SEBI’S Cyber Shield: Assessing the Strength of the CSCRF Framework
[By Anoushka Das, Dhaval Bothra & Arya Vansh Kamrah] The authors are students of SLS Pune. Introduction The Securities and Exchange Board of India (SEBI) has recently released its circular dated August 20, 2024, detailing a cyber security framework for its Regulated Entities (REs) in light of the rapid increase in technological developments in the securities market. The integration of technology into the securities market poses a double-edged sword, which may expose the players in the market to cyber risks and cyber incidents. While the integration of technology brings efficiency and innovation, it simultaneously exposes market participants to potential cyber threats, including data breaches, ransomware attacks, and fraudulent activities. SEBI, after due consultation with the stakeholders, has prudently formulated a framework via its circular to meet its six cyber security goals for combating cybercrime, i.e., governance, identification, protection, detection, response, and evolution. SEBI has outlined a robust scheme designed to safeguard stakeholders from the complex and evolving cybersecurity threats facing the securities market. Key Highlights of the Framework Under this framework, SEBI has categorized the REs into five categories based on the extent of operations, trade volume, number of clients, etc. In pursuance of SEBI’s focus on cybersecurity and cyber resilience, the market regulator has framed the following guidelines in accordance with its cybersecurity functions: Governance: SEBI has mandated that all REs continuously allocate and communicate clear roles and responsibilities related to cybersecurity risk management. Additionally, it has introduced the Cyber Capability Index (CCI) as a tool to assess and monitor the cybersecurity progress of Market Infrastructure Institutions and Qualified REs Identification: REs are mandated to identify and classify critical systems according to their operational importance and sensitivity. This includes periodic IT risk assessments and prioritizing responses based on current threats and vulnerabilities. Protection: REs must ensure that a robust authentication and access policy is in place with due log collection and documentation. Moreover, SEBI has enumerated a list of guidelines, including audits, vulnerability assessment and penetration testing, and security solutions that need to be mandatorily implemented. Detection: The REs are mandated to institute a Security Operations Centre (SOC), either internally or via third parties, and ensure that the functional efficacy of the same is measured on a half-yearly or yearly basis based on the category it belongs to. Response: The REs must compulsorily formulate a Cyber Crisis Management Plan (CCMP), and in the event of any incident, a Root Cause Analysis (RCA) must be conducted to understand the root cause of the incident. Recovery: SEBI in its circular has provided an indicative recovery plan based on which REs must document a comprehensive plan for response and recovery from cyberattacks. Evolution: SEBI has mandated that the REs must formulate “adaptive and evolving” controls to tackle vulnerabilities. The circular takes cognizance of the ever-evolving nature of technology and its role in the securities market and undertakes to evolve with the changing times by making updates to the circular as and when the need arises. This forward-looking approach leaves enough room for the framework to evolve while making a sufficient attempt at tackling the pre-existing problems. Implementation of the CSCRF SEBI has phased the implementation of CSCRF compliance based on the categories in which the REs fall. The implementation date for the six categories of REs that already have circulars in place is January 1, 2025, while for REs to which the CSCRF measures are being extended for the first time, the implementation date is April 1, 2025. The market regulator has considered the challenges that first-time compliance imposes on regulators and has allowed a relaxed timeline to accommodate these difficulties. A robust monitoring mechanism further underscores the efficacy of the framework. The CSCRF has divided the compliance reporting between two authorities. For Security Brokers and Depository Participants classified as Qualified REs, the reporting authority will be the relevant stock exchange or depository. For MIIs and the remaining Qualified REs, SEBI will serve as the reporting authority. While CSCRF does not provide for obligations of the REs in case of non-compliance of the implementation dates, SEBI has power under the SEBI Act, 1992, to impose penalties on REs that fail to comply with its directives and frameworks. Analysing the Impact of the Framework The REs are now burdened with the additional responsibility of adhering to the cybersecurity measures outlined in the circular. On one hand, the compliance requirements and strengthened governance structures may bolster investor confidence in the securities market. Complying with the CSCRF framework can help the REs align with international cybersecurity standards and enhance their reputation and credibility in the global market. The rigorous standards may drive innovation in cybersecurity technology and solutions as REs look for efficient methods to fulfil compliance without compromising productivity. However, on the other hand, the framework is likely to compel the REs to overhaul their internal systems, procedures and infrastructure to meet the new cybersecurity standards. The additional list of compliances would result in significant expenses for the REs. Smaller REs could face considerable challenges in complying with the CSCRF standards. This may further lead to a competitive disadvantage and an increased dependency on larger institutions for cybersecurity and cyber resilience support. Moreover, the lack of regulation regarding external SOCs leads to a regulatory gap and creates uncertainty with respect to the obligations of REs that opt for third-party SOCs, in case of non-compliance with CSCRF standards. The circular is a progressive step in addressing the cybersecurity issues prevalent in the market. However, the effectiveness of the circular can only be adjudged upon observing the cooperation of the REs and the diligent monitoring of market players against the established standards once implementation begins. Recommendations The CSCRF aims to ensure uniformity of cybersecurity guidelines for all REs. However, the framework may not fully address the unique challenges faced by different categories, potentially leading to compliance issues and security gaps. For example, while the CSCRF’s cybersecurity controls are crucial for market safety, they are resource-intensive, especially for smaller REs, which may struggle with the
SEBI’S Cyber Shield: Assessing the Strength of the CSCRF Framework Read More »









