The Securities and Exchange Board of India (SEBI) has imposed a total penalty of Rs 1 crore on Central Depository Services (India) Limited (CDSL) for multiple cybersecurity and regulatory lapses that culminated in the malware attack on its systems in November 2022.
In an order issued on July 20, SEBI held that CDSL failed to classify a critical internet-facing server as a critical asset, implement mandatory cybersecurity controls, and adequately monitor its systems, allowing the attack to compromise key depository operations. However, the regulator dropped monetary penalty proceedings against CDSL’s former Chief Information Security Officer (CISO) and Chief Technology Officer (CTO).
Context: CDSL disclosed on November 18, 2022 that it had detected malware on a few internal machines after completing its end-of-day operations. The depository isolated the affected systems and disconnected itself from other capital market participants to contain the attack, resulting in a delay to securities settlements. CDSL said its initial assessment found no compromise of confidential information or investor data. It reported the incident to the relevant authorities and worked with cybersecurity advisers to investigate its impact.
Two days later, the company announced that it had restored its systems following validation checks and resumed normal operations. The deferred settlement was completed on November 20.
What SEBI found: While the order acknowledged that the depository had taken extensive remedial measures after the incident, it repeatedly stressed that post-incident corrective action could not excuse earlier regulatory failures.
- ADFS server was a critical asset that should have been protected
- SEBI found that the internet-facing Active Directory Federation Services (ADFS) server should have been classified as a critical asset and subjected to the same cybersecurity controls as other critical infrastructure. Because CDSL did not classify it as such, it also failed to identify threats and vulnerabilities associated with the server and did not deploy adequate security controls. The adjudicating officer rejected CDSL’s argument that the May 2022 circular allowed discretion in identifying critical assets, concluding that the server fell within the expanded scope of the revised cybersecurity framework.
- Critical systems were excluded from vulnerability testing
- The order also held that CDSL failed to perform vulnerability assessment and penetration testing (VAPT) on all critical infrastructure components. Although the depository carried out VAPT exercises in mid-2022, the ADFS server was excluded despite being internet-facing. The adjudicating officer concluded that this omission meant CDSL had failed to comply with SEBI’s requirement that VAPT cover “all critical assets and infrastructure components like servers, networking systems and security devices.”
- Disaster recovery framework failed during the malware…
Source link
Disclaimer
We strive to uphold the highest ethical standards in all of our reporting and coverage. We blogs.grocliq.com want to be transparent with our readers about any potential conflicts of interest that may arise in our work. It’s possible that some of the investors we feature may have connections to other businesses, including competitors or companies we write about. However, we want to assure our readers that this will not have any impact on the integrity or impartiality of our reporting. We are committed to delivering accurate, unbiased news and information to our audience, and we will continue to uphold our ethics and principles in all of our work. Thank you for your trust and support.
Website Upgradation is going on for any glitch kindly connect at [email protected]