The regulator levied a penalty of ₹90 lakh under the SEBI Act and ₹10 lakh under the Depositories Act, holding that CDSL failed to comply with several provisions of SEBI's cybersecurity framework and the code of conduct applicable to depositories.
The malware attack occurred in the early hours of 18 November 2022 after CDSL had completed its end-of-day operations. The attack rendered several servers and end-user computers inaccessible, forcing the depository to isolate its systems and disconnect its network to prevent the malware from spreading. The disruption affected critical depository services, including settlement operations and normalcy was restored only after recovery measures undertaken over the next two days.
SEBI's investigation found that the attack originated from an inadequately secured internet-facing active directory federation services (ADFS) server which CDSL had failed to classify as a critical asset despite revised cybersecurity requirements. Because the server was not designated as critical, it was excluded from vulnerability assessment and penetration testing (VAPT), security information and event management (SIEM) monitoring and other essential security controls, leaving it exposed to exploitation by threat actors.
The regulator also observed several serious deficiencies in CDSL's access-control mechanisms. A privileged domain administrator account was protected by a weak password set to ‘never expire’, two-factor authentication had not been implemented for remote access, account lockout policies had been relaxed during the COVID-19 period and were not reinstated, while privileged identity management controls remained inadequate. These weaknesses enabled attackers to gain and retain unauthorised access without triggering timely alerts.
According to SEBI, CDSL also failed to adequately monitor its security infrastructure. Although several security tools generated alerts indicating suspicious activity, these warnings were neither properly correlated nor investigated. The ADFS server was not integrated with the SIEM platform, preventing effective real-time monitoring of malicious activity and delaying detection of the cyber intrusion.
The malware attack disrupted several critical depository functions, including settlement, corporate actions, inter-depository transfers and margin pledge operations. Settlement activities scheduled for 18 November 2022 had to be completed only on 20 November 2022, causing disruption to market participants and affecting the smooth functioning of the securities market. SEBI noted that CDSL also failed to declare a disaster within the prescribed timeline and restore operations within the stipulated recovery time objective (RTO).
SEBI further held that CDSL did not fully comply with its advisory on remote access and telecommuting issued during the COVID-19 pandemic. The regulator found deficiencies in remote-access security, including the absence of multi-factor authentication, inadequate monitoring of remote access sessions and failure to integrate remote access systems with its security operations centre (SOC).
While the adjudication proceedings also examined the role of Rajesh Nadkarni, the then chief information security officer (CISO) and Amit Mahajan, chief technology officer (CTO). However, the monetary penalty has been imposed on CDSL itself.
SEBI concluded that the depository had violated multiple provisions of its cybersecurity framework and the code of conduct applicable to market infrastructure institutions, exposing the securities market to significant operational and cyber risks.
Passing the order, Jai Sebastaian, adjudicating officer (AO) of SEBI imposed a penalty of ₹90 lakh under Section 15HB of the SEBI Act and ₹10 lakh under Section 19G of the Depositories Act, taking the total penalty on CDSL to ₹1 crore.
Muthoot Finance, 5 Other NBFCs Slapped with ₹23.60 Lakh Fine for KYC and Regulatory Lapses
Moneylife Digital Team
20 July 2026
Reserve Bank of India (RBI) has imposed penalties totalling ₹23.60 lakh on six non-banking financial companies (NBFCs), including Muthoot Finance Ltd, for violating various regulatory directions relating to know-your-customer (KYC)...
DGS Bars Deployment of Indian Seafarers through Strait of Hormuz as Gulf Conflict Escalates
Moneylife Digital Team
17 July 2026
India has directed shipowners, ship managers and recruitment agencies to stop deploying Indian seafarers on vessels transiting the Strait of Hormuz until further orders, as escalating attacks on merchant ships in the Gulf region have...
Raghuram Rajan, Raj Chetty and Asha Sharma Named to Key US Fed Task Forces Reviewing Monetary Policy
Moneylife Digital Team
17 July 2026
Reserve Bank of India's (RBI) former governor Raghuram Rajan, Delhi-born economist Raj Chetty and Microsoft executive Asha Sharma have been appointed to key independent task forces constituted by the US Federal Reserve (Fed) to review...
Beware of 'TradeInn' Dabba Trading Platform, NSE Files Police Complaint
Moneylife Digital Team
17 July 2026
The National Stock Exchange of India Ltd (NSE) has cautioned investors against dealing with an entity named 'TradeInn', which is allegedly offering illegal or dabba trading services. The exchange says a person identifying herself as...
As long as CTOs and CISOs are set free even after Serious Cyber Security Events, the system is not going to learn. There should be very serious penalty on CTOs and CISOs if they failed to follow cybersecurity framework. For repeated occurrences these people should face criminal charges against them.