The Securities and Exchange Board of India (SEBI) imposed a Rs 1 crore penalty on Central Depository Services (India) Limited (CDSL) for cybersecurity and regulatory lapses that led to a malware attack in November 2022, according to an order issued on July 20. The attack disrupted key depository operations and delayed securities settlements.
CDSL disclosed the malware detection on November 18, 2022, after completing end-of-day operations. The company isolated affected systems and disconnected from other market participants to contain the attack. It reported no compromise of confidential or investor data and resumed normal operations by November 20 after validation checks. SEBI found that CDSL failed to classify a critical internet-facing server as a critical asset, implement mandatory cybersecurity controls, and adequately monitor its systems, which allowed the attack to occur.
The penalty highlights regulatory scrutiny on cybersecurity practices in India's capital markets. CDSL's delayed securities settlements and operational disruption drew attention to the importance of robust cybersecurity frameworks. SEBI dropped monetary penalty proceedings against CDSL’s former Chief Information Security Officer and Chief Technology Officer, focusing the fine on the company itself. The case underscores the regulator’s enforcement approach following significant cybersecurity incidents.
The malware attack caused deferred securities settlements that were completed on November 20, 2022, according to the SEBI order available on medianama.com.