The Securities and Exchange Board of India (SEBI) has imposed a ₹1 crore penalty on Central Depository Services (India) Ltd. (CDSL) for cybersecurity and compliance failures linked to a malware attack in November 2022 that disrupted the depository’s operations and affected securities settlement activities. The market regulator concluded that the cyber incident was not solely the result of an external attack but was exacerbated by deficiencies in CDSL’s cybersecurity framework, governance, and operational controls.

The enforcement action underscores SEBI’s increasing focus on cyber resilience across India’s financial market infrastructure institutions. Depositories, stock exchanges, and clearing corporations are considered critical market infrastructure entities, making robust cybersecurity controls essential to ensure uninterrupted trading, settlement, and investor protection.

SEBI Finds Multiple Cybersecurity Lapses

According to SEBI’s order, the November 2022 malware attack exposed weaknesses in CDSL’s cybersecurity preparedness and compliance with regulatory requirements.

The regulator found shortcomings related to:

  • Cybersecurity governance.
  • Security monitoring and incident detection.
  • Operational controls.
  • Risk management processes.
  • Compliance with SEBI’s cybersecurity framework.

SEBI said these deficiencies increased the impact of the malware attack and compromised the resilience expected from a systemically important market infrastructure institution.

SEBI Enforcement Action

ItemDetails
Entity penalizedCentral Depository Services (India) Ltd. (CDSL)
Penalty₹1 crore
IncidentNovember 2022 malware attack
RegulatorSecurities and Exchange Board of India (SEBI)
Primary findingCybersecurity and compliance lapses

2022 Malware Attack Disrupted Market Operations

The malware attack, which occurred in November 2022, disrupted several of CDSL’s critical systems, affecting depository services and delaying parts of the securities settlement process.

Following the incident, CDSL isolated affected systems to contain the malware while restoring operations in phases. Although trading continued, the disruption highlighted the importance of cyber resilience for institutions that handle dematerialized securities and settlement infrastructure.

Impact of the Incident

AreaEffect
Depository systemsOperational disruption
Settlement activitiesDelays in processing
Market infrastructureTemporary operational impact
Regulatory responseInvestigation and penalty

Why the Order Matters

CDSL is one of India’s two central securities depositories and plays a vital role in holding securities in electronic form and facilitating settlement across capital markets.

SEBI emphasized that failures at a depository can have broader implications because of the interconnected nature of India’s financial market infrastructure. The regulator noted that maintaining strong cybersecurity controls is critical for ensuring market integrity, operational continuity, and investor confidence.

Importance of Cybersecurity for Depositories

AreaImportance
Investor protectionSafeguards securities records
Settlement systemsEnsures uninterrupted transactions
Market stabilityReduces systemic cyber risks
Regulatory complianceMeets mandatory cyber standards

Stronger Regulatory Focus on Cyber Resilience

The penalty reflects SEBI’s broader push to strengthen cybersecurity standards across regulated entities as cyber threats become more sophisticated.

Financial institutions are increasingly expected to:

  • Continuously monitor cyber risks.
  • Upgrade security infrastructure.
  • Conduct regular vulnerability assessments.
  • Strengthen incident response capabilities.
  • Ensure board-level oversight of cybersecurity.

The order serves as a reminder that regulators expect market infrastructure institutions to proactively manage cyber risks rather than simply respond after incidents occur.

Looking Ahead

SEBI’s ₹1 crore penalty against CDSL sends a strong message that cybersecurity failures at critical financial infrastructure institutions will attract regulatory action, particularly when they expose the broader securities market to operational risks. As cyberattacks targeting financial institutions continue to increase globally, regulators are placing greater emphasis on governance, resilience, and compliance alongside traditional financial oversight.

For CDSL, the focus will now shift to strengthening its cybersecurity framework and ensuring full compliance with SEBI’s standards. More broadly, the order is likely to encourage stock exchanges, depositories, clearing corporations, and other regulated entities to reassess their cyber defenses and incident response capabilities to minimize the risk of future disruptions.

Get the day’s top stories in your inbox

One concise email. No spam, unsubscribe anytime.