The short answer

On 20 July 2026, the Securities and Exchange Board of India (SEBI) issued an adjudication order against Central Depository Services India Limited (CDSL) concerning a malware attack that occurred on 18 November 2022. CDSL operates one of India's two securities depositories — the backbone of equity and debt settlement for all stock exchange transactions.

The order signals that SEBI holds critical financial infrastructure to heightened standards of information security, and any breach or inadequacy in cyber controls can trigger regulatory action, even months or years after the incident. For listed companies, traders and investment intermediaries, this ruling underscores that your counterparties — depositories, clearing corporations and custodians — are under strict SEBI supervision on security.

What SEBI found

Malware Incident Triggered Regulatory Review

CDSL suffered a malware attack on 18 November 2022. SEBI's Adjudication Officer examined whether CDSL's information security policies, systems and incident response procedures met the regulatory standards expected of a critical market infrastructure operator licensed and supervised under the Securities and Exchange Board of India Act, 1992, and the Depositories Act, 1996.

SEBI Found Control Deficiencies

The order indicates SEBI's Adjudication Officer concluded that CDSL's existing cybersecurity controls were inadequate to prevent or mitigate the malware incident. The specific technical or procedural gaps are referenced in the order, establishing a factual basis for SEBI's direction to strengthen defences going forward.

Corrective Directions Issued, Not Monetary Penalty

SEBI's order directed CDSL to implement remedial measures to enhance its cybersecurity posture. The order is framed as a supervisory directive to a licensed depository operator — the primary aim is to prevent recurrence and protect the integrity of India's settlement infrastructure, not to impose punitive financial penalties.

Systemic Risk in India's Financial Markets

A depository breach affects millions of investor accounts and trillions of rupees in securities value. SEBI's enforcement action emphasises that cybersecurity failures at market infrastructure level are regulatory violations, not merely operational matters, and will be treated as such under SEBI's enforcement authority.

◆ What it means for you — the Vinayakam view

This order carries three critical lessons for Indian intermediaries and market participants. First, if you are a custodian, clearing member, or depository participant, assume that SEBI will investigate any material cyber incident affecting securities or investor records — delay in disclosure or discovery of inadequate controls will aggravate the regulator's view. Second, cybersecurity is now explicitly a compliance obligation, not a best-practice recommendation. CDSL's experience shows that even large, well-known depositories cannot rely on operational continuity or historical market standing to shield them from scrutiny after a breach. Third, the 3+ year gap between the November 2022 attack and the July 2026 order illustrates that SEBI's enforcement action timeline for cyber matters can be lengthy; businesses should not assume that months of silence after an incident means the matter is closed. Vinayakam Consultants assists market intermediaries, custodians and listed companies in documenting their cyber incident response protocols, conducting tabletop exercises, and creating audit trails that demonstrate to SEBI that controls are not merely in place but tested and improving.

Your action checklist

  • If you operate a depository, custodian or clearing function: document your information security policies against SEBI's regulatory framework (Depositories Act 1996, and any SEBI circulars on cybersecurity and business continuity) and commission an independent audit of controls at least annually.
  • Establish a formal cyber incident response

Frequently asked questions

What did SEBI order CDSL to do after the 2022 malware attack?

SEBI's Adjudication Officer issued corrective directions ordering CDSL to strengthen its cybersecurity controls and implement remedial measures to enhance its overall cybersecurity posture.

What are the regulatory standards SEBI applies to critical market infrastructure?

SEBI holds critical financial infrastructure operators like depositories to heightened standards of information security under the Securities and Exchange Board of India Act, 1992, and the Depositories Act, 1996.

How does the CDSL cybersecurity ruling affect listed companies and traders?

The ruling underscores that counterparties—depositories, clearing corporations and custodians—are under strict SEBI supervision on security, emphasizing heightened cyber control expectations across the market ecosystem.

SEBICybersecurityMarket InfrastructureDepositories
Need help acting on this?
Talk to an advisor