SEBI Fines CDSL Over Login Server Left Outside Its Own Security Controls
The depository left an internet-facing login server outside mandatory security checks and ignored the alerts that flagged the intrusion until attackers had spent nearly a year inside the network.
Topics
News
- CuspAI Launches Global AI Network to Discover New Materials
- Google Develops Gemini-Linked Chip
- Kanishka Narayan Takes UK AI Policy Into Cabinet
- Hackers Exploit Critical WordPress Flaws Worldwide
- SEBI Fines CDSL Over Login Server Left Outside Its Own Security Controls
- Companies Double Down on AI Despite Elusive ROI: KPMG
Image Credit- Chetan Jha/ MIT Sloan Management Review India
India’s market regulator has fined Central Depository Services (India) Ltd ₹1 crore (about $104,000) after finding that it left an internet-facing login server outside critical security controls and failed to act adequately on threat alerts before a 2022 malware attack that disrupted securities settlements.
The Securities and Exchange Board of India (Sebi) said in an 88-page order on Monday, 20 July, that the failures allowed attackers to enter CDSL’s network and remain undetected. The penalty comprises ₹90 lakh under the SEBI Act and ₹10 lakh under the Depositories Act.
The breach began through an Active Directory Federation Services server, which manages user access to applications. CDSL had not classified the server as a critical asset despite rules introduced in May 2022 requiring internet-facing systems to receive that designation.
It was therefore excluded from mandatory security testing, event monitoring and controls governing administrator access. Sebi had flagged deficiencies in August 2022, but CDSL did not correct them, the regulator said.
A forensic investigation found that attackers had entered CDSL’s network in November 2021, nearly a year before the malware was detected on 18 November 2022. The attack eventually infected 135 of 547 servers and 177 of 506 desktops and laptops.
Sebi also found that an administrator account had a weak password set never to expire. Two-factor authentication was absent, account-lockout rules relaxed during the covid pandemic had not been restored, and privileged accounts were inadequately monitored.
Security tools generated several warnings indicating malware activity and misuse of administrator privileges, but CDSL failed to investigate or respond adequately, the regulator said. An internet-accessible remote desktop connection also remained exposed because the server had not undergone mandatory testing.
CDSL isolated affected systems after detecting the malware. The shutdown disrupted settlements, inter-depository transfers, corporate actions and pledge-related services.
Settlement operations were affected for 46 hours and inter-depository transfers for 54.5 hours. A settlement scheduled for 18 November was completed on 20 November after coordination with other market institutions.
Sebi said CDSL also failed to declare a disaster promptly or restore services within the required recovery period.
The regulator said the failures had implications beyond CDSL because the depository manages about 70% of India’s investor accounts and forms a critical part of the country’s securities infrastructure.
“The malware attack was the foreseeable outcome of lapses that had built up over time,” Sebi said, citing policy deviations, unimplemented regulatory directions and missing safeguards.
Proceedings against former chief information security officer Rajesh Nadkarni and former chief technology officer Amit Mahajan were closed without monetary penalties because the alleged failures could not be attributed to them individually.
CDSL said the order would have no material effect on its finances or operations beyond payment of the penalty.

