SEBI Slaps Rs 1 Crore Fine on CDSL Over 2022 Cybersecurity Failure The market regulator has directed Central Depository Services Limited to pay 10 million rupees within 45 days for failing to secure its internet-facing servers, which led to a malware attack in November 2022. The Securities and Exchange Board of India has taken strict action against Central Depository Services (India) Limited by imposing a hefty financial penalty of Rs 1 crore. This massive fine is a direct consequence of severe cybersecurity negligence that paved the way for a disruptive malware attack on the institution back in November 2022. The market regulator's decisive move sends a clear message regarding the non-negotiable nature of digital security protocols for entities managing the country's core financial infrastructure. The Technical Failures Behind the 2022 Breach The entire controversy traces back to November 18, 2022, when a sophisticated malware attack crippled several critical systems at the depository. In an exhaustive 88-page regulatory order, SEBI outlined a series of glaring technical oversights that left the company completely vulnerable. A primary failure was the institution's inability to accurately classify its internet-facing Active Directory Federation Services server as a vital digital asset. Because this crucial server was misclassified, the company explicitly excluded it from the routine Vulnerability Assessment and Penetration Testing framework. This mandatory testing process is designed to proactively identify and patch software loopholes before malicious actors can exploit them. The regulator noted that despite having strict overarching guidelines in place, the depository completely failed to implement even the most basic cybersecurity measures required to protect such an exposed, internet-facing system. Breakdown of the Financial Sanctions The Rs 1 crore penalty handed down to the institution is divided into two distinct regulatory buckets. The regulator imposed a fine of 90 lakh specifically for violations under the overarching SEBI Act, while an additional 10 lakh was charged under the provisions of the Depository Act for failing to meet stringent operational requirements. The company has been issued a strict deadline and must pay the entire sum within 45 days, failing which it could face further regulatory heat. When calculating this final penalty amount, the regulatory body did not act blindly. SEBI formally acknowledged the corrective actions and systemic upgrades the depository undertook immediately following the malware disruption. Furthermore, the authorities factored in a separate financial penalty of 10 lakh that had already been levied on the institution previously. That earlier fine was imposed under the Standard Operating Procedure guidelines specifically for issues related to the timely reporting of cybersecurity incidents. The Systemic Risk to Retail Investors While handing down the order, the market regulator highlighted the irreplaceable role that a depository plays in maintaining overall market integrity and preserving investor confidence. As a designated Market Infrastructure Institution, the depository essentially holds the digital wealth of millions of citizens across the country. SEBI strongly asserted that when cyber risks materialize at such foundational institutions, the negative ripple effects are never limited to just that single entity. A breach threatens the stability of the entire trading ecosystem. A compromised core system could halt trading or put sensitive data at risk, meaning robust digital defenses are not just a corporate best practice, but an absolute necessity to protect the broader public interest. Former Tech Leaders Cleared of Personal Liability Even as the corporate entity faced significant financial repercussions, the regulatory body decided to drop the ongoing proceedings against two key individuals who held top technical roles at the time of the incident. Rajesh Nadkarni, the former Chief Information Security Officer, and Amit Mahajan, who served as the Chief Technology Officer, were thoroughly investigated in connection with the institutional cybersecurity failures. Ultimately, SEBI concluded the inquiry against both former executives without imposing any individual financial penalties on them. The regulator formally determined that the systemic corporate lapses and the failure to classify the servers correctly could not be pinned on Nadkarni and Mahajan as a matter of personal, individual liability. The verdict squarely places the burden of infrastructure safety on the institutional management framework rather than individual employees. What this means for you • Across India: CDSL holds the demat accounts for millions of retail investors. This strict regulatory action ensures better protection for your digital shares and personal financial data moving forward. • In the Stock Market: The massive penalty could have a short-term negative impact on CDSL's stock price, as the regulatory crackdown directly affects its immediate financial outlook. Questions & Answers 1. How much penalty did SEBI impose on CDSL? SEBI has imposed a massive penalty of Rs 1 crore on the depository for severe cybersecurity lapses. 2. What incident triggered this regulatory action? The penalty stems from a major malware attack that breached CDSL's critical systems on November 18, 2022. 3. What is the deadline for the company to pay the fine? The market regulator has given the institution a strict 45-day window to deposit the entire penalty amount. 4. Were the technical officers held personally liable? No, SEBI cleared former Chief Information Security Officer Rajesh Nadkarni and former Chief Technology Officer Amit Mahajan of any individual financial liability. https://trendkia.com/en/market/sebi-ne-saibara-suraksha-men-chuka-para-cdsl-ko-diya-jhataka-lagaya-1-karora-rupaye-ka-jurmana-9884 TrendKia — Har trend, sabse pehle.