New Delhi: The Securities and Exchange Board of India (SEBI) has imposed a total penalty of ₹1 crore on Central Depository Services (India) Ltd. (CDSL) for cybersecurity lapses linked to the November 2022 malware attack. In its 88-page order, SEBI concluded that the cyberattack was not an unforeseeable incident but a foreseeable consequence of the company’s failure to comply with mandatory cybersecurity standards.
The regulator imposed a ₹90 lakh penalty under the SEBI Act and an additional ₹10 lakh under the Depositories Act. However, proceedings against CDSL’s former Chief Information Security Officer (CISO) Rajesh Nadkarni and former Chief Technology Officer (CTO) Amit Mahajan were disposed of without any monetary penalty.
According to SEBI, CDSL failed to classify its internet-facing Active Directory Federation Services (ADFS) server as a critical asset under the revised cybersecurity framework. As a result, the server was excluded from mandatory security testing, risk assessments, and continuous security monitoring.
The investigation also found weaknesses in password management, deviations from prescribed cybersecurity policies, and inadequate monitoring and timely response to security alerts. SEBI observed that CDSL had failed to maintain the basic level of cybersecurity hygiene expected from a market infrastructure institution.
Forensic investigators determined that the attackers had gained access to CDSL’s network as early as November 2021, nearly a year before the malware attack was detected on November 18, 2022. SEBI said the prolonged compromise highlighted significant shortcomings in the company’s cybersecurity monitoring framework.
The malware attack disrupted several critical depository services, including settlement, securities transfer, and pledge transactions, forcing market participants to defer a number of transactions over the weekend.
Renowned cybercrime expert and former IPS officer Prof. Triveni Singh said that cybersecurity failures in financial market institutions are not merely technical issues but pose a serious threat to investor confidence and the stability of the financial system. He stressed that organisations should ensure proper identification of critical assets, conduct regular security audits, maintain 24×7 security monitoring, enforce strong access controls, implement timely patch management, and adopt Multi-Factor Authentication (MFA) across critical systems.
SEBI reiterated that compliance with prescribed cybersecurity standards is mandatory for market infrastructure institutions and warned that similar lapses would continue to attract strict regulatory action. The regulator concluded that the deficiencies identified during the investigation significantly increased the risk of the malware attack and that the incident could have been substantially mitigated through proper cybersecurity controls.
