India’s market regulator has moved its cyber incident reporting to an international template, aligning the portal regulated firms use to flag breaches with the Financial Stability Board’s common reporting format. On its face, it is a technical change, but it points to a larger shift in how supervisors want cyber incidents described: in the same language, across borders.
In a circular dated 24 August 2026 (No. HO/(449)2026-ITD-5_DIV1/I/19448/2026), the Securities and Exchange Board of India said its Cyber Incident Reporting Portal has been aligned with the FIRE format, the Format for Incident Reporting Exchange finalised by the FSB in 2025. The change standardises the fields, definitions, and classifications that SEBI-regulated entities use when reporting a cyber incident.
What FIRE is, and why the FSB built it
FIRE is the FSB’s answer to a problem regulators have complained about for years: a firm operating across several jurisdictions can face a different incident-reporting form, a different set of defined terms and a different threshold in each one, all for the same event. The FSB finalised the format in April 2025 as a common structure that authorities can adopt to collect operational and cyber incident information in a consistent, comparable way, cutting duplicative reporting for firms and making the data more useful to supervisors. It is a template to converge on, not a binding rule.
SEBI is among the authorities now doing exactly that. By mapping its own portal to FIRE’s fields, the regulator lets an Indian market participant describe an incident in a structure that a supervisor in another FIRE-aligned jurisdiction would recognise and, over time, lets SEBI compare incidents on a like-for-like basis rather than reading each report as a bespoke narrative.
What changes for regulated entities
The obligation itself is not new. SEBI-regulated entities already report cyber incidents under the regulator’s Cybersecurity and Cyber Resilience Framework (CSCRF), and the established timelines- an initial notification by email within six hours of detecting or being notified of an incident, and reporting through the portal within 24 hours continue to apply. What changes is the report's format.
Under the aligned portal, reporting is designed to be structured and staged: an initial notification when an incident is detected, updates as the picture develops, and a final submission when the incident is closed. That staged model mirrors how mature incident-reporting regimes elsewhere are built, and it asks firms to treat a report not as a one-off form filed under time pressure but as a record maintained across the life of the incident. Compliance readers should confirm the precise field-level requirements and any transition date against the SEBI circular itself before adjusting internal playbooks.
Part of a global convergence on incident reporting
SEBI’s move does not stand alone. Operational and cyber resilience has become one of the most active fronts in financial regulation, and supervisors across regions are tightening how, and how fast, incidents must be surfaced. In Europe, ESMA has put the operational resilience of crypto-asset service providers under review, and regulators have penalised firms for weak cyber controls, as when Hong Kong’s SFC fined a broker over ransomware-related failings. In Asia, authorities such as the Monetary Authority of Singapore have stood up joint task forces on emerging cyber threats and set expectations for longer-horizon risks like quantum resilience.
Adopting a shared format is the connective tissue for all of this. If a multinational group can report the same incident once, in one structure, to multiple aligned supervisors, cross-border reporting friction falls, and the quality of the resulting data rises, which is precisely the outcome the FSB designed FIRE to produce.
Why it matters for compliance and cyber teams
For chief information security officers, operational-resilience leads, and compliance teams at SEBI-regulated entities, stock exchanges, depositories, brokers, mutual funds, and the market infrastructure institutions in between, the practical task is to re-map internal incident response runbooks to the FIRE-aligned fields now, rather than discovering the mismatch mid-incident. That means knowing which data points the portal now demands at each stage, ensuring detection-to-notification workflows can meet the six-hour and 24-hour clocks, and pre-drafting the structured artefacts a staged report requires.
For global firms, SEBI’s alignment is a signal worth reading strategically: building an internal incident record to the FIRE template, rather than to any single national form, is increasingly the efficient default, as more supervisors converge on it. Teams should treat FIRE fluency as a cross-border capability, not an India-only compliance chore.
Read the primary sources: SEBI’s circular on aligning its Cyber Incident Reporting Portal with the FIRE format and the FSB’s final FIRE report (PDF).
