The bulk of the advisory's operational substance is in Annexure-A. Ten controls, paraphrased for clarity:
1. Patch immediately, virtual-patch the rest. Update all operating systems and applications with the latest patches to mitigate identified/known vulnerabilities. Where a patch isn't available, use virtual patching (WAF rules, IPS signatures) as an interim defensive measure.
2. Regular Vulnerability Assessment & audits. Run VA using both conventional and AI-based tools where appropriate, plus security audits on a regular/continuous basis — aligned to SEBI's existing Cyber Security and Cyber Resilience Framework (CSCRF).
3. Engage third-party vendors on patch cadence. Push your third-party vendors (including empaneled application vendors providing COTS) to release timely patches. Exchanges and depositaries shall direct vendors to comprehensively assess AI-led vulnerability detection risks and implement safeguards: patches, VAPT, continuous monitoring, system hardening.
4. Change Management with teeth. Every change — even "minor" ones — must include full documentation, impact analysis, structured review, rigorous testing, and secure deployment. The intent is operational resilience and system stability; the implicit warning is that small changes are how AI-discoverable regressions creep in.
5. API Security.
- Maintain an up-to-date inventory of all APIs and the applications consuming them.
- Enforce strong authentication and authorization — least-privilege, end-user identity verification, restricted information transfer.
- Apply API rate limiting and throttling to prevent and detect abuse.
- API connections strictly on a whitelist-based approach.
6. SOC Monitoring — including the low-priority alerts.
- Vigorous day-to-day monitoring of systems and networks. Examine low-priority alerts, not just high-priority ones — AI-driven attacks often hide in the noise.
- Implement SOAR playbooks integrated with SIEM, properly tested before rollout.
- The Market SOC (M-SOC) — established by NSE and BSE — is the centralized 24×7 monitoring platform for the securities market. All eligible REs not yet onboarded must expedite onboarding.
- MIIs must run awareness and handholding workshops to make that M-SOC onboarding actually happen.
7. Risk Assessment that includes AI as a scenario. SEBI's CSCRF already mandates periodic risk assessment of REs and their third-party providers. The advisory adds: assessments must include scenario-based testing that explicitly considers AI-model capability as a risk vector — both attacker AI and defender AI failure modes.
8. System hardening with Zero Trust. Adopt secure configurations, disable unnecessary services and default accounts, enforce least-privilege, and move toward Zero Trust Network Architecture (ZTNA) to minimize attack surface.
9. Asset Inventory and SBOM. Periodically update the asset inventory and the Software Bill of Materials (SBOM) for all critical applications — explicitly including the open-source stack. AI tools weaponize known-vulnerable transitive dependencies faster than humans can; you can't defend what you can't enumerate.
10. IT-committee guidance and a long-term AI plan. MIIs and REs must seek guidance from their IT committees on mitigating AI-led VA risks. All REs must prepare a long-term plan for the use of AI in:
- Detection
- Autonomous / agentic mitigation
- Risk recalibration for AI-accelerated threats
- AI-augmented SOC transformation
- Continuous vulnerability management with AI tools