Cyber Security Governance & Incident Reporting
FGP Limited maintains robust information technology policies, controls, and oversight mechanisms to safeguard investor data, system integrity, and financial reporting systems.
1. IT Governance & Board Oversight
The Board of Directors oversees the IT Governance and Information Security framework of FGP Limited. In alignment with regulatory expectations, the company has implemented a Board-approved Information Security Policy which includes:
- Oversight Committee: Periodic review of IT infrastructure resilience, data security compliance, and vulnerability mitigations.
- Security Policy Framework: Regular reviews of system access controls, data storage encryption protocols, and backup systems.
- Risk Mitigation: Annual employee security awareness initiatives, threat simulations, and strict password complexity policies.
2. Cybersecurity Controls & Vulnerability Auditing
To maintain operational stability and protect stakeholder information, FGP Limited implements key technical security controls:
- Data Encryption: All sensitive investor coordinates and transactional records are encrypted both in transit (SSL/TLS) and at rest.
- Access Management: Strict role-based access control (RBAC) restricts internal administration panel access to authorized personnel only.
- External Audits: Periodic Vulnerability Assessment and Penetration Testing (VAPT) conducted by certified information security consultants to identify and patch system flaws.
- Web Application Security: Content-Security-Policy (CSP) and HTTP security headers (HSTS, X-Content-Type-Options) configured to block cross-site scripting (XSS), clickjacking, and mime-type sniffing.
3. Incident Response & Mandatory Reporting
FGP Limited maintains a defined Cyber Crisis Management Plan (CCMP) to respond to potential cybersecurity events. In compliance with the Indian Computer Emergency Response Team (CERT-In) and respective stock exchange guidelines:
- Rapid Notification: Any major cyber incident or data breach must be reported to CERT-In within the mandated 6-hour window of detection.
- Material Event Disclosure: Significant cybersecurity breaches impacting operations or containing material information are promptly reported to BSE Limited under Regulation 30 of SEBI (LODR) Regulations.
- Compliance Reporting: Status reports on cybersecurity events are submitted quarterly to the stock exchanges as part of the Corporate Governance Report.
Quarterly Cybersecurity Incident Log (SEBI Reg 27(2)(ba))
As required under the SEBI corporate governance format, FGP Limited discloses the details of cybersecurity incidents, data breaches, or loss of data/documents on a quarterly basis:
| Financial Year | Quarter | Incident/Breach Occurred (Yes/No) | Date of Event | Brief Details / Action Taken |
|---|---|---|---|---|
| FY 2025-26 | Quarter 4 (Q4) | No | - | Nil incidents reported during the quarter. Systems operational. |
| Quarter 3 (Q3) | No | - | Nil incidents reported during the quarter. Systems operational. | |
| Quarter 2 (Q2) | No | - | Nil incidents reported during the quarter. Systems operational. | |
| Quarter 1 (Q1) | No | - | Nil incidents reported during the quarter. Systems operational. | |
| FY 2024-25 | Quarter 4 (Q4) | No | - | Nil incidents reported during the quarter. Systems operational. |
| Quarter 3 (Q3) | No | - | Nil incidents reported during the quarter. Systems operational. | |
| Quarter 2 (Q2) | No | - | Nil incidents reported during the quarter. Systems operational. | |
| Quarter 1 (Q1) | No | - | Nil incidents reported during the quarter. Systems operational. |
