← All posts

Cyber incident? RAs must report it — SEBI's portal now uses the FIRE format

Many Research Analysts assume cyber rules are only for big firms. They're not. RAs and IAs are Regulated Entities under SEBI's Cybersecurity & Cyber Resilience Framework (CSCRF), and reporting a cyber incident is a real obligation. SEBI has now aligned its Cyber Incident Reporting Portal with the FIRE format — here's what that means for you.

SEBI Circular: “Alignment of SEBI's Cyber Incident Reporting Portal with FIRE Format”
Circular No.: HO/(449)2026-ITD-5_DIV1/I/19448/2026  ·  Date: 24 August 2026
Read the official circular on SEBI →

Yes — this applies to Research Analysts

  • RAs & IAs are Regulated Entities (REs) under SEBI's CSCRF. The framework applies to you, in a category proportionate to your size.
  • Cyber-incident reporting is central to CSCRF. If you suffer a cyber incident (breach, ransomware, data leak, account compromise, etc.), you're expected to report it to SEBI — via SEBI's Cyber Incident Reporting Portal — and to CERT-In, and then do a root-cause analysis once contained.
  • This new circular is about how those reports are captured — SEBI's portal is now aligned to the FIRE format (a standardised incident-report format), so reporting is consistent across entities.

The two reporting “clocks”

CERT-InWithin 6 hours of detection for specified incident types (CERT-In's April 2022 directions under the IT Act).
SEBI / CSCRFReport to SEBI (or your exchange/depository) within the CSCRF timelines, via the portal — now in the FIRE format — followed by root-cause analysis.

What RAs should do

  • Know your CSCRF category and the baseline requirements that apply to you.
  • Keep a simple incident-response plan: who detects, who reports, and where (SEBI portal + CERT-In), so you can act within hours — not days.
  • Practise basic cyber hygiene: MFA on email/portals, strong unique passwords, updated devices, backups, and access control for client data.
  • If your KYC/records/website are run through a vendor, confirm they support timely incident detection & reporting.
  • When you report, use the current portal / FIRE format as specified in the circular.

References & official sources

SEBI — Alignment of Cyber Incident Reporting Portal with FIRE Format (24 Aug 2026)SEBI SEBI — CSCRF for Regulated Entities (framework & clarifications)CSCRF CERT-In — cyber incident reporting (6-hour directions)CERT-In
This is a plain-English summary of the 24 Aug 2026 SEBI circular and the broader CSCRF framework. The exact reporting timelines, formats and your applicable CSCRF category are set out in the official SEBI circulars — read them on sebi.gov.in and confirm before acting.

More for SEBI Research Analysts

RA Sahayak is free & ad-free. A small UPI tip keeps it maintained. 😊

Disclaimer

This post is a plain-English awareness summary, compiled with the help of AI. It is for general information only and is not legal, compliance, tax, or investment advice. It paraphrases the circular's subject and the broader CSCRF framework, not its exact wording.

Always read the full official SEBI circular and the CSCRF, and confirm your applicable category, reporting timelines and formats from the official sources (sebi.gov.in / cert-in.org.in), or consult a qualified professional, before acting. RA Sahayak is a free, non-commercial resource and is not affiliated with SEBI, BSE, CERT-In or any regulator.