Skip to main content

Capital Markets

Protecting 1.7M+ users with SEBI compliance for Marketwolf

SEBI cyber security and cyber resilience framework compliance for a high-volume retail trading platform.

Scale

1.7 million+ users

Marketwolf

  • SEBI Compliance Audit
  • Application Security Testing
Protecting 1.7M+ users with SEBI compliance for Marketwolf

The brief

Bring a retail trading platform serving over 1.7 million users to SEBI's cyber security and cyber resilience expectations.

What we did

  • Gap assessment against the SEBI cyber security and cyber resilience framework
  • Application, API and mobile assessment of the trading platform
  • Governance and policy work: incident response, access control, third party risk
  • Evidence pack prepared for the regulator's format

A trading platform sits under a regulator that asks specific questions and expects specific evidence. The technical work matters, but the reason engagements like this succeed or fail is usually the governance layer, because that is where the regulator looks first.

The gap between secure and demonstrable

Marketwolf's platform was not insecure. Most of the initial gap sat in the distance between controls that operated and controls that could be shown to operate to somebody who was not in the room. A policy that exists but was last reviewed two years ago, an access review that happens informally, an incident process that lives in the heads of three people.

SEBI's framework is explicit about governance, and the finding pattern reflects that. We ran the gap assessment against the framework clause by clause and separated the findings into two lists: things that needed building, and things that needed evidencing.

The technical assessment

Trading platforms carry a specific risk profile. Order manipulation, race conditions around order state, and authorisation between accounts matter more than they would on a content platform, because the exploit outcome is financial and immediate.

Mobile was in scope alongside web and API, since a retail platform's real attack surface is the app most users hold rather than the site.

Governance work

We wrote and reworked the artefacts the framework requires: incident response with named owners and escalation timing, access control policy with a review cadence that actually happens, third party risk covering the vendors in the critical path.

The test of whether this work landed is not the document. It is whether the second access review, six months later, still happened without us.

What was handed over

The gap assessment mapped to framework clauses, technical findings with reproduction and retesting, the governance artefacts, and an evidence pack organised the way the regulator asks for it.

Users protected
1.7 million+
Framework
SEBI cyber security and resilience
Scope
Web, API, mobile, governance

Engagement detail is summarised. Specific findings, payloads and architecture remain confidential under our client agreements.

Not sure where to start?

Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.