// 1 CRITICAL · 6 ZERO-DAY · 8 CVE · 9 EXPLOIT · 2 ADVISORY IN THE LAST 24H
India's securities regulator SEBI has fined Central Depository Services Limited (CDSL) ₹1 crore for cybersecurity lapses that enabled the November 2022 LockBit 3.0 ransomware attack. The July 20, 2026 order establishes a regulatory precedent: when technical gaps are systemic and documented, the incident is not an external event but the foreseeable result of uncorrected choices. CDSL, which handles roughly 70% of India's demat accounts, saw settlement halted for ~46 hours and inter-depository transfers blocked for over 54 hours. Proposed penalties against the former CISO and CTO were dropped; SEBI ruled the failure was institutional, not individual.

On July 20, 2026, SEBI Adjudicating Officer Jai Sebastian imposed a total penalty of ₹1 crore on Central Depository Services Limited (CDSL) for the severe cybersecurity deficiencies that enabled the November 18, 2022 LockBit 3.0 ransomware attack. The order sets a clear regulatory precedent: when technical failings are systemic and documented, the incident is not an external event but the foreseeable result of uncorrected choices.

CDSL manages approximately 70% of demat accounts in India. The disruption halted settlement activities for roughly 46 hours, with inter-depository transfers blocked for more than 54 hours, delivering a systemic impact across the Indian equity market. Monetary sanctions against former CISO Rajesh Nadkarni and former CTO Amit Mahajan were dropped: SEBI determined that primary responsibility rested with the entity, not individual executives.

Key Takeaways
  • SEBI fined CDSL ₹1 crore (₹90 lakh + ₹10 lakh) via order dated July 20, 2026 for violations of the SEBI Act and the Depositories Act.
  • The November 18, 2022 LockBit 3.0 attack disrupted settlement for ~46 hours and inter-depository transfers for over 54 hours.
  • The internet-facing ADFS server was not classified as a critical asset and was excluded from VAPT and SIEM monitoring; the domain admin account had a "Never Expire" password with no 2FA.
  • The attacker had access to CDSL servers since November 2021, nearly a year before detection, with 135 of 547 servers and 177 of 506 desktops infected, including Disaster Recovery Site systems.

The "Foreseeable Outcome": How SEBI Reconstructs the Causal Chain

The SEBI order does more than sanction the incident; it reconstructs the causal chain that made it possible. The internet-exposed ADFS (Active Directory Federation Services) server was not classified as a critical asset by CDSL. That decision kept it out of the Vulnerability Assessment and Penetration Testing (VAPT) program and SIEM monitoring. SEBI had updated its relevant circular in May 2022; CDSL retained the classification despite the regulatory change.

On that same server, the domain administrator account operated with a password set to "Never Expire" and without 2FA enabled. According to the order as reported by sources, SEBI had already flagged the deficiencies in August 2022, but remediation was not implemented before the attack. The Adjudicating Officer explicitly rejected the argument of corporate discretion in asset classification: the choice to exclude ADFS from the protection perimeter was deemed an unjustified deviation.

"On consideration of the aforesaid, it becomes evident that the malware attack was the foreseeable outcome of lapses that had built up over time, which, inter alia, included unwarranted policy deviations, unimplemented regulatory directions, absence of the cybersecurity measures on ADFS server and a failure to re-audit notwithstanding a specific direction"
— SEBI Adjudicating Officer Jai Sebastian, order dated 20/07/2026

A Year of Dwell Time and the Disaster Recovery Failure

Forensic reconstruction documents that the attacker had access to CDSL servers since November 2021, nearly a year before the attack was detected. This aligns the incident with the category of long-persistence pre-ransomware attacks, where initial access is consolidated before cryptographic payload deployment.

At the time of the attack, 135 of 547 servers and 177 of 506 corporate desktops/laptops were infected. The most systemically significant finding is that the malware also compromised the Disaster Recovery Site (DRS) systems. The Adjudicating Officer explicitly rejected DRS contamination as a valid defense: "the contamination of DRS cannot be accepted as a valid defence."

CDSL did not declare the disaster within the 30 minutes required by the regulatory framework, nor did it restore operations within the subsequent 45 minutes. With the DRS already compromised, the disaster recovery procedure could not be activated within the mandated timeframes. The settlement scheduled for November 18, 2022 was only completed on November 20.

Why Individual Penalties Were Dropped

Proposed monetary sanctions against former CISO Rajesh Nadkarni and former CTO Amit Mahajan were dropped. This is significant for regulatory interpretation: SEBI ruled that institutional responsibilities prevail over individual ones when governance processes are deficient, while also establishing that process robustness is a non-derogable obligation of the entity.

The logic is that a CISO or CTO cannot be held responsible if the governance framework does not support control implementation. At the same time, the entity cannot offload onto individual executives a responsibility that stems from systemic choices in classification, budget, or prioritization. Dropping the individual penalties reinforces the message: the fine is institutional because the failure was institutional.

Implications for Indian Market Infrastructure Institutions

CDSL is classified as a Market Infrastructure Institution (MII) under the Indian regulatory framework. The SEBI order of July 20, 2026 raises the bar for this perimeter: asset classification, implementation of basic controls such as password policies and 2FA, SIEM monitoring, and adherence to Recovery Time Objectives (RTO) are non-derogable obligations.

The "foreseeable outcome" concept used by the Adjudicating Officer changes the risk calculus for CISOs at financial institutions. It is no longer sufficient to demonstrate post-incident corrective actions; they must document that controls were operational before the event and that regulatory directions were implemented within required timeframes. Failure to remediate flagged deficiencies becomes an aggravating factor, not a mitigating one.

For other Indian MIIs and market infrastructure operators in jurisdictions with analogous regulators, the CDSL case provides an enforcement model that directly links pre-existing technical violations to institutional liability. The message for boards is that cybersecurity risk is no longer manageable as compliance box-ticking: the persistence of gaps over time builds liability for the next incident.

Why It Matters

The SEBI order does not specify technical remedial measures CDSL must implement, nor does it detail the exact content of the order beyond the penalties and violations reported by secondary sources. The record does not document whether CDSL has appealed the decision or the status of any legal proceedings.

The sources do not specify the full nature of data exposed or compromised, beyond the operational impact on settlement systems. CDSL initially stated there was no "compromise of confidential information"; available sources neither confirm nor definitively refute this claim. The identity of the attacker or specific LockBit affiliate is not stated in the sources, nor is any ransom demand or payment mentioned.

The case remains significant for its regulatory architecture: SEBI built an explicit bridge between pre-existing governance gaps and liability for the incident, using legal language that other market regulators could adopt. For CISOs, the precedent is that downstream remediation documentation does not erase upstream implementation failures.

Sources

Information verified against cited sources as of publication.

Sources


Sources and references
  1. livelawbiz.com
  2. medianama.com
  3. cnbctv18.com
  4. fortuneindia.com