कौन ज़िम्मेदार? KaunZimmedar

Malware attack delayed CDSL settlements by 2 days, SEBI finds

This order addresses a malware attack on Central Depository Services (India) Limited (CDSL) that occurred on November 18, 2022, and examines alleged failures by CDSL and its senior IT officers to comply with SEBI’s cybersecurity regulations, specifically regarding the classification of critical assets and vulnerability testing.

Central Depository Services (India) Limited (CDSL), Mr. Rajesh Nadkarni (then Chief Information Security Officer), and Mr. Amit Mahajan (then Chief Technology Officer).

  • SEBI alleged that CDSL failed to identify and classify the ADFS server as a critical asset, contrary to SEBI Circulars dated July 06, 2015 (as modified May 20, 2022).
  • SEBI alleged that CDSL failed to include the ADFS server in vulnerability assessment and penetration testing (VAPT) and did not integrate it with Security Information and Event Management (SIEM) and Privileged Identity Management (PIM).
  • The order cites alleged violations of the SEBI (Depositories and Participants) Regulations, 2018, and various SEBI circulars regarding cybersecurity and remote access.
  • A Show Cause Notice was issued on October 24, 2024, alleging that CDSL disregarded the cyber-security framework on the pretext of COVID-19 hybrid working requirements.
  • The order notes that CDSL admitted in January 2024 that it had not classified the affected ADFS server as critical.

Written from the document by AI, and checked against it. The original below is authoritative.

The original document

Order 2026-07-20
Tap “Open the PDF” above to view this document.
Document details
Official titleAdjudication Order in the matter of Central Depository Services India Limited malware attack on November 18, 2022
Source bodySecurities & Exchange Board of India (SEBI) — enforcement orders
Reference numberOrder/JS/RJ/2026-27/32498-32500
Statusclosed (order)
Year2026
Closing date
Documents1

Discussion (0)

Citizens discussing these documents. A discussion space — nothing here is verified fact or an official finding. Reading is free; sign in to take part.

Open discussion (0) →