discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

SEBI Fines CDSL Rs 1 Crore Over 2022 Malware Attack and Cybersecurity Lapses

SEBI has imposed a total penalty of Rs 1 crore on Central Depository Services (India) Limited (CDSL) for multiple cybersecurity and regulatory lapses that culminated in the malware attack on its systems in November 2022.

By Nikhil Pahwa·Jul 21·medianama.com·2 min read

Intelligence analysis by Llama

SEBI Fines CDSL Rs 1 Crore Over 2022 Malware Attack and Cybersecurity Lapses
Image: medianama.com

SEBI fined CDSL Rs 1 crore for cybersecurity and regulatory lapses that led to a malware attack in 2022. The regulator found that CDSL failed to classify a critical internet-facing server as a critical asset, implement mandatory cybersecurity controls, and adequately monitor its systems.

Why it matters

The SEBI fine highlights the importance of robust cybersecurity measures in the financial sector and the need for companies to comply with regulatory requirements to prevent data breaches and other security incidents.

Imagine you're in charge of a big computer system that helps people buy and sell stocks. If someone hacks into your system, it can cause big problems. CDSL, a company that helps with stock transactions, had a big hack in 2022. They didn't do a good job of protecting their system, and now they have to pay a big fine. This is important because it shows how important it is to have good cybersecurity to protect people's money and information.

Analysis

A Rs 1 Crore Penalty for CDSL's Cybersecurity Failures

The Securities and Exchange Board of India (SEBI) has imposed a total penalty of Rs 1 crore on Central Depository Services (India) Limited (CDSL) for multiple cybersecurity and regulatory lapses that culminated in the malware attack on its systems in November 2022. The regulator found that CDSL failed to classify a critical internet-facing server as a critical asset, implement mandatory cybersecurity controls, and adequately monitor its systems.

Why CDSL's Failures Were So Costly

The malware attack on CDSL's systems in November 2022 was a significant incident that highlighted the importance of robust cybersecurity measures in the financial sector. The attack compromised key depository operations and resulted in a delay to securities settlements. While CDSL took extensive remedial measures after the incident, the regulator found that the company's earlier regulatory failures were a major contributor to the attack.

The Importance of Disaster Recovery Planning

The SEBI fine highlights the importance of disaster recovery planning in the financial sector. CDSL's failure to declare a disaster within 30 minutes of the malware incident and restore operations, including from its disaster recovery site, within 45 minutes of the declaration of 'disaster' was a regulatory breach. The regulator found that CDSL's argument that its decision not to invoke the disaster recovery site 'may appear justified in the present factual context as it might have exacerbated the situation' was not a valid defence.

Key points

  • SEBI fined CDSL Rs 1 crore for cybersecurity and regulatory lapses.
  • CDSL failed to classify a critical internet-facing server as a critical asset.
  • CDSL failed to implement mandatory cybersecurity controls and adequately monitor its systems.
  • The malware attack on CDSL's systems in November 2022 compromised key depository operations and resulted in a delay to securities settlements.
  • CDSL's failure to declare a disaster within 30 minutes of the malware incident and restore operations, including from its disaster recovery site, within 45 minutes of the declaration of 'disaster' was a regulatory breach.
The Upside

The SEBI fine on CDSL may lead to improved cybersecurity measures in the financial sector, reducing the risk of data breaches and other security incidents.

The Downside

The SEBI fine on CDSL may not be enough to deter other companies from neglecting cybersecurity measures, potentially leading to more data breaches and security incidents.

Originally reported at

medianama.com

Discernion covers the story. Read the full piece at the source.

TagscybersecurityregulationSEBICDSLmalwaredata breachfinancial sector

Author

Nikhil Pahwa

Intelligence analysis by

Llama

Published

Jul 21, 2026

Source

medianama.com

Share

Topics

cybersecurityregulationSEBICDSLmalwaredata breachfinancial sector

Related

More from this desk

Jul 21·prajavani.net

Karnataka Daily News: 2026ರ ಜುಲೈ 21: ಈ ದಿನದ ಪ್ರಮುಖ 10 ಸುದ್ದಿಗಳು ಇಲ್ಲಿವೆ..

Karnataka's top 10 daily news stories for July 21, 2026, including protests, subsidies, and more.

Jul 21·medianama.com

Karnataka challenges safe harbour protection in case against Snapdeal over sale of erectile dysfunction pills

The Karnataka government has moved the Supreme Court, challenging the quashing of criminal proceedings against Snapdeal and its co-founders, Kunal Bahl and Rohit Kumar Bansal, over the alleged sale of erectile dysfunction pills on its platform without a valid licence or a…

Jul 21·medianama.com

Four strategic takeaways from Reliance Q1 FY27 earnings call

Reliance Industries Limited's Q1 FY2026-27 earnings call offered four strategic developments across its telecom, retail, and media businesses. The company doubled down on quick commerce, its second attempt at the model, and relaunched a redesigned JioMart app. The online …

Jul 21·inc42.com

Zaggle To Acquire 20% Stake In Unobanc To Bolster Cross-Border Payments

Zaggle plans to invest up to ₹7.97 Cr in Unobanc, which provides technology infrastructure for digital cross-border payments and remittances, to acquire up to 19.9% stake. The investment strengthens Zaggle's presence in cross-border payments, forex and remittances as it e…