CDSL delayed settlements by 2 days after malware attack, SEBI order finds
This order addresses a malware attack on Central Depository Services (India) Limited (CDSL) on November 18, 2022, and examines whether CDSL and its senior IT officers failed to comply with SEBI’s cybersecurity regulations regarding the identification of critical assets and vulnerability testing.
Central Depository Services (India) Limited (CDSL), Mr. Rajesh Nadkarni (then Chief Information Security Officer), and Mr. Amit Mahajan (then Chief Technology Officer).
- SEBI alleged that CDSL failed to classify the Azure Cloud ADFS server as a 'critical asset' as required by SEBI Circulars dated July 06, 2015 (modified May 20, 2022).
- SEBI alleged that CDSL failed to include the ADFS server in Vulnerability Assessment and Penetration Testing (VAPT) and did not integrate it with Security Information and Event Management (SIEM) systems.
- SEBI alleged that CDSL and its officers violated specific clauses of the SEBI (Depositories and Participants) Regulations, 2018, and various SEBI circulars regarding cybersecurity and remote access.
- The order notes that CDSL admitted in January 2024 that it had not classified the affected ADFS server as critical.
- The order is an adjudication proceeding under Section 15-I of the SEBI Act and Section 19H of the Depositories Act, 1996.
Written from the document by AI, and checked against it. The original below is authoritative.
The original document
Document details
| Official title | Adjudication Order in the matter of Central Depository Services India Limited malware attack on November 18, 2022 |
| Source body | Securities & Exchange Board of India (SEBI) — enforcement orders |
| Reference number | Order/JS/RJ/2026-27/32498-32500 |
| Status | None (order) |
| Year | 2026 |
| Closing date | — |
| Documents | 1 |