Market regulator Sebi has penalized Central Depository Services (India) Limited (CDSL) ₹1 crore following a November 2022 malware attack that disrupted critical market operations. The regulator found that systemic security failures and unaddressed vulnerabilities led to extended downtime, impacting settlement processes and inter-depository transfers for nearly 50 hours.
The Securities and Exchange Board of India (Sebi) has imposed a penalty of ₹1 crore on Central Depository Services (India) Limited (CDSL) after an investigation into a major cybersecurity breach. The regulatory action centers on a malware incident that occurred in November 2022, which caused significant operational delays across India’s securities market infrastructure.
According to the regulatory order, the attack resulted in a 46-hour disruption of settlement processes and affected inter-depository transfers for 49.5 hours. Sebi determined that these outages were not merely technical glitches but the result of underlying security flaws. The investigation highlighted that CDSL had failed to implement necessary cybersecurity safeguards and had deviated from established policies, making the entity’s critical infrastructure vulnerable to such threats.
Sebi’s findings pointed to specific governance and technical oversights that existed well before the 2022 incident. The regulator noted that signs of unauthorized access were detected as early as November 2021, yet the security gaps remained unaddressed for a year. Among the issues identified were the creation of an administrator account with a password set to never expire and the relaxation of lockout thresholds for failed login attempts. These configurations, which are contrary to standard cybersecurity practices, provided an opening for the eventual breach.
For investors and market participants, the case underscores the growing importance of operational resilience within financial market infrastructure providers. As depositories are central to the digital settlement of shares, any prolonged downtime creates systemic risks that can affect liquidity and investor confidence. The regulator emphasized that the interconnected nature of India's financial ecosystem means that a failure at a depository can have a cascading impact on other market entities.
CDSL, as one of the two main depositories in India, plays a crucial role in maintaining electronic records of securities. The company has historically faced scrutiny regarding its IT infrastructure given the volume of sensitive data it processes. While this fine is a singular event regarding the 2022 breach, shareholders and market participants typically monitor such regulatory findings to gauge how effectively a company manages its operational risks and updates its cybersecurity protocols. Moving forward, the key monitorable for investors will be any follow-up actions taken by the company to bolster its IT infrastructure and the degree to which it complies with updated regulatory directives on cyber resilience.
