Malware attack delayed CDSL settlements by 2 days, SEBI finds
This order addresses a malware attack on Central Depository Services (India) Limited (CDSL) that occurred on November 18, 2022, and examines alleged failures by CDSL and its senior IT officers to comply with SEBI’s cybersecurity regulations, specifically regarding the classification of critical assets and vulnerability testing.
Central Depository Services (India) Limited (CDSL), Mr. Rajesh Nadkarni (then Chief Information Security Officer), and Mr. Amit Mahajan (then Chief Technology Officer).
- SEBI alleged that CDSL failed to identify and classify the ADFS server as a critical asset, contrary to SEBI Circulars dated July 06, 2015 (as modified May 20, 2022).
- SEBI alleged that CDSL failed to include the ADFS server in vulnerability assessment and penetration testing (VAPT) and did not integrate it with Security Information and Event Management (SIEM) and Privileged Identity Management (PIM).
- The order cites alleged violations of the SEBI (Depositories and Participants) Regulations, 2018, and various SEBI circulars regarding cybersecurity and remote access.
- A Show Cause Notice was issued on October 24, 2024, alleging that CDSL disregarded the cyber-security framework on the pretext of COVID-19 hybrid working requirements.
- The order notes that CDSL admitted in January 2024 that it had not classified the affected ADFS server as critical.
Written from the document by AI, and checked against it. The original below is authoritative.
The original document
Document details
| Official title | Adjudication Order in the matter of Central Depository Services India Limited malware attack on November 18, 2022 |
| Source body | Securities & Exchange Board of India (SEBI) — enforcement orders |
| Reference number | Order/JS/RJ/2026-27/32498-32500 |
| Status | closed (order) |
| Year | 2026 |
| Closing date | — |
| Documents | 1 |