
Malware Attack Exposes Gaps at CDSL: SEBI Slams Penalty for Cybersecurity Failures
Capital markets regulator SEBI has imposed a significant penalty on Central Depository Services (India) Ltd, or CDSL, over cybersecurity lapses related to a major malware attack that occurred in November 2022. The adjudication order, passed by the regulator, highlighted serious systemic vulnerabilities within CDSL's infrastructure, leading to market disruption and delayed settlements.SEBI levied penalties against CDSL for the security breaches. A penalty of Rs 90 lakh was imposed under Section 15HB of the SEBI Act, and an additional Rs 10 lakh was assigned under Section 19G of the Depositories Act. The regulator stated that these penalties were directly commensurate with the lapses and omissions observed on CDSL's part regarding system security.
The company has been directed to remit the total penalty amount within 45 days of receiving the official order.
How the Malware Attack Compromised Depository Operations
The incident was first noticed by CDSL staff around 3 am on November 18, 2022, after the completion of end-of-day operations. Staff observed that several critical servers and associated end-user computers had become inaccessible. Investigation confirmed the cause as a targeted malware attack against the depository systems.CDSL immediately initiated containment protocols. The organization isolated all affected servers and disconnected its network to halt the progression of the malware. This necessary action impacted crucial functions linked to various depository processes.
The recovery process involved creating a separate virtual local area network featuring clean desktops and scanned servers. Settlements that were originally scheduled for November 18 were subsequently carried out on November 20, after the recovery exercise was completed on November 19, 2022.
Critical System Disruption and Impact Analysis
SEBI’s findings indicated a severe disruption across critical systems. Settlement processes experienced a complete disruption lasting 46 hours, while inter-depository transfers were affected for 54.5 hours. The regulator noted that this level of disruption had significant spillover impact because the normal functioning of CDSL systems is fundamental to the overall securities market settlement activities.The core focus of the regulatory findings centered on CDSL’s Active Directory Federation Services (ADFS) server. SEBI specified that the ADFS server, being an internet-facing application, should have been treated as a critical asset under the mandatory cybersecurity framework.
Technical Lapses Lead to Regulatory Penalty
The final root cause analysis report confirmed that the inadequately secured internet-accessible ADFS server was the primary source of the incident. This key piece of infrastructure had not undergone vulnerability assessment or penetration testing. Crucially, it had also not been integrated with essential monitoring systems like Security Information and Event Management (SIEM) and Privileged Identity Management (PIM).SEBI observed that these security gaps were exploited by the threat actor to gain access to CDSL's internal systems without triggering any immediate alerts for malicious activity. The regulator rejected the defense put forth by CDSL, which argued that the ADFS server was not critical because it did not host sensitive investor data or business applications.
Access Control and Security Monitoring Failures
The regulatory order also highlighted severe lapses in access control management within CDSL's environment. It was found that a domain admin account on the ADFS server possessed a weak password, making it susceptible to dictionary attacks. Furthermore, the password for one privileged account had been set to “Never Expire,” potentially prolonging the threat actor’s tenure within the system.The regulator pointed out that the PIM solution was improperly configured and was not in place to control or monitor directory services activities. This flaw allowed the threat actor to achieve lateral movement using privileged accounts unnoticed by the security team. The ADFS server's lack of integration with SIEM meant that logs were unavailable for thorough auditing and review post-incident.
Disclaimer: Due care and diligence have been taken in compiling and presenting news and market-related content. However, errors or omissions may arise despite such efforts.
The information provided is for general informational purposes only and does not constitute investment advice, a recommendation, or an offer to buy or sell any securities. Readers are advised to rely on their own assessment and judgment and consult appropriate financial advisers, if required, before taking any investment-related decisions.
Any views, opinions, or statements expressed, where applicable, are those of the respective analysts or experts and do not reflect the views of this website. The website has no association with such viewpoints and does not assume any responsibility for them.