The Securities and Exchange Board of India (SEBI) has imposed a hefty ₹1 crore penalty on Central Depository Services (India) Ltd (CDSL) due to significant lapses in cybersecurity. These deficiencies culminated in a malware attack in November 2022 that disrupted vital depository operations, causing forced isolation of systems and delaying settlements.
Incident Overview
In a detailed 88-page ruling published this week, SEBI underscored serious shortcomings in CDSL’s compliance with its cybersecurity framework. Notably, the regulator found that CDSL failed to identify critical IT assets and did not conduct comprehensive vulnerability assessments or enforce effective access controls. This neglect allowed a malware attack that disrupted key processes for a significant period.
The attack forced CDSL to delay settlements originally scheduled for November 18, 2022, until November 20. This incident not only raised questions about CDSL’s operational integrity but also highlighted potential risks for investors and other stakeholders relying on the stability of financial markets.
Key Security Lapses Identified
SEBI’s order emphasized specific failures by CDSL that contributed to the malware breach. One critical oversight was the failure to classify an internet-facing Active Directory Federation Services (ADFS) server as a critical asset. Consequently, this server was not subjected to the necessary vulnerability assessment and penetration testing.
The absence of these essential security checks exposed CDSL to avoidable risks, allowing unauthorized access to its systems. SEBI’s review pointed out that the ADFS server was neither linked to Security Information and Event Management (SIEM) nor Privileged Identity Management (PIM) systems, which are crucial for monitoring and defending against cyber threats.
Moreover, CDSL had relaxed crucial password and account lockout policies during the Covid-19 pandemic and failed to reinstate adequate cybersecurity measures even after conditions normalized. This lapse significantly heightened vulnerability to cyber threats, a risky oversight in an increasingly digital finance landscape.
Accountability and Implications
The repercussions of the attack extend beyond CDSL, as SEBI also named Rajesh Nadkarni, the then Chief Information Security Officer, and Amit Mahajan, the former Chief Technology Officer, as accountable for these violations. By holding top executives responsible, SEBI reinforces the importance of leadership in establishing robust cybersecurity frameworks.
This incident sheds light on the urgent need for Indian financial institutions to prioritize cybersecurity. With rising cyber threats, the financial sector must enhance its resilience and compliance with regulatory frameworks to protect market integrity and consumer confidence.
What This Means
The penalty imposed on CDSL serves as a wake-up call for all players in the Indian financial market. It underscores the critical importance of following established cybersecurity guidelines and implementing comprehensive checks to prevent breaches. As markets continue to digitize, regulatory bodies like SEBI are likely to intensify their scrutiny of cybersecurity practices to ensure protection for investors and uphold market integrity.
The incident also highlights the broader implications for companies in the financial sector, urging them to adopt proactive measures to safeguard their systems. As cyber threats evolve, so should the strategies employed to counter them, making cybersecurity not just a regulatory requirement but a fundamental component of business operations.
Frequently Asked Questions
What was the cause of the malware attack on CDSL?
The attack was primarily due to CDSL’s failure to comply with several cybersecurity provisions, including not identifying critical IT assets and allowing vulnerabilities due to relaxed security policies during the Covid-19 pandemic.
How much was the penalty imposed on CDSL?
SEBI has imposed a penalty of ₹1 crore on CDSL for its lapses in cybersecurity.
What is CDSL’s role in the financial market?
Central Depository Services (India) Ltd (CDSL) facilitates the holding of securities in electronic form and is pivotal in the Indian capital market infrastructure.
What can other financial institutions learn from this incident?
Other institutions can learn the importance of adhering to cybersecurity frameworks, conducting regular vulnerability assessments, and ensuring that all critical systems are secured against potential cyber threats.





