On April 25, 2026, India's Union Finance Minister, Nirmala Sitharaman, addressed the Securities and Exchange Board of India (SEBI) and the nation's financial sector, urging them to significantly bolster their cyber defenses against a new wave of advanced threats. The minister warned that a single successful cyberattack on a major exchange or broker could destabilize the market, erase substantial wealth, and shatter public confidence. She specifically identified the use of Artificial Intelligence (AI) to automate and scale attacks, the proliferation of deepfake technology for investment scams, and the spread of fraudulent advice by financial influencers ('fin-fluencers') as key areas of concern. In response, she launched "Mission Jagrook," a national campaign to enhance investor awareness and digital safety.
The Finance Minister's address serves as a high-level directive to SEBI and all regulated entities to proactively enhance their cybersecurity posture. While not a new law, it signals a strong regulatory focus on cyber resilience within India's capital markets. The speech endorsed SEBI's existing Cybersecurity and Cyber Resilience Framework, which became operational in April 2025, as a foundational element but stressed the need for continuous evolution to counter emerging threats.
The core of the message was a shift from reactive defense to proactive preparation for highly sophisticated, AI-driven attacks. This implies that regulators will expect market participants to demonstrate capabilities in threat hunting, real-time anomaly detection, and resilience against attacks designed to evade traditional security measures.
This directive affects the entire Indian financial ecosystem, including:
While specific new rules were not announced, the speech implies that SEBI will be pushing for stricter adherence and enhancement of existing frameworks. Key compliance areas highlighted include:
The call to action is immediate. The SEBI Cybersecurity and Cyber Resilience Framework has been operational since April 2025, and the expectation is for continuous improvement. "Mission Jagrook" was launched on April 25, 2026, and is expected to roll out nationwide.
The business impact of this regulatory focus will be an increase in compliance costs for financial institutions as they invest in advanced cybersecurity technologies like AI-powered threat detection, deepfake detection services, and more robust security operations centers. Firms will need to allocate more resources to cybersecurity training, not just for employees but also for customers. Failure to keep pace with regulatory expectations could result in penalties, reputational damage, and a loss of market share. For the broader market, a successful push for stronger defenses could increase stability and investor confidence in the long term.
Although not explicitly stated, failure to adhere to SEBI's cybersecurity mandates can result in financial penalties, operational restrictions, and public reprimands. The minister's statement that a single breach could "shake public confidence" suggests that regulators will take a hard line on institutions found to be negligent in their cybersecurity duties.
Financial institutions in India should take the following tactical steps:
The 'Mission Jagrook' campaign is a direct application of this mitigation, aimed at educating investors to recognize and avoid fraud.
SEBI's framework mandates regular audits and monitoring for financial institutions to ensure compliance and detect threats.
Implementing advanced behavior-based detection is necessary to counter the AI-driven threats mentioned by the minister.
SEBI's Cybersecurity and Cyber Resilience Framework became operational.
Finance Minister Nirmala Sitharaman delivered a keynote address at SEBI's 38th Foundation Day and launched 'Mission Jagrook'.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
Help others stay informed about cybersecurity threats