SEBI has fined CDSL ₹10 million for cybersecurity failures during a 2022 malware attack. The regulator identified an unsecured internet-facing server as the root cause, leading to significant delays in market settlements. The penalty underscores the strict enforcement of cybersecurity standards for all market intermediaries handling investor data.
India’s markets regulator, the Securities and Exchange Board of India (SEBI), has imposed a penalty of ₹10 million on Central Depository Services (India) Ltd (CDSL) for failing to safeguard critical systems during a 2022 malware attack.
The Securities and Exchange Board of India (SEBI) announced on Monday that it has imposed a total penalty of ₹10 million (1 crore) on Central Depository Services (India) Ltd (CDSL). The fine stems from significant cybersecurity and compliance failures that led to a major malware incident in November 2022. This development marks a stern regulatory response to lapses that disrupted key depository operations, including settlement activities and margin pledges, affecting one of the country's largest repositories of investor accounts.
Anatomy of the 2022 Malware Attack
The investigation by SEBI focused on a security breach that occurred in the early hours of November 18, 2022, after the completion of daily operations. CDSL reported that several servers and end-user computers became inaccessible due to a malware infection. The depository was forced to isolate affected systems and disconnect its network to prevent further spread, resulting in a widespread disruption of critical market functions.
Settlement activities, which are vital for the smooth functioning of the securities market, were stalled for nearly 47 hours, while inter-depository transfers were disrupted for over 54 hours. SEBI’s adjudication order highlighted that the root cause of the incident was an inadequately secured, internet-facing Active Directory Federation Services (ADFS) server. The regulator found that CDSL had failed to classify this server as a "critical asset," thereby excluding it from the mandatory vulnerability assessments and penetration testing required under SEBI’s cybersecurity framework.
Regulatory Findings and Compliance Gaps
Beyond the failure to secure the ADFS server, SEBI’s investigation identified a broader pattern of "accumulated cyber-security lapses." The regulator noted that CDSL failed to:
Detect intrusions in real-time.
Properly analyze security alerts generated by its monitoring systems.
Comply with established protocols for resuming trade settlements through backup sites.
SEBI rejected CDSL’s argument that the ADFS server was not critical because it did not store sensitive investor data. The regulator emphasized that any internet-facing application is required to be designated as a critical asset under the May 2022 cybersecurity circular. Consequently, SEBI imposed ₹9 million under Section 15HB of the SEBI Act and an additional ₹1 million under Section 19G of the Depositories Act, totaling the ₹10 million fine. The proceedings against two former officials, the then-Chief Information Security Officer and the then-Chief Technology Officer, were disposed of without monetary penalties.
Why It Matters
For investors and market participants, this penalty reinforces the importance of robust cybersecurity infrastructure in an increasingly digitized financial landscape. As CDSL manages over 83 million investor accounts—representing roughly 70% of the country’s total—the integrity of its systems is paramount. The fine serves as a warning to other market intermediaries that failure to comply with cybersecurity protocols can lead to significant financial and reputational consequences.
Key Facts at a Glance
Total Penalty: ₹10 million (₹9 million + ₹1 million).
Root Cause: Inadequately secured internet-facing ADFS server.
Impact: 46-to-54-hour disruption of critical settlement and transfer services.
Regulator: Securities and Exchange Board of India (SEBI).
Frequently Asked Questions
What led to the penalty on CDSL?
The penalty was imposed due to cybersecurity lapses and a failure to secure critical assets, which allowed a 2022 malware attack to disrupt essential depository services.
Was any investor data compromised?
The regulatory report focused on the disruption of settlement systems and the failure to follow cybersecurity frameworks, rather than a breach of sensitive investor data.
How much is the total fine?
SEBI imposed a total fine of ₹10 million (₹1 crore), split into ₹9 million and ₹1 million under different sections of the SEBI and Depositories Acts.
Source: Securities and Exchange Board of India (SEBI), Central Depository Services (India) Ltd (CDSL), The Economic Times