Key Facts
- Penalty: ₹1 crore imposed on Central Depository Services (India) Ltd (CDSL) — ₹90 lakh under SEBI Act, ₹10 lakh under Depositories Act
- Date of Order: 20 July 2026
- Incident: Malware attack on 18 November 2022
- Scope: 135 of 547 servers and 177 of 506 desktops infected
- Impact: Settlement activities disrupted for 46 hours; inter-depository transfers for 54.5 hours
- Root Cause: Failure to classify an internet-facing ADFS server as a critical asset
- Finding: Attack was “foreseeable” — not an unforeseeable or random event
- Individuals Cleared: Former CISO Rajesh Nadkarni and former CTO Amit Mahajan — lapses attributed to institutional processes, not individuals
Direct Answer
On 20 July 2026, the Securities and Exchange Board of India (SEBI) imposed a cumulative penalty of ₹1 crore on Central Depository Services (India) Ltd (CDSL) for cybersecurity lapses that enabled a malware attack in November 2022.
In its 88-page order, SEBI held that the attack was “a foreseeable consequence of lapses in cyber security controls” and could have been prevented through compliance with mandatory security standards. The regulator found that CDSL failed to classify an internet-facing Active Directory Federation Services (ADFS) server as a critical asset, excluded it from vulnerability testing, and ignored deficiencies flagged by SEBI three months before the attack.
Attackers had gained access nearly a year earlier — in November 2021 — and went undetected. The malware infected 135 servers and 177 desktops, disrupting settlement activities for 46 hours and inter-depository transfers for 54.5 hours.
SEBI cleared the former CISO and CTO of individual liability, holding that the lapses were institutional failures involving multiple levels of oversight, including the board. The order is a clear signal: cybersecurity is a governance obligation, not a technical detail.
In this article:
- The Incident: What Happened on 18 November 2022
- The SEBI Order: What Went Wrong
- The Findings: A “Foreseeable” Attack
- Why the CISO and CTO Were Cleared
- The Impact: 46 Hours of Market Disruption
- What This Means for Every Board
- FAQ
By Adv. Shoeb Hakim — Criminal defence, AML, digital forensics, and cybercrime specialist; former General Counsel, Credit Suisse; training police and judiciary since 1996.
The Incident: What Happened on 18 November 2022
On the morning of 18 November 2022, CDSL observed that some servers and end-user computers had become inaccessible. Upon investigation, it was found to be a malware attack.
CDSL immediately isolated the affected systems and disconnected its network to stop the spread of the malware. The attack affected critical systems linked to various depository processes, including settlement, pay-in/pay-out, and pledge-related activities.
The recovery exercise was completed on 19 November 2022, and settlements scheduled for 18 November were carried out on 20 November.
But the damage — and the questions — lingered for nearly four years until SEBI’s order finally addressed the root causes.
The SEBI Order: What Went Wrong
In its 88-page order dated 20 July 2026, SEBI detailed a catalogue of failures:
1. Failure to Classify Critical Assets
CDSL failed to classify its internet-facing Active Directory Federation Services (ADFS) server as a critical asset. This server was excluded from vulnerability assessment and penetration testing (VAPT) and was not integrated with Security Information and Event Management (SIEM) and Privileged Identity Management (PIM) systems.
The significance: The ADFS server manages user access to applications. Leaving it outside security controls meant that attackers could exploit it to gain access to CDSL’s entire network. This server was “the root cause of the malware attack”.
2. Ignored Regulatory Warnings
SEBI had flagged these deficiencies to CDSL in August 2022 — three months before the attack. The depository did not address them and instead relied on an earlier, deficient VAPT exercise.
3. Weak Password Controls
CDSL created an administrator account in 2021 with a password set to never expire. This policy deviation — introduced during the COVID-19 period — remained unaddressed even after normalcy returned. The regulator also noted relaxation regarding the lockout threshold to three failed attempts was not addressed until the attack.
4. Inadequate Monitoring
SEBI found that CDSL failed to detect intrusions in real time and to properly analyse security alerts. Attackers had gained access as early as November 2021 — nearly a year before the malware attack was detected.
5. Policy Deviations
The order noted “unwarranted policy deviations, unimplemented regulatory directions, and the absence of certain cybersecurity measures”.
The Findings: A “Foreseeable” Attack
SEBI rejected CDSL’s defence that the attack was an unfortunate cyber incident. The adjudicating officer concluded that the malware attack was “not an unforeseeable or random event” but “a foreseeable consequence of lapses in cyber security controls”.
“The failures… could, and ought to have been avoided in the normal course,” the order said, adding that the deficiencies reflected a “failure to adhere to basic cyber security hygiene” expected of a market infrastructure institution.
The regulator noted that the attack was “the foreseeable outcome of accumulated cyber-security lapses, including inadequate monitoring, weak password controls and failure to implement required cyber-security safeguards”.
Why the CISO and CTO Were Cleared
SEBI disposed of adjudication proceedings against former Chief Information Security Officer Rajesh Nadkarni and former Chief Technology Officer Amit Mahajan without imposing any monetary penalty.
The regulator held that the alleged lapses “could not be attributed to them individually”. The order noted that:
- The classification of critical assets was “only a proposal until approved by the SCOT Committee”
- Password policy deviations had been “reviewed by relevant IT officials and approved in accordance with internal procedures during the Covid-19 period”
- VAPT-related decisions were “institutional processes involving multiple levels of oversight, including CDSL’s Systems and Technology Committee (SCOT) and its board”
The implication: These were not rogue decisions by individual executives. They were institutional failures that involved board-level oversight. The buck stops at the top.
The Impact: 46 Hours of Market Disruption
The malware attack infected 135 of 547 servers and 177 of 506 desktops and laptops. Critical systems, including the settlement process and inter-depository transfer, faced disruption for 46 hours and 54.5 hours, respectively.
The spillover effect
CDSL handles 83 million investor accounts — 70% of India’s investor base. SEBI noted that “the disruption at Noticee No. 1 had a major spillover impact as the settlement activities for the entire securities market were also dependent upon the normal functioning of CDSL systems”.
The regulator observed that “the interconnectedness and interdependency of the depositories pose broader implications for cyber risk”. A failure at one market infrastructure institution can paralyse the entire market.
What This Means for Every Board
The CDSL order is a governance document as much as it is a penalty order. It sends several clear signals:
1. Cybersecurity Is a Board Responsibility
The regulator cleared the CISO and CTO because the failures were institutional. The Systems and Technology Committee and the board were involved in critical asset classification and policy approvals. Boards cannot delegate cybersecurity to IT teams and claim ignorance.
2. Regulatory Warnings Must Be Acted Upon
SEBI flagged the deficiencies in August 2022. CDSL did not act. The penalty followed. Boards must ensure that regulatory observations are addressed promptly — not filed away.
3. COVID-Era Relaxations Must Be Reviewed
Password policies were relaxed during COVID-19 and never restored. Boards must review all temporary policy deviations and ensure they are reversed once the emergency has passed.
4. Critical Assets Must Be Properly Classified
The ADFS server was left outside security testing because it was not classified as critical. Boards must oversee the classification of critical assets and ensure all internet-facing systems are secured.
5. Monitoring Must Be Continuous
Attackers were inside CDSL’s network for nearly a year. Boards must ensure that intrusion detection and security monitoring are robust enough to detect compromises in real time.
6. Cyber Risk Has Systemic Implications
CDSL’s failure affected the entire securities market. For market infrastructure institutions, cybersecurity is not just about protecting the entity — it is about protecting the market.
FREQUENTLY ASKED QUESTIONS (FAQ)
Q: Does this order set a precedent for other market institutions?
Ans: Absolutely. It signals that all market infrastructure institutions (MIIs) must treat cyber-hygiene as a board-level governance duty.
Q: Why did SEBI clear the individuals?
Ans: The regulator concluded that the security flaws were part of institutional processes and board-approved policy deviations, rather than decisions by individual officers.
Q: What is the most critical takeaway for Boards?
Ans: Cybersecurity is a core governance obligation. You cannot delegate cyber-risk management to the IT department without active, documented, and questioning Board oversight.
How much was CDSL fined and why?
SEBI imposed a total penalty of ₹1 crore on CDSL — ₹90 lakh under the SEBI Act and ₹10 lakh under the Depositories Act — for cybersecurity lapses that enabled a November 2022 malware attack.
What was the root cause of the malware attack?
CDSL failed to classify its internet-facing Active Directory Federation Services (ADFS) server as a critical asset, leaving it outside security testing and monitoring. This server was the root cause of the attack.
When did the attackers first gain access?
Forensic investigation indicated that attackers first gained access to CDSL’s network in November 2021 — nearly a year before the malware attack was detected on 18 November 2022.
How extensive was the damage?
The malware infected 135 of 547 servers and 177 of 506 desktops. Critical systems, including settlement and inter-depository transfer, were disrupted for 46 hours and 54.5 hours respectively.
Were the former CISO and CTO penalised?
No. SEBI disposed of proceedings against former CISO Rajesh Nadkarni and former CTO Amit Mahajan without imposing any monetary penalty, holding that the lapses could not be attributed to them individually.
Why were the CISO and CTO cleared?
The order noted that critical asset classification, password policy deviations, and VAPT-related decisions were institutional processes involving multiple levels of oversight, including CDSL’s Systems and Technology Committee and its board.
What did SEBI say about the foreseeability of the attack?
SEBI concluded that the malware attack was “not an unforeseeable or random event” but “a foreseeable consequence of lapses in cyber security controls”.
What is the key governance lesson from this order?
Cybersecurity is a board responsibility. The failures were institutional, not individual. Boards must oversee critical asset classification, ensure regulatory warnings are acted upon, review COVID-era policy deviations, and ensure continuous monitoring.
What is the systemic impact of CDSL’s failure?
CDSL handles 83 million investor accounts — 70% of India’s investor base. The disruption had a “major spillover impact” on the entire securities market. A failure at one market infrastructure institution can paralyse the market.
What must boards do now?
Treat cybersecurity as a governance obligation, ensure critical assets are classified and secured, restore pre-COVID security standards, act on regulatory alerts, and monitor for intrusions in real time.
KNOWLEDGE CHECK QUIZ
Q: What was the total penalty imposed on CDSL by SEBI?
Ans: SEBI imposed a cumulative penalty of ₹1 crore (₹90 lakh under the SEBI Act and ₹10 lakh under the Depositories Act).
Q: What was the root cause of the malware attack?
Ans: The failure to classify the internet-facing Active Directory Federation Services (ADFS) server as a critical asset, which left it excluded from security monitoring.
Q: Why were the former CISO and CTO cleared of individual liability?
Ans: SEBI determined the failures were systemic and institutional, involving multiple levels of oversight by the Board and the Systems and Technology Committee (SCOT).
Q: How long did the attackers have access to the CDSL network?
Ans: The forensic investigation revealed attackers gained access in November 2021, nearly a year before the November 2022 malware incident.
By Adv. Shoeb Hakim
Criminal defence, AML, digital forensics, and cybercrime specialist; former General Counsel, Credit Suisse; training police and judiciary since 1996.
📌 Connect: https://www.linkedin.com/in/shoebhakim | https://shoebhakim.com/shoeb-hakim-blog/
📌 Visit my website for more articles: https://www.shoebhakim.com
📌 Visit my website for legal knowledge: https://www.vakilverse.com
📌 Visit my website for research fellowship: https://www.legalcomplaince.in
Disclaimer: This content is for informational purposes only and does not constitute legal advice. Readers should consult qualified legal counsel for advice on their specific circumstances.
#AdvShoebHakim #CDSL #SEBI #CyberSecurity #CorporateGovernance #BoardAccountability #MarketInfrastructure #Compliance #CyberRisk #FinancialRegulation #DigitalForensics #RegulatoryFine #LegalComplianceIN



Leave a Reply