SEBI Fines CDSL Rs 1 Crore Over 2022 Malware Attack and Cybersecurity Lapses
SEBI has imposed a total penalty of Rs 1 crore on Central Depository Services (India) Limited (CDSL) for multiple cybersecurity and regulatory lapses that culminated in the malware attack on its systems in November 2022.
Intelligence analysis by Llama

SEBI fined CDSL Rs 1 crore for cybersecurity and regulatory lapses that led to a malware attack in 2022. The regulator found that CDSL failed to classify a critical internet-facing server as a critical asset, implement mandatory cybersecurity controls, and adequately monitor its systems.
Imagine you're in charge of a big computer system that helps people buy and sell stocks. If someone hacks into your system, it can cause big problems. CDSL, a company that helps with stock transactions, had a big hack in 2022. They didn't do a good job of protecting their system, and now they have to pay a big fine. This is important because it shows how important it is to have good cybersecurity to protect people's money and information.
Analysis
A Rs 1 Crore Penalty for CDSL's Cybersecurity Failures
The Securities and Exchange Board of India (SEBI) has imposed a total penalty of Rs 1 crore on Central Depository Services (India) Limited (CDSL) for multiple cybersecurity and regulatory lapses that culminated in the malware attack on its systems in November 2022. The regulator found that CDSL failed to classify a critical internet-facing server as a critical asset, implement mandatory cybersecurity controls, and adequately monitor its systems.
Why CDSL's Failures Were So Costly
The malware attack on CDSL's systems in November 2022 was a significant incident that highlighted the importance of robust cybersecurity measures in the financial sector. The attack compromised key depository operations and resulted in a delay to securities settlements. While CDSL took extensive remedial measures after the incident, the regulator found that the company's earlier regulatory failures were a major contributor to the attack.
The Importance of Disaster Recovery Planning
The SEBI fine highlights the importance of disaster recovery planning in the financial sector. CDSL's failure to declare a disaster within 30 minutes of the malware incident and restore operations, including from its disaster recovery site, within 45 minutes of the declaration of 'disaster' was a regulatory breach. The regulator found that CDSL's argument that its decision not to invoke the disaster recovery site 'may appear justified in the present factual context as it might have exacerbated the situation' was not a valid defence.
Key points
- SEBI fined CDSL Rs 1 crore for cybersecurity and regulatory lapses.
- CDSL failed to classify a critical internet-facing server as a critical asset.
- CDSL failed to implement mandatory cybersecurity controls and adequately monitor its systems.
- The malware attack on CDSL's systems in November 2022 compromised key depository operations and resulted in a delay to securities settlements.
- CDSL's failure to declare a disaster within 30 minutes of the malware incident and restore operations, including from its disaster recovery site, within 45 minutes of the declaration of 'disaster' was a regulatory breach.
The SEBI fine on CDSL may lead to improved cybersecurity measures in the financial sector, reducing the risk of data breaches and other security incidents.
The SEBI fine on CDSL may not be enough to deter other companies from neglecting cybersecurity measures, potentially leading to more data breaches and security incidents.



