Capital markets regulator Sebi has imposed a penalty of Rs 1 crore on Central Depository Services (India) Ltd, or CDSL, for cybersecurity lapses linked to a malware attack in November 2022 that disrupted key depository operations and delayed market settlements.
The adjudication order was passed in the matter of the malware attack on CDSL on November 18, 2022. The order also named Rajesh Nadkarni, then chief information security officer, and Amit Mahajan, then chief technology officer, as noticees. SEBI, however, disposed of proceedings against the two former officials without imposing any monetary penalty.
Sebi imposed Rs 90 lakh on CDSL under Section 15HB of the Sebi Act and Rs 10 lakh under Section 19G of the Depositories Act. The regulator said the penalty was commensurate with the lapses and omissions on the part of CDSL. The company has been directed to pay the amount within 45 days of receiving the order.
What happened in 2022
According to the order, CDSL observed around 3 am on November 18, 2022, after completion of end-of-day operations, that some servers and end-user computers had become inaccessible. On checking the cause, it was found to be a malware attack.
CDSL isolated servers and end-user computers and disconnected its network to stop the spread of malware. The attack affected critical systems linked to various depository processes. CDSL then created a separate virtual local area network with clean desktops and servers after scanning. The recovery exercise was completed on November 19, 2022, and settlements scheduled for November 18 were carried out on November 20.
Sebi said critical systems, including settlement process and inter-depository transfer, were disrupted for 46 hours and 54.5 hours, respectively. It said the disruption had a major spillover impact because settlement activities for the securities market also depended on the normal functioning of CDSL systems.
Also Read: Absolute Projects, Jindal Supreme secure Sebi’s nod to float IPOs
ADFS server at centre of case
The regulator’s findings focused on CDSL’s Active Directory Federation Services, or ADFS, server. SEBI said the ADFS server was an internet-facing application and should have been treated as a critical asset under the cybersecurity framework.
The order said the final root cause analysis report found that an inadequately secured internet-accessible ADFS server was the root cause of the incident. The server had not been included in vulnerability assessment and penetration testing, and had not been integrated with Security Information and Event Management and Privileged Identity Management systems. SEBI said these gaps were exploited by the threat actor to access CDSL systems without generating alerts for malicious activity.
Sebi rejected CDSL’s argument that the ADFS server was not critical because it did not host business applications or sensitive investor data. The regulator said internet-facing applications were required to be included as critical assets under SEBI’s May 2022 cybersecurity circular.
The order also said CDSL had admitted during SEBI’s High Powered Steering Committee on Cyber Security meetings in March and May 2023 that the ADFS server should have been designated as a critical asset and subjected to relevant audits.
Access control lapses
Sebi also found lapses in access controls. The order said a domain admin account on the ADFS server had a weak password that could be brute-forced through common dictionary attacks. It also said the password for the privileged account was set to “Never Expire”, which may have allowed the threat actor to retain access for a longer period.
The regulator noted that the Privileged Identity Management solution was not configured to control and monitor directory services. This allowed the threat actor to move laterally using privileged accounts without being noticed. SEBI also said the threat actor was able to stop the endpoint detection and response solution on an endpoint machine using system account privileges.
The regulator further said the ADFS server was not integrated with SIEM, so logs were not available for audit and review. It also noted that some alerts related to possible data exfiltration, malware activity and beaconing were identified at CDSL’s head office and disaster recovery site, but the alerts were not acknowledged.
(Disclaimer: Recommendations, suggestions, views and opinions given by the experts are their own. These do not represent the views of Economic Times)


