Introduction
The Securities and Exchange Board of India (SEBI) has launched the Cybersecurity and Cyber Resilience Framework (CSCRF) for bettering the cybersecurity of financial institutions.
As cyber threats and supply chain attacks rise, SEBI is focusing on two key areas – Software Bill of Materials (SBOM) and AI governance. This is a move away from traditional cybersecurity to full visibility and control of software and AI systems.

What is SEBI CSCRF?
SEBI CSCRF is a cybersecurity framework for regulated financial entities. It assists organizations in:
Avoid cyber incidents
Setting defensive benchmarks to stop attacks before they breach the perimeter.
Identify security vulnerabilities early
Discovering structural weaknesses before they are targeted.
Respond appropriately to attacks
Mitigating breaches effectively with well-defined response plans.
Recover systems fast
Rebuilding systems and restoring user trust immediately following an event.
Keep cyber resilience ongoing
Ensuring long-term security posture through continuous vigilance.
It follows international cybersecurity practices and improves overall security governance.
