Why Did SEBI Chairman Say “Cooperate. Prepare. Respond.”

At the SEBI Symposium on Cyber Defence, Chairman Tuhin Kanta Pandey outlined a comprehensive cyber-resilience agenda for India’s securities market, moving the conversation from IT security and periodic compliance to collective defence, continuous preparedness, emerging technology risks and board-level accountability.

Cybersecurity is no longer an issue that can be contained within an organisation’s IT department. That was one of the clearest messages from Securities and Exchange Board of India (SEBI) Chairman Tuhin Kanta Pandey at the SEBI Symposium on Cyber Defence on August 17, 2026.

Addressing domestic participants alongside international participants from 15 IOSCO jurisdictions, Pandey described cybersecurity as an ecosystem-wide responsibility involving regulators, financial institutions, market infrastructure institutions, technology providers, academia and other participants.

Financial markets are increasingly interconnected, and a weakness in one part of the ecosystem can have consequences elsewhere. His closing message captured the direction of his address in three words: “Cooperate. Prepare. Respond.”

Far from being a rhetorical conclusion, the three words provide a framework for how the securities ecosystem needs to approach cyber risk.

The cyber threat is becoming an ecosystem risk

He began by acknowledging that measures taken by SEBI, fellow financial-sector regulators, market infrastructure institutions and regulated entities have strengthened cybersecurity and resilience across financial markets. But the threat environment is evolving faster than ever, with threats becoming increasingly interconnected and sophisticated.

Interconnectedness generates efficiency, but it also creates dependencies. An incident may begin in one organisation and travel through a vendor, technology platform, third party or connected institution.

This is why he believes the central question can no longer be limited to, “Is my organisation secure?” The more important question is, “Is the ecosystem resilient?”

That represents an important change in the risk-management lens. An institution can have robust internal controls and still be exposed to vulnerabilities elsewhere in its technology and operational chain. Cyber resilience therefore cannot be achieved entirely through individual institutional defence. It requires collective capability.

From cybersecurity to cyber resilience

His second major theme was the shift from cybersecurity to cyber resilience.

He suggested that the industry should move beyond asking whether a cyber incident will happen. The more relevant questions are how quickly it can be detected, contained and recovered from, and how quickly the lessons from the incident can be shared so another institution does not become the next victim.

Cyber resilience does not assume that systems can never be attacked. Instead, it means building the capability to anticipate, withstand, respond to, recover from and learn from an attack.

For financial institutions, this distinction is significant. The objective is not simply to build stronger walls around the organisation. It is to ensure that the organisation can continue functioning when those walls are breached.

A recovery plan cannot remain on paper

He placed considerable emphasis on incident-response and recovery planning.

Every organisation should have a clear incident-response and recovery plan, but it cannot be a plan that exists only in a document. It must be tested. Employees must know their roles, decision-making authority must be clear, and organisations must know who will isolate an affected system, communicate with regulators and stakeholders, and restore critical operations safely and quickly.

This brings leadership directly into the cyber-resilience discussion. Incident response requires leadership, preparation, coordination and clarity of responsibility.

That is also why the format of the symposium matters. Participants were to engage in workshops, tabletop exercises and real-time scenarios through a Cyber Range, alongside technology providers, researchers and industry practitioners.

He encouraged participants to use these exercises to discover where their assumptions might fail under pressure.

The distinction is important: having a response plan is not the same as being response ready.

Vulnerability management must become continuous

One of the more technically significant portions of Pandey’s speech concerned vulnerability management.

For years, the conventional process has been predictable: conduct a VAPT, identify and classify vulnerabilities, remediate them and repeat the exercise months or even a year later. Pandey described that approach as increasingly outdated.

Software, cloud configurations, APIs and third-party dependencies are changing continuously. At the same time, newer AI models are accelerating both attacks and defence. Vulnerability management therefore needs to become continuous, dynamic and risk-driven, rather than a periodic compliance exercise.

The Chairman distilled the desired approach into a five-stage cycle:

Discover. Assess. Prioritise. Remediate. Validate. Repeat.

The principle extends to patch management. Knowing about a vulnerability does not eliminate the risk if it remains unpatched for weeks or months.

He called for intelligent, risk-based and increasingly automated patch management, particularly for critical vulnerabilities, along with verification that remediation has worked.

Preparing for threats that do not yet exist

SEBI’s cyber-resilience agenda is not limited to current vulnerabilities. Pandey also highlighted risks that may not yet be fully visible today, particularly quantum computing.

SEBI has embedded quantum resilience as a core pillar of its cybersecurity and cyber-resiliency strategy, aligned with India’s National Quantum Mission. SEBI is also contributing internationally through IOSCO’s work on quantum computing capacity and preparedness.

Quantum computing could challenge some cryptographic assumptions underlying today’s digital systems. But Pandey highlighted a more immediate concern: data captured today could potentially be decrypted in the future.

This means post-quantum cryptography cannot remain a research topic for tomorrow. It needs to become a migration programme today. Financial institutions need to identify quantum-vulnerable cryptography, affected systems, applications, vendors and third parties, while assessing how long replacement would take and whether they have crypto-agility, the ability to change cryptographic algorithms without redesigning the entire system.

AI is becoming part of cyber defence, but it must be governed

He also addressed the growing role of artificial intelligence.

AI, agentic systems, automation and advanced analytics can identify anomalies, correlate intelligence, prioritise vulnerabilities, recommend actions and, where appropriately governed, initiate defensive responses.

But greater autonomy creates new risks. Pandey therefore stressed that AI for cybersecurity must itself be secure, governed and accountable.

For boards and risk committees, this introduces a new governance challenge. AI-enabled cyber defence cannot be separated from accountability, oversight and control over automated decision-making.

From individual defence to collective defence

Perhaps the most important transition in Pandey’s address was his statement that cybersecurity is no longer only an IT issue.

It is a board-level issue, a business-continuity issue, a market-integrity issue and an investor-confidence issue.

For a securities market, the implications extend beyond the organisation suffering an incident. Cyber threats do not respect organisational, regulatory or national boundaries. Consequently, the response cannot stop at those boundaries either.

If one institution learns from an attack, that learning should help protect others. If a regulator develops a successful practice, it should become a reference point for others.

Information sharing becomes a resilience capability

This philosophy is reflected in the initiatives announced at the symposium.

The revamped SEBI Incident Reporting Portal is designed to make incident reporting more structured, timely and actionable, while aligning with the FSB FIRE framework. The objective is greater uniformity and reduced friction in cross-border incident reporting.

The Cyber Suraksha Portal is intended to create a central hub for sharing cybersecurity knowledge, vulnerability warnings, policy measures and incident insights across the securities-market ecosystem.

Their real value, Pandey noted, will come from the knowledge they enable institutions to share and the action that knowledge enables.

A symposium designed to build capability

Pandey also made clear that the symposium should not become merely another industry event.

He called for participants to exchange experiences, share difficult lessons, discuss what did not work, challenge conventional thinking, understand new technologies and build relationships that remain useful after the symposium concludes.

The objective is simple: every participant should leave better prepared than when they arrived, taking back a new idea, capability or connection that strengthens organisational preparedness.

Why “Cooperate. Prepare. Respond.” matters

Pandey’s final three words bring the entire speech together.

Cooperate, because cyber threats are borderless.

Prepare, because resilience is built before an incident, not during it.

Respond, because when an incident occurs, speed, coordination and decisive action matter.

The formulation is therefore more than a cybersecurity slogan. It is a compact description of the resilience model SEBI wants the securities ecosystem to develop.

The larger message is that financial-sector cyber risk management is moving from periodic compliance towards continuous preparedness, from individual defence towards collective defence, and from technology ownership towards board-level risk ownership.

The objective is no longer simply to build systems that are difficult to penetrate. It is to build an ecosystem capable of anticipating, withstanding, responding to, recovering from and learning from cyber incidents.

That requires stronger governance, continuous vulnerability management, faster remediation, tested response plans, third-party preparedness, information sharing and forward-looking preparation for technologies such as AI and quantum computing.

Most importantly, it requires institutions to recognise that their cyber resilience is connected to the resilience of everyone around them.

That is ultimately why Pandey chose to end his address with “Cooperate. Prepare. Respond.”

The three words describe a cycle. Cooperation creates collective awareness. Preparation converts awareness into capability. Response tests that capability when an incident occurs. The lessons from that response then strengthen cooperation and preparation for the next threat.

As he concluded, AI will evolve, attack techniques will evolve and technology will evolve. The implication for India’s financial markets is clear: cyber defence must evolve faster.

For India’s securities ecosystem, the next phase of cybersecurity will therefore not be defined only by stronger technology. It will be defined by stronger preparedness, stronger governance and stronger connections between the institutions that collectively keep the market functioning.

Top