On 20 July 2026, the Securities and Exchange Board of India (SEBI) issued an adjudication order against Central Depository Services India Limited (CDSL) concerning a malware attack that occurred on 18 November 2022. CDSL operates one of India's two securities depositories — the backbone of equity and debt settlement for all stock exchange transactions.
The order signals that SEBI holds critical financial infrastructure to heightened standards of information security, and any breach or inadequacy in cyber controls can trigger regulatory action, even months or years after the incident. For listed companies, traders and investment intermediaries, this ruling underscores that your counterparties — depositories, clearing corporations and custodians — are under strict SEBI supervision on security.
What SEBI found
CDSL suffered a malware attack on 18 November 2022. SEBI's Adjudication Officer examined whether CDSL's information security policies, systems and incident response procedures met the regulatory standards expected of a critical market infrastructure operator licensed and supervised under the Securities and Exchange Board of India Act, 1992, and the Depositories Act, 1996.
The order indicates SEBI's Adjudication Officer concluded that CDSL's existing cybersecurity controls were inadequate to prevent or mitigate the malware incident. The specific technical or procedural gaps are referenced in the order, establishing a factual basis for SEBI's direction to strengthen defences going forward.
SEBI's order directed CDSL to implement remedial measures to enhance its cybersecurity posture. The order is framed as a supervisory directive to a licensed depository operator — the primary aim is to prevent recurrence and protect the integrity of India's settlement infrastructure, not to impose punitive financial penalties.
A depository breach affects millions of investor accounts and trillions of rupees in securities value. SEBI's enforcement action emphasises that cybersecurity failures at market infrastructure level are regulatory violations, not merely operational matters, and will be treated as such under SEBI's enforcement authority.
This order carries three critical lessons for Indian intermediaries and market participants. First, if you are a custodian, clearing member, or depository participant, assume that SEBI will investigate any material cyber incident affecting securities or investor records — delay in disclosure or discovery of inadequate controls will aggravate the regulator's view. Second, cybersecurity is now explicitly a compliance obligation, not a best-practice recommendation. CDSL's experience shows that even large, well-known depositories cannot rely on operational continuity or historical market standing to shield them from scrutiny after a breach. Third, the 3+ year gap between the November 2022 attack and the July 2026 order illustrates that SEBI's enforcement action timeline for cyber matters can be lengthy; businesses should not assume that months of silence after an incident means the matter is closed. Vinayakam Consultants assists market intermediaries, custodians and listed companies in documenting their cyber incident response protocols, conducting tabletop exercises, and creating audit trails that demonstrate to SEBI that controls are not merely in place but tested and improving.
Your action checklist
- If you operate a depository, custodian or clearing function: document your information security policies against SEBI's regulatory framework (Depositories Act 1996, and any SEBI circulars on cybersecurity and business continuity) and commission an independent audit of controls at least annually.
- Establish a formal cyber incident response
Frequently asked questions
SEBI's Adjudication Officer issued corrective directions ordering CDSL to strengthen its cybersecurity controls and implement remedial measures to enhance its overall cybersecurity posture.
SEBI holds critical financial infrastructure operators like depositories to heightened standards of information security under the Securities and Exchange Board of India Act, 1992, and the Depositories Act, 1996.
The ruling underscores that counterparties—depositories, clearing corporations and custodians—are under strict SEBI supervision on security, emphasizing heightened cyber control expectations across the market ecosystem.