भारी वर्षाको प्रक्षेपणपछि काभ्रेमा सचेतना
The Nepal Stock Exchange opened again on Tuesday after a major data centre problem forced the market to suspend trading for a full day. For many people, the immediate relief is that trading has resumed.
But investors should be asking a much bigger question.
How safe is their investment when almost everything they own in the stock market exists today as digital data?
The recent ransomware attack at Data Hub has brought this question directly to the surface. The data centre hosts the systems of 72 brokerage companies. The attack affected several interconnected services, including trading management systems, systems related to CDSC and payment gateways. Because the affected systems were connected to the wider market infrastructure, continuing trading was considered risky.
This was not simply a website going offline.
A stock market is built on information. Who owns which shares, how many shares they own, what they bought, what they sold, how much money they have paid, what is waiting for settlement and what has already been settled are all recorded electronically.
When that information becomes unavailable, corrupted or manipulated, the problem can become much bigger than a one day trading suspension.
The frightening question is what happens if an attack is much worse next time.
What if hackers do not simply stop a system but enter it?
What if they alter records?
What if they encrypt the data and demand money?
What if they destroy the main database and the backup at the same time?
What if somebody changes the ownership record of shares?
What if a transaction is shown as completed when it was not?
What if money is transferred to the wrong account?
And most importantly, what happens if the market authorities cannot immediately establish which record is the correct one?
These are not imaginary questions anymore. The latest incident has shown that a cyberattack on one important data centre can affect a large part of the market.
There is, however, one important point that investors should understand.
A cyberattack does not automatically mean that billions of rupees worth of shares simply disappear. Nepal’s securities infrastructure is not based on one single database alone. CDSC is the central depository responsible for recording ownership and settlement of securities, while investors also interact through depository participants and brokerage systems. CDSC says investor holdings are stored in its centralised database and that it maintains backup systems and encrypted communication.
But this does not eliminate the risk.
The real danger is the loss, corruption or manipulation of the records that prove ownership and transactions.
If a person owns shares worth Rs 10 million, the physical shares are no longer sitting in a safe somewhere. The person’s ownership exists through electronic records. If those records become unavailable or unreliable, the investor could face a serious legal and operational problem even though the underlying company and its shares still exist.
This is why the recent incident deserves a much deeper investigation.
The investigation should not stop at asking who caused the technical failure.
It should ask whether Nepal’s capital market infrastructure was properly prepared for such an attack.
The first question should be about backup.
Where exactly are the backup copies of critical investor and transaction data?
Are they stored separately from the main system?
Can hackers who compromise the main system also reach the backup?
How frequently are backups made?
Are they tested regularly?
Most importantly, can the market actually restore the system from those backups after a complete cyberattack?
A backup that has never been tested is not much comfort during a real disaster.
The second question should concern disaster recovery.
If the main data centre becomes unavailable, how quickly can the market move to another system?
Does Nepal have a fully functional alternative data centre?
Can all affected brokers immediately shift to it?
Can trading continue without putting investor records at risk?
Reports have raised questions about disaster recovery arrangements following the latest ransomware incident. These questions should now be answered with evidence rather than assurances.
The third question is about concentration.
If 72 out of the country’s brokerage companies depend on the same data centre, what happens when that single facility goes down?
A system may be efficient when everything is working normally. But concentration can become a major weakness during a crisis.
The investigation should therefore examine whether too much of Nepal’s capital market infrastructure has been placed in too few hands.
The fourth question is about access.
Who can access investor data?
How many people or companies have administrative access?
Are their activities recorded?
Can an employee or outside contractor change important records?
Are privileged accounts protected with strong authentication?
Are there independent logs that cannot be secretly altered?
Cybersecurity is not only about hackers sitting somewhere outside Nepal. Internal access can also become a security risk if controls are weak.
The fifth question is perhaps the most important.
Can Nepal prove who owns what after a major cyberattack?
Suppose an investor’s records show 5,000 shares today but 3,000 shares after a serious cyber incident.
Which record will be treated as final?
Suppose a sale appears in one system but not another.
Which system will have legal authority?
Suppose a transaction is completed but the relevant records are corrupted.
Who will bear the loss?
These questions should have clear answers before a major disaster happens, not after it.
The sixth question concerns responsibility.
Nepal’s capital market involves NEPSE, CDSC, SEBON, brokers, technology companies, data centres, banks and payment systems. When everything works, the division of responsibility may appear straightforward.
During a cyberattack, however, responsibility can quickly become complicated.
The investigation should clearly establish who was responsible for cybersecurity at each layer, who was monitoring the system, who received warnings, who had authority to shut down systems and whether anyone failed to follow an established security procedure.
The seventh question should be about regular independent testing.
SEBON had already directed NEPSE to conduct an IT audit and vulnerability assessment and penetration testing of its trading management system.
The latest incident makes such testing even more important.
Security cannot be established by saying that a system has security features. It must be demonstrated through independent testing.
Authorities should know what happens when an attacker tries to break the system.
They should know how long it takes to detect an attack.
They should know how quickly the system can be isolated.
They should know whether the backup survives.
And they should know whether trading can safely continue through another route.
The eighth question is about investor protection.
If a cyberattack causes permanent loss or manipulation of records, who compensates the investor?
Does Nepal have a clear compensation mechanism?
Does insurance cover such an event?
Are brokers responsible?
Is the technology provider responsible?
Does the exchange bear responsibility?
Or does the investor ultimately carry the risk?
An investor should not have to discover the answer to these questions after losing access to years of savings.
The latest incident should therefore be treated as a warning rather than simply a technical problem that has now been fixed.
The market has resumed trading. That is good news.
But reopening the market does not mean the cybersecurity questions have disappeared.
Nepal’s capital market now holds enormous amounts of public wealth in digital form. Recent reporting has put the value of investors’ assets at more than Rs 4.5 trillion.
That is too much wealth to protect with assumptions.
Investors do not need to understand ransomware, servers, encryption or network architecture. They need only one basic assurance.
When they buy shares, their ownership must remain safe even if a computer system fails or is attacked.
That assurance cannot come from a press statement.
It must come from strong architecture, independent audits, tested backups, alternative systems, clear responsibility and a legally enforceable mechanism for restoring investor records.
The SEBON investigation therefore has a much bigger task than explaining why the market was closed on September 21.
It should answer a fundamental question for every Nepali investor.
If the worst possible cyberattack happens tomorrow, can the country’s capital market prove exactly who owns what?
If the answer is yes, investors deserve to know how that protection works.
If the answer is no, the country has a problem that cannot be solved simply by reopening the market.
A stock market is ultimately a market of trust.
Prices may rise and fall every day.
But the ownership record must never become a matter of uncertainty.
