NISM Professor

Cyber Security Risk

Also written Cyber risk · CSCRF · Cyber Security and Cyber Resilience Framework · Cyber security risk (AIF compliance)

The risk that an AIF's or its service providers' systems are breached, corrupted or disrupted — governed by SEBI's Cyber Security and Cyber Resilience Framework, which all AIFs had to comply with by 31 August 2025.

In plain language

An AIF processes, stores and transmits large amounts of electronic information — transaction data for the fund and personally identifiable information of its investors — and so do its service providers. With increased use of technology and artificial intelligence, investment vehicles and their service providers may be prone to information security risks arising from cyber-attacks.

The workbook lists what those attacks look like: stealing or corrupting data maintained online or digitally, denial-of-service attacks on websites, unauthorised release of confidential information, and causing operational disruption.

It is also honest about the limit of any answer. AIFs should have adequate internal procedures and systems, but such procedures cannot provide absolute security, and it may be difficult even to detect the techniques used to obtain unauthorised access.

How it works

The baseline obligations. All securities market intermediaries are required to store their data within Indian geographical boundaries and to have adequate controls and checks as per CERT-In. Any incident must be reported to the sector regulator and the central government within 6 hours.

The framework. SEBI's Cyber Security and Cyber Resilience Framework (CSCRF) follows a graded approach, classifying regulated entities into five categories: Market Infrastructure Institutions, Qualified REs, Mid-size REs, Small-size REs and Self-certification REs. The category is decided at the beginning of the financial year on the previous year's data, and the entity stays in that category for the whole year whatever happens to the parameters; the reporting authority validates it at the time of compliance submission. All AIFs were required to comply by 31 August 2025.

Categorisation is done at Manager level, not fund level — and if the manager of an AIF also manages VCFs, the corpus of those VCF schemes is clubbed in:

CriterionQualified REsMid-size REsSmall-size REsSelf-certification REs
Sum of corpus of all AIFs, VCFs and their schemes managed by a ManagerN/ARs 10,000 crore and aboveMore than Rs 3,000 crore and less than Rs 10,000 croreRs 3,000 crore and below

Managers classified as self-certification REs with a client base of fewer than 100 are exempted from the mandatory Market-SOC (M-SOC) requirement — a shared security operations centre designed for smaller entities, cheaper than building a full SOC from scratch.

One more classification matters for the exam. Cyber security risk sits in the workbook's list of risks that are not measurable, alongside macro-economic, legal and regulatory, operational and country-specific risk. No ratio in Chapter 9 captures it.

A worked example

Bhima Asset Managers runs three AIF schemes and one legacy VCF scheme:

VehicleCorpus
Bhima Credit Fund IRs 4,200 crore
Bhima Growth Fund IIRs 3,100 crore
Bhima Long-Short Fund (Cat III)Rs 1,500 crore
Bhima VCF Scheme ARs 600 crore
Clubbed at Manager levelRs 9,400 crore

At Rs 9,400 crore Bhima is a Small-size RE — more than Rs 3,000 crore, less than Rs 10,000 crore — for the whole financial year.

It closes a new scheme of Rs 700 crore in November, taking the clubbed corpus to Rs 10,100 crore. Nothing changes this year: the category was fixed at the start of the financial year and stays fixed. From the next financial year, Bhima is a Mid-size RE, with the heavier standards that follow.

In February, a service provider's network is compromised and investor KYC files for 310 investors are exposed.

Incident detected              Thursday, 09:40
Report to sector regulator and
  central government due by     Thursday, 15:40   (within 6 hours)

Bhima is not exempt from the M-SOC requirement either — that exemption needs both self-certification status and fewer than 100 clients, and Bhima fails both tests. A single scheme closing at Rs 700 crore, taken alone, looks like a commercial decision; through the CSCRF it is a compliance-category decision as well.

Why NISM asks about it

Chapter 9 section 9.5 lists cyber security risk among the types of risk in AIFs and gives the 6-hour reporting rule and the data localisation requirement; Chapter 11 section 11.11 carries the CSCRF, the five categories, the corpus thresholds, the manager-level clubbing and the 31 August 2025 date. Expect a threshold-to-category question and a 'within how many hours' question.

Common exam traps

  • Categorisation is at Manager level, clubbing every AIF and VCF scheme that manager runs — not per fund and not per scheme.
  • Once fixed at the start of the financial year, the category holds for the year, however the corpus moves.
  • For AIFs and VCFs the Qualified RE row is N/A. The top band that can apply is Mid-size, at Rs 10,000 crore and above.
  • 6 hours is the incident reporting window, to the sector regulator and the central government; data must be stored inside India per CERT-In.
  • The M-SOC exemption needs both conditions — self-certification RE status and a client base below 100.
  • Cyber security risk is in the not-measurable list. No Chapter 9 metric quantifies it, which is why the answer is controls and a framework rather than a ratio.

Where this is taught

Free preparation for NISM Series XIX-D

Related terms

← All terms
Something look wrong? Report it