Get App
Download App Scanner
Scan to Download
Advertisement

SEBI Fines CDSL Rs 1 Crore Over 2022 Malware Attack, Cybersecurity Lapses

SEBI said the 2022 CDSL malware attack was foreseeable, citing cybersecurity lapses including weak password controls and inadequate security monitoring.

SEBI Fines CDSL Rs 1 Crore Over 2022 Malware Attack, Cybersecurity Lapses
In an 88-page order, the regulator levied a Rs 90 lakh penalty under the SEBI Act and Rs 10 lakh under the Depositories Act.
Photo Source: NDTV Profit/AI generated image
  • SEBI fined CDSL Rs 1 crore for cybersecurity lapses causing Nov 2022 malware attack
  • The attack was deemed foreseeable and preventable with proper security compliance
  • CDSL failed to classify a key server as critical, missing mandatory security testing

India's markets regulator has imposed a cumulative penalty of Rs 1 crore on Central Depository Services (India) Ltd (CDSL) for cybersecurity lapses that led to the November 2022 malware attack, holding that the breach was "foreseeable" and could have been prevented through compliance with mandatory security standards.

In an 88-page order, the Securities and Exchange Board of India (SEBI) levied a Rs 90 lakh penalty under the SEBI Act and Rs 10 lakh under the Depositories Act, while disposing of proceedings against CDSL's former Chief Information Security Officer Rajesh Nadkarni and former Chief Technology Officer Amit Mahajan without imposing monetary penalties.

ALSO READ | SEBI Says Business Transfers Can't Bypass Mandatory Debt Listing Rules

Rejecting CDSL's defence that the attack was an unfortunate cyber incident, the adjudicating officer concluded that the malware attack was "not an unforeseeable or random event" but "a foreseeable consequence of lapses in cyber security controls."

SEBI found that CDSL failed to classify its internet-facing Active Directory Federation Services (ADFS) server as a critical asset despite revised cybersecurity norms, leaving it outside mandatory security testing and monitoring. The regulator also identified weak password controls, deviations from security policies and inadequate monitoring of security alerts.

"The failures... could, and ought to have been avoided in the normal course," the order said, adding that the deficiencies reflected a "failure to adhere to basic cyber security hygiene" expected of a market infrastructure institution.

According to the order, forensic investigation indicated that attackers first gained access to CDSL's network in November 2021, almost a year before the malware attack was detected on Nov. 18, 2022. The regulator said the prolonged compromise underscored shortcomings in CDSL's cyber monitoring framework.

ALSO READ | 'Boss Scam', Fake Trading Apps, Phishing: SEBI, NSE Sound Alarm On New-Age Investment Frauds

The malware attack disrupted several depository services, including settlement, transfer and pledge transactions, forcing market participants to defer settlements over the weekend.

Essential Business Intelligence, Sharp Market Insights, Practical Personal Finance Advice, Daily Fuel, Gold and Silver Prices and Latest Stories — On NDTV Profit.

Newsletters

Update Email
to get newsletters straight to your inbox
⚠️ Add your Email ID to receive Newsletters
Note: You will be signed up automatically after adding email

News for You

Set as Trusted Source
on Google Search
Add NDTV Profit As Google Preferred Source
Listen to the latest songs, only on JioSaavn.com