
India's markets regulator has imposed a cumulative penalty of ₹1 crore on Central Depository Services (India) Ltd (CDSL) for cybersecurity lapses that led to the November 2022 malware attack. According to the Securities and Exchange Board of India (SEBI), the penalty comprises ₹90 lakh under Section 15HB of the SEBI Act and ₹10 lakh under Section 19G of the Depositories Act. The regulator also disposed of proceedings against CDSL's former Chief Information Security Officer Rajesh Nadkarni and former Chief Technology Officer Amit Mahajan without imposing monetary penalties. As per CNBC TV18, the company has been directed to pay the amount within 45 days of receiving the order. In an 88-page order issued on Monday, SEBI held that CDSL failed to comply with several provisions of its cybersecurity framework, including identifying critical IT assets, conducting adequate vulnerability assessments and implementing appropriate access controls.
Forensic investigation revealed that attackers first gained access to CDSL's network in November 2021, almost a year before the malware attack was detected on November 18, 2022. According to the latest order, CDSL observed around 3 am on November 18, 2022, after completion of end-of-day operations, that some servers and end-user computers had become inaccessible. The malware attack infected 135 of 547 servers and 177 of 506 desktops and laptops, disrupting several depository services, including settlement, transfer and pledge transactions, forcing market participants to defer settlements over the weekend. According to SEBI, critical systems, including the settlement process and inter-depository transfer, were disrupted for 46 hours and 54.5 hours, respectively, making it evident that the disruption had a major spillover impact on the entire securities market. The attack affected critical depository processes, forcing CDSL to isolate its systems and delay settlements scheduled for November 18, 2022, until November 20.
SEBI found that CDSL failed to classify its internet-facing Active Directory Federation Services (ADFS) server as a critical asset despite revised cybersecurity norms, leaving it outside mandatory security testing and monitoring. According to the regulator's 88-page order, the failures included weak password controls, deviations from security policies and inadequate monitoring of security alerts. The order noted that CDSL created an admin account in 2021 whose password was set to never expire, and its relaxation regarding the lockout threshold to three failed attempts was not addressed until the malware attack. SEBI also found that the depository had relaxed password and account lockout policies during the Covid-19 period and failed to restore the required cybersecurity controls even after normalcy returned, increasing the risk of compromise. Notably, SEBI had flagged these deficiencies to CDSL in August 2022, but the depository did not address them and instead relied on an earlier, deficient VAPT exercise.
CDSL shares fell as much as 0.94% to ₹1,372.10 on the NSE following the SEBI penalty announcement. According to Livemint, the company stated that there was no material impact on financials, operation or other activities of the company, except the payment of the proposed penalty amount. The stock has risen 1% in three months but has fallen 5% on a year-to-date basis. At 10:30 AM, CSDL shares were trading 0.61% lower at ₹1,376.70 on the NSE. SEBI emphasized that the disruption had a major spillover impact because settlement activities for the securities market also depended on the normal functioning of CDSL systems, highlighting the systemic nature of the vulnerabilities.