For AIFs, this is particularly relevant because AIFs are expressly included among the entities covered by the circular.
What changes?
🔹 6-hour reporting: Cyber incidents must be reported to SEBI through the prescribed email channel within 6 hours.
🔹 24-hour portal reporting: The incident must also be reported through SEBI’s Cyber Incident Reporting Portal within 24 hours.
🔹 FIRE-based reporting: SEBI’s portal is now aligned with the FSB FIRE framework, introducing common information fields, standardised definitions and consistent incident classifications.
🔹 Reporting is ongoing: Reporting is not simply a one-time exercise. The portal supports initial reporting, subsequent updates and final closure as the incident progresses.
What does this mean for AIF Managers?
AIFs and their technology/service providers should ensure that there is a clear cyber-incident response and reporting workflow, with defined ownership, escalation mechanisms and the ability to capture the information required for SEBI reporting within the prescribed timelines.
The circular also requires regulated entities to put systems in place for implementation and to consider necessary changes to relevant rules, regulations or bye-laws where applicable.
For AIFs, cybersecurity is no longer only an IT issue — it is a regulatory reporting and governance issue.



