Mumbai: The Securities and Exchange Board of India (SEBI) has imposed a monetary penalty of ₹1 crore on Central Depository Services (India) Limited (CDSL) over lapses linked to the malware attack that occurred in 2022. The regulatory action underscores the growing importance of cybersecurity governance in India’s financial infrastructure and serves as a reminder that organizations handling critical financial data must maintain strong cyber resilience.
According to SEBI’s order, the regulator identified deficiencies in CDSL’s cybersecurity management and oversight. The investigation found that attackers remained within the organization’s environment for nearly a year before the malicious activity was fully detected. The prolonged presence of threat actors raised concerns regarding visibility into digital assets, monitoring mechanisms, and overall cyber risk management practices.
SEBI observed shortcomings in the management of certain unmonitored and unmanaged assets, which potentially contributed to delayed detection of the compromise. However, the order did not impose any monetary penalties on the Chief Technology Officer (CTO) or Chief Information Security Officer (CISO), despite their names being referenced during the proceedings.
Cybersecurity experts note that modern cyber incidents are increasingly linked to governance failures rather than purely technical vulnerabilities. Continuous monitoring, asset inventory management, early threat detection, and board-level oversight are now considered essential elements of an organization’s security posture.
The action against CDSL reflects the regulator’s broader emphasis on ensuring that financial institutions strengthen their cyber defence capabilities. Financial market infrastructure entities are increasingly targeted by sophisticated threat actors seeking access to sensitive financial systems, making proactive risk management and timely incident response critical.
Industry observers believe the order sends a strong message to organizations across sectors that cybersecurity must be treated as a strategic business risk rather than merely an IT function. Boards and senior leadership are expected to actively oversee cyber risk governance, ensure accountability, and allocate adequate resources for security controls.
As India’s digital financial ecosystem continues to expand, regulators are expected to maintain close scrutiny of cybersecurity preparedness across stock exchanges, depositories, banks, and other critical institutions. The latest enforcement action reinforces the need for stronger governance, better visibility of digital assets, and continuous monitoring to reduce cyber risks and protect market integrity.
