Fin Maverick
Foundations VocabularyAccounting & ReportingEconomics & MacroQuant Methods & ProgrammingBusiness & Company AnalysisCorporate Finance & ValuationBehavioural Finance
Banking & Market InfrastructureFixed Income & RatesDerivatives & Structured ProductsPublic EquitiesTransactions & DealsPortfolio ConstructionFunds & AMCs
Private Markets & AlternativesRisk, Treasury & ControlAI & Digital FinanceStochastic Calculus & PricingWealth & Personal FinanceIndian Markets & RegulationProfessional Practice
CalculatorComparison
Frameworks
Explore Bootcamps
Equity ResearchPortfolio ManagementMutual Fund MasteryFinancial LiteracyInvestment Banking Analyst
Private Equity AnalystHedge Funds AnalystBreaking Into VCBreaking Into QuantsAI For Finance
Financial Analyst ProgramRisk Management ProgramPrivate Wealth ManagementDebt Capital MarketsDerivatives Foundation
Explore Internships
Equity Research InternMutual Fund Intern
Portfolio Management InternFinancial Literacy Intern
Explore Micro Courses

Equity Research6

Writing an Investment ThesisBuilding a Discounted Cash FlowReading an Annual Report FastReading a Sector Before a CompanySpotting Quality of Earnings Red FlagsBuilding a Revenue Forecast From Drivers

Portfolio Management3

Rebalancing: When, Why and What It CostsStrategic and Tactical Asset AllocationMeasuring Risk in a Portfolio

Mutual Fund Mastery3

Comparing Funds Without Being FooledHow a NAV Is Struck and Which Day You GetReading a Fund Factsheet Properly

Derivatives Unlocked4

Hedging a Real ExposureThe Greeks, PracticallyFutures, the Basis and What Moves ItReading an Option Payoff

AI For Finance2

Retrieval and Grounding for FinanceDocument Extraction in Finance

Breaking Into Quants4

Backtesting a StrategyHypothesis TestingCleaning Financial DataRegression for Finance

Breaking Into VC3

Sizing a MarketReading a Term Sheet as a FounderHow a Venture Round Actually Works

Financial Analyst Program4

Common Size and Trend AnalysisReading a Cash Flow StatementRatio Analysis That Says SomethingBuilding a Working Capital Schedule

Risk Management Program2

Credit Exposure and How It Is ReducedValue at Risk and What It Hides

Investment Banking Analyst3

Precedent Transactions and Why They DifferReading a Term Sheet StructurallyBuilding a Comparable Companies Table

Private Wealth Management3

Tax Aware Portfolio DecisionsBuilding a Client Risk ProfileGoal Based Planning Arithmetic

Debt Capital Markets3

Analysing an Issuer's CreditDuration and What It Does Not Tell YouBond Pricing and Yield Mechanics

Private Equity Analyst2

Fund Waterfalls and CarryThe LBO in Structure

Hedge Funds Analyst2

Short Selling MechanicsLong Short Mechanics
Courses
Explore Career Roadmaps
Investment Banking AnalystEquity Research AnalystVC AnalystPrivate Equity AnalystHedge Funds Analyst
Quant AnalystAI For FinanceFinancial Analyst ProgramPrivate Wealth ManagementDebt Capital Markets
Risk Management ProgramDerivatives FoundationPortfolio ManagementMutual Fund Mastery
PartnershipsShowdown
Log inSign up
Indian Markets, Regulation & Professional Standards
1Registration, Professional Standards and the Rulebook
Portfolio ManagerResearch AnalystActs, Rules, Regulations, Circulars…Financial Regulators in IndiaCompliance FunctionInvestment AdviceResearch Analyst vs Adviser…NISM CertificationRecord RetentionLicence, Recognition and What…Risk ProfilingHow to Map a…
2Intermediaries
UnderwriterDebenture TrusteeInvestment ManagerForeign Portfolio Investor vs…Merchant BankerRegistrar to an Issue…Stock BrokerCredit Rating Agency
3Market Infrastructure, Settlement and Technology
Market Infrastructure InstitutionAlgorithmic Trading in IndiaAlgorithmic Trading vs API TradingDematerialisationPay-In and Pay-OutBeneficial OwnerCybersecurity for Regulated EntitiesSettlement FinalityDepository ParticipantsForeign Portfolio InvestorInvestor Protection FundPrepaid Payment InstrumentHow Payment-System Regulation Works…Securities Appellate TribunalSelf-Regulatory Organisation
4Issuance
Offer DocumentHow to Read a…Public Issue TypesListingLock-InAnchor InvestorBook Building and the Price BandQualified Institutions PlacementRed Herring Prospectus
5Listed Markets
Compliance OfficerDisclosure ObligationsHow to Map a…Listing ObligationsListed Entity vs Intermediary
6Market Conduct
Market ConductSupervisory ActionsEnforcement OrdersAdjudication and PenaltyInsider TradingAnti-Money LaunderingHow to Identify a…How Financial-Promotion Rules Differ…
7Pensions and Insurance
Insurance IntermediariesHow Insurance and Pension…The NPS ArchitectureNPS vs APYPension AdviserPension Fund Under the NPS

Cybersecurity for Regulated Entities: Weaknesses and Incidents

A cybersecurity incident is any event that touches the confidentiality, the integrity or the availability of a regulated firm's systems or data, and defined categories of it must be reported to the regulator. A vulnerability assessment is the periodic hunt for weaknesses before anybody uses them. The framework published by the Securities and Exchange Board of India (SEBI), read at sebi.gov.in, sets out what must be assessed, what must be reported and by when.

Everything below is India, and the scope is narrow. Six questions carry the whole of it: what makes an event an incident rather than a nuisance, what an assessment produces and what it does not, why two numbers have to be reported side by side, who inside a firm actually carries the obligation, what has to exist in writing afterwards, and where the requirement itself is opened rather than somebody's description of it.

Underneath all of it sits one idea that is uncomfortable enough that most firms only meet it once. Finding weaknesses is cheap, quick and easy to show off. Closing them is slow, expensive and invisible. The report counts what was found rather than what was fixed. So a firm can commission every assessment it is asked to commission, receive a thorough report, circulate it to everyone who should see it, and be standing in precisely the same place it stood before. A firm that lets the count of what was found merge into the count of what was fixed has built a reporting habit instead of a security programme.

Here is the version everybody has already lived. A housing society commissions a structural survey of its two buildings. The surveyor is good and the report is honest: 23 defects, four of them urgent. The committee circulates it, fixes the four urgent ones, feels that the matter has been dealt with, and files the report. Two years later a section of parapet comes down. The survey is written proof that the society knew about that parapet and chose the other four, so the survey is now the most damaging document in the building. Nobody in that committee did anything wrong at any single moment, and the outcome is still worse than if they had never surveyed at all.

Hold on to the housing society. A regulated firm is in exactly the same position, with one addition: the firm is required to survey. So the question is never whether to look, and it is always what happens to what looking turns up.

What counts as a cybersecurity incident for a regulated firm?

The instinct here is wrong in a specific way, so start with the definition. Most people picture an incident as somebody breaking in and taking something. Breaking in and taking something is one shape out of three, and the other two happen more often and are noticed less. A cybersecurity incidentAn event affecting the confidentiality, the integrity or the availability of a firm's systems or its data, whatever caused it. is an event affecting one of three properties of a firm's systems or its data: whether the right people alone could see it, whether it is still what it was, and whether it could be reached when somebody needed it.

Notice what that definition leaves out, and leaves out on purpose. The definition says nothing about intent, so a mistake counts. Nothing about a person on the outside, so an internal act counts. Nothing about damage, so an event that cost nothing at all counts. The definition is written around what happened to the system rather than around how bad it felt. Classify by feeling and a firm reports almost nothing. No other distinction in the definition matters as much.

AN INCIDENT IS AN EVENT THAT TOUCHES ONE OF THESE THREE THINGS CONFIDENTIALITY Something was seen by somebody who should not have seen it. WHAT THE FIRM NOTICES Client records reached from an account with no business in them INTEGRITY Something was changed and the change was never authorised. WHAT THE FIRM NOTICES A stored figure that no longer matches the record it came from AVAILABILITY Something could not be reached at the moment it was needed. WHAT THE FIRM NOTICES A system that will not open on a working morning, for anybody One event can touch two of the three at once, and which category it lands in is what decides whether it must be reported. Not one of the three says anything about how somebody got in. That is a technical subject and it is not described here.
An incident is defined by which of confidentiality, integrity or availability was affected, not by how serious the event felt to the people in the room.

Availability is the one that surprises people, so it is worth pressing. A system that will not open, for reasons nobody can explain, on a morning when clients need it, is an incident under that definition even if nobody was anywhere near it and the cause turns out to be a failed disk. Bhadra Securities Private Limited, an invented broker and depository participant, carries 11,400 client accounts. If the record of those accounts cannot be reached on a working morning, the fact that nobody attacked anything is a comfort to the firm and no comfort at all to the 11,400.

Financial Literacy Bootcamp — Fin Maverick

What is a Vulnerability Assessment, and what does it not do?

A vulnerability assessmentA periodic exercise that goes looking for weaknesses in a firm's systems before anybody has used one. is a periodic exercise that goes looking for weaknesses in a firm's systems before anybody has used one. Somebody, usually an outside specialist, examines what the firm runs, compares it against what is known to be weak, and hands back a list. Sumana Rege, who runs technology at Bhadra Securities Private Limited, commissions it, sits with the people doing it, and receives the report at the end.

How often it happens is set in the cyber security and cyber resilience framework, and that interval has been revised. A firm running to a half remembered interval is running to nothing. The current version carries the interval, and it is read there on the day the question arises.

The shape of what comes back matters much more than the interval. An assessment is a survey, not a repair, and every disappointment firms have with assessments comes from forgetting that one sentence. It produces a list, a severity mark against each item, and, if the firm insisted on it in advance, a named person against each item. The assessment does not produce a fixed system, it does not make a decision about what to do first, and it changes precisely nothing about the firm's exposure on the day it lands.

WHAT THE ASSESSMENT HANDS BACK, AND WHAT IT LEAVES TO THE FIRM WHAT IT PRODUCES A list of items, counted A severity mark on each one A named person, if asked for A dated, signed report ALL OF IT ARRIVES ON ONE DAY WHAT IT DOES NOT PRODUCE A single fixed system A decision about what goes first Any change to the exposure Anything to stand behind later ALL OF IT IS THE FIRM'S OWN WORK The left panel is bought and arrives on a date. The right panel is built, by the firm, over the months after that date. A firm that budgeted for the left panel and not the right one has budgeted for half a programme.
The assessment delivers a counted list on a single day, and everything that changes the firm's actual exposure has to be built by the firm afterwards.

What did the assessment at Bhadra Securities actually find?

The abstraction only bites once there are numbers on it, so take the case at Bhadra Securities. The periodic assessment at Bhadra Securities Private Limited found 23 items. Four of them were marked as needing immediate action, and those four were closed. On the day the report was signed, 19 items remained open.

The split of those items across four areas is set out below, and the totals reconcile across it rather than being merely asserted. Four areas, 23 items found, 4 closed, 19 open, and the last column records whether the firm had set itself a date for the item at all.

Area the item sat inFoundClosedStill openFirm set a date
Access and permissions725Yes
Software versions in use918No
Backup and recovery413Yes
Logging and monitoring303No
Total on the day the report was signed23419Two of four

Read the two headline figures together and neither one is comfortable. Read either alone and both are. 23 found says the firm went looking, and going looking is genuinely something. 19 open says most of what it found is still exactly where it was, and the firm would rather not write that sentence. Both statements are true at once, and only the pair says anything about where Bhadra Securities actually stands.

There is a second detail in the case that is easy to read past. One cybersecurity incident was reported during the year, and it was found by the assessment rather than by anybody noticing an effect. Nothing had visibly gone wrong. No client called, no screen froze, no figure looked odd. The instinct is to treat an incident count of one as a statement about how safe the firm is, and an incident count is nothing of the kind. An incident count is a statement about how the firm finds things.

THE SAME COUNT OF ONE INCIDENT, FOUND TWO COMPLETELY DIFFERENT WAYS HOW IT SURFACED A line in the assessment report. Nobody had complained, nothing had stopped, no figure looked wrong. Somebody was looking, and looking is what turned it up. DETECTION WORKED This is the good version, and it reads like the bad one. HOW IT SURFACED A client rang because something on a screen was wrong. The effect arrived first and the firm worked backwards from it. Nobody inside had seen anything. ONLY THE OBVIOUS ONES Everything quieter than this is still running, uncounted. An incident count measures what a firm can see. A firm that only ever finds incidents through their effects has a count of the loud ones.
An incident found by the assessment shows the detection is working, while an incident found because something visibly broke shows only the loud ones are being counted.
Try it out

An incident is found by an assessment rather than by anybody noticing an effect. Good sign or bad sign?

Equity Research Bootcamp — Fin Maverick

Why must the found count and the closed count be reported separately?

The two counts answer different questions, and one of the two is the question that actually matters. The found count answers whether the firm went looking. The open itemA weakness that has been found and has not yet been closed. The weakness is still there, and now it is written down. count answers where the firm stands. Only the second one describes exposure, and it is the one that most often never leaves the technology team.

Watch the movement across three steps. The last of the three is the step nobody prints.

FROM WHAT WAS FOUND TO WHAT IS STILL THERE, IN THREE STEPS BHADRA SECURITIES PRIVATE LIMITED, ON THE DAY THE REPORT WAS SIGNED. EVERY FIGURE INVENTED. 23 4 19 FOUND CLOSED STILL OPEN the number that gets reported the number that is the work the firm's actual position
Bhadra Securities found 23 items, closed 4 and left 19 open, and only the third bar describes where the firm actually stood that day.

The shape the case makes over several cycles is the whole argument, so push the same case forward. Suppose each future assessment finds roughly what this one found and the firm closes roughly what it closed, four out of twenty three. Every cycle adds nineteen to the pile. Now suppose instead that the firm closes twenty of every twenty three. The two paths are drawn below, and each is arithmetic on its own closure rate carried forward six cycles.

THE CATALOGUE OF KNOWN OPEN WEAKNESSES, CYCLE AFTER CYCLE AN ARITHMETIC PROJECTION OF ONE INVENTED CASE. NOT A RATE AT WHICH ANY FIRM FINDS OR CLOSES ANYTHING. ITEMS FOUND AND NOT YET CLOSED, RUNNING TOTAL 0 30 60 90 120 CLOSING 4 OF EVERY 23: PLUS 19 A CYCLE CLOSING 20 OF EVERY 23 114 CYCLE 1 CYCLE 2 CYCLE 3 CYCLE 4 CYCLE 5 CYCLE 6 Both firms are running the assessment. Both look diligent in a report that prints only what was found. The red firm is assembling a written record of weaknesses it can be shown to have known about and left alone.
Two firms both run every assessment, and the one that closes four items in twenty three is building a catalogue of known weaknesses that reaches 114 by the sixth cycle.

The climbing red path is what happens when a firm keeps looking and stops short of fixing. RemediationThe work of actually closing a weakness that an assessment found, as distinct from recording that it exists. is where the money and the arguments live, and it produces nothing anybody can photograph. Knowledge is what turns a weakness into a decision somebody took, so a firm with a growing catalogue of known open weaknesses stands in a materially worse position than a firm that never looked. Nobody plans it. The red path is simply where an honest assessment programme with no remediation programme always arrives.

Try it out

A firm's found count rises with every assessment cycle. Diligence, or a problem?

Try it out

An assessment finds 23 items and 4 are closed by the time the report is signed. Before the control below is moved, how many can the firm be shown to have known about and not fixed?

Play with it

Move the share of items remediated, and watch which of the two numbers refuses to move.

The assessment at Bhadra Securities Private Limited found 23 items. The control opens at 17 per cent remediated. 23 multiplied by 0.17, rounded to a whole item, gives 4 closed and 19 still open. Both figures are exactly the position on the day the report was signed, and the worked example above carries the same reading in prose. The two buttons follow. One button shows the panel a board usually sees, and that panel prints the found count alone. The other shows the same 23 items split into what is closed and what is not.

Two views of one assessment. Load either, and move the share under both:
Share of the 23 found items that have been remediated: 17 per cent. That share is moved on the control to show a relationship, and it is not a rate at which anything is closed anywhere. It is not a requirement, a target or an expectation of any kind. The only value on this control that describes anything real is 17 per cent, which reproduces the invented case.
Items found
23
Items closed
4
Still open
19
What the report prints
Found, closed, open
At 17 per cent remediated, 4 of the 23 items the assessment found at Bhadra Securities Private Limited are closed and 19 are still open, which is exactly where the firm stood on the day the report was signed. Those 19 are weaknesses the firm can be shown to have known about.
Educational illustration. The 23 items, the 4 closed and the 19 open belong to Bhadra Securities Private Limited alone. All 23 are weighted equally here, and no real assessment weights them equally: a single item can matter more than the other twenty two put together, and the panel cannot show that. No interval, window or requirement appears on this control.
Debt Capital Markets Bootcamp — Fin Maverick

What must be reported to the regulator, and what stays inside the firm?

Not everything is reported, and the line between the two is not drawn by the people in the room on the day. Defined categories of incident carry a reporting obligationThe duty to tell the regulator about the categories of incident the framework defines, in the manner and by the route it sets., and the categories, the route and the timing are written in the framework in advance. An event that falls outside those categories is recorded internally and kept. Recording is a different thing from forgetting.

Why does the test sit in a document written months earlier rather than in somebody's judgement on the night? Because of who is in the room. The people deciding whether an event qualifies are tired, they are the people whose systems it happened on, and every one of them has a perfectly human reason to hope the answer is no. A test written in advance takes the decision away from the only people who will ever have an interest in the answer. Taking the decision away from them is the entire reason for writing the test in advance.

THE REPORTING TEST IS ANSWERED BY A DOCUMENT, NOT BY THE ROOM DOES THE EVENT FALL INSIDE A CATEGORY THAT THE FRAMEWORK ALREADY DEFINES? YES NO REPORT IT by the route and in the manner the framework sets, read at its source RECORD IT INTERNALLY with the reasoning that put it outside, dated and signed The call was settled before anybody was under pressure The firm can still show what it considered, and when NOBODY IN THE ROOM DECIDES WHETHER IT FELT SERIOUS ENOUGH The categories, the route and the timing are set in the framework and read at its source.
Whether an incident must be reported turns on categories the framework defines in advance, rather than on how serious the event felt to the people handling it.
India

Where the requirement itself lives

The obligations described above are set out in the cyber security and cyber resilience framework published by the Securities and Exchange Board of India, together with the circulars issued under it, read at sebi.gov.in on 18 August. The framework reaches regulated entities and not only the institutions underneath them. A depository participant such as Bhadra Securities Private Limited is therefore inside it. The assessment interval, the incident classification, the reporting window and the penalty all sit in the framework, each has been amended, and a description of an amended requirement is not the requirement. The version in force is the one to open. If the firm also carries an obligation on the payment side, the corresponding requirement is read at rbi.org.in rather than inferred from this one.

Try it out

Why is the reporting test written down before anything happens?

Measuring Risk in a Portfolio — free micro-course from Fin Maverick

Cybersecurity vs Cyber Resilience: which question is the firm answering?

Cybersecurity and cyber resilience get said in one breath so often that the join between them has worn away, and the join is the point. Cybersecurity is a question about the boundary: can somebody get in, and can something get out. Cyber resilienceThe ability to keep operating through a disruption, as opposed to the ability to prevent one. is a question about the morning after the boundary failed: does the firm keep doing what it exists to do.

Take a wedding. The shape is identical and everybody has stood in one. Security is the man at the gate matching names against a list, and he is genuinely useful. Resilience is whether there is a second gas connection when the first cylinder runs out at nine, a second person who knows where the accounts are, and a plan for the hall losing power in the middle of dinner. A wedding can have a superb man on the gate and still collapse at nine o'clock, and the two facts have nothing to do with each other. Nobody at that wedding will remember the gate, and everybody will remember the ninety minutes with no food.

TWO DIFFERENT QUESTIONS, AND A GOOD SCORE ON ONE PREDICTS NOTHING CYBERSECURITY THE QUESTION Can somebody get in at all? HOW IT IS TESTED By trying the boundary A GOOD RESULT LOOKS LIKE Nobody got through HOW EASY IT IS TO JUSTIFY Easy: it has a story to tell CYBER RESILIENCE THE QUESTION Does the firm keep working anyway? HOW IT IS TESTED By assuming it already failed A GOOD RESULT LOOKS LIKE A completely ordinary day HOW EASY IT IS TO JUSTIFY Hard: success looks like nothing Read the four rows across rather than down. Every row asks the same question of two different objectives, and every answer differs.
Security is tested by attempting the boundary and resilience by assuming it already failed, so a clean record on one says nothing at all about the other.

The bottom row of both panels explains most of what goes wrong. Security spending can be described afterwards: the boundary was tried, here is what was found, here is what was shut. Resilience spending, when it works, produces an ordinary Tuesday and nothing else. There is no photograph of a disaster that did not happen. The result is that resilience is the easier line to postpone in every budget conversation, and the postponement is invisible right up until the morning it is not.

Try it out

A firm has never been broken into and would be unable to operate for a week if it were. Strong on which?

Measuring Risk in a Portfolio teaches you to compute and interpret the standard portfolio risk measures and say what each one misses. Document Extraction in Finance — free micro-course from Fin Maverick

Who inside the firm is answerable, and why is it never the technology team alone?

Because the obligation is regulatory rather than technical, and regulation attaches to the registration. Sumana Rege and her team find things and fix things, and neither of those acts is the obligation. The obligation is to have looked, to have reported what qualifies, to have been in a position to keep working, and to be able to show all three. The obligation sits where the registration sits. In this firm the registration means Yashodhan Pai as compliance officer and the board above him.

THE WORK RUNS UPWARD, AND THE OBLIGATION SITS AT THE TOP THE BOARD Answerable for whether the firm was prepared at all COMPLIANCE OFFICER, YASHODHAN PAI Decides what qualifies, sends it, keeps the file TECHNOLOGY, SUMANA REGE Finds the items, closes them, reports upward The registration is held here, so the duty is held here too Translates a technical fact into a regulatory question Does the work, and cannot carry the obligation alone The report goes to both the compliance officer and the board, because neither of them can answer for something they never saw.
The technology team finds and closes items while the compliance officer and the board carry the regulatory obligation, which is why the report has to reach all three.

There is a practical consequence, and it is the reason the diagram has the report reaching two places rather than one. If the assessment report stops at the technology team, the compliance officer cannot form a view about what qualifies and the board cannot answer for a state of affairs it was never shown. An obligation that sits above the people who hold the information is only met when the information is deliberately pushed upward, and pushing it upward is itself a step somebody has to be responsible for.

Try it out

Who carries the regulatory obligation for a cybersecurity incident at a registered firm?

Document Extraction in Finance teaches you to design an extraction pipeline for a financial document and set the confidence threshold honestly.

What records must exist afterwards, and which column is read first?

Each of these acts leaves a record behind, and the record is the only version that survives. The assessment leaves a dated report. The remediation leaves a record of what was closed, by whom and when. The reporting decision leaves a note of the category the event fell into, or the reasoning that put it outside. The incident itself leaves a timeline of what was done in what order.

WHAT AN INSPECTION DOES WITH THE ASSESSMENT REPORT PERIODIC VULNERABILITY ASSESSMENT, SIGNED AREA FOUND CLOSED OPEN DATE SET Access and permissions 7 2 5 yes Software versions in use 9 1 8 no Backup and recovery 4 1 3 yes Logging and monitoring 3 0 3 no TOTAL 23 4 19 2 of 4 Signed by the assessor and received by the compliance officer and the board. Every figure above is invented. 1 The shaded column is read first. It describes exposure. 2 Then the last column. An open item with no date set is an item nobody owes. 3 Then the sign off, which settles who had seen this.
An inspection reads the column recording what remains open before anything else, because that column is the only one describing the firm's exposure today.

The last column of that facsimile is worth a sentence of its own. An open item with a date the firm set itself is work in progress. An open item with no date at all is not work in progress, it is an item nobody is answerable for, and the two look identical in a total. Counting open items without also counting how many of them nobody has taken a date against will flatter any firm that has stopped short of assigning the work.

Try it out

An inspection opens the assessment report. Which column does it read first?

What does a firm do in the first hour of an incident?

The order is fixed and it is not the order instinct suggests. Instinct says find out what happened. Finding out what happened is the fourth thing, not the first. ContainmentStopping an incident from spreading further, before anybody understands what caused it. comes first, and it is done without understanding. Understanding takes longer than the spreading does.

THE FIRST HOUR HAS AN ORDER, AND DIAGNOSIS IS NOT AT THE START OF IT 1 CONTAIN stop it spreading 2 PRESERVE keep what happened 3 TELL those who must be told 4 DIAGNOSE work out the cause EVERYTHING LEFT OF THE DASHED LINE IS DONE BEFORE ANYBODY KNOWS THE CAUSE Step 2 is the one that gets skipped, and it is the one that cannot be recovered: the evidence of what happened is routinely destroyed by the well meant tidying up that follows step 1. No duration appears anywhere in this sequence. The order is fixed; the clock on any step is set in the framework and read there.
Contain first, preserve what happened second, tell whoever must be told third, and only then establish the cause, which is the reverse of what instinct suggests.

Step two is the one that disappears under pressure. Restoring a system tidily and preserving what it looked like are opposite instincts. So the people fixing the problem are also, without meaning to be, the people erasing the evidence of it. Establishing the root causeWhat actually allowed the incident, established calmly after containment rather than guessed at during it. a week later is only possible if somebody, in the middle of the worst hour, thought to keep a copy of the mess. That is why it is a written step with a name against it rather than something anybody is expected to remember.

Try it out

First hour of an incident. Contain, or diagnose?

What does the firm tell its clients, and when is that a separate duty?

Telling the regulator and telling the people affected are two different obligations with two different triggers, and a firm that satisfies the first can still have done nothing about the second. Anasuya Kolhapure, whose holding of 800 shares sits in a demat account with Bhadra Securities Private Limited, is not a party to the report that goes to the regulator and will never see it.

Her own entitlement is a different question, answered by whether her records or her access were affected, and by whatever the firm's own terms and the applicable requirements say about telling her. The client communication is judged by whether the person affected could act on what they were told. Whether the regulator received what it was owed is a completely different test. A notice that is accurate, timely and incomprehensible has met one duty and failed the other.

How does anybody outside the firm actually use these two numbers?

Outside the firm, the found count and the open count stop being an internal argument. Three readers use them, and each one uses them differently.

The pair of counts is a cheap and unusually honest read on whether a firm finishes work, so an institutional client deciding whether to place business with a broker asks for both across the last few cycles. A firm that supplies the found count and hesitates over the closed count has answered the question. An acquirer running diligence on a broker does something harder and reads the open register item by item. Every open item is a known liability it would be buying, and a known liability is priced differently from an unknown one. And an inspection, as the facsimile above shows, goes straight to the same column.

Anasuya Kolhapure can do none of this, and it is worth being honest about that. A retail client has no route to either number. Regulation therefore places the obligation to look, to report and to be answerable on the firm, rather than leaving it to be demanded by the people who would be affected. The same logic sits under most of securities regulation. The people carrying the risk cannot see it, so the duty goes where the information is.

The failure: a firm that reports what it found and never reports what it closed

The assessment happens on time. The report is thorough and honest. The items are catalogued, circulated and filed. A bigger number of findings does look like better looking. So the board sees a number that rises with every cycle and reads the rise as evidence of a maturing programme. Nobody in that chain has done anything dishonest.

The wrong reading is that finding is the work. Finding is the cheap half, and it is the half with a deliverable. The cost of the misreading is specific rather than vague. The firm accumulates a written, dated, signed record of weaknesses it can be shown to have known about and not addressed, and a written record of that kind is a worse place to stand than never having looked. Nobody chooses that outcome and it is exactly where a diligent assessment programme with no remediation programme arrives, every time, without anybody noticing the turn. The tell is easy to check. Any firm can be asked for its found count and its closed count for the same period. If one of them takes a week to produce, that is the answer.

How any attack technique works, and how a system is secured, is a technical subject taught elsewhere. The assessment interval, the reporting window, the incident classification and the penalty are each read at the source named below. The resilience obligations that sit specifically on market infrastructure institutions are set out under market infrastructure institutions, and the appeal route from any order that follows an inspection is set out under the securities appellate tribunal.

Breaking Into Quants Bootcamp — Fin Maverick

References

SourceDocumentWhere
Securities and Exchange Board of IndiaThe cyber security and cyber resilience framework and the circulars issued under it, named here for the existence of an assessment obligation, an incident reporting obligation and a defined set of reportable categories. The interval, window, classification and penalty are read in the framework itselfsebi.gov.in
Securities and Exchange Board of IndiaThe regulations made for depositories and for depository participants, named here only to establish that a participant is a registered entity in its own right and therefore carries these obligations itself rather than inheriting them from the depository it connects tosebi.gov.in
Reserve Bank of IndiaThe corresponding technology and incident requirements issued for entities under that regulator, named so that a firm whose activities sit partly on the payment side knows there is a second address to read rather than assuming one answer covers bothrbi.org.in
The depositories and the exchanges, on their own sitesNamed for operational fact alone, such as what a participant is asked to connect to and what it must be able to demonstrate to them. Never treated here as the source of a regulatory obligationnsdl.co.in, cdslindia.com, nseindia.com, bseindia.com
International Organization of Securities CommissionsNamed for the existence of international work on cyber matters in securities markets, which is where a reader who wants the cross border framing should start rather than generalising from one marketiosco.org

Bhadra Securities Private Limited, Anasuya Kolhapure, Yashodhan Pai and Sumana Rege are invented.
Educational material. Not advice on any investment, tax, budget or market position.

← PreviousNext →
Fin Maverick Micro CoursesExplore Micro Courses
Fin Maverick BootcampsExplore Bootcamps
Fin Maverick

Finance education that ends in a job, not a certificate that gathers dust. Built for young India.

LEARN
CalculatorsFrameworksComparisonsCareersShowdown
RESOURCES
All CoursesMicro CoursesBootcampsInternships
COMPANY
AboutJob openingPartnership
LEGAL
Privacy PolicyTerms & ConditionsContent LicenseReturn & Refund Policy
© 2026 FIN MAVERICK / BUILT FOR INDIA.DO FINANCE, DO NOT JUST READ ABOUT IT.