Cyber Security Policy for Research Analysts
The purpose of this Cyber Security Policy is to establish guidelines and procedures to safeguard the confidentiality, integrity, and availability of sensitive data handled by Research Analysts (RAs).
This policy applies to all Research Analysts, employees, and third-party service providers who access, process, or manage sensitive data.
1. Data Protection Responsibilities
- Research Analysts are responsible for protecting sensitive data, including client information and proprietary research findings.
- RAs must comply with all applicable laws and regulations related to data protection and privacy.
2. Access Control
- Access to sensitive data must be restricted to authorized personnel only. RAs should use strong, unique passwords and change them regularly.
- Multi-factor authentication (MFA) must be implemented for accessing sensitive systems and data.
3. Data Encryption
- Sensitive data must be encrypted both in transit and at rest to protect against unauthorized access and data breaches.
- RAs must use secure communication channels (e.g. VPNs, encrypted email) when transmitting sensitive information.
4. Device Security
- All devices used by RAs, including laptops and mobile devices, must have up-to-date antivirus software and security patches.
- RAs must lock devices when not in use and avoid using public Wi-Fi networks for accessing sensitive information.
5. Training and Awareness
- RAs are required to participate in regular cybersecurity training sessions to stay informed about current threats and best practices.
- Awareness campaigns will be conducted to promote a culture of security within the organization.
6. Data Retention and Disposal
- Sensitive data must be retained only as long as necessary for business purposes and must be securely disposed of when no longer needed.
- Digital data should be deleted using secure deletion methods, and physical documents must be shredded.
7. SaaS Advisory for Financial Sector Organizations
- The Ministry of Electronics & Information Technology (MeitY) has informed SEBI that financial sector institutions are increasingly using Software as a Service (SaaS) solutions for managing Governance, Risk, and Compliance (GRC) functions to enhance their cyber security posture.
- While SaaS offers ease of use and quick turnaround, it may also pose significant risks, particularly as risk and compliance data may move beyond India’s legal jurisdiction due to the nature of shared cloud services, thereby compromising data safety and security.
- The Indian Computer Emergency Response Team (CERT-In) has issued an advisory for financial sector organizations, which has been forwarded to SEBI. Compliance with this advisory is essential for maintaining data integrity.
- Organizations must ensure complete protection and seamless control over critical systems through continuous monitoring and direct control mechanisms, while keeping critical data within India’s legal boundaries.
- Research Analysts are required to report compliance with this advisory to SEBI on a half-yearly basis, providing an undertaking that states, “Compliance with the SEBI circular for Advisory for Financial Sector Organizations regarding Software as a Service (SaaS) based solutions has been made.”
8. Compliance Monitoring
- Compliance with this policy will be monitored regularly, and audits may be conducted to ensure adherence to cybersecurity protocols.
- Violations of this policy may result in disciplinary action, up to and including termination.
9. Effective Date
This Cyber Security Policy is effective as of 13 April 2026 and will be reviewed annually for updates.
Regards,
Trade Nova Technologies Private Limited
SEBI Registered Research Analyst
SEBI Registration No.: INH000026789
Need help with this?
Our Principal Officer, Harinder Singh, and Compliance Officer, Pardeep Kumar, are available MonโFri ยท 9:00 AM to 5:00 PM.