The Securities and Exchange Board of India (SEBI) is planning to expand its stringent IT and cybersecurity mandates to the subsidiaries of Market Infrastructure Institutions to plug regulatory gaps.

  • SEBI proposes extending IT/Cybersecurity frameworks from MIIs to their subsidiaries.
  • Applicability depends on whether subsidiaries handle MII data or share critical infrastructure.
  • MIIs can seek exemptions if they provide compensatory security controls.
  • Public comments on the proposal are open until October 2.

The Securities and Exchange Board of India (SEBI) has introduced a strategic proposal to extend the comprehensive IT and cybersecurity framework currently applicable to Market Infrastructure Institutions (MIIs) to their subsidiary companies. MIIs, which include stock exchanges, depositories, and clearing corporations, form the backbone of India's financial markets. While the parent institutions are strictly governed by SEBI's digital mandates, the regulatory jurisdiction over their subsidiaries has remained ambiguous until now.

This regulatory shift comes as MIIs increasingly diversify their business models. SEBI has observed that many MIIs utilize their subsidiaries to carry out core activities, often sharing technology infrastructure, market data, and critical IT resources. This interdependency creates a potential vulnerability; a security breach in a subsidiary could theoretically compromise the integrity of the parent MII and, by extension, the entire financial ecosystem.

Why This Matters

BozokMedia analysis shows that this move is a preemptive strike against systemic risk. In an era of high-frequency trading and digitized assets, the "perimeter" of a financial institution is no longer just its own servers but the entire network of its trusted partners and arms. By closing this loophole, SEBI ensures that there are no 'weak links' in the chain of command that could be exploited by cyber attackers.

According to the proposal, the framework will apply to any subsidiary that meets at least one of three criteria: performing activities the MII is supposed to do, handling data intended for the MII, or sharing critical IT infrastructure with the parent entity. Such subsidiaries will be required to comply with strict system audits, incident reporting protocols, and overall technology governance.

"Extending cybersecurity mandates to subsidiaries is no longer optional; it is a necessity to prevent systemic contagion in interconnected financial markets."

For MIIs that believe a specific subsidiary should be exempt—particularly those that only share infrastructure but do not handle sensitive data—SEBI has provided a path for exemption. However, this requires a rigorous application detailing "compensatory controls" to prove that the MII's overall resilience remains intact. These requests must be backed by the Standing Committee on Technology (SCOT) and the MII's board.

Did You Know?: Market Infrastructure Institutions (MIIs) are considered 'systemically important' because their failure could lead to a total collapse of the national trading system.

Frequently Asked Questions

Q1: Which institutions are classified as MIIs?
MIIs primarily include stock exchanges (like BSE and NSE), depositories (like NSDL and CDSL), and clearing corporations.

p>Q2: What happens if a subsidiary does not meet the three criteria?
If a subsidiary does not handle MII data, perform MII activities, or share infrastructure, the parent MII's IT and cybersecurity framework will not apply to it.