ProductsIntelligencePricingMethodologyContact
Cresthaven AnalyticsIntelligence Brief

India SEBI Brief

July 20, 2026·Securities and Exchange Board of India·APAC

SEBI issues adjudication order against CDSL for November 2022 malware attack on depository infrastructure

SEBI issued an adjudication order against Central Depository Services (India) Limited following a malware attack on its systems on November 18, 2022. The order concludes SEBI's formal enforcement proceeding against India's largest depository by registered beneficial owner accounts.

SEBI's adjudication order against CDSL establishes a live enforcement precedent for cybersecurity failures at market infrastructure institutions. Depositories, stock exchanges, and clearing corporations operating under SEBI's regime now face a documented enforcement record confirming that inadequate cyber-resilience is an adjudicable violation. The order's specific findings, penalty quantum, and cited regulatory provisions are material compliance inputs that require review of the full order text.

  • Formal Enforcement Conclusion Against a Market Infrastructure Institution: SEBI has closed its adjudication proceeding against CDSL, a systemically significant depository holding accounts for over 100 million beneficial owners. The order represents a formal regulatory finding on a cybersecurity failure at a core piece of Indian capital market infrastructure.
  • Cybersecurity Obligations Now Carry Demonstrated Enforcement Consequence: The proceeding confirms that SEBI treats cybersecurity failures at market infrastructure institutions as adjudicable violations. Depositories, stock exchanges, clearing corporations, and other market infrastructure institutions operating under SEBI's framework now have a live enforcement precedent against which their own cyber-resilience posture is measured.
  • The 2022 Incident Involved Isolation of CDSL Systems from Exchanges: The November 18, 2022 malware attack prompted CDSL to isolate its systems, temporarily disrupting connectivity with stock exchanges and depository participants. The adjudication order formalizes SEBI's assessment of CDSL's preparedness and response obligations under the applicable regulatory framework.
  • Penalty Quantum and Specific Findings Require Verification from the Full Order Text: The source release does not reproduce the operative findings, penalty amount, or specific rule violations cited in the order. Readers requiring the precise penalty figure, the regulatory provisions invoked, and the factual findings must access the full order at the SEBI enforcement portal.

- No prior SEBI adjudication order against a depository for a cybersecurity breach has been publicly identified. This is a first-in-kind enforcement action against this category of market infrastructure institution. - The order converts a 2022 operational incident into a formal enforcement record, establishing that cyber-resilience failures at depositories fall within SEBI's adjudicatory scope. - SEBI's 2023 cybersecurity and cyber-resilience framework for market infrastructure institutions, issued after the CDSL incident, now has a backward-looking enforcement anchor that reinforces its prospective obligations.

HIGH — This order introduces a first-in-kind enforcement precedent confirming SEBI's adjudicatory reach over cybersecurity failures at market infrastructure institutions, requiring all depositories, stock exchanges, and clearing corporations to assess their cyber-resilience posture against a live enforcement standard.

Monitor SEBI's enforcement portal for the full adjudication order text, including the penalty quantum, specific regulatory provisions cited, and factual findings, which constitute the operative compliance reference for this precedent.

SEBI (Depositories and Participants) Regulations, 2018; SEBI Circular SEBI/HO/MRD/MRD-PoD-1/P/CIR/2023/0169 (Cybersecurity and Cyber Resilience Framework for Market Infrastructure Institutions)

www.sebi.gov.in — Source ↗

This is a sample intelligence brief from Cresthaven Analytics. Live subscribers receive briefs like this on a daily or weekly cadence depending on tier.