Arihant Intellect logoArihant Intellect

Website Security for SEBI-Registered Intermediaries: A Practical Guide

Guide by Arihant Intellect · September 2026

Your website is the public face of a SEBI-regulated business — and it holds or links to sensitive client information. A defaced homepage, a spoofed email, or a few hours of downtime isn’t just embarrassing; for a regulated intermediary it’s a trust and compliance problem. The good news: most attacks are preventable with a handful of well-known controls.

This applies to you if you are…

Cyber-hygiene expectations under SEBI apply across the board — not only to large brokers:

Research Analysts (RA)Investment Advisers (IA)Stock Brokers Depository ParticipantsPortfolio ManagersMutual Funds / AMCs Merchant BankersRegistrars & Transfer AgentsKYC Registration Agencies AIFsCustodiansAny SEBI-registered intermediary

Why intermediaries are targeted

Financial-sector websites are attractive because they carry credibility and client data. Attackers want one of three things: to impersonate you (phishing your clients), to deface or take down your site (reputational damage), or to steal data or credentials. Threat activity also tends to rise around high-profile national events, when opportunistic and automated attacks increase across Indian websites generally.

The threats, in plain language

What SEBI expects

SEBI’s Cyber Security and Cyber Resilience Framework (CSCRF) asks regulated entities to protect their IT systems, websites and client data, with the depth of controls scaled to the size of the entity. Even a solo Research Analyst or Investment Adviser is expected to follow basic cyber-hygiene — secure hosting, strong authentication, backups, and an ability to respond to an incident. Always confirm the requirements applicable to your category on the official SEBI website.

The practical security checklist

1. Website & server

2. Email & accounts

3. Availability (DDoS)

4. Data & recovery

As your developer, here’s how we harden your site

Security isn’t a plugin you bolt on later — it’s how the site is built and hosted. This is what Arihant Intellect does by default:

Get a free website security check

We’ll review your current site for the basics above — hosting, HTTPS, email spoofing protection and exposure — and tell you where you stand, no obligation.

Request a free check on WhatsApp

Frequently asked questions

Does SEBI require intermediaries to secure their websites?

Yes — SEBI’s CSCRF expects regulated entities to protect their systems, websites and client data, scaled to the size of the entity. Confirm your category’s requirements on sebi.gov.in.

My site is just a one-page compliance site — do I still need this?

Yes. Even a static page can be defaced, impersonated, or have its email domain spoofed. A well-built static site on a hardened host removes most of the risk at very low cost.

What should I do if I suspect an attack?

Preserve logs, take the affected system offline if needed, restore from a trusted backup, and report the incident to CERT-In. Having a plan ready in advance is half the battle.

This article is general information for awareness, not legal, compliance or security-certification advice. Arihant Intellect is a web & IT service provider, not a SEBI-registered intermediary, and does not provide investment advice. Verify all regulatory requirements with official SEBI and CERT-In sources.