Remember November 2022, when CDSL had a malware attack and settlement activities came to a halt? SEBI has now imposed a ₹1 crore penalty.
According to SEBI’s 88-page order, the attackers had already gained access to CDSL’s systems in November 2021 and remained there for almost a year before the malware attack was detected. The regulator says an internet-facing ADFS server wasn’t classified as a critical system, so it wasn’t covered under vulnerability testing, privileged access management or security monitoring. There was also an administrator account with a password set to never expire, no two-factor authentication, relaxed account lockout policies, and multiple security alerts that were either ignored or not investigated.
SEBI’s conclusion is the impact was largely due to failures in implementing basic cybersecurity controls rather than the sophistication of the attack.
Everyone is busy selling the future while the backbone of the market feels stuck in the past. Brokers are in an arms race over AI, instant onboarding, smarter charts, and every new feature imaginable. Yet exchanges, depositories, and other market infrastructure often feel like they’re running on stone age tech and processes.
SEBI’s order doesn’t point to some Hollywood-style cyberattack. It points to basic cybersecurity lapses. That’s the worrying part. You can build the smartest trading app in the world, but if the infrastructure that settles trades and holds our securities can’t consistently get the fundamentals right, every shiny new feature is built on a weak foundation.