Skip to main content

Red Teaming and SEBI CSCRF

What the Cyber Security and Cyber Resilience Framework asks of regulated entities, where adversarial testing sits within it, and how the tiering decides how much applies to you.

By Siddarth G
August 19, 2026 Last updated 7 min read

If SEBI regulates you, start with your tier. CSCRF classifies regulated entities, and the classification decides how much of the framework applies to you.

Tier before requirement

CSCRF sorts regulated entities into categories by size and significance, and the parameters differ by entity type. What classifies a stock broker is not what classifies an asset manager. An organisation reading the framework without first establishing its own classification will over- or under-read almost every obligation in it.

Read the thresholds against the April 2025 clarifications, not the master circular on its own. A classification settled earlier can put an entity in the wrong band, and every downstream obligation inherits the error. If your tier was fixed before those clarifications and nobody has revisited it since, that is the first piece of work, ahead of any testing decision.

PR.IP.S16 shows how much turns on the band. It requires ISO 27001 certification for Market Infrastructure Institutions. For Qualified REs the August 2025 clarifications restated it as encouraged and recommended. Same provision, same framework, and the weight it carries changes with where you sit.

Security Brigade maintains the entity-by-entity reading: SEBI CSCRF.

Where adversarial testing sits

The framework's own name carries both halves: cyber security and cyber resilience, the ability to withstand, respond to and recover from an incident. Adversarial exercises sit closer to the resilience half, because what they measure is response, not the presence of a vulnerability.

Routine testing is part of the programme you are assessed on: the clarifications direct regulated entities to submit summaries of their VAPT and cyber audit reports. An adversarial exercise sits alongside that work, and a red team run in place of the testing programme satisfies nothing.

The reverse is the more interesting gap: an entity meeting every testing interval has established what is broken and nothing about whether anyone would notice an intruder who got past it. No cadence reaches that question, however diligently met. That is the argument for the exercise, and it is a risk argument, not a compliance one.

What the amendments did to the testing language

The technical clarifications of 28 August 2025 softened DE.CM.S3 guideline 3.c and dropped the acronyms BAS and CART from the instrument. The provision now reads that it is recommended REs consider deploying a range of security solutions in consultation with their IT Committee, such as threat simulation, vulnerability management and decoy systems.

That changes how you read a proposal. A vendor selling a continuous automated red teaming or breach and attack simulation platform on the authority of CSCRF is citing an acronym the instrument no longer carries. The tooling may still be a sensible purchase on its merits; the compliance argument for it has gone. See adversary simulation and breach and attack simulation for what those platforms reach and what they leave alone.

It also tells you who signs. A recommendation routed through the IT Committee is a governance decision with a minute against it, not a line item a security manager approves alone. Budget the committee cycle into the timeline.

Exclusivity, Equivalence and the group problem

Most Indian financial groups of any size hold more than one licence. A bank with a broking arm and an asset manager sits under the RBI for one entity and SEBI for another, and the security team is usually one team serving all of them.

CSCRF handles that with two principles. Exclusivity: the framework applies to the SEBI-regulated activity, not to everything the group does. Equivalence: where another regulator's framework covers the same ground, a duplicate exercise can be avoided, on a mapping you can show control by control.

So one exercise can serve two regulators, but only if scope is drawn against the regulated activity before it starts and the mapping is written in advance. A provider can write scope that maps cleanly. The mapping is yours to own and to defend.

The RBI side is asymmetric. Its 2026 Directions treat red teams permissively, at ¶162 for commercial banks and in the equivalent paragraphs for small finance banks, payments banks and credit information companies. The urban co-operative bank and NBFC instruments do not use the phrase, and no instrument sets a frequency: red teaming under the RBI's 2026 Directions.

What sits outside the scope, and how much of it there is

This is where SEBI-regulated buyers get the largest surprise. A broker's order flow, a depository participant's back office, an asset manager's registrar and transfer agent, the exchange connectivity: much of the stack that matters is operated by somebody else. You cannot authorise testing of a system you do not control, and no provider should offer to test one on your say-so.

The exercise stops at that boundary and the report should record where it stopped. What remains testable on your own side is more than it first looks:

  • The credentials your staff hold into the vendor's platform, and how easily one is obtained by asking.
  • The network path and the trust the integration assumes, including what a foothold on your side reaches through it.
  • The data a member of your staff can pull out of a vendor portal in an afternoon, which is often the entire record set.
  • Your own detection of all three.

Scheduling is the other constraint. Anything touching production has to fit around trading hours and the settlement work that follows them, and the usable window is narrow. Agree it in writing, and name the person on your side who can call a halt mid-exercise: scoping a red team.

Where the evidence lives

PR.DS.S2, the data localisation provision, was placed in abeyance by the clarifications of 31 December 2024. Suspended, not repealed: the provision exists and can be restored by notification.

Settle your own posture before the exercise starts. A red team produces screenshots, credential material, extracted records and a written account of how it moved through your estate. Where that pack is held, how long it is retained and what happens to it at the end are cheap to agree in advance and impossible to retrofit afterwards. If the provision is restored, the engagement scoped on the assumption that it would stay suspended is the one that gets re-examined.

Reading a compliance claim

Three questions, the same as for any Indian instrument:

  • Which provision, and for which tier? A requirement that binds a top-tier entity may not bind you at all. A vendor quoting CSCRF without asking your classification has not read it carefully.
  • Which version of the text? CSCRF is a master circular plus amendments, and the amendments moved things. A proposal citing the master circular alone is citing a text that has since been clarified more than once.
  • Does the claim say "shall" where the framework says otherwise? A proposal asserting that CSCRF mandates red teaming for all regulated entities is making a checkable statement. Check it.

The same discipline applies to who may perform the work. Every Indian regulator that accepts an audit report accepts it from a CERT-In empanelled auditor, and empanelment is a matter of public record, so confirm it before you sign. We have held it continuously since 2008, across more than 6,700 assessments.

When not to buy one

Three situations where the honest answer is no, or not yet:

  • Nothing is being watched. If no one reviews alerts outside business hours, the exercise has a known result and you have paid to confirm it. Build the monitoring first, or run a purple team, which teaches while it tests. On what an exercise measures: what it tells you about detection.
  • Your CSCRF audit is weeks away. A red team report will not produce the control-by-control assurance an auditor is looking for. Book the audit, and schedule the exercise into the following cycle.
  • Almost everything critical is somebody else's system. The scope collapses to your office network and your staff. That may still be the right exercise, at a smaller size, and it should be priced and described as such.

Who owns what comes next

The exercise ends with a narrative, a set of findings and a debrief, and the work starts there. Each finding needs a named owner inside your organisation, a date, and a place in the register the IT Committee sees. The technical fixes are usually the easy half: the detection and process gaps belong to whoever runs your monitoring, and closing those takes longer than patching.

Agree the retest when you agree the exercise. A finding closed without one is a finding somebody believes is closed. For the document itself see what a red team report contains, and for the shape of the engagement, what a red team assessment involves.

About the author

Siddarth G

Practice Director — Cybersecurity

Leads Security Brigade's offensive security practice with deep expertise in vulnerability research, penetration testing, and red team operations. Ranked Top 80 globally on Bugcrowd.