Tuesday, 21 July 2026 · World
USD/EUR 0.8758 USD/GBP 0.7444 USD/JPY 162.5 USD/CNY 6.778 All rates →
RSS
EUROS The World Financial Report
Nº 10 Tuesday, 21 July 2026 · World Edition
LATEST
Asia

Sebi imposes ₹1 crore penalty on CDSL for 2022 cybersecurity failures

EUROS Newsroom · 6h ago · 1 min read · 🇮🇳 India
Sebi imposes ₹1 crore penalty on CDSL for 2022 cybersecurity failures

India’s market regulator has penalized Central Depository Services for critical cybersecurity failures that enabled a 2022 malware breach, highlighting ongoing operational risks for financial market infrastructure providers.

The Securities and Exchange Board of India (Sebi) has imposed a ₹1 crore penalty on Central Depository Services (India) Ltd (CDSL) for severe cybersecurity lapses. The fine stems from a November 2022 malware attack that disrupted critical depository operations.

Following the regulatory action, CDSL shares traded lower on the National Stock Exchange, dropping as much as 0.94 percent to ₹1,372.10. The stock remains down 5 percent year-to-date, though it has delivered 132 percent returns over the past three years.

In an 88-page order, the regulator detailed how CDSL failed to classify its internet-facing Active Directory Federation Services server as a critical asset. Consequently, the system was excluded from vulnerability assessment and penetration testing, violating basic cyber resilience requirements.

Sebi noted that these specific deficiencies were flagged to the depository in August 2022. Instead of rectifying the issues, CDSL relied on an earlier, inadequate testing exercise before the breach occurred.

The regulatory findings reveal that attackers infiltrated CDSL servers as early as November 2021, nearly a year before detection. The eventual malware infection compromised 135 of 547 servers and 177 of 506 desktops and laptops.

This breach disrupted key market functions on November 18, 2022, including settlement, pay-in and pay-out processes, and pledge-related activities. CDSL has maintained that the incident will have no material impact on its financials or ongoing operations beyond the penalty payment.

The regulator separately disposed of adjudication proceedings against former Chief Information Security Officer Rajesh Nadkarni and former Chief Technology Officer Amit Mahajan. Sebi determined that the alleged lapses could not be attributed to them individually, sparing them from monetary penalties.

CDSL has been directed to remit the ₹90 lakh penalty under the Sebi Act and ₹10 lakh under the Depositories Act within 45 days. The ruling underscores heightened regulatory scrutiny on the cyber resilience of financial market infrastructure, signaling that operational risk management will remain a focal point for investors evaluating depository stocks.