See Full Document Text
परिपत्र / CIRCULAR
HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026 05.05.2026
To,
प्रति,
All Alternative Investment Funds (AIFs)
सभी ऑल्टिनेटटव इनवेस्टमेंट फंड )एआईफ(
All Bankers to an Issue (BTI) and Self-
सभी बकैं ि टू इश्य ू औि सल्े फ-सटटिफाइड ससडं ीकेट
Certified Syndicate Banks (SCSBs)
बकैं )एससीएसबी(
All Clearing Corporations
सभी क्लीयरिगं कािपोिेशन
All Collective Investment Schemes (CIS)
सभी कलेक्क्टव इनवेस्टमेंट स्कीमें )सीआईएस(
सभी क्रेडडट िेटटगं एजेंससया ाँ )सीआिए( All Credit Rating Agencies (CRAs)
सभी कस्टोडडयन All Custodians
All Debenture Trustees (DTs)
सभी डडबेंचि ट्रस्टी )डीटी(
All Depositories
सभी डडपॉक्िटिी
All Designated Depository Participants
सभी डसे सग्नेटेड डडपॉक्िटिी पाटटिससपेंट )डीडीपी(
(DDPs)
सभी डडपॉक्िटिी पाटटिससपेंट )डडपॉक्िटिीि के All Depository Participants through
Depositories
जरिए(
All Investment Advisors (IAs) / Research
सभी ननवेश सलाहकाि )आईए( / अनसु धं ान
Analysts (RAs)
ववश्लेषक )आिए(
सभी केवाईसी िक्जस्ट्रेशन एजेंससयााँ )केआिए( All KYC Registration Agencies (KRAs)
सभी मचेंट बकैं ि )एमबी( All Merchant Bankers (MBs)
सभी म्यचू ुअल फंड )एमएफ( / असेट मनै ेजमेंट All Mutual Funds (MFs)/ Asset Management
Companies (AMCs)
कंपननयााँ )एएमसी(
All Portfolio Managers
सभी पोटिफोसलयो प्रबधं क
सभी िक्जस्ट्राि टू इश्य ू औि शये ि ट्रांसफि एजेंट All Registrar to an Issue and Share
Transfer Agents (RTAs)
)आिटीए(
All Stock Brokers through Exchanges
सभी स्टॉक ब्रोकि )एक्सचेंजों के जरिए(
सभी स्टॉक एक्सचेंज All Stock Exchanges
सभी वेंचि कैवपटल फंड )वीसीएफ( All Venture Capital Funds (VCFs)
पष्ृ ठ स.ं 1 (कुल पष्ृ ठ 7) Page 1 of 7महोदय/महोदया, Dear Sir/Madam,
Subject: Advisory on Emerging Advanced
ववषय: खासमयों )वल्निेबबसलटी( का पता लगाने के
Artificial Intelligence (AI) Tools
सलए आए नए-नए एडवांस्ड एआई टूल for Vulnerability Detection (like
)जैसे Mythos( के सबं धं में एडवाइििी
Mythos)
A. The rapid evolution of emerging
क. खाममयों (वल्नरेबिमलटी) का पता लगाने वाले
technologies including AI-driven
नए-नए एआई टूल (जैस े Claude Mythos)
vulnerability identification tools (E.g.
आने लग े हैं, जजनकी िदौलत ववननयममत
Claude Mythos) has introduced new
(रेग्यलू ेटेड) एटं टटटयों के सामने नए-नए
dimensions of risks for Regulated Entities.
जोखखमों की आशकं ाएँ पदै ा हो रही हैं । जैसा
Such tools may give rise to heightened risk
कक ये टूल िड़ी तजे ़ी से और िड े पमै ाने पर
exposure by enabling identification and
काम करत े हैं, तो यह ममु ककन है कक इनकी
िदौलत जोखखमों की आशकं ा भ़ी काफी िढ़ potential exploitation of existing
जाए । इसके अलावा, यह भ़ी ममु ककन है vulnerabilities using speed and scale. It
कक डाटा की गोपऩीयता भ़ी खतरे में आ जाए,
may also introduce concerns relating to
ऐजललकेशन की ववश्वसऩीयता पर भ़ी सवाल
data confidentiality, application integrity
खडा हो, और तो और उसके नत़ीजों को लेकर
and reliability of outputs.
भ़ी भरोसा न हो ।
B. Due to the interconnectedness and
ख. जैसा कक मसक्यरू रटीज़ माकेट की समचू ़ी
interdependency of market participants in
व्यवस्था में सभ़ी माकेट पाटटिमसपेंट्स का
the Securities Market Ecosystem, a
एक-दसू रे से सरोकार भ़ी रहता है और उनकी
periodic coordinated approach for
एक-दसू रे पर ननभरि ता भ़ी रहत़ी है, इस़ीमलए
vulnerability management, information
यह जरूरी है कक इनकी खाममयों
sharing and monitoring/assessment is
(वल्नरेबिमलटी) को दरू करने, जानकारी एक-
दसू रे से साझा करने और इन पर नज़र रखन े required to prevent a cascading impact.
/ इनका आकलन करने के मलए एक साझा
प्रयास ककया जाए, ताकक कहीं ऐसा न हो कक
ककस़ी एक जगह या ककस़ी एक पर अगर आचँ
आए तो उसका असर ताश के पत्तों की तरह
दसू री जगह या दसू रों पर भ़ी बिखरता नज़र
आए ।
पष्ृ ठ स.ं 2 (कुल पष्ृ ठ 7) Page 2 of 7C. In view of the above, a task force, namely
ग. उपरोक्त के मद्देनज़र, एक काय-ि दल (टास्क
cyber-suraksha.ai, (email id: project-
फोस)ि , जजसका नाम cyber-suraksha.ai है
(ईमेल आईड़ी: project-cyber- cyber-suraksha.ai@sebi.gov.in) has been
suraksha.ai@sebi.gov.in) िनाया गया है, constituted comprising representatives
जजसमें MIIs, QRTAs, सभ़ी QREs और दसू रे from MIIs, QRTAs, all QREs, and other
related stakeholders with the following
सिं धं ित स्टेकहोल्डस ि के प्रनतननधियों को
शाममल ककया गया है । इस काय-ि दल के mandate to:
मख्ु य काय ि इस प्रकार हैं:
i. िारीकी से यह जाँचना कक एआई वाल े i. Closely examine the cybersecurity risks
मॉडल से साइिर सरु क्षा को लेकर क्या- posed by AI based models and devise a
क्या जोखखम हो सकत े ह ैं और ऐस े मॉडल uniform mitigation strategy against the
की वजह से पदै ा हो सकन े वाले जोखखमों risks posed by such models.
से ननपटने के मलए एकसमान ऩीनत
ननिाररत करना ।
ii. अगर ककस़ी खतरे की आशकं ा की कोई ii. Facilitate sharing of threat intelligence,
best practices on vulnerability
जानकारी ममले, तो उस े साझा करना;
management, use cases and playbooks
खाममयों (वल्नरेबिमलटी) को दरू करने के
to respond to the threat vector etc.
मलए अपनाए जाने वाले िहे तरीन तरीकों
की जानकारी साझा करना; यह जानकारी
साझा करना कक खतरों से कैसे ननपटा
जाए।
iii. मसक्यरू रटीज़ माकेट में साइिर सरु क्षा की iii. Report on a priority basis, cyber
incidents or malicious activities,
व्यवस्था को और पख्ु ता करने के मलहाज
से साइिर हमलों की, गडिड़ी की हो रही significant attack vectors, information
कोमशशों की या िड े हमलों की तत्काल on vulnerabilities etc. that may be
सचू ना देना, खाममयों (वल्नरेबिमलटी) आटद relevant to strengthen the cyber security
की तत्काल सचू ना देना । posture of the securities markets.
iv. यह सम़ीक्षा करना कक थड ि पाटी ऐललीकेशन iv. Review the cyber security posture of the
third party application service providers
सववसि प्रोवाइडस ि (सचू ़ी में शाममल वेंडरों
including empaneled vendors.
सटहत) के यहाँ साइिर सरु क्षा की व्यवस्था
कैस़ी है ।
पष्ृ ठ स.ं 3 (कुल पष्ृ ठ 7) Page 3 of 7D. A meeting of the task force cyber-
घ. Mythos जैस े एआई ललेटफॉम ि की वजह स े
suraksha.ai was convened (with MIIs and
पदै ा हो सकने वाल े जोखखमों की सम़ीक्षा करन े
QRTAs) to review the risks posed by AI
और उनसे ननपटने के मलए उठाए जाने वाल े
platforms like Mythos and discuss the
कदमों के िारे में चचाि करने के मलए MIIs
mitigation measures. Based on the
और QRTAs के साथ काय-ि दल (टास्क फोस)ि
consultation with the said task force, an
cyber-suraksha.ai की एक िठै क िलु ाई गई
advisory is enclosed at Annexure-A.
थ़ी । काय-ि दल (टास्क फोस)ि की इस िठै क
में हुए ववचार-ववमश ि के आिार पर, एक
एडवाइज़री सलं ग्नक-क )Annexure-A) के
रूप में सलं ग्न है ।
E. This advisory should be read in
ङ. इस एडवाइज़री के साथ-साथ सेि़ी के लाग ू
conjunction with the applicable SEBI
पररपत्रों (सकुिलस)ि [जजनमें साइिर सरु क्षा और
circulars (including but not limited to
साइिर हमलों से ननपटने की क्षमता के ढाचँ े
Cybersecurity and Cyber Resilience
के सिं िं में जारी ककया गया पररपत्र शाममल
framework) and any subsequent updates
है] और सेि़ी द्वारा िाद में समय-समय पर
issued by SEBI from time to time.
ककए जाने वाल े अपडटे पर भ़ी अवश्य गौर
ककया जाए ।
च. यह पररपत्र (सकुिलर) भारत़ीय प्रनतभनू त और
F. This circular is issued in exercise of
powers conferred under Section 11 (1) of
ववननमय िोड ि अधिननयम, 1992 (सेि़ी एक्ट,
the Securities and Exchange Board of
1992) की िारा 11(1) [जो मसक्यरू रटीज़
India Act, 1992, to protect the interests of
माकेट में ननवेश करने वाले ननवेशकों के टहतों
investors in securities and to promote the
की रक्षा करने और मसक्यरू रटीज़ माकेट के
development of, and to regulate the
ववकास को िढ़ावा देने और उसे ववननयममत
(रेग्यलू ेट) करने स े सिं धं ित है] के तहत प्रदान securities market.
की गई शजक्तयों का प्रयोग करत े हुए जारी
ककया जा रहा है ।
भवदीया Yours Faithfully,
ममता िॉय Mamata Roy
उप महाप्रबंधक
Deputy General Manager
दिू भाष / Phone: 022-26449599
ईमेल / Email: mamtar@sebi.gov.in
पष्ृ ठ स.ं 4 (कुल पष्ृ ठ 7) Page 4 of 7Annexure-A
1. Update all operating systems and applications with the latest patches on
immediate basis to mitigate any identified/known vulnerabilities. As an interim
measure for the vulnerabilities where patches are not available, virtual patching
can be considered for protecting systems and networks.
2. Conduct Vulnerability Assessment (Using conventional and suitable AI based
Vulnerability Assessment Tools where possible) and undertake security audits
on a regular/continuous basis in accordance with Cyber Security and Cyber
Resilience Framework of SEBI.
3. Engage with the respective RE’s third party vendors to release timely patches
and deploy them appropriately. Exchanges and Depositaries shall direct their
empaneled application vendors (providing COTS solution to respective
members) to undertake comprehensive assessment of the risks arising from the
use of AI-led vulnerability detection models. Based on the assessment, vendors
shall implement appropriate safeguards including updating patch, VAPT,
continuous monitoring, hardening measures etc.
4. Change Management: Any change in the systems (including minor changes)
should encompass full documentation, thorough impact analysis, structured
review, rigorous testing and secure deployment to ensure operational resilience
and system stability.
5. API Security:
a) Inventory of all APIs and the applications using the APIs should be updated
regularly.
b) Ensure strong authentication and authorization mechanisms to enable
secure verification of end-user client identity as well as limit the information
access/ transfer to users/ systems based on least privilege.
c) API rate limiting and throttling to prevent and detect abuse.
d) Connections through APIs to be strictly on a whitelist-based approach.
पष्ृ ठ स.ं 5 (कुल पष्ृ ठ 7) Page 5 of 76. SOC Monitoring:
a) Regular day-to-day monitoring of the systems and networks must be carried
out vigorously. SOC alerts should be adequately examined including the
low-priority alerts.
b) Implement enhanced security orchestration and Automated Response
(SOAR) playbooks integrated with Security Incident and Event
Management (SIEM) solutions, after thorough testing wherever feasible.
c) The Market SOC (M-SOC), established by NSE and BSE, which serves as
a centralized security platform, provides 24x7 real-time monitoring and
threat detection across digital infrastructure. In the view of enhanced risks
posed by AI-driven attacks, all eligible REs (not on boarded with any M-
SOC) shall expedite the onboarding.
d) MIIs are required to conduct awareness and handholding programs,
including periodic workshops to ensure a smooth onboarding process and
integration with M-SOC.
7. Risk Assessment: The Cyber Security and Cyber Resilience Framework
(CSCRF) of SEBI has mandated periodic Risk Assessment of the REs including
their Third Party Service Providers to enhance visibility and conduct a
reasonably accurate assessment of the overall cybersecurity risk posture. Risk
assessment shall include comprehensive scenario-based testing for assessing
risks (including both internal and external risks) related to cybersecurity in REs’
IT environment. The capability of AI based models may also be considered as
one of the risk scenarios.
8. Implement system hardening by adopting secure configurations, disabling
unnecessary services and default accounts, and enforcing solutions like least
privilege, Zero Trust Network (ZTNA) to minimize the attack surface.
9. Periodically update Asset Inventory and Software Bill of Materials for all critical
applications including open source stack.
पष्ृ ठ स.ं 6 (कुल पष्ृ ठ 7) Page 6 of 710. MIIs and other Regulated Entities shall seek guidance from their respective IT
committees for mitigating risks emanating from AI-led vulnerability detection
models. Further, all REs need to prepare a long-term plan for usage of AI in
detection and autonomous/agentic mitigation. Also, undertake other measures
including recalibration of risks for AI accelerated threats, AI augmented SOC
transformation, and continuous vulnerability management using AI tools.
**********************
पष्ृ ठ स.ं 7 (कुल पष्ृ ठ 7) Page 7 of 7