The Bombay Stock Exchange (BSE) on January 08, 2025, notified regarding the Standard Operating Procedure (SOP) for handling Cyber Security Incidents.
The following has been stated namely: -
• It states that the REs, Members, and DPs shall report cyber security incidents within 6 hours and implement precautionary measures to prevent threats, as per SEBI/MIIs guidelines attached in Annexure A.
• It states precautionary measures that the Connectivity with Exchanges/Depositories will be disabled for CRITICAL or HIGH severity cyber incidents and restored only after submission of a mitigation report certified by a Cert-IN empaneled auditor confirming complete risk mitigation.
• It provides the timelines applicable for incident reporting(s)/submissions by the REs/Members/DP to SEBI/Exchange/Depository.
• It also provides the penalty framework as applicable in case of delay/non-submission of Immediate Cyber Incident, Mitigation Report, RCA, VAPT Report, or Forensic Audit Report is attached in Annexure B.
• It further provides the Penalty framework as applicable based on the review of the cyber security incidents by the Joint/Relevant Committee of the Exchange(s) /Depositories is attached in Annexure C
Detailed notification is attached below.
[Circular no. - 20250108-42]