Skip to main content

Biometric Check Mulled for Stock Trading via Apps

Biometric Check Mulled for Stock Trading via Apps
Securities and Exchange Board of India (Sebi) has proposed biometric authentication for traders and investors when they access mobile applications to buy and sell stocks.
Aimed at improving cyber security, this is part of a long list of recommended dos and don’ts compiled by the markets regulator in a note recently shared with stock exchanges and brokers.
“The draft note says that in case of applications installed on mobile devices such as smartphones and tablets, a cryptographically secure biometric twofactor authentication mechanism may be used,” a person familiar with the subject told ET.
The proposal, if implemented, would require retail investors use touch ID-enabled smartphones for trading and sharing biometric features like fingerprint or eye-scan to access their trading and demat accounts. Offered as an option to accountholders by some of the private sector banks, the mechanism involves the handheld device carrying out one step of the authentication instead of the service provider.
According to the Sebi note, after a certain number of failed log-in attempts, the customer’s account should be ‘locked’ till fresh authentication is completed by sending an email or a random one-time password to the customer. The paper asks brokers to ensure that no person by virtue of rank or position has any right to access confidential data, applications, system resources or facilities.
Further, they should formulate an internet access policy to monitor and regulate the use of internet and internet-based services such as social media sites and cloud-based internet storage sites within a broker’s critical IT infrastructure.
Concerns for Small Brokers
 
“For algorithmic trading facilities, adequate measures should be taken to isolate and secure the perimeter and connectivity to the servers running algo trading applications,” said the note.
 
Also, employees and outsources staff (such as employees of vendors or service providers) who may have authorised access to a broker’s critical system should be subject to stringent monitoring, says one of the recommenddations.“Sebi has sought comments from different people and will have to examine the preparedness of brokers before implementing it. We have done categorisation. The proposals will be implemented in phases,” said a regulatory official.
 
Some of the recommendations in the draft note can be onerous for small brokers who operate on waferthin margins and low-cost structure. “For instance, one of the suggestions is that off-the-shelf products being used for core business functionality, such as back office applications, should bear Indian common criteria for evaluation assurance level 4. Any technology person will admit this is a very demanding requirement as there are only one or two labs from where such certification can be obtained. The telecom department had attempted this in the past,” said a brokerage official.
 
According to an industry person, keeping in mind smaller brokers who can’t afford the cost, the regulator may explore the possibility of one of the stock exchanges managing the security setup for these entities.While the Sebi draft paper is a compilation of suggestions from an expert committee, it has been circulated at a time when two well-known brokers serving retail and high networth investors faced cyber-attacks.
 
One of the intermediaries informed clients about the breach involving unauthorised access to customer information; in the other case, a virus found its way into a few back office servers and PCs, and even though there was no data breach or trading interruption, the brokerage concerned had to run some of the back office processes manually for a day or two till those servers were brought back online after a clean-up.The attack on stockbrokers follows malware attacks on some of the Indian banks and credit card data bases over the past few years.

The Business Standard, New Delhi, 23rd April 2018

Comments

Popular posts from this blog

Credit card spending growth declines on RBI gaze, stress build-up

  Credit card spends have further slowed down to 16.6 per cent in the current financial year (FY25), following the Reserve Bank of India’s tightening of unsecured lending norms and rising delinquencies, and increased stress in the portfolio.Typically, during the festival season (September–December), credit card spends peak as several credit card-issuing banks offer discounts and cashbacks on e-commerce and other platforms. This is a reversal of trend in the past three financial years stretching to FY21 due to RBI’s restrictions.In the previous financial year (FY24), credit card spends rose by 27.8 per cent, but were low compared to FY23 which surged by 47.5 per cent. In FY22, the spending increased 54.1 per cent, according to data compiled by Macquarie Research.ICICI Bank recorded 4.4 per cent gross credit losses in its FY24 credit card portfolio as against 3.2 per cent year-on-year. SBI Cards’ credit losses in the segment stood at 7.4 per cent in FY24 and 6.2 per cent in FY23, the...

SFBs should be vigilant, proactive to mitigate risks: RBI deputy guv

  The Reserve Bank of India’s Deputy Governor Swaminathan J on Friday instructed the directors of small finance banks (SFBs) to be vigilant and proactive in identifying emerging risks in the sector.Speaking at a conference for directors on the boards of SFBs, Swaminathan highlighted the role of governance in guiding SFBs towards sustainable growth with stability. He also emphasised the importance of sustainable business models.Additionally, he highlighted the need for strengthening cybersecurity to protect the entities against digital threats and urged for a stronger focus on financial inclusion, customer service, and grievance redressal to ensure a broader reach of banking services.Executive Directors S C Murmu, Rohit Jain, and R L K Rao, along with other senior officials representing the Supervision, Regulation, and Enforcement Departments of the RBI, also participated in the conference.   -  Business Standard  30 th  September, 2024

Brigade Hotel Ventures files draft papers with Sebi for Rs 900 crore IPO

  Brigade Hotel Ventures Ltd, owner and developer of hotels in South India, has filed draft papers with capital markets regulator Sebi to raise Rs 900 crore through an initial public offering (IPO).The proposed IPO is entirely a fresh issue of equity shares with no Offer-for-Sale (OFS) component, according to the draft red herring prospectus (DRHP).Proceeds from the issue to the tune of Rs 481 crore will go towards payment of debt, Rs 412 crore will be allocated to the company and Rs 69 crore to its material subsidiary, SRP Prosperita Hotel Ventures Ltd.Additionally, Rs 107.52 crore will be used to purchase an undivided share of land from the Promoter, BEL, and the remaining funds will support acquisitions, other strategic initiatives, and general corporate purposes.The company may raise up to Rs 180 crore through a Pre-IPO Placement.   If the placement is undertaken, the issue size will be reduced.Brigade Hotel Ventures Ltd is a wholly-owned subsidiary of Brigade Enterprises ...