SEBI adjudication order on CDSL November 2022 malware attack
SEBI issued an adjudication order in the matter of the Central Depository Services India Limited (CDSL) malware attack of 18 November 2022.
SEBI has adjudicated the 2022 CDSL malware incident, reinforcing supervisory expectations on cyber resilience for critical market infrastructure. The order signals that lapses in cybersecurity governance at depositories will attract enforcement, raising the bar for MIIs and their participants on incident detection, reporting, and remediation.
Sets precedent for enforcement against MIIs on cyber failings; participants and custodians relying on depositories face indirect operational and reputational exposure.
Action Required
Review depository and market infrastructure cyber incident response, patching, and reporting controls against SEBI's adjudicatory findings.
First-order enforcement against a core Indian market infrastructure for a cyber incident; shapes future cyber supervisory expectations.
Reassess reliance on CDSL as a critical service provider. Validate cyber incident notification SLAs, review third-party risk assessments of depositories, and align internal cyber controls with SEBI's evolving expectations for MIIs.
“SEBI adjudication order in the matter of Central Depository Services India Limited malware attack on November 18, 2022.”