The Securities and Exchange Board of India (SEBI) has imposed a ₹1 crore penalty on Central Depository Services (India) Ltd. (CDSL) for cybersecurity and compliance failures linked to a malware attack in November 2022 that disrupted the depository’s operations and affected securities settlement activities. The market regulator concluded that the cyber incident was not solely the result of an external attack but was exacerbated by deficiencies in CDSL’s cybersecurity framework, governance, and operational controls.
The enforcement action underscores SEBI’s increasing focus on cyber resilience across India’s financial market infrastructure institutions. Depositories, stock exchanges, and clearing corporations are considered critical market infrastructure entities, making robust cybersecurity controls essential to ensure uninterrupted trading, settlement, and investor protection.
SEBI Finds Multiple Cybersecurity Lapses
According to SEBI’s order, the November 2022 malware attack exposed weaknesses in CDSL’s cybersecurity preparedness and compliance with regulatory requirements.
The regulator found shortcomings related to:
- Cybersecurity governance.
- Security monitoring and incident detection.
- Operational controls.
- Risk management processes.
- Compliance with SEBI’s cybersecurity framework.
SEBI said these deficiencies increased the impact of the malware attack and compromised the resilience expected from a systemically important market infrastructure institution.
SEBI Enforcement Action
| Item | Details |
|---|---|
| Entity penalized | Central Depository Services (India) Ltd. (CDSL) |
| Penalty | ₹1 crore |
| Incident | November 2022 malware attack |
| Regulator | Securities and Exchange Board of India (SEBI) |
| Primary finding | Cybersecurity and compliance lapses |
2022 Malware Attack Disrupted Market Operations
The malware attack, which occurred in November 2022, disrupted several of CDSL’s critical systems, affecting depository services and delaying parts of the securities settlement process.
Following the incident, CDSL isolated affected systems to contain the malware while restoring operations in phases. Although trading continued, the disruption highlighted the importance of cyber resilience for institutions that handle dematerialized securities and settlement infrastructure.
Impact of the Incident
| Area | Effect |
|---|---|
| Depository systems | Operational disruption |
| Settlement activities | Delays in processing |
| Market infrastructure | Temporary operational impact |
| Regulatory response | Investigation and penalty |
Why the Order Matters
CDSL is one of India’s two central securities depositories and plays a vital role in holding securities in electronic form and facilitating settlement across capital markets.
SEBI emphasized that failures at a depository can have broader implications because of the interconnected nature of India’s financial market infrastructure. The regulator noted that maintaining strong cybersecurity controls is critical for ensuring market integrity, operational continuity, and investor confidence.
Importance of Cybersecurity for Depositories
| Area | Importance |
|---|---|
| Investor protection | Safeguards securities records |
| Settlement systems | Ensures uninterrupted transactions |
| Market stability | Reduces systemic cyber risks |
| Regulatory compliance | Meets mandatory cyber standards |
Stronger Regulatory Focus on Cyber Resilience
The penalty reflects SEBI’s broader push to strengthen cybersecurity standards across regulated entities as cyber threats become more sophisticated.
Financial institutions are increasingly expected to:
- Continuously monitor cyber risks.
- Upgrade security infrastructure.
- Conduct regular vulnerability assessments.
- Strengthen incident response capabilities.
- Ensure board-level oversight of cybersecurity.
The order serves as a reminder that regulators expect market infrastructure institutions to proactively manage cyber risks rather than simply respond after incidents occur.
Looking Ahead
SEBI’s ₹1 crore penalty against CDSL sends a strong message that cybersecurity failures at critical financial infrastructure institutions will attract regulatory action, particularly when they expose the broader securities market to operational risks. As cyberattacks targeting financial institutions continue to increase globally, regulators are placing greater emphasis on governance, resilience, and compliance alongside traditional financial oversight.
For CDSL, the focus will now shift to strengthening its cybersecurity framework and ensuring full compliance with SEBI’s standards. More broadly, the order is likely to encourage stock exchanges, depositories, clearing corporations, and other regulated entities to reassess their cyber defenses and incident response capabilities to minimize the risk of future disruptions.
Get the day’s top stories in your inbox
One concise email. No spam, unsubscribe anytime.