors Depend on Digital Platforms

Retail participation in Indian securities markets has expanded substantially.

Investors increasingly open accounts digitally, receive information through mobile applications and execute trades online.

The convenience has helped broaden capital-market participation.

It simultaneously increases reliance on continuously available and secure technology.

A large digital user base also gives cybercriminals more potential targets.

Market Growth Requires Trust

Financial markets depend heavily on confidence.

Investors need to believe that account information is protected.

They need confidence that trades will be processed correctly.

Market participants need assurance that settlement systems will continue operating during disruptions.

Cyber resilience therefore supports market development itself.

A secure financial system can encourage greater digital participation, while repeated security failures could undermine adoption.

Symposium Continues Through August 21

SEBI’s programme extends beyond the August 18 hands-on sessions.

Technology Discussions Follow Practical Exercises

August 19 will focus on technology sessions and expert panels covering incident reporting, blockchain security, AI-related cyber threats, quantum resilience and AI-assisted red teaming.

August 20 will feature cybersecurity paper presentations, tabletop exercises and a technology exhibition.

The symposium concludes on August 21 with a closing ceremony and demonstrations.

The five-day structure combines technical training with policy, research and operational discussion. (NISM)

Capacity Building Is Central Objective

NISM describes the programme as targeting junior- to mid-level cybersecurity professionals and officials heading information-security functions.

The symposium is intended to strengthen practical competencies around threat detection, incident response, recovery, live-fire exercises and cyber-range simulations. (NISM)

Developing these capabilities across a wider group of professionals is particularly important because cybersecurity expertise remains scarce relative to demand.

Conclusion

SEBI’s Symposium on Cyber Defence continuing in Mumbai on August 18 reflects the regulator’s increasingly operational approach to strengthening cybersecurity across India’s financial markets.

The second day moves participants into hands-on exercises, red-team and blue-team simulations and a Capture the Flag challenge, while subsequent sessions will examine AI-driven threats, blockchain security, quantum resilience and large-scale incident response.

The broader objective extends beyond protecting individual companies. India’s exchanges, depositories, brokers, clearing corporations and other financial institutions operate through an interconnected digital ecosystem in which disruption can spread quickly.

As capital markets become more technologically sophisticated, cyber resilience is becoming inseparable from business continuity, investor protection and market integrity. SEBI’s five-day programme signals that preparing people and institutions to respond effectively to real cyber incidents is now becoming as important as building technological defences designed to prevent them.