News From Multiple Perspectives

SEBI imposes Rs 1 crore penalty on CDSL for 2022 malware attack

Published July 22, 2026 at 10:33 AM UTC

Authored by
Every article published on DirectionFreeNews undergoes editorial review by our editorial team. Our editors research publicly available information from multiple trusted news organizations, compare differing perspectives, verify key facts, and publish balanced summaries intended to help readers better understand important events. Our editorial process is designed to reduce editorial bias by considering multiple reputable sources rather than relying on a single viewpoint

The Securities and Exchange Board of India has imposed a penalty of Rs 1 crore on the Central Depository Services Limited for failing to adequately protect its systems during a 2022 malware attack. The market regulator found that the depository did not follow necessary cybersecurity protocols, which allowed the breach to occur. This action highlights the growing focus of Indian financial authorities on the digital resilience of market infrastructure.

In November 2022, CDSL reported a malware incident that affected some of its internal systems. While the company stated at the time that it had isolated the affected segments and initiated a forensic investigation, the regulator's subsequent probe revealed significant lapses in the company's security framework. The penalty serves as a formal recognition of these deficiencies.

CDSL acts as a critical pillar of the Indian stock market, holding securities in electronic form for millions of investors. Because it stores sensitive financial data, the regulator mandates strict adherence to cybersecurity guidelines to prevent unauthorized access or system outages. The failure to meet these standards poses a risk to the integrity of the entire market ecosystem.

Beyond the financial penalty, the order underscores the responsibility of market intermediaries to maintain robust defense mechanisms against evolving cyber threats. The regulator emphasized that the scale of operations at a depository requires a higher standard of care than standard corporate entities.

Investors and market participants should view this as a signal that the regulator is tightening its oversight of digital infrastructure. Moving forward, CDSL will likely face increased scrutiny regarding its technology audits and incident response plans. The company has not yet detailed its specific plans for upgrading its security architecture in response to this order.