What SEBI’s CDSL order says about the assets you forgot to list
One internet-facing server left off the critical-asset list, and therefore out of testing and monitoring. A ₹1 crore penalty, a compromised disaster recovery site, and what it means for asset inventories.
What happened
CDSL is one of India’s two depositories, holding securities in dematerialised form for the whole market. On 18 November 2022 it detected malware on internal machines after completing end-of-day operations, isolated the affected systems and disconnected itself from other capital market participants to contain it. Settlement was deferred and completed on 20 November. In a market where the depository is shared infrastructure, an interruption of that kind is a systemic event rather than a company-level one.
The scale only became clear later. The order records that the LockBit malware encrypted systems across the head office, the data centre and the disaster recovery site, infecting 135 of 547 servers and 177 of 506 desktops and laptops. SEBI also notes that attackers had access to CDSL’s environment as early as November 2021 — roughly a year before anything was detected.
The adjudication concluded on 20 July 2026, with Adjudicating Officer Jai Sebastian imposing a combined penalty of ₹1 crore — ₹90 lakh under section 15HB of the SEBI Act and ₹10 lakh under section 19G of the Depositories Act — for breaches of the SEBI (Depositories and Participants) Regulations, 2018 and the associated cyber security framework circulars.
What SEBI actually found
The order is more interesting than the headline. Its findings fall into two groups: a cluster about scope and classification, and a separate one about whether the depository could recover once the attack landed.
| Finding | Why it mattered |
|---|---|
| An internet-facing ADFS server was not classified as a critical asset following a May 2022 circular update | Classification is what pulls a system into the mandatory regime. Left out, it fell outside audit and monitoring obligations |
| Vulnerability assessment and penetration testing did not cover all critical assets and infrastructure components | Testing was performed, but against a scope derived from the same incomplete list |
| Weak access controls on the server, including a “Never Expire” password on a domain administrator account | A basic hygiene failure on precisely the asset that nobody was reviewing |
| Inadequate monitoring of the affected systems | Detection depends on coverage, and coverage followed the same classification decision |
| Failure to declare a disaster within 30 minutes and restore operations within 45 minutes of that declaration | A breach of the prescribed business continuity timelines, independent of the classification failure |
| Failure to re-audit despite a specific direction, and cyber deficiencies flagged in August 2022 left unaddressed | The regulator had already pointed at the problem months before the attack |
The disaster recovery finding deserves separate attention, because it is the one a reader looking only for the inventory lesson will miss. CDSL argued it could not fail over: the primary Active Directory had already been compromised, and moving workloads risked infecting the recovery environment. The adjudicating officer accepted that the decision “may appear justified in the present factual context” — and held it made no difference to the breach, because forensic evidence showed the ransomware had already reached the disaster recovery infrastructure. A recovery site that shares a trust domain with the thing it is recovering from is not a recovery site. The defence was rejected as “bereft of any merit”.
SEBI’s reading of its own 2022 mandate is the pivot of the order: the requirement was intentionally expansive, framed so that all internet-facing systems be treated as critical assets. CDSL had applied discretion where the regulator had intended a rule. The testing, monitoring and configuration failures — untested, unmonitored, weakly configured — all followed from that single upstream judgement.
It would be too neat to say the classification decision explains everything, and the order does not say so. SEBI’s own summary is that the attack was “the foreseeable outcome of lapses that had built up over time, which, inter alia, included unwarranted policy deviations, unimplemented regulatory directions, absence of the cybersecurity measures on ADFS server and a failure to re-audit notwithstanding a specific direction”. The word doing the work there is foreseeable. This was not a sophisticated adversary defeating a well-run programme; it was a set of known gaps, some of them already pointed out by the regulator, left open long enough for someone to walk through one.
Institutional, not individual
Proceedings were also initiated against the security officers, and this is the part most commonly reported wrongly. SEBI disposed of the charges against them, holding that the failures were institutional rather than individual. No monetary penalty was imposed on the individuals.
That is a more demanding outcome for a board than the alternative, not a softer one. A finding that names an individual permits a comforting story: the wrong person held the role. A finding that the failure was institutional says the organisation’s process for deciding what counts as critical was itself the defect — and that process is a governance artefact, owned above the security function.
Why asset inventories fail in this specific way
Nothing about this requires incompetence. Inventories drift for structural reasons, and the drift is always in the same direction — toward under-inclusion.
- Classification is a judgement made once, under time pressure. A system is categorised when it is commissioned. The categorisation is rarely revisited when the system’s exposure changes, and almost never when a regulation changes underneath it — which is precisely the May 2022 circular case.
- Scope inherits from the list. Testing, monitoring and audit all take their scope from the inventory. An omission therefore propagates silently into every downstream control, and each of those controls will report success.
- Nothing in the process looks from the outside. Every artefact — the register, the VAPT scope, the monitoring configuration — is generated from internal knowledge. An attacker enumerates what is actually reachable. The two views diverge, and nothing in a conventional programme measures the gap.
This is the failure mode the order should be read for, and it generalises well beyond depositories: a control programme that is complete with respect to its own inventory can be arbitrarily incomplete with respect to reality.
What would have caught it
An outside-in measurement has one structural advantage here, and it is worth stating precisely rather than expansively: it does not take its scope from your inventory.
Attribution-based external measurement enumerates the internet-facing estate associated with an organisation from public signals — domains, certificates, address allocations, hosting relationships — and assesses what it finds. An internet-facing ADFS server is exactly the class of asset that appears in that view. It resolves publicly, presents a certificate, and answers on the open internet. Its absence from an internal register has no bearing on whether it shows up. A security rating is built from that enumeration, which is why the discrepancy between an attributed estate and an asset register is often the most useful output of a first assessment.
The honest limits, since this is a case where overclaiming would be easy:
- External measurement would have surfaced the server as an attributed, internet-facing asset and graded its observable configuration. It would not have known that CDSL’s register omitted it — that comparison is something a person has to make.
- A “Never Expire” password on a domain administrator account is not externally observable. No outside-in tool would have found it. What outside-in visibility does is put the host on the list of things somebody must look at.
- It is not a substitute for VAPT. It defines the surface honestly; remediation and testing still do the work.
- It has nothing to say about the recovery failure. Whether a disaster recovery site shares a trust domain with production, and whether it can be invoked within the prescribed window, are internal architecture questions. Half this order is about something no external measurement can see, and it would be dishonest to imply otherwise.
Put plainly: the control that failed at CDSL was not a scanner or a firewall. It was the list. Any assurance activity whose scope is derived from that list inherits its blind spots, and the only reliable corrective is a view of the estate that was not drawn from the same source. For Indian regulated entities, the same reasoning now runs through the RBI and SEBI expectations set out in what boards must evidence.
Findings, quoted passages, penalty amounts and infection counts are from the SEBI adjudication order of 20 July 2026 in the matter of Central Depository Services (India) Limited, by Adjudicating Officer Jai Sebastian — ₹90 lakh under section 15HB of the SEBI Act, 1992 and ₹10 lakh under section 19G of the Depositories Act, 1996. The order should be read in full before relying on any characterisation of it, including this one. This page is commentary on a published enforcement action, not legal advice, and makes no assessment of CDSL’s current security posture — the order itself records that extensive remedial measures were taken after the incident. External attribution and measurement referenced here are Bitsight capabilities; BitScore Cybertech LLP is an authorised Bitsight partner.