Updated
Updated · WTVB · Jul 20
SEBI Fines CDSL 10 Million Rupees Over 2022 Malware Attack on 83 Million Accounts
Updated
Updated · WTVB · Jul 20

SEBI Fines CDSL 10 Million Rupees Over 2022 Malware Attack on 83 Million Accounts

3 articles · Updated · WTVB · Jul 20

Summary

  • 10 million rupees is the penalty SEBI imposed on CDSL over cybersecurity and compliance failures tied to a November 2022 malware attack that disrupted depository operations.
  • CDSL, which handles 83 million investor accounts—about 70% of India’s total—failed to classify and protect an internet-facing server as a critical asset, and SEBI said that server was the root cause of the breach.
  • SEBI also cited failures to detect intrusions in real time, properly analyze security alerts and follow backup-site rules for resuming trade settlement.
  • The attack delayed settlements due on Nov. 18, 2022 and disrupted settlement activity, corporate actions, margin pledges and inter-depository transfers.
  • The regulator said the incident was a foreseeable result of accumulated lapses, including weak password controls, inadequate monitoring and missing required safeguards.

Insights

Is a ₹1 crore fine enough to secure 70% of India's investor accounts from the next major cyberattack?
SEBI fined the institution but cleared its executives. Does this create a loophole for future cybersecurity accountability?