The Securities and Exchange Board of India (SEBI) has imposed a penalty of ₹1 crore on Central Depository Services (India) Ltd. (CDSL) after concluding that multiple cybersecurity and compliance failures contributed to a malware attack that disrupted the depository's operations in November 2022.
In its order issued on Monday, SEBI said CDSL failed to classify an internet-facing server as a critical asset and did not implement the required security safeguards, allowing the server to become the entry point for the malware attack. The regulator said the lapse violated cybersecurity requirements that mandate enhanced protection for critical systems.
CDSL, one of India's two securities depositories, manages around 83 million investor accounts, accounting for nearly 70% of the country's demat accounts.
According to SEBI, the cyberattack disrupted several critical depository services, including settlement activities, corporate actions, margin pledge processing and inter-depository transfers, resulting in delays to settlements scheduled for November 18, 2022.
The regulator also found that CDSL failed to detect intrusions in real time, adequately analyse security alerts and comply with regulatory requirements for resuming settlement operations through its disaster recovery site.
SEBI said the malware incident was the result of accumulated cybersecurity weaknesses, including inadequate security monitoring, weak password controls and failure to implement prescribed cybersecurity safeguards.
"The malware attack was the foreseeable outcome of accumulated cyber-security lapses," the regulator said in its order.
The enforcement action highlights SEBI's increasing focus on cybersecurity governance and operational resilience across India's financial market infrastructure, where depositories, exchanges and other market intermediaries are required to maintain robust cyber defence, incident detection and business continuity capabilities.
The order serves as a reminder that regulators are placing greater emphasis not only on preventing cyberattacks but also on ensuring organisations can detect threats early, respond effectively and maintain critical financial services during cyber incidents.
In its order issued on Monday, SEBI said CDSL failed to classify an internet-facing server as a critical asset and did not implement the required security safeguards, allowing the server to become the entry point for the malware attack. The regulator said the lapse violated cybersecurity requirements that mandate enhanced protection for critical systems.
CDSL, one of India's two securities depositories, manages around 83 million investor accounts, accounting for nearly 70% of the country's demat accounts.
According to SEBI, the cyberattack disrupted several critical depository services, including settlement activities, corporate actions, margin pledge processing and inter-depository transfers, resulting in delays to settlements scheduled for November 18, 2022.
The regulator also found that CDSL failed to detect intrusions in real time, adequately analyse security alerts and comply with regulatory requirements for resuming settlement operations through its disaster recovery site.
SEBI said the malware incident was the result of accumulated cybersecurity weaknesses, including inadequate security monitoring, weak password controls and failure to implement prescribed cybersecurity safeguards.
"The malware attack was the foreseeable outcome of accumulated cyber-security lapses," the regulator said in its order.
The enforcement action highlights SEBI's increasing focus on cybersecurity governance and operational resilience across India's financial market infrastructure, where depositories, exchanges and other market intermediaries are required to maintain robust cyber defence, incident detection and business continuity capabilities.
The order serves as a reminder that regulators are placing greater emphasis not only on preventing cyberattacks but also on ensuring organisations can detect threats early, respond effectively and maintain critical financial services during cyber incidents.





