Cybersecurity for Regulated Entities: Weaknesses and Incidents
A cybersecurity incident is any event that touches the confidentiality, the integrity or the availability of a regulated firm's systems or data, and defined categories of it must be reported to the regulator. A vulnerability assessment is the periodic hunt for weaknesses before anybody uses them. The framework published by the Securities and Exchange Board of India (SEBI), read at sebi.gov.in, sets out what must be assessed, what must be reported and by when.
Everything below is India, and the scope is narrow. Six questions carry the whole of it: what makes an event an incident rather than a nuisance, what an assessment produces and what it does not, why two numbers have to be reported side by side, who inside a firm actually carries the obligation, what has to exist in writing afterwards, and where the requirement itself is opened rather than somebody's description of it.
Underneath all of it sits one idea that is uncomfortable enough that most firms only meet it once. Finding weaknesses is cheap, quick and easy to show off. Closing them is slow, expensive and invisible. The report counts what was found rather than what was fixed. So a firm can commission every assessment it is asked to commission, receive a thorough report, circulate it to everyone who should see it, and be standing in precisely the same place it stood before. A firm that lets the count of what was found merge into the count of what was fixed has built a reporting habit instead of a security programme.
Here is the version everybody has already lived. A housing society commissions a structural survey of its two buildings. The surveyor is good and the report is honest: 23 defects, four of them urgent. The committee circulates it, fixes the four urgent ones, feels that the matter has been dealt with, and files the report. Two years later a section of parapet comes down. The survey is written proof that the society knew about that parapet and chose the other four, so the survey is now the most damaging document in the building. Nobody in that committee did anything wrong at any single moment, and the outcome is still worse than if they had never surveyed at all.
Hold on to the housing society. A regulated firm is in exactly the same position, with one addition: the firm is required to survey. So the question is never whether to look, and it is always what happens to what looking turns up.
What counts as a cybersecurity incident for a regulated firm?
The instinct here is wrong in a specific way, so start with the definition. Most people picture an incident as somebody breaking in and taking something. Breaking in and taking something is one shape out of three, and the other two happen more often and are noticed less. A cybersecurity incidentAn event affecting the confidentiality, the integrity or the availability of a firm's systems or its data, whatever caused it. is an event affecting one of three properties of a firm's systems or its data: whether the right people alone could see it, whether it is still what it was, and whether it could be reached when somebody needed it.
Notice what that definition leaves out, and leaves out on purpose. The definition says nothing about intent, so a mistake counts. Nothing about a person on the outside, so an internal act counts. Nothing about damage, so an event that cost nothing at all counts. The definition is written around what happened to the system rather than around how bad it felt. Classify by feeling and a firm reports almost nothing. No other distinction in the definition matters as much.
Availability is the one that surprises people, so it is worth pressing. A system that will not open, for reasons nobody can explain, on a morning when clients need it, is an incident under that definition even if nobody was anywhere near it and the cause turns out to be a failed disk. Bhadra Securities Private Limited, an invented broker and depository participant, carries 11,400 client accounts. If the record of those accounts cannot be reached on a working morning, the fact that nobody attacked anything is a comfort to the firm and no comfort at all to the 11,400.
What is a Vulnerability Assessment, and what does it not do?
A vulnerability assessmentA periodic exercise that goes looking for weaknesses in a firm's systems before anybody has used one. is a periodic exercise that goes looking for weaknesses in a firm's systems before anybody has used one. Somebody, usually an outside specialist, examines what the firm runs, compares it against what is known to be weak, and hands back a list. Sumana Rege, who runs technology at Bhadra Securities Private Limited, commissions it, sits with the people doing it, and receives the report at the end.
How often it happens is set in the cyber security and cyber resilience framework, and that interval has been revised. A firm running to a half remembered interval is running to nothing. The current version carries the interval, and it is read there on the day the question arises.
The shape of what comes back matters much more than the interval. An assessment is a survey, not a repair, and every disappointment firms have with assessments comes from forgetting that one sentence. It produces a list, a severity mark against each item, and, if the firm insisted on it in advance, a named person against each item. The assessment does not produce a fixed system, it does not make a decision about what to do first, and it changes precisely nothing about the firm's exposure on the day it lands.
What did the assessment at Bhadra Securities actually find?
The abstraction only bites once there are numbers on it, so take the case at Bhadra Securities. The periodic assessment at Bhadra Securities Private Limited found 23 items. Four of them were marked as needing immediate action, and those four were closed. On the day the report was signed, 19 items remained open.
The split of those items across four areas is set out below, and the totals reconcile across it rather than being merely asserted. Four areas, 23 items found, 4 closed, 19 open, and the last column records whether the firm had set itself a date for the item at all.
| Area the item sat in | Found | Closed | Still open | Firm set a date |
|---|---|---|---|---|
| Access and permissions | 7 | 2 | 5 | Yes |
| Software versions in use | 9 | 1 | 8 | No |
| Backup and recovery | 4 | 1 | 3 | Yes |
| Logging and monitoring | 3 | 0 | 3 | No |
| Total on the day the report was signed | 23 | 4 | 19 | Two of four |
Read the two headline figures together and neither one is comfortable. Read either alone and both are. 23 found says the firm went looking, and going looking is genuinely something. 19 open says most of what it found is still exactly where it was, and the firm would rather not write that sentence. Both statements are true at once, and only the pair says anything about where Bhadra Securities actually stands.
There is a second detail in the case that is easy to read past. One cybersecurity incident was reported during the year, and it was found by the assessment rather than by anybody noticing an effect. Nothing had visibly gone wrong. No client called, no screen froze, no figure looked odd. The instinct is to treat an incident count of one as a statement about how safe the firm is, and an incident count is nothing of the kind. An incident count is a statement about how the firm finds things.
An incident is found by an assessment rather than by anybody noticing an effect. Good sign or bad sign?
Why must the found count and the closed count be reported separately?
The two counts answer different questions, and one of the two is the question that actually matters. The found count answers whether the firm went looking. The open itemA weakness that has been found and has not yet been closed. The weakness is still there, and now it is written down. count answers where the firm stands. Only the second one describes exposure, and it is the one that most often never leaves the technology team.
Watch the movement across three steps. The last of the three is the step nobody prints.
The shape the case makes over several cycles is the whole argument, so push the same case forward. Suppose each future assessment finds roughly what this one found and the firm closes roughly what it closed, four out of twenty three. Every cycle adds nineteen to the pile. Now suppose instead that the firm closes twenty of every twenty three. The two paths are drawn below, and each is arithmetic on its own closure rate carried forward six cycles.
The climbing red path is what happens when a firm keeps looking and stops short of fixing. RemediationThe work of actually closing a weakness that an assessment found, as distinct from recording that it exists. is where the money and the arguments live, and it produces nothing anybody can photograph. Knowledge is what turns a weakness into a decision somebody took, so a firm with a growing catalogue of known open weaknesses stands in a materially worse position than a firm that never looked. Nobody plans it. The red path is simply where an honest assessment programme with no remediation programme always arrives.
A firm's found count rises with every assessment cycle. Diligence, or a problem?
An assessment finds 23 items and 4 are closed by the time the report is signed. Before the control below is moved, how many can the firm be shown to have known about and not fixed?
Move the share of items remediated, and watch which of the two numbers refuses to move.
The assessment at Bhadra Securities Private Limited found 23 items. The control opens at 17 per cent remediated. 23 multiplied by 0.17, rounded to a whole item, gives 4 closed and 19 still open. Both figures are exactly the position on the day the report was signed, and the worked example above carries the same reading in prose. The two buttons follow. One button shows the panel a board usually sees, and that panel prints the found count alone. The other shows the same 23 items split into what is closed and what is not.
What must be reported to the regulator, and what stays inside the firm?
Not everything is reported, and the line between the two is not drawn by the people in the room on the day. Defined categories of incident carry a reporting obligationThe duty to tell the regulator about the categories of incident the framework defines, in the manner and by the route it sets., and the categories, the route and the timing are written in the framework in advance. An event that falls outside those categories is recorded internally and kept. Recording is a different thing from forgetting.
Why does the test sit in a document written months earlier rather than in somebody's judgement on the night? Because of who is in the room. The people deciding whether an event qualifies are tired, they are the people whose systems it happened on, and every one of them has a perfectly human reason to hope the answer is no. A test written in advance takes the decision away from the only people who will ever have an interest in the answer. Taking the decision away from them is the entire reason for writing the test in advance.
Where the requirement itself lives
The obligations described above are set out in the cyber security and cyber resilience framework published by the Securities and Exchange Board of India, together with the circulars issued under it, read at sebi.gov.in on 18 August. The framework reaches regulated entities and not only the institutions underneath them. A depository participant such as Bhadra Securities Private Limited is therefore inside it. The assessment interval, the incident classification, the reporting window and the penalty all sit in the framework, each has been amended, and a description of an amended requirement is not the requirement. The version in force is the one to open. If the firm also carries an obligation on the payment side, the corresponding requirement is read at rbi.org.in rather than inferred from this one.
Why is the reporting test written down before anything happens?
Cybersecurity vs Cyber Resilience: which question is the firm answering?
Cybersecurity and cyber resilience get said in one breath so often that the join between them has worn away, and the join is the point. Cybersecurity is a question about the boundary: can somebody get in, and can something get out. Cyber resilienceThe ability to keep operating through a disruption, as opposed to the ability to prevent one. is a question about the morning after the boundary failed: does the firm keep doing what it exists to do.
Take a wedding. The shape is identical and everybody has stood in one. Security is the man at the gate matching names against a list, and he is genuinely useful. Resilience is whether there is a second gas connection when the first cylinder runs out at nine, a second person who knows where the accounts are, and a plan for the hall losing power in the middle of dinner. A wedding can have a superb man on the gate and still collapse at nine o'clock, and the two facts have nothing to do with each other. Nobody at that wedding will remember the gate, and everybody will remember the ninety minutes with no food.
The bottom row of both panels explains most of what goes wrong. Security spending can be described afterwards: the boundary was tried, here is what was found, here is what was shut. Resilience spending, when it works, produces an ordinary Tuesday and nothing else. There is no photograph of a disaster that did not happen. The result is that resilience is the easier line to postpone in every budget conversation, and the postponement is invisible right up until the morning it is not.
A firm has never been broken into and would be unable to operate for a week if it were. Strong on which?
Who inside the firm is answerable, and why is it never the technology team alone?
Because the obligation is regulatory rather than technical, and regulation attaches to the registration. Sumana Rege and her team find things and fix things, and neither of those acts is the obligation. The obligation is to have looked, to have reported what qualifies, to have been in a position to keep working, and to be able to show all three. The obligation sits where the registration sits. In this firm the registration means Yashodhan Pai as compliance officer and the board above him.
There is a practical consequence, and it is the reason the diagram has the report reaching two places rather than one. If the assessment report stops at the technology team, the compliance officer cannot form a view about what qualifies and the board cannot answer for a state of affairs it was never shown. An obligation that sits above the people who hold the information is only met when the information is deliberately pushed upward, and pushing it upward is itself a step somebody has to be responsible for.
Who carries the regulatory obligation for a cybersecurity incident at a registered firm?
What records must exist afterwards, and which column is read first?
Each of these acts leaves a record behind, and the record is the only version that survives. The assessment leaves a dated report. The remediation leaves a record of what was closed, by whom and when. The reporting decision leaves a note of the category the event fell into, or the reasoning that put it outside. The incident itself leaves a timeline of what was done in what order.
The last column of that facsimile is worth a sentence of its own. An open item with a date the firm set itself is work in progress. An open item with no date at all is not work in progress, it is an item nobody is answerable for, and the two look identical in a total. Counting open items without also counting how many of them nobody has taken a date against will flatter any firm that has stopped short of assigning the work.
An inspection opens the assessment report. Which column does it read first?
What does a firm do in the first hour of an incident?
The order is fixed and it is not the order instinct suggests. Instinct says find out what happened. Finding out what happened is the fourth thing, not the first. ContainmentStopping an incident from spreading further, before anybody understands what caused it. comes first, and it is done without understanding. Understanding takes longer than the spreading does.
Step two is the one that disappears under pressure. Restoring a system tidily and preserving what it looked like are opposite instincts. So the people fixing the problem are also, without meaning to be, the people erasing the evidence of it. Establishing the root causeWhat actually allowed the incident, established calmly after containment rather than guessed at during it. a week later is only possible if somebody, in the middle of the worst hour, thought to keep a copy of the mess. That is why it is a written step with a name against it rather than something anybody is expected to remember.
First hour of an incident. Contain, or diagnose?
What does the firm tell its clients, and when is that a separate duty?
Telling the regulator and telling the people affected are two different obligations with two different triggers, and a firm that satisfies the first can still have done nothing about the second. Anasuya Kolhapure, whose holding of 800 shares sits in a demat account with Bhadra Securities Private Limited, is not a party to the report that goes to the regulator and will never see it.
Her own entitlement is a different question, answered by whether her records or her access were affected, and by whatever the firm's own terms and the applicable requirements say about telling her. The client communication is judged by whether the person affected could act on what they were told. Whether the regulator received what it was owed is a completely different test. A notice that is accurate, timely and incomprehensible has met one duty and failed the other.
How does anybody outside the firm actually use these two numbers?
Outside the firm, the found count and the open count stop being an internal argument. Three readers use them, and each one uses them differently.
The pair of counts is a cheap and unusually honest read on whether a firm finishes work, so an institutional client deciding whether to place business with a broker asks for both across the last few cycles. A firm that supplies the found count and hesitates over the closed count has answered the question. An acquirer running diligence on a broker does something harder and reads the open register item by item. Every open item is a known liability it would be buying, and a known liability is priced differently from an unknown one. And an inspection, as the facsimile above shows, goes straight to the same column.
Anasuya Kolhapure can do none of this, and it is worth being honest about that. A retail client has no route to either number. Regulation therefore places the obligation to look, to report and to be answerable on the firm, rather than leaving it to be demanded by the people who would be affected. The same logic sits under most of securities regulation. The people carrying the risk cannot see it, so the duty goes where the information is.
The failure: a firm that reports what it found and never reports what it closed
The assessment happens on time. The report is thorough and honest. The items are catalogued, circulated and filed. A bigger number of findings does look like better looking. So the board sees a number that rises with every cycle and reads the rise as evidence of a maturing programme. Nobody in that chain has done anything dishonest.
The wrong reading is that finding is the work. Finding is the cheap half, and it is the half with a deliverable. The cost of the misreading is specific rather than vague. The firm accumulates a written, dated, signed record of weaknesses it can be shown to have known about and not addressed, and a written record of that kind is a worse place to stand than never having looked. Nobody chooses that outcome and it is exactly where a diligent assessment programme with no remediation programme arrives, every time, without anybody noticing the turn. The tell is easy to check. Any firm can be asked for its found count and its closed count for the same period. If one of them takes a week to produce, that is the answer.
How any attack technique works, and how a system is secured, is a technical subject taught elsewhere. The assessment interval, the reporting window, the incident classification and the penalty are each read at the source named below. The resilience obligations that sit specifically on market infrastructure institutions are set out under market infrastructure institutions, and the appeal route from any order that follows an inspection is set out under the securities appellate tribunal.
References
| Source | Document | Where |
|---|---|---|
| Securities and Exchange Board of India | The cyber security and cyber resilience framework and the circulars issued under it, named here for the existence of an assessment obligation, an incident reporting obligation and a defined set of reportable categories. The interval, window, classification and penalty are read in the framework itself | sebi.gov.in |
| Securities and Exchange Board of India | The regulations made for depositories and for depository participants, named here only to establish that a participant is a registered entity in its own right and therefore carries these obligations itself rather than inheriting them from the depository it connects to | sebi.gov.in |
| Reserve Bank of India | The corresponding technology and incident requirements issued for entities under that regulator, named so that a firm whose activities sit partly on the payment side knows there is a second address to read rather than assuming one answer covers both | rbi.org.in |
| The depositories and the exchanges, on their own sites | Named for operational fact alone, such as what a participant is asked to connect to and what it must be able to demonstrate to them. Never treated here as the source of a regulatory obligation | nsdl.co.in, cdslindia.com, nseindia.com, bseindia.com |
| International Organization of Securities Commissions | Named for the existence of international work on cyber matters in securities markets, which is where a reader who wants the cross border framing should start rather than generalising from one market | iosco.org |
Bhadra Securities Private Limited, Anasuya Kolhapure, Yashodhan Pai and Sumana Rege are invented.
Educational material. Not advice on any investment, tax, budget or market position.
