← All posts

Is your RA practice cyber-ready? A practical security checklist

Attacks on Indian websites and networks rise sharply around high-visibility periods — phishing, website defacement and denial-of-service (DDoS) are the usual playbook, now supercharged by AI-generated scams and deepfakes. Research Analysts are squarely in the risk zone: you hold client KYC and personal data, you run a public website, and your whole practice rests on trust. Here's a plain-English readiness checklist.

Does SEBI's cyber framework (CSCRF) apply to you?

A nuance many RAs get wrong:

  • A person registered only as a Research Analyst (no other SEBI registration) is currently exempt from the formal Cybersecurity & Cyber Resilience Framework (CSCRF).
  • But if you also hold another SEBI registration (stock broker, depository participant, investment adviser, etc.), CSCRF applies to you at the highest applicable category.

Either way, basic cyber hygiene is non-negotiable — you still handle client personal data (a DPDP Act responsibility), and a hacked or defaced RA website is a serious reputational and regulatory problem regardless of CSCRF status.

The threats every RA should recognise

PhishingFake emails/messages with malicious attachments or links, often impersonating regulators, banks or "official advisories." AI now makes them look flawless.
DefacementAttackers exploit an unpatched website to alter or take it down — damaging your credibility instantly.
DDoSFlooding your site with traffic so genuine clients can't reach it.
RansomwareMalware that encrypts your files and demands payment. Verified offline backups are your best defence.
BEC / fraudBusiness Email Compromise — a spoofed email asking you (or a client) to change bank details or pay a fake invoice.
ImpersonationFake WhatsApp / Telegram channels or profiles in your name, giving "tips" and collecting money from your clients.
DeepfakesAI-generated voice/video impersonating you or an official to authorise a payment or extract credentials.
Account takeoverSIM-swap or credential theft to hijack your email, hosting or social accounts.

Your readiness checklist

  • Turn on Multi-Factor Authentication (MFA) everywhere — email, hosting, domain registrar, social accounts. This single step blocks most account takeovers.
  • Patch & update your website, CMS/plugins and server software promptly.
  • Keep verified backups — ideally offline — of your site and any client database, and test that they actually restore.
  • Use a CDN / Web Application Firewall (e.g. Cloudflare, often free) — it absorbs DDoS and blocks common attacks automatically.
  • Be sceptical of "official" emails — verify the sender through a separate channel before opening attachments/links; never run files like .exe .scr .js .vbs; keep Office macros disabled.
  • Strong, unique passwords + a password manager; give staff only the access they need.
  • Limit file uploads on your site and watch for unknown files (web-shells).
  • Verify unusual requests for credentials, documents or payment — especially voice/video (deepfakes).
  • Protect client KYC/PII — encrypt sensitive files; don't leave them on internet-facing machines.
  • Have a simple incident-response plan — who detects, who reports, and where — before you need it.

Extra alerts — specific to Research Analysts

  • Watch for fake "you" online. Scammers create look-alike Telegram/WhatsApp channels using your name and SEBI number to sell fake tips. Periodically search for your brand and report impostors to the platform.
  • Tell your clients what you'll never do — you will never ask for their OTP, password or login, and you only collect fees through your official @valid UPI / SEBI-recognised channel. This one line prevents a lot of fraud.
  • Beware fake "SEBI/BSE" or "KYC update" messages sent to you or your clients — regulators don't ask for money or credentials over WhatsApp.
  • Vendor/insider risk — if a third party runs your KYC, website or mailers, confirm they follow basic security and can detect/report an incident quickly.

If something happens — report fast

CERT-InWithin 6 hours of detection for specified incident types — email incident@cert-in.org.in (CERT-In directions under the IT Act).
SEBI (if covered)CSCRF-covered REs report via SEBI's Cyber Incident Reporting Portal, now aligned to the FIRE format, within the CSCRF timeline.
Cyber-crimeFor fraud / online crime, use cybercrime.gov.in or call 1930. Preserve logs and evidence for a root-cause review.

References & official sources

CERT-In — Indian Computer Emergency Response Team (advisories & incident reporting)↗CERT-In National Cyber Crime Reporting Portal — report fraud / cyber-crime (helpline 1930)↗MHA SEBI — Cybersecurity & Cyber Resilience Framework (CSCRF) for Regulated Entities↗SEBI MeitY — Digital Personal Data Protection (DPDP) Act, 2023 framework↗MeitY NCIIPC — National Critical Information Infrastructure Protection Centre↗NCIIPC SEBI Check — verify a registered intermediary's UPI / payment authenticity↗SEBI
You don't need an enterprise security team — you need MFA, patching, backups, a WAF, and a healthy suspicion of "urgent" emails. Ten minutes of setup today can save you a very bad week later. Always follow current CERT-In and SEBI guidance.

More for SEBI Research Analysts

RA Sahayak is free & ad-free. A small UPI tip keeps it maintained. 😊

Disclaimer

This post is a general cyber-awareness checklist, compiled with the help of AI. It is for general information only and is not legal, compliance or cyber-security advice, nor a substitute for a professional security assessment of your own setup.

Always follow current official guidance from CERT-In (cert-in.org.in) and SEBI (sebi.gov.in), confirm your applicable CSCRF category and reporting obligations, and consult a qualified professional for your specific environment. RA Sahayak is a free, non-commercial resource and is not affiliated with SEBI, BSE, CERT-In or any regulator.