18 views 59 secs 0 comments

SEBI penalizes Central Depository Services for cybersecurity lapses related to 2022 malware attack, imposes Rs 1 crore penalty

In Legal News, Finance
July 20, 2026

MoneyControl reports:

Market regulator Securities and Exchange Board of India (SEBI) has imposed a penalty of Rs 1 crore [USD $103,683.10 at today’s rate] on Central Depository Services (India) Ltd (CDSL), holding that a series of cybersecurity failures enabled the malware attack that disrupted the depository’s operations in November 2022 and affected settlement activities across the securities market.

In an 88-page adjudication order, Adjudicating Officer Jai Sebastian concluded that the attack was not merely the result of an external cyber intrusion but was aggravated by CDSL’s failure to implement key cybersecurity safeguards mandated under SEBI’s regulatory framework. The order points to lapses in identifying critical systems, conducting security assessments, monitoring cyber threats and ensuring timely disaster recovery.

Read more at MoneyControl