Regulatory updates

Publications – India

Updates from SEBI

Financial sector organisations, stock exchanges, depositories, mutual funds and other financial entities have been experiencing cyber incidents, growing rapidly in frequency and sophistication.

Further, given the persistence of these threats, many traditional approaches to risk management and governance that worked in the past may not be comprehensive enough to address the rapid changes in the threat environment.

In order to address these concerns, recently, SEBI vide a circular dated 22 February 2023 issued an advisory for SEBI REs regarding cybersecurity best practices (the advisory), wherein it has recommended the SEBI REs to implement the practices as suggested by the Financial Computer Security Incident Response Team (CSIRT-Fin). Some of the best practices discussed pertain to:

  • Roles and responsibilities of Chief Information Security Officer (CISO)/designated officer,
  • Measures against phishing attacks/websites,
  • Measures for data protection and data breach,
  • Log retention,
  • Password policy/authentication mechanisms, etc.

To access the text of the advisory, please click here

Our Insights

Resources

Reach out to us

;