Is your RA practice cyber-ready? A practical security checklist
Attacks on Indian websites and networks rise sharply around high-visibility periods — phishing, website defacement and denial-of-service (DDoS) are the usual playbook, now supercharged by AI-generated scams and deepfakes. Research Analysts are squarely in the risk zone: you hold client KYC and personal data, you run a public website, and your whole practice rests on trust. Here's a plain-English readiness checklist.
Does SEBI's cyber framework (CSCRF) apply to you?
A nuance many RAs get wrong:
- A person registered only as a Research Analyst (no other SEBI registration) is currently exempt from the formal Cybersecurity & Cyber Resilience Framework (CSCRF).
- But if you also hold another SEBI registration (stock broker, depository participant, investment adviser, etc.), CSCRF applies to you at the highest applicable category.
Either way, basic cyber hygiene is non-negotiable — you still handle client personal data (a DPDP Act responsibility), and a hacked or defaced RA website is a serious reputational and regulatory problem regardless of CSCRF status.
The threats every RA should recognise
Your readiness checklist
- Turn on Multi-Factor Authentication (MFA) everywhere — email, hosting, domain registrar, social accounts. This single step blocks most account takeovers.
- Patch & update your website, CMS/plugins and server software promptly.
- Keep verified backups — ideally offline — of your site and any client database, and test that they actually restore.
- Use a CDN / Web Application Firewall (e.g. Cloudflare, often free) — it absorbs DDoS and blocks common attacks automatically.
- Be sceptical of "official" emails — verify the sender through a separate channel before opening attachments/links; never run files like
.exe .scr .js .vbs; keep Office macros disabled. - Strong, unique passwords + a password manager; give staff only the access they need.
- Limit file uploads on your site and watch for unknown files (web-shells).
- Verify unusual requests for credentials, documents or payment — especially voice/video (deepfakes).
- Protect client KYC/PII — encrypt sensitive files; don't leave them on internet-facing machines.
- Have a simple incident-response plan — who detects, who reports, and where — before you need it.
Extra alerts — specific to Research Analysts
- Watch for fake "you" online. Scammers create look-alike Telegram/WhatsApp channels using your name and SEBI number to sell fake tips. Periodically search for your brand and report impostors to the platform.
- Tell your clients what you'll never do — you will never ask for their OTP, password or login, and you only collect fees through your official @valid UPI / SEBI-recognised channel. This one line prevents a lot of fraud.
- Beware fake "SEBI/BSE" or "KYC update" messages sent to you or your clients — regulators don't ask for money or credentials over WhatsApp.
- Vendor/insider risk — if a third party runs your KYC, website or mailers, confirm they follow basic security and can detect/report an incident quickly.
If something happens — report fast
References & official sources
More for SEBI Research Analysts
Ask RA Mitra
Free AI answers to your SEBI RA compliance questions.
Ask now →Cyber Incident Reporting
How RAs report a cyber incident (SEBI FIRE format).
Read more →Post-Reg Compliance
The full 16-step checklist every SEBI RA must complete.
Open checklist →Join our Telegram
Free live SEBI alerts & updates for RAs and IAs.
Join now →RA Sahayak is free & ad-free. A small UPI tip keeps it maintained. 😊
Disclaimer
This post is a general cyber-awareness checklist, compiled with the help of AI. It is for general information only and is not legal, compliance or cyber-security advice, nor a substitute for a professional security assessment of your own setup.
Always follow current official guidance from CERT-In (cert-in.org.in) and SEBI (sebi.gov.in), confirm your applicable CSCRF category and reporting obligations, and consult a qualified professional for your specific environment. RA Sahayak is a free, non-commercial resource and is not affiliated with SEBI, BSE, CERT-In or any regulator.