The order said the attack affected critical depository processes, forcing CDSL to isolate its systems and delay settlements scheduled for November 18, 2022, until November 20

The Securities and Exchange Board of India (SEBI) has imposed a total penalty of ₹1 crore on Central Depository Services (India) Ltd (CDSL) for lapses in cybersecurity that led to the malware attack on the depository's systems in November 2022 but disposed of adjudication proceedings against two of its former senior technology executives.In an 88-page order issued on Monday, the market regulator held that CDSL failed to comply with several provisions of its cybersecurity framework, including identifying critical IT assets, conducting adequate vulnerability assessments and implementing appropriate access controls, resulting in a malware attack that disrupted key depository operations.Security lapsesThe order said the attack affected critical depository processes, forcing CDSL to isolate its systems and delay settlements scheduled for November 18, 2022, until November 20. SEBI found that the depository had failed to classify an internet-facing Active Directory Federation Services (ADFS) server as a critical asset, leaving it outside the scope of vulnerability assessment and penetration testing."The ADFS server was not included in the vulnerability assessment and penetration testing (VAPT) and was not integrated with Security Information and Event Management (SIEM) and Privileged Identity Management (PIM)," the order said, adding that these weaknesses were exploited by the threat actor to gain access to CDSL's systems.SEBI also said that the depository had relaxed password and account lockout policies during the Covid-19 period and failed to restore the required cybersecurity controls even after normalcy returned, increasing the risk of compromise.The regulator held CDSL, its then Chief Information Security Officer Rajesh Nadkarni and then Chief Technology Officer Amit Mahajan responsible for violations of the prescribed cybersecurity framework and the code of conduct applicable to market infrastructure institutionsPublished on July 20, 2026