Case Overview
The adjudication proceedings were initiated against Central Depository Services (India) Limited (CDSL), its then Chief Information Security Officer Mr. Rajesh Nadkarni, and its then Chief Technology Officer Mr. Amit Mahajan concerning a malware attack that occurred on November 18, 2022.
The attack was discovered at 03:00 hours IST post completion of End of Day operations when several servers and end-user computers became inaccessible. CDSL isolated affected systems and disconnected its network to prevent spread. The recovery process involved creating a separate virtual local area network with clean systems, completed on November 19, 2022. Settlements scheduled for November 18 were executed on November 20, 2022.
SEBI's examination found that an inadequately secured internet-facing Active Directory Federation Services (ADFS) server hosted on Microsoft Azure cloud was the root cause. The threat actor gained access through an open Remote Desktop Protocol port using legitimate credentials of a privileged account (DLPADMIN) created in April 2021 with a weak password set to never expire. The attacker had persistent access since November 2021 but remained undetected until November 2022.
SEBI alleged multiple violations against CDSL including:
- Failure to identify and classify the ADFS server as a critical asset despite SEBI Circular dated May 20, 2022 mandating inclusion of all internet-facing systems
- Failure to perform vulnerability assessment and penetration testing (VAPT) on all critical assets including the ADFS server
- Inadequate access controls including non-enforcement of password policy, two-factor authentication, and account lockout policies
- Failure to integrate the ADFS server with Security Information and Event Management (SIEM) and Privileged Identity Management (PIM) solutions
- Failure to detect intrusions in real-time and monitor network logs
- Failure to declare disaster within 30 minutes and restore systems from disaster recovery site within 45 minutes as required
The examination found that 135 out of 547 servers and 177 out of 506 desktops/laptops were infected across primary and disaster recovery sites. Critical depository services including settlement processes (46 hours disruption), inter-depository transfers (54.5 hours disruption), corporate actions, margin pledges, and off-market transfers were affected.
Final Outcome
The Adjudicating Officer found CDSL guilty of multiple violations:
- Violation of clauses 1 and 5 of Part-D of Third Schedule read with regulation 17 of SEBI (Depositories and Participants) Regulations, 2018
- Violation of paragraphs 3(a), 3(b), 11, 12, 15-21, 35, 40, 42, 43, 45, 46 and 47 of Annexure A of SEBI Circular dated July 6, 2015 (as modified by SEBI Circular dated May 20, 2022)
- Violation of paragraphs 4.1, 4.2, 4.6, 5.1, 5.2 and 5.3 of SEBI Circular dated December 7, 2018
- Violation of paragraphs 4(c) and 4(e) of SEBI Circular dated March 22, 2021
CDSL was imposed a total penalty of ₹1 crore (₹90 lakh under Section 15HB of SEBI Act and ₹10 lakh under Section 19G of Depositories Act, 1996). The proceedings against Mr. Rajesh Nadkarni and Mr. Amit Mahajan were disposed of without any penalty due to insufficient evidence of personal culpability.
Topics: Cybersecurity Compliance, Market Infrastructure Regulation, Depository Operations