Breaking India News Today | In-Depth Reports & Analysis – IndiaNewsWeekBreaking India News Today | In-Depth Reports & Analysis – IndiaNewsWeek
  • Home
  • Nation
  • Politics
  • Economy
  • Sports
  • Entertainment
  • International
  • Technology
  • Auto News
Reading: SEBI Fines CDSL ₹1 Crore Amid Malware Attack Breach Concerns
Share
Breaking India News Today | In-Depth Reports & Analysis – IndiaNewsWeekBreaking India News Today | In-Depth Reports & Analysis – IndiaNewsWeek
  • Home
  • Nation
  • Politics
  • Economy
  • Sports
  • Entertainment
  • International
  • Technology
  • Auto News
© 2024 All Rights Reserved | Powered by India News Week
Trending Now: Stay updated with the latest breaking news from India and around the world
Malware attack lapses: SEBI imposes ₹1 crore fine on CDSL
Breaking India News Today | In-Depth Reports & Analysis – IndiaNewsWeek > Economy > SEBI Fines CDSL ₹1 Crore Amid Malware Attack Breach Concerns
Economy

SEBI Fines CDSL ₹1 Crore Amid Malware Attack Breach Concerns

Indianewsweek By Indianewsweek July 21, 2026 5 Min Read
Share
SHARE

The Securities and Exchange Board of India (SEBI) has imposed a hefty ₹1 crore penalty on Central Depository Services (India) Ltd (CDSL) due to significant lapses in cybersecurity. These deficiencies culminated in a malware attack in November 2022 that disrupted vital depository operations, causing forced isolation of systems and delaying settlements.

Incident Overview

In a detailed 88-page ruling published this week, SEBI underscored serious shortcomings in CDSL’s compliance with its cybersecurity framework. Notably, the regulator found that CDSL failed to identify critical IT assets and did not conduct comprehensive vulnerability assessments or enforce effective access controls. This neglect allowed a malware attack that disrupted key processes for a significant period.

The attack forced CDSL to delay settlements originally scheduled for November 18, 2022, until November 20. This incident not only raised questions about CDSL’s operational integrity but also highlighted potential risks for investors and other stakeholders relying on the stability of financial markets.

Key Security Lapses Identified

SEBI’s order emphasized specific failures by CDSL that contributed to the malware breach. One critical oversight was the failure to classify an internet-facing Active Directory Federation Services (ADFS) server as a critical asset. Consequently, this server was not subjected to the necessary vulnerability assessment and penetration testing.

The absence of these essential security checks exposed CDSL to avoidable risks, allowing unauthorized access to its systems. SEBI’s review pointed out that the ADFS server was neither linked to Security Information and Event Management (SIEM) nor Privileged Identity Management (PIM) systems, which are crucial for monitoring and defending against cyber threats.

Moreover, CDSL had relaxed crucial password and account lockout policies during the Covid-19 pandemic and failed to reinstate adequate cybersecurity measures even after conditions normalized. This lapse significantly heightened vulnerability to cyber threats, a risky oversight in an increasingly digital finance landscape.

Accountability and Implications

The repercussions of the attack extend beyond CDSL, as SEBI also named Rajesh Nadkarni, the then Chief Information Security Officer, and Amit Mahajan, the former Chief Technology Officer, as accountable for these violations. By holding top executives responsible, SEBI reinforces the importance of leadership in establishing robust cybersecurity frameworks.

This incident sheds light on the urgent need for Indian financial institutions to prioritize cybersecurity. With rising cyber threats, the financial sector must enhance its resilience and compliance with regulatory frameworks to protect market integrity and consumer confidence.

What This Means

The penalty imposed on CDSL serves as a wake-up call for all players in the Indian financial market. It underscores the critical importance of following established cybersecurity guidelines and implementing comprehensive checks to prevent breaches. As markets continue to digitize, regulatory bodies like SEBI are likely to intensify their scrutiny of cybersecurity practices to ensure protection for investors and uphold market integrity.

The incident also highlights the broader implications for companies in the financial sector, urging them to adopt proactive measures to safeguard their systems. As cyber threats evolve, so should the strategies employed to counter them, making cybersecurity not just a regulatory requirement but a fundamental component of business operations.

Frequently Asked Questions

What was the cause of the malware attack on CDSL?

The attack was primarily due to CDSL’s failure to comply with several cybersecurity provisions, including not identifying critical IT assets and allowing vulnerabilities due to relaxed security policies during the Covid-19 pandemic.

How much was the penalty imposed on CDSL?

SEBI has imposed a penalty of ₹1 crore on CDSL for its lapses in cybersecurity.

What is CDSL’s role in the financial market?

Central Depository Services (India) Ltd (CDSL) facilitates the holding of securities in electronic form and is pivotal in the Indian capital market infrastructure.

What can other financial institutions learn from this incident?

Other institutions can learn the importance of adhering to cybersecurity frameworks, conducting regular vulnerability assessments, and ensuring that all critical systems are secured against potential cyber threats.

TAGGED:Economy NewsNews
Share This Article
Twitter Copy Link
Previous Article Nolan Wells’ Death: Two Weeks On, Questions Remain Unanswered in Investigation
Next Article Delhi Police Under Fire for Alleged Misconduct with Known Individual
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest News

Six-Year-Old Polio Survivor in Iron Lung Becomes World’s Longest-Living Patient

July 21, 2026

BJP Government Faces Backlash Over Plans to Demolish 1,000-Year-Old Mosque in UP

July 21, 2026

General Montgomery Visits Troops at Gazala Defences After Rommel’s Offensive

July 21, 2026

Marcello Hernández’s Kevin Hart Impression Shocks Sheinelle and Al on Live TV

July 21, 2026

Jamiat Chief Opposes Jauhar University Demolition, Advocates for Muslim Students’ Future

July 21, 2026

Delhi Police’s Heavy-Handed Tactics Draw Criticism During Jantar Mantar Protests

July 21, 2026

You Might Also Like

Nestlé recalls baby formula from at least 48 countries over toxin contamination fears
Nation

Nestlé Recalls Baby Formula in 48 Countries Due to Toxin Contamination Concerns

6 Min Read
Excelsoft Technologies IPO sees stellar demand, subscribed 23.45x so far on final day, Sudeep Pharma IPO nears full subscription on Day 1
Economy

Prudential Launches $300 Million Pre-IPO Share Sale in Indian Venture

2 Min Read
Assam govt sets up inquiry panel headed by HC judge to probe Zubeen Garg’s death
Nation

Assam Government Forms High Court Panel to Investigate Zubeen Garg’s Death

2 Min Read
Radico Khaitan launches Jamun SpicyMint vodka variant
Economy

Radico Khaitan Unveils Exciting Jamun SpicyMint Vodka Flavor

2 Min Read

About IndiaNewsWeek

IndiaNewsWeek is your trusted source for breaking news, in-depth analysis, and comprehensive coverage of India and the world. We deliver accurate, timely reporting across politics, economy, sports, entertainment, and technology.

contact@indianewsweek.com

Quick Links

  • Nation
  • Politics
  • Economy
  • International
  • Sports
  • Entertainment

More Sections

  • Technology
  • Auto News
  • Education
  • About Us
  • Contact
  • Privacy Policy

Stay Connected

Follow us on social media for the latest updates and breaking news.

Facebook
X (Twitter)
YouTube
Follow US
© 2026 IndiaNewsWeek. All Rights Reserved.
Welcome Back!

Sign in to your account

Lost your password?