SEBI fines CDSL 10 million rupees for 2022 malware lapses
India’s markets regulator penalised Central Depository Services for systemic cybersecurity failures that disrupted trade settlements, underscoring the operational risks embedded in the country’s financial infrastructure.
India’s markets regulator fined Central Depository Services (India) Ltd 10 million rupees on Monday over a cascade of cybersecurity and compliance failures that enabled a malware attack to cripple depository operations in November 2022.
The penalty from the Securities and Exchange Board of India (SEBI) draws attention to the operational vulnerabilities sitting at the core of India's financial infrastructure. CDSL holds 83 million investor accounts, equating to 70 per cent of the country's total market participation. For investors and fund managers, the sheer scale of the depository means that internal security lapses pose a systemic threat rather than an isolated IT issue.
When the malware struck, it immediately halted critical market plumbing. Settlement activities ground to a halt, corporate actions were delayed, margin pledges were frozen, and inter-depository transfers stopped. The disruption forced a delay in settlements originally scheduled for November 18, 2022. For market professionals, such freezes tie up capital, complicate risk management and erode confidence in the execution of trades.
SEBI’s post-mortem revealed that the crisis was entirely preventable. The regulator found that the root cause of the attack was an internet-facing server that CDSL had failed to classify as a critical asset. Under existing rules, this server required stringent safeguards. By leaving it unprotected, the depository effectively opened a door for cyber threats to enter its broader network.
The investigation also exposed severe deficiencies in how CDSL monitored its systems. The firm failed to detect the intrusions as they happened and lacked the capability to properly analyse the security alerts it did receive. Furthermore, when the attack hit, CDSL did not comply with regulatory requirements for shifting trade settlement operations to backup sites.
Regulators concluded that the breach was the direct and foreseeable consequence of accumulated negligence. Weak password controls, inadequate system monitoring and a broader failure to implement mandated cybersecurity safeguards allowed the attack to succeed. For executives across the region, the 10 million rupee fine serves as a baseline warning about regulatory tolerance for IT negligence in institutions that anchor national capital markets.
The fine itself is relatively modest for an institution of CDSL's size, but the regulatory rebuke carries heavier weight. It signals to global and domestic investors that SEBI is actively scrutinising how financial utilities manage digital risk, an issue that will likely demand increased capital expenditure on cybersecurity across India's broader financial sector.