SEBI Fines CDSL 10 Million Rupees Over 2022 Malware Attack on 83 Million Accounts
Updated
Updated · WTVB · Jul 20
SEBI Fines CDSL 10 Million Rupees Over 2022 Malware Attack on 83 Million Accounts
3 articles · Updated · WTVB · Jul 20
Summary
10 million rupees is the penalty SEBI imposed on CDSL over cybersecurity and compliance failures tied to a November 2022 malware attack that disrupted depository operations.
CDSL, which handles 83 million investor accounts—about 70% of India’s total—failed to classify and protect an internet-facing server as a critical asset, and SEBI said that server was the root cause of the breach.
SEBI also cited failures to detect intrusions in real time, properly analyze security alerts and follow backup-site rules for resuming trade settlement.
The attack delayed settlements due on Nov. 18, 2022 and disrupted settlement activity, corporate actions, margin pledges and inter-depository transfers.
The regulator said the incident was a foreseeable result of accumulated lapses, including weak password controls, inadequate monitoring and missing required safeguards.