The regulator, however, disposed of adjudication proceedings against the former Chief Information Security Officer Rajesh Nadkarni and former Chief Technology Officer Amit Mahajan without imposing any monetary penalty, holding that the alleged lapses could not be attributed to them individually.
The order stems from a malware attack on November 18, 2022, which disrupted several critical systems at CDSL.
In its 88-page order, the market regulator said CDSL failed to classify its internet-facing Active Directory Federation Services (ADFS) server as a critical asset, excluded it from vulnerability assessment and penetration testing (VAPT), and did not implement basic cybersecurity controls despite regulatory requirements.
The regulator noted that it had flagged these deficiencies to CDSL in August 2022, but the depository did not address them and instead relied on an earlier, deficient VAPT exercise.
SEBI also observed that attackers had gained access to CDSL’s servers as early as November 2021, nearly a year before the malware attack was detected in November 2022. It further pointed to policy deviations, including an administrator account with a password set to never expire, which remained unaddressed even after the COVID-19 situation had normalised.
According to the order, the malware attack infected 135 of 547 servers and 177 of 506 desktops and laptops, disrupting key depository operations, including settlement, pay-in/pay-out and pledge-related activities, on November 18, 2022.
“Critical systems, including the settlement process and inter-depository transfer, faced disruption for 46 hours and 54.5 hours, respectively. Thus, it is evident that the disruption at Noticee No. 1 had a major spillover impact as the settlement activities for the entire securities market were also dependent upon the normal functioning of CDSL systems,” SEBI noted.
On the role of the former CISO and CTO, SEBI said the classification of critical assets, approval of password policy deviations and VAPT-related decisions were institutional processes involving multiple levels of oversight, including CDSL’s Systems and Technology Committee (SCOT) and its board.
It noted that the list of critical assets was only a proposal until approved by the SCOT Committee and that the password policy deviation had been reviewed by relevant IT officials and approved in accordance with internal procedures during the Covid-19 period.
While determining the quantum of penalty, the regulator took into account the critical role played by depositories in maintaining market integrity and investor confidence, observing that cyber risks at such market infrastructure institutions have implications beyond the entity itself.
At the same time, SEBI said it had considered the remedial measures undertaken by CDSL after the malware attack as well as the financial disincentive of ₹10 lakh already imposed separately under its standard operating procedure for reporting cybersecurity incidents.
Accordingly, the regulator imposed a penalty of ₹90 lakh under the SEBI Act and ₹10 lakh under the Depositories Act on CDSL for failing to comply with various cybersecurity and cyber resilience requirements prescribed by the regulator.
The regulator directed CDSL to pay the penalty within 45 days.
