Economy

SEBI Consultation: Cyber Rules for MII Subsidiaries

SEBI Consultation: Cyber Rules for MII Subsidiaries

Why in news?

The Securities and Exchange Board of India, or SEBI, issued a consultation paper on 11 September 2026. It proposes extending relevant technology and cybersecurity requirements to certain subsidiaries of Market Infrastructure Institutions, or MIIs. Comments are invited until 2 October. The paper is a proposal for consultation, not a final rule already imposed on every subsidiary.

The institutions behind a securities transaction

Stock exchanges, clearing corporations and depositories provide essential infrastructure for securities markets. An exchange brings trading interests together under its rules. A clearing corporation calculates obligations and manages associated settlement risks. A depository maintains securities in electronic form and enables transfers through the market’s record-keeping system.

These functions are related but not interchangeable. Matching a buy order with a sell order does not itself complete every subsequent obligation. Funds and securities must still move correctly. A disruption outside the visible trading screen can therefore affect investors. The initial transaction may have appeared successful while later processing failed.

A depository is also different from a depository participant. The participant provides an interface through which customers access depository services. A broker facilitates trading, while a bank handles relevant money-account functions. Understanding these separate roles helps identify where an operational failure occurs and which institution is responsible for addressing it.

Why subsidiaries enter the discussion

Large market institutions may use subsidiaries to operate technology or related services. Corporate separation does not necessarily mean technical separation. Systems may depend on shared infrastructure, common databases or privileged access. A disruption in one entity can therefore affect services delivered by another entity within the same group.

SEBI’s proposal identifies three alternative connections that would trigger coverage. A subsidiary may perform an activity belonging to the parent MII’s domain. Alternatively, it may handle data the MII is responsible for, or share the MII’s infrastructure. Meeting any one condition would be enough under the proposed approach.

For subsidiaries meeting none of these conditions, the parent MII’s framework would not apply through this proposal. A narrower exemption route is also proposed for entities connected only by shared infrastructure. That would require a request to SEBI, compensatory safeguards and views from the relevant technology committee and board.

From cybersecurity to operational resilience

Cybersecurity seeks to protect systems and information against unauthorised access, misuse or disruption. Resilience adds the ability to withstand incidents and restore essential services. A market institution needs both. Preventing an attack is important, but so is maintaining accurate records and recovering safely when prevention fails.

SEBI’s existing Cybersecurity and Cyber Resilience Framework provides the broader regulatory context. The new paper addresses which connected subsidiaries should fall within applicable requirements. It does not create the idea of cybersecurity supervision from nothing. Nor should it be confused with an unrelated proposal about measuring technology resilience.

Business continuity concerns maintaining essential functions during disruption. Disaster recovery concerns restoring technology and data after a serious failure. Backups contribute to recovery, but are not the entire solution. Institutions must know whether restored records are accurate and whether interconnected services can resume together without creating new errors.

Why ordinary users have a stake

A trading-system outage can prevent orders from being placed or changed. A clearing problem can delay fulfilment of obligations. A record-integrity problem can create uncertainty about securities balances. These are distinct risks, but each can undermine confidence in the market infrastructure on which many participants depend.

The international Principles for Financial Market Infrastructures stress operational reliability and business continuity. They also emphasise risks arising from service providers and links between institutions. The underlying lesson is straightforward: a dependable institution must understand its dependencies. Assessing only systems owned directly by the parent leaves an incomplete risk picture.

Recovery plans therefore need testing, not merely documentation. Staff must understand responsibilities, escalation routes and the sequence for restoring services. Tests should reveal whether assumptions about outside providers are realistic. This is why technology governance belongs at board level as well as within specialist technical teams.

Balancing coverage and proportionality

The proposal’s central judgment is that regulation should follow relevant activities, data and infrastructure. Applying identical requirements to every group company could be unnecessarily broad. Excluding every separately incorporated company could leave important dependencies unchecked. The proposed criteria attempt to draw a boundary between those two situations.

For example, a teaching subsidiary with no access to market systems presents a different connection from a shared technology operator. The key question is actual access and function, not the subsidiary’s label. An institution would need to document those relationships clearly. Organisational charts alone may not reveal how services really depend on one another.

A useful consultation should test whether the criteria are clear enough for consistent application. It should also examine how exemptions would be assessed and monitored. These are implementation questions, not evidence of a newly discovered breach. The consultation paper does not announce that a specific subsidiary has suffered a cyberattack.

Conclusion

SEBI is proposing to align cybersecurity oversight with the way market groups actually use technology. The issue is the connection between a subsidiary and critical market functions. Clear coverage, justified exceptions and tested recovery arrangements would support that aim. Until the process produces final directions, the September document remains a consultation proposal.

Sources

Sign in Today’s news
Current affairs Daily news Daily quiz News Blitz Shorts Economic Survey 2025-26 Subjects
Polity Economy Geography Environment History Science & Tech Intl. Relations Internal Security Art & Culture Social Issues
All subjects Exam info UPSC Syllabus Prelims syllabus Mains syllabus Exam pattern Eligibility & attempts OBC & EWS checker Resources Free downloads Booklist 2026 Previous year papers Video notes YouTube channel