
On July 20, 2026, the Securities and Exchange Board of India (SEBI) imposed a ₹1 crore penalty on Central Depository Services (India) Ltd for cybersecurity failures that enabled a malware attack on November 18, 2022. The attack infected 135 of 547 servers and 177 of 506 desktops, disrupting critical operations including securities settlement, pay-in/pay-out, and pledge-related services. Settlement systems remained down for approximately 47 hours, while inter-depository transfer services were affected for over 54 hours, impacting the smooth functioning of India's securities market.
The penalty breakdown was ₹90 lakh under the SEBI Act and ₹10 lakh under the Depositories Act, with payment required within 45 days. While SEBI named two former senior technology executives—then Chief Information Security Officer Rajesh Nadkarni and Chief Technology Officer Amit Mahajan—as noticees, it disposed of proceedings against them without monetary penalties, holding that the alleged lapses were institutional in nature involving oversight from CDSL's Systems and Technology Committee (SCOT) and its board.
SEBI's severity assessment was based on multiple factors. Attackers had gained unauthorized access to CDSL's systems as early as November 2021—nearly a full year before the malware attack was detected in November 2022. This prolonged undetected access significantly aggravated the breach. The regulator also noted that it had explicitly flagged deficiencies to CDSL in August 2022, including an internet-facing Active Directory Federation Services (ADFS) server that had been excluded from vulnerability assessment and penetration testing, but the depository failed to address these issues.
The attack's systemic impact was crucial to SEBI's determination. The disruption had a "major spillover impact" since settlement activities for the entire securities market depended on CDSL's normal functioning. Additionally, CDSL had failed to declare a disaster within the prescribed timeline and restore operations within the mandated Recovery Time Objective, leading to market-wide disruption.
CDSL violated multiple provisions of SEBI's cybersecurity framework for Market Infrastructure Institutions. The primary violation was failing to classify its internet-facing ADFS server as a critical asset, despite revised cybersecurity norms issued in May 2022 requiring all internet-facing applications and ancillary systems to be treated as critical. As a result, the server was excluded from Vulnerability Assessment and Penetration Testing (VAPT), Security Information and Event Management (SIEM) monitoring, and Privileged Identity Management (PIM), leaving it exposed without generating alerts.
The depository also violated SEBI's May 2, 2022 circular on System and Network Audit of MIIs, which requires comprehensive asset inventories, regular security assessments, and board-approved critical system classifications. Specific policy lapses included an administrator account created in 2021 with a password set to never expire, and an account lock-out policy relaxed during the COVID-19 period that was never restored even after normalisation.
The ₹1 crore penalty represents just 0.22% of CDSL's FY26 net profit of ₹455.07 crore and 0.08% of revenue, making it financially immaterial from a pure numbers perspective. CDSL's strong balance sheet—with zero debt and EBITDA margins above 50%—provides ample capacity to absorb the cost without material impact on operating margins.
However, the associated remediation costs could be more substantial. Industry benchmarks suggest financial services should allocate 0.8-1.0% of revenue to cybersecurity, which for CDSL would translate to ₹9.9-12.4 crore annually. Post-incident remediation could require 2-3 times normal cybersecurity budgets, potentially reaching ₹30-78 crore for comprehensive security infrastructure upgrades including SIEM implementation, enhanced access controls, and advanced threat detection capabilities.
The attack revealed systemic governance failures across multiple oversight levels. CDSL's Standing Committee on Technology (SCOT), which includes public interest directors, the MD & CEO, and external experts, failed to ensure the ADFS server was classified as critical despite May 2022 SEBI regulations. Board-approved critical asset lists were incomplete, and there was no mechanism to periodically review and update classifications.
COVID-19 era policy relaxations, such as reducing the account lock-out threshold to three attempts, were never restored post-pandemic. An administrator account created in 2021 with a password set to "never expire" remained unaddressed. SEBI had flagged the ADFS server deficiency in August 2022—three months before the attack—but SCOT failed to ensure timely remediation, and a specific direction to re-audit was not implemented.
The CDSL incident demonstrates how cybersecurity vulnerabilities at a single depository can pose systemic risks to the entire financial ecosystem. Research shows that cyber-attacks on financial institutions can trigger loss of confidence, funding liquidity risks that transform into market liquidity shocks, and ultimately solvency risks through complex interconnections.
CDSL's dominant position—holding 75% of India's retail demat accounts (18 crore accounts) with ₹70.52 trillion in assets under custody—creates significant concentration risk that cannot be easily mitigated. The 46-hour settlement disruption and 54.5-hour inter-depository transfer outage exceeded acceptable thresholds for systemically important infrastructure, potentially triggering market-wide settlement delays, cross-border transaction failures, and contractual breach exposures.
The enforcement action creates both challenges and opportunities for CDSL competitively. NSDL, which dominates institutional markets with 86.81% custody value share compared to CDSL's 13.19%, may leverage the security perception advantage in high-value client acquisition. NSDL earns nearly three times more transaction revenue per account (₹91.69 vs. ₹33.21) and has long-term relationships with mutual funds, banks, insurance companies, and foreign portfolio investors who are more security-conscious.
However, CDSL's retail dominance provides competitive insulation. Retail investors cannot easily switch depositories as the choice is made by brokers, and major discount brokers including Zerodha, Groww, and Upstox are committed to CDSL infrastructure. The mandatory security upgrades could paradoxically create competitive advantages if CDSL leverages them to build best-in-class capabilities and transparent client communication.
The CDSL penalty establishes important precedents for Market Infrastructure Institutions. The ₹1 crore penalty sets a reference point for future cybersecurity enforcement actions, while naming former executives creates personal liability exposure for senior management. The detailed 88-page order provides specific compliance guidance that other MIIs can use to avoid similar enforcement.
The incident is likely to trigger compliance acceleration across other MIIs. NSDL, stock exchanges, clearing corporations, and depository participants are expected to conduct immediate security reviews, enhance VAPT coverage, and implement comprehensive SIEM solutions within 3-6 months. Industry-wide security standards will likely elevate, with enhanced expectations for board oversight, individual accountability, continuous compliance monitoring, and public disclosure around cybersecurity incidents.
SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) issued in August 2024 is expected to be more aggressively enforced following the CDSL incident, with greater focus on board-level cybersecurity governance documentation, executive responsibility, and continuous monitoring requirements rather than periodic compliance checks.