Skip to main content

Red Teaming and SEBI CSCRF

What the Cyber Security and Cyber Resilience Framework asks of regulated entities, where adversarial testing sits within it, and how the tiering decides how much applies to you.

2 min read

If SEBI regulates you, the first question is not what CSCRF requires. It is which tier you are in, because the framework classifies regulated entities and the classification decides how much of it applies.

Tier before requirement

CSCRF sorts regulated entities into categories by size and significance, and the parameters differ by entity type — what classifies a stock broker is not what classifies an asset manager. An organisation reading the framework without first establishing its own classification will over- or under-read almost every obligation in it.

Security Brigade maintains the entity-by-entity reading, which runs to considerably more than a page: SEBI CSCRF.

Where adversarial testing sits

CSCRF is prescriptive about routine security testing and about resilience — the ability to withstand, respond to and recover from an incident. Adversarial exercises sit closer to the resilience half than to the testing half, because what they measure is response rather than the presence of a vulnerability.

The honest position, as with the RBI's Directions, is that the framework's mandatory testing cadence and a red team are different things, and the second is not a substitute for the first. An entity that runs a red team and skips its required vulnerability assessment has satisfied nothing.

The reverse also holds and is the more interesting gap: an entity meeting every testing interval has established what is broken and nothing about whether anyone would notice an intruder who got past it. That question is not reached by any cadence, however diligently met — which is the argument for the exercise, and it is a risk argument rather than a compliance one.

Reading a compliance claim

Two questions, the same as for any Indian instrument:

  • Which provision, and for which tier? A requirement that binds a top-tier entity may not bind you at all. A vendor quoting CSCRF without asking your classification has not read it carefully.
  • Does the claim say "shall" where the framework says otherwise? A proposal asserting that CSCRF mandates red teaming for all regulated entities is making a checkable statement. Check it.

The same discipline applies to who may perform work — CERT-In empanelment governs a large class of Indian audit requirements, and whether it applies to a given engagement is a question about the instrument that binds you rather than about a vendor's preference.

For the RBI position see red teaming under the RBI's 2026 Directions; for what the exercise involves, see what a red team assessment involves.