Probe finds attacker had access a year before incident; SEBI cites prolonged cyber lapses that delayed settlements and risked market integrity

Market regulator Securities and Exchange Board of India has imposed a total penalty of ₹1 crore on Central Depository Services (CDSL) for cybersecurity lapses linked to the malware attack that disrupted the depository’s operations in November 2022. The regulator imposed a ₹90 lakh penalty under the SEBI Act and another ₹10 lakh under the Depositories Act, while dropping monetary penalties against CDSL’s former Chief Information Security Officer (CISO) Rajesh Nadkarni and former Chief Technology Officer (CTO) Amit Mahajan.
The order stems from Sebi’s examination of the malware attack that occurred on November 18, 2022, after which several CDSL servers and end-user computers became inaccessible, affecting critical depository operations, including settlements. CDSL isolated its systems to contain the attack and restored services over the following two days.
According to the adjudication order, the root cause analysis found that an internet-facing Active Directory Federation Services (ADFS) server had not been classified as a critical asset, was excluded from vulnerability assessment and penetration testing (VAPT), and was not integrated with the Security Information and Event Management (SIEM) and Privileged Identity Management (PIM) systems.
“The inadequately secured internet accessible ADFS server was the root cause of the incident,” the order noted. It further said the vulnerabilities “were exploited by the threat actor in getting access to the CDSL systems without generating any alerts for malicious activity.”
Sebi also observed that CDSL failed to implement key cybersecurity controls. The regulator said a privileged administrator account had a weak password that could be “easily brute-forced,” its password was set to “Never Expire,” and two-factor authentication had not been implemented for the server. The order also stated that the server was not integrated with SIEM, preventing effective monitoring of malicious activity.
Further, the regulator found that alerts generated by security tools during the attack “were not acknowledged” and that suspicious activities, including malware deployment and attempts at data exfiltration, remained undetected because critical events were not being monitored through the SIEM platform.
The regulator also held that CDSL failed to declare a disaster within the prescribed timeline and restore critical systems within the recovery time objective mandated by Sebi. As a result, settlement activities and inter-depository transfers remained disrupted for nearly 46 hours and 54.5 hours, respectively, delaying market settlements and impacting participants across the securities market.
In its findings, Sebi said the attacker had gained access to CDSL’s servers in November 2021, nearly a year before the malware attack was detected. The regulator said the cybersecurity weaknesses had continued even after pandemic-related work arrangements ended.
“The malware attack was the foreseeable outcome of lapses that had built up over time,” the order said, adding that the integrity of the securities market “was put at risk not by an unforeseeable or random event, but by a series of failures that could, and ought to have been avoided in the normal course.”
While imposing the penalty, SEBI noted that it had considered the corrective measures taken by CDSL after the incident, as well as an earlier financial disincentive of ₹10 lakh imposed under its cyber incident reporting framework.