Skip to content

SEBI Cybersecurity Framework India: 7 Engineering Checks for Fintech

For Indian fintechs, complying with the SEBI cybersecurity framework is non-negotiable. This guide breaks down the engineering requirements, helping founders and CTOs build robust, resilient systems that meet regulatory standards and protect sensitive financial data.

By Krapton Engineering9 min readSecurity

In India's rapidly expanding financial markets, fintech innovation is booming. However, this growth comes with increased scrutiny, especially from regulators like the Securities and Exchange Board of India (SEBI). For Indian founders, CTOs, and product leaders in start-ups, SMEs, and even global capability centres (GCCs) operating in the capital markets, understanding and implementing the SEBI Cybersecurity Framework is not just a compliance checkbox; it’s a foundational requirement for trust and market participation. A single breach can erode investor confidence and trigger significant penalties, making proactive security engineering indispensable.

TL;DR: The SEBI Cybersecurity Framework mandates specific engineering practices for Indian fintechs, brokers, and other market intermediaries. Key areas include robust access controls, secure network architecture, continuous vulnerability management, comprehensive incident response, and strong third-party risk management. Prioritise these to build cyber-resilient systems, ensure regulatory compliance, and safeguard sensitive financial data.

Key takeaways

Detailed view of a padlock securing a metal gate with a chain, emphasizing safety and security.
Photo by Larkin Hammond on Pexels
  • The SEBI Cybersecurity Framework (as updated in 2023) is a critical compliance and security mandate for all regulated entities in India's capital markets.
  • Engineering teams must focus on implementing multi-factor authentication, granular access controls, network segmentation, and encryption for data at rest and in transit.
  • Proactive measures like regular VAPT (Vulnerability Assessment and Penetration Testing) and a robust Secure Development Lifecycle (SDLC) are non-negotiable.
  • A well-defined incident response plan, aligned with both SEBI and CERT-In reporting timelines, is crucial for minimising breach impact.
  • Vendor risk management and supply chain security are integral, demanding due diligence on third-party integrations and dependencies.

Understanding the SEBI Cybersecurity Framework in India

A close-up of a padlock securing a wire fence, symbolizing protection and safety.
Photo by Connor Scott McManus on Pexels

The SEBI (Cyber Security and Cyber Resilience) Regulations, 2018, along with subsequent circulars and master circulars (most recently March 2023), establish a comprehensive framework for Market Infrastructure Institutions (MIIs), Stock Brokers, Depository Participants (DPs), Investment Advisers (IAs), and other regulated entities. The goal is to ensure cyber resilience against evolving threats, protecting investor assets and market integrity. For fintechs building trading platforms, investment apps, or advisory tools, this means embedding security from design to deployment.

Unlike the broader Digital Personal Data Protection Act 2023 (DPDP Act) which focuses on personal data, SEBI's framework specifically targets the operational and transactional security of financial market participants. It addresses everything from network security and access control to incident management and business continuity planning. Our team often finds that while founders are aware of DPDP, the granular engineering requirements of SEBI can be overlooked, leading to compliance gaps.

When NOT to Prioritise Every SEBI Guideline Simultaneously

For early-stage Indian fintech start-ups, a 'big bang' approach to SEBI compliance can be overwhelming and cost-prohibitive. Instead, prioritise critical controls that address the highest risks and are fundamental requirements. Focus on data encryption, strong authentication, and a basic incident response plan first. More advanced measures like sophisticated SIEM deployments or extensive red-teaming can be phased in as your organisation scales and secures further funding. This doesn't mean ignoring requirements, but strategically sequencing their implementation based on risk and resource availability.

Architecting for Cyber Resilience: Core Principles

Building for SEBI compliance isn't about patchwork fixes; it demands a strategic, security-first architectural approach. This means adopting principles like defence-in-depth, least privilege, and zero trust. Every component, from your React Native mobile app to your backend microservices, must be designed with security boundaries in mind.

Defence-in-depth: Implement multiple layers of security controls, so if one fails, others can still protect your assets. Think firewalls, intrusion detection systems, application-level security, and data encryption. For example, a web app might have a WAF, strong input validation, and a robust API gateway, preventing a single point of failure.

Zero Trust: Never implicitly trust any user, device, or network inside or outside your perimeter. Always verify. This involves strong identity verification, device health checks, and granular access policies for every resource. This is particularly crucial for fintechs handling sensitive transactions, where internal threats can be as damaging as external ones.

Implementing Robust Access Control and Identity Management

One of the most common vulnerabilities our engineers encounter is weak access control. SEBI mandates stringent controls over who can access what, and how. This goes beyond simple passwords.

  • Multi-Factor Authentication (MFA): Mandatory for all administrative access and highly recommended for all user accounts. In India, this often involves OTPs via SMS or email, or authenticator apps.
  • Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC): Implement granular permissions. A developer should not have production database access unless absolutely necessary and for a limited time. A customer service agent only needs access to customer data relevant to their query, not all financial records.
  • Privileged Access Management (PAM): Solutions to manage, monitor, and audit superuser accounts. These accounts are prime targets for attackers.
  • Regular Access Reviews: Periodically review and revoke access rights, especially for employees who have changed roles or left the organisation.

On a production rollout for an investment platform, our team measured a significant reduction in potential breach surface after implementing fine-grained RBAC and enforcing MFA across all internal tools. This required careful mapping of roles and permissions, but the security uplift was substantial.

Secure Network Architecture and Data Protection

Your network is the lifeline of your fintech operations. SEBI expects strong network segmentation, robust perimeter defences, and comprehensive data protection measures.

  • Network Segmentation: Isolate critical systems (e.g., trading engines, customer databases) from less sensitive ones (e.g., marketing websites, internal HR systems). Use VLANs, subnets, and firewalls to control traffic flow.
  • Firewalls and Intrusion Detection/Prevention Systems (IDS/IPS): Essential for monitoring and blocking malicious traffic.
  • Data Encryption: Encrypt sensitive data both at rest (e.g., database encryption, encrypted storage volumes) and in transit (e.g., TLS 1.2+ for all communications). This is also crucial for compliance with RBI's payment data localisation mandates for any payment data you handle.
  • DDoS Protection: Implement measures to mitigate Distributed Denial of Service attacks, ensuring service availability.

For web applications, secure HTTP headers are a low-cost, high-impact way to enhance client-side security. For example, a Content Security Policy (CSP) can prevent XSS attacks.

# Nginx example for secure headers
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
add_header X-Frame-Options "DENY";
add_header X-Content-Type-Options "nosniff";
add_header Referrer-Policy "no-referrer";
add_header Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline' example.com; style-src 'self' 'unsafe-inline'; img-src 'self' data:; connect-src 'self' api.example.com; font-src 'self';";

Proactive Vulnerability Management and Secure Development Lifecycle (SDLC)

Security isn't an afterthought; it's an integral part of your development process. SEBI expects continuous efforts to identify and remediate vulnerabilities.

  • Vulnerability Assessment and Penetration Testing (VAPT): Regular VAPT by CERT-In empaneled auditors is mandatory. This includes both your applications and infrastructure.
  • Secure Development Lifecycle (SDLC): Integrate security into every phase of development: requirements, design, coding, testing, and deployment. This includes threat modelling, static application security testing (SAST), dynamic application security testing (DAST), and dependency scanning for open-source libraries.
  • Security Training: Ensure your developers are regularly trained on secure coding practices, covering common vulnerabilities like those in the OWASP Top 10.
  • Dependency Management: Actively monitor and update third-party libraries and frameworks (e.g., npm packages, Python libraries) to mitigate supply chain risks.

In a recent client engagement, we helped an Indian fintech integrate SAST tools into their CI/CD pipeline. This caught several critical vulnerabilities early in the development cycle, significantly reducing the cost and effort of remediation compared to finding them during a pre-production pentest. Krapton offers dedicated development teams that embed these security practices from day one.

Incident Response and Reporting: Beyond the 6-Hour Window

No system is 100% immune to attacks. SEBI, much like CERT-In, places significant emphasis on robust incident response and timely reporting. While CERT-In mandates a six-hour reporting window for significant cyber incidents, SEBI has its own specific reporting requirements for market intermediaries.

  • Incident Response Plan (IRP): Develop, test, and regularly update a comprehensive IRP. This should detail roles, responsibilities, communication protocols, and escalation paths.
  • Log Retention and Monitoring: Collect and retain logs from all critical systems for a specified period (typically 12-18 months as per CERT-In directions). Implement a Security Information and Event Management (SIEM) system to centralise logs, detect anomalies, and trigger alerts.
  • Breach Reporting: Understand SEBI's specific reporting channels and timelines for cyber incidents, which may differ from CERT-In. Ensure your IRP accounts for both. This isn't legal advice; always refer to the official CERT-In and SEBI guidelines.
  • Forensics Readiness: Design your systems to facilitate forensic investigations, ensuring logs are immutable and contain sufficient detail.

Our experience shows that many Indian organisations struggle with effective log correlation across disparate systems. Investing in a robust SIEM solution, even an open-source one like ELK Stack (Elasticsearch, Logstash, Kibana), can dramatically improve detection and response capabilities for the SEBI cybersecurity framework India expects.

Vendor Risk Management and Supply Chain Security

Modern fintechs rely heavily on third-party services, from cloud providers to payment gateways and analytics tools. Each vendor introduces a potential attack vector. SEBI's framework mandates robust vendor risk management.

  • Due Diligence: Conduct thorough security assessments of all third-party vendors, especially those handling sensitive data or critical operations. Request their security certifications (e.g., ISO 27001, SOC 2) and audit reports.
  • Contractual Agreements: Ensure service level agreements (SLAs) include specific cybersecurity clauses, incident reporting obligations, and data protection responsibilities.
  • API Security: If integrating with third-party APIs, ensure secure authentication (OAuth 2.0, API keys), input validation, and rate limiting are in place.
  • Software Bill of Materials (SBOM): Maintain an SBOM for your applications to track all open-source and commercial components, facilitating rapid response to new vulnerabilities in your supply chain.

Managing third-party risk is a continuous process. For an Indian D2C brand integrating multiple payment gateways and logistics partners, we implemented a centralised vendor security assessment workflow, standardising security questionnaires and continuous monitoring. This ensures that their secure web app builds remain robust even with complex integrations.

FAQ

What is the SEBI Cybersecurity Framework?

It's a set of regulations and guidelines from the Securities and Exchange Board of India (SEBI) aimed at enhancing cyber security and resilience for entities operating in the Indian capital markets, including brokers, DPs, and fintechs. It outlines mandatory controls and practices to protect financial systems and investor data.

How does SEBI’s framework differ from the DPDP Act 2023?

The DPDP Act 2023 is a general data privacy law for all personal data. SEBI's framework is sector-specific, focusing on the operational and transactional security of financial market intermediaries. While there's overlap in protecting data, SEBI's scope is narrower and deeper for its regulated entities.

What are the penalties for non-compliance with SEBI cybersecurity rules?

Non-compliance can lead to significant penalties, including monetary fines, suspension of operations, and reputational damage. The exact penalties depend on the severity and nature of the violation, as determined by SEBI's enforcement actions.

Do small fintech start-ups in India need to comply with SEBI cybersecurity?

Yes, if your fintech operations fall under SEBI's definition of a regulated entity (e.g., a stock broker, depository participant, or investment adviser), compliance is mandatory regardless of size. Scalability in compliance can be achieved through a phased approach, but core requirements remain.

Get a security-minded engineering team

Navigating the complexities of the SEBI Cybersecurity Framework requires deep technical expertise and a proactive approach. At Krapton IT Consultancy Pvt Ltd, we specialise in building secure, compliant, and high-performance applications for Indian and international businesses. Whether you need to secure your trading platform, ensure data protection for your investment app, or integrate robust incident response, our experienced engineers are here to help. Share your project brief with Krapton to build cyber-resilient financial technology.

About the author

Krapton Engineering comprises principal-level software engineers and security strategists with years of hands-on experience building and securing complex web, mobile, and SaaS applications for fintechs, D2C brands, and enterprises across India and globally, ensuring compliance with regulations like SEBI and DPDP.

  • application security
  • fintech security
  • SEBI
  • India
  • cyber resilience
  • regulatory compliance
  • devsecops
  • incident response
  • data security
  • capital markets

Building something in India? Let’s talk.

Tell Krapton what you want to build and get a clearly scoped plan, team and starting point.