📣 Send us your press release
Site updates every 15 minutes
Technology

SEBI fines CDSL Rs 1 crore for 2022 malware attack

India's Securities and Exchange Board (SEBI) has imposed a Rs 1 crore penalty on Central Depository Services (India) Limited (CDSL) for multiple cybersecurity and regulatory lapses that culminated in a malware attack in November 2022.

21 July 2026
SEBI fines CDSL Rs 1 crore for 2022 malware attack
Image is an AI-generated illustration

The Securities and Exchange Board of India (SEBI) has levied a Rs 1 crore (approximately $120,000) penalty on Central Depository Services (India) Limited (CDSL). The penalty stems from multiple cybersecurity and regulatory failures identified following a malware attack on the company's systems in November 2022, which led to delays in securities settlements.

In an order issued on July 20, SEBI stated that CDSL failed to classify a critical internet-facing server as a critical asset, implement mandatory cybersecurity controls, and adequately monitor its systems. These omissions allowed the malware attack to compromise key depository operations. However, SEBI dropped monetary penalty proceedings against the company's former Chief Information Security Officer and Chief Technology Officer.

The incident, disclosed by CDSL on November 18, 2022, affected several internal machines and resulted in a delay to securities settlements. While CDSL reported no compromise of confidential information or investor data and restored normal operations within two days, SEBI emphasized that post-incident corrective actions do not excuse prior regulatory failures.

SEBI's investigation found that CDSL had not classified an internet-facing Active Directory Federation Services (ADFS) server as a critical asset and excluded it from vulnerability testing. Furthermore, the company's disaster recovery infrastructure was compromised by the malware, violating SEBI's requirements for business continuity and disaster recovery timelines.

Original source: medianama.com