However, the regulator concluded adjudication proceedings against the former Chief Information Security Officer Rajesh Nadkarni and former Chief Technology Officer Amit Mahajan without imposing any financial penalties, clarifying that the alleged shortcomings could not be solely attributed to them.
The order originates from a malware breach that occurred on November 18, 2022, affecting multiple critical systems at CDSL.
In a comprehensive 88-page order, the market regulator stated that CDSL failed to designate its internet-facing Active Directory Federation Services (ADFS) server as a critical asset, omitted it from vulnerability assessment and penetration testing (VAPT), and neglected to implement fundamental cybersecurity measures despite existing regulatory obligations.
SEBI pointed out that these deficiencies had been highlighted to CDSL in August 2022, but the depository failed to address them and instead relied on a prior inadequate VAPT assessment.
It was also noted that unauthorized access to CDSL’s servers began as early as November 2021, nearly a year before the malware incident was detected in November 2022. The report highlighted policy deviations, including an administrator account with a password set to never expire, which remained uncorrected even after the COVID-19 situation improved.
According to the order, the malware attack compromised 135 out of 547 servers and 177 of 506 desktops and laptops, interrupting crucial depository functions such as settlement, pay-in/pay-out, and pledge-related operations on November 18, 2022.
“Key systems like the settlement process and inter-depository transfer experienced disruptions for 46 hours and 54.5 hours, respectively. Therefore, it’s clear that the disruption at Noticee No. 1 significantly affected the settlement functions across the entire securities market,” SEBI remarked.
Regarding the responsibilities of the former CISO and CTO, SEBI noted that the classification of critical assets, approval of deviations in password policy, and VAPT-related decisions were organizational procedures involving multiple oversight tiers, including CDSL’s Systems and Technology Committee (SCOT) and its board.
The regulator clarified that the classification of critical assets was only provisional until ratified by the SCOT Committee and that the password policy deviations were subject to review by relevant IT personnel and approved according to internal procedures during the pandemic.
In determining the penalty amount, the regulator acknowledged the essential role depositories play in upholding market integrity and ensuring investor confidence, emphasizing that cyber risks affecting such market infrastructure institutions have repercussions beyond the organization itself.
Simultaneously, SEBI factored in the corrective actions taken by CDSL following the malware incident and the financial penalty of ₹10 lakh that had already been imposed separately under its standard operating procedures for reporting cybersecurity issues.
Consequently, the regulator imposed a total fine of ₹90 lakh under the SEBI Act and ₹10 lakh under the Depositories Act on CDSL for failing to adhere to various cybersecurity and cyber resilience standards mandated by the regulator.
SEBI directed CDSL to remit the penalty within 45 days.