The Securities and Exchange Board of India (SEBI) has issued a formal penalty of ₹1 crore against Central Depository Services Ltd (CDSL). This disciplinary action follows a thorough investigation into a significant malware attack that compromised the depository's infrastructure in 2022.
Regulators found that CDSL failed to uphold essential cybersecurity standards, citing vulnerabilities in access controls and insufficient monitoring protocols. These technical oversights directly hindered the firm's ability to safeguard critical market systems.
The breach resulted in operational disruptions that impacted settlement processes, raising alarm among market participants. SEBI emphasized that the depository neglected to implement robust defensive measures despite explicit industry-wide mandates for digital security.
This enforcement serves as a stern reminder to financial institutions regarding their responsibility to fortify digital assets. CDSL is now expected to bolster its internal security framework to prevent a recurrence of such systemic failures.