SEBI Fines CDSL ₹1 Crore for 2022 Malware Attack Lapses
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The Securities and Exchange Board of India (SEBI) fined Central Depository Services (India) Ltd (CDSL) ₹1 crore for cybersecurity lapses that led to a malware attack in November 2022. The attack exploited a misclassified internet-facing Active Directory Federation Services (ADFS) server, which was not included in vulnerability assessments. This oversight caused significant disruptions in depository operations, delaying critical settlements scheduled for November 18, 2022, until November 20. SEBI's order highlighted failures in identifying critical IT assets, conducting vulnerability assessments, and implementing proper access controls. The regulator also noted that CDSL had relaxed password policies during the Covid-19 pandemic and failed to restore necessary cybersecurity measures afterward. SEBI held CDSL and two former executives accountable for these violations, but adjudication proceedings against the executives were disposed of.
Key Points: • SEBI imposed a ₹1 crore fine on CDSL for cybersecurity failures linked to a 2022 malware attack. • The malware attack exploited a misclassified ADFS server, disrupting key depository operations. • CDSL failed to conduct adequate vulnerability assessments and restore cybersecurity controls post-Covid.