SEBI Fines CDSL Rs 1 Crore For Cybersecurity Compliance Failures After 2022 Malware Attack Review

The Securities and Exchange Board of India (SEBI) has imposed a penalty of Rs 1 crore on Central Depository Services Limited (CDSL) over alleged cybersecurity lapses following a malware attack in November 2022.

In its order, SEBI said the attack disrupted critical systems, including the settlement process and inter-depository transfer, for 46 hours and 54.5 hours, respectively, affecting securities market operations. The regulator noted that the incident was linked to lapses such as deviations from cybersecurity policies, pending implementation of regulatory directions and gaps in security measures. SEBI also highlighted that the attacker had gained access to CDSL’s servers in November 2021, while the breach was detected a year later.

The regulator said that the interconnection between depositories increases the impact of cyber risks across the securities market.

a

Magazine made for you.