Sebi fined the depository Rs 1 crore for cybersecurity violations.
The November 2022 malware attack disrupted market settlement infrastructure.
Hackers exploited an open server port during the breach.
Sebi fined the depository Rs 1 crore for cybersecurity violations.
The November 2022 malware attack disrupted market settlement infrastructure.
Hackers exploited an open server port during the breach.
In a regulatory enforcement action, the Securities and Exchange Board of India (Sebi) has imposed a penalty on the Central Depository Services (India) Limited (CDSL). The capital market regulator imposed a monetary penalty of Rs. 90 lakh on the depository under Section 15HB of the Sebi Act, 1992. The market regulator also levied a penalty of Rs. 10 lakh under Section 19G of the Depositories Act, 1996. Cumulatively, the depository has been penalised Rs 1 crore.
Notably, Sebi’s order follows an investigation of a cybersecurity breach that occurred in November 2022. While the adjudicating authority disposed of the proceedings against the company’s former Chief Information Security Officer and former Chief Technology Officer, the depository itself has been penalised for the breach.
Sebi’s order follows the investigation of a malware attack that took place on November 18, 2022. The breach disrupted critical market settlement infrastructure. The regulator found multiple structural failures in the depository’s adherence to prescribed cybersecurity frameworks.
One of the failures found in the framework was the failure to declare an Active Directory Federation Services server as a critical asset. The server, deployed during the COVID-19 pandemic to enable remote work authentication, was left facing the internet without being subjected to mandatory vulnerability assessments, penetration testing, or integration with real-time security.
Sebi’s order included an account lock-out policy meant to trigger after three failed attempts, which had the purpose of monitoring tools.The investigation found that the hackers used an open Remote Desktop Protocol port on the server. Additionally, other vulnerabilities, such as access control lapses, were also added to the issue.
One of the other major failures has been relaxed for over eighteen months.
For retail and institutional investors, Sebi’s order underlines the critical importance of operational security in market infrastructure. When the breach was detected, core depository processes, including pay-in and pay-out settlements, inter-depository transfers, and margin pledge activities, faced disruptions lasting between 46 and 54.5 hours. The malware infected 135 servers and 177 computers, and the institution failed to declare a disaster within the mandatory 30-minute window or restore operations within the stipulated 45-minute Recovery Time Objective.
However, trade settlements scheduled for November 18, 2022, were completed over the weekend without any compromise of investor demat data or financial loss. The market watchdog's order is a signal to investors that regulatory authorities are holding market infrastructure institutions accountable to stringent standards of digital safety. Following the incident, the depository has overhauled its cyber infrastructure. The enforced upgrades aim to ensure greater resilience and prevent future market freezes.
Following the release of the regulatory order, shares of Central Depository Services (India) were trading around Rs 1365.3 on the National Stock Exchange, down by approximately 1.4 per cent during early trade.