The Multi-Commodity Exchange (MCX) on December 16, 2025, issued an updated cybersecurity advisory for exchange members.
It has issued an updated cybersecurity advisory in continuation of earlier circulars, highlighting the increasing sophistication and frequency of cyber-attacks targeting the global and Indian BFSI and financial markets sector. Recent incidents reported by members include ransomware attacks, phishing and spear-phishing, data exfiltration, and large-scale DDoS attacks, all of which pose serious operational, financial, regulatory, and reputational risks.
To strengthen cyber resilience, members are advised to implement comprehensive security controls across their infrastructure. These include strong access control measures such as mandatory multi-factor authentication, adherence to the principle of least privilege, and regular audits of user access. Members should ensure robust patch and vulnerability management with an updated asset inventory.
Further, organisations are urged to adopt effective ransomware and data protection measures, including well-defined backup policies, deployment of data loss prevention tools, and advanced endpoint detection and response solutions. Network security must be reinforced through segmentation of critical systems and the use of reliable cloud-based DDoS mitigation services.
Members are also required to maintain a tested incident response plan and promptly report any suspected or actual cyber incidents to the Exchange and relevant regulators. The Exchange emphasizes that cyber security is a shared responsibility, and strict adherence to these measures is essential to safeguard individual organisations and the overall stability and trust of the market.
[Circular no.: MCX/TECH/639/2025]