Compliance & Risk Advisory
Gap assessments, policies and playbooks aligned with RBI, SEBI CSCRF, CERT-In, IRDAI, PCI DSS and DPDP.
Learn more about Compliance & Risk Advisory →CSCRF brings SEBI's earlier cyber security circulars into a single framework for SEBI-regulated entities (REs). It is built around standard cyber security functions — governance, identification, protection, detection, response and recovery — and sets expectations for cyber resilience, not only compliance.
Obligations are graded by category. Larger and more critical entities face more requirements, while smaller entities have a lighter, proportionate set. Knowing your category is the first step.
Board-approved cyber security and cyber resilience policy, defined roles and oversight proportionate to your category.
Inventory of critical systems and data, with risk assessment of those assets.
Access control, data security, network security, patch and configuration management.
Log collection and monitoring through a security operations centre, which may be own, third-party or market SOC depending on category.
Periodic vulnerability assessment and penetration testing, with remediation tracked and reported.
Periodic cyber audit and reporting of compliance to SEBI as specified for your category.
MIIs and Qualified REs measure their cyber resilience maturity using the Cyber Capability Index.
A response and recovery plan, and reporting of cyber incidents to SEBI and CERT-In within prescribed timelines.
Aligned with, not endorsed by any regulator. This page is a plain-English summary for awareness — confirm obligations against the latest official circulars or with your compliance officer.
Gap assessments, policies and playbooks aligned with RBI, SEBI CSCRF, CERT-In, IRDAI, PCI DSS and DPDP.
Learn more about Compliance & Risk Advisory →Find and fix weaknesses in apps, APIs, networks and cloud before attackers exploit them.
Learn more about VAPT →Independent review of your systems, controls and architecture against the rules you must follow.
Learn more about Security Audit →24/7 SIEM and EDR monitoring, threat hunting and dark-web monitoring for your environment.
Learn more about Managed Security Monitoring (SOC/MDR) →Call us when it matters: triage, containment, recovery and regulator reporting support.
Learn more about 24/7 Incident Response →Categories depend on entity type and thresholds defined by SEBI. We help you confirm your category and map the obligations that follow.
Security monitoring is expected across categories, but the form differs. Smaller entities may use a market SOC or third-party SOC. We help you choose what fits.
SEBI specifies auditor requirements, such as CERT-In empanelment for certain audits. We tell you clearly what we deliver and where a qualified auditor signs.
We assess where you stand, close the gaps and prepare the evidence your auditors and regulator will ask for.
support@trustnetsecure.com · +91 93229 37312 · +91 88300 61438
Under attack right now? Go to emergency help →
📍 Location not reported
📍 Location not reported
📍 Location not reported
📍 Location not reported
📍 Location not reported
📍 Location not reported
Source: The Hacker News — headlines only, each linking to the original article.