SEBI Fines CDSL ₹1 Crore Over Cybersecurity Failures Behind 2022 Malware Attack

SEBI Fines CDSL ₹1 Crore Over

You can set Kotak Neo as a preferred source to receive regular market updates.

Add as preferred source on Google

SEBI fined CDSL ₹1 crore for cybersecurity failures enabling a 2022 malware attack that disrupted settlement operations for 46 hours. The attacker had accessed CDSL servers undetected since November 2021.

India's markets regulator has penalised Central Depository Services (India) Ltd (CDSL) with a ₹1 crore fine after finding that a 2022 malware attack that disrupted settlement operations across the securities market was made possible by years of accumulated cybersecurity failures rather than a sophisticated external breach.

In an 88-page adjudication order, the Securities and Exchange Board of India (SEBI) found that the attacker had gained access to CDSL's servers as early as November 2021, a full year before the attack was discovered, exploiting weaknesses that the depository had failed to address despite regulatory directives.

CDSL shares traded lower on Tuesday following the SEBI order. The stock fell as much as 1.25% to ₹1,367.90 at 11:14 AM on the National Stock Exchange (NSE).

The entry point was an internet-facing Active Directory Federation Services server that CDSL had not designated as a critical asset, in breach of a May 2022 regulatory requirement mandating that all internet-facing systems be treated as such.

Because the server fell outside the critical asset classification, it was excluded from vulnerability assessment and penetration testing, security monitoring and privileged identity management, leaving it exposed without generating any alerts.

Alongside the misclassification, investigators identified a series of basic security failures:

  • An administrator account created in 2021 carried a password set to never expire.

  • Account lockout was configured to trigger only after three failed login attempts.

  • No two-factor authentication protected privileged accounts.

  • An internet-accessible Remote Desktop Protocol port had never undergone mandatory vulnerability testing.

  • Multiple security tool alerts pointing to malware activity and privilege abuse were neither investigated nor acted upon.

When CDSL isolated its systems following discovery of the attack, the consequences extended well beyond the depository itself. Settlement operations, inter-depository transfers, corporate actions and pledge-related activities were all suspended. The settlement scheduled for 18 November 2022 was completed only on 20 November after coordination with other market infrastructure institutions.

The settlement process was disrupted for 46 hours and inter-depository transfers for 54.5 hours. SEBI found that CDSL failed to declare a disaster within the prescribed timeline and missed its mandated Recovery Time Objective.

CDSL manages approximately 70% of India's demat accounts, giving it a systemically critical position in the country's financial market infrastructure. SEBI said the attack was not an isolated technical incident but a foreseeable outcome of policy deviations, unimplemented regulatory directions and an absence of basic cybersecurity controls on a server that served as the gateway into the entire system.

The penalty breaks down as ₹90 lakh under the SEBI Act and ₹10 lakh under the Depositories Act. CDSL has not commented publicly on the order.

Also Read - SBI Funds Management IPO Listing: Shares Open 6.85% Above Issue Price On NSE

This article is for informational purposes only and should not be considered investment advice from Kotak Neo. For compliance T&C and disclaimers, visit https://www.kotakneo.com/disclaimer/

About the Author
Kotak News Desk
Kotak News Desk

Kotak News Desk brings you latest updates, expert insights, and market-ready ideas - helping you stay informed and invest smarter.

Connect on: Linkedin

Did you enjoy this article?

0 people liked this article.