The Securities and Exchange Board of India (SEBI) has imposed a ₹1 crore penalty on the Central Depository Services (India) Limited (CDSL) for alleged cybersecurity and operational lapses, according to multiple reports. The action follows a malware incident that disrupts CDSL’s operations. SEBI’s order states that the depository did not adequately secure critical systems and that weaknesses in cybersecurity contributed to the incident. One report also notes that CDSL isolates systems from the market after the event, reflecting steps taken to manage the disruption.

The orders also highlight broader implications for cyber risk given the interconnected nature of depositories and their interdependency in the securities infrastructure ecosystem. While SEBI imposes the monetary penalty on CDSL, at least one report says no monetary penalty is levied on former top officials involved with the matter. The reports indicate SEBI’s focus is on compliance with cybersecurity and operational resilience expectations for depositories, given the potential impact of such failures on market functioning.