On the Morning of 18th November 2022, the SEBI-registered Central Depository Services (India) Limited (CDSL) operations team discovered that several of their servers and end-user computers were inaccessible.
The malware had already spread. CDSL isolated its systems, disconnected the network, and began damage assessment. The malware was identified as LockBit 3.0 ransomware, one of the most active and destructive ransomware families operating globally at the time.
The consequence for India’s securities market was immediate and significant. Settlement activities remained disrupted for approximately 46 hours while inter-depository transfers were affected for over 54 hours, necessitating the completion of the settlement scheduled for November 18 on November 20. MEDIANAMA
CDSL holds demat accounts for millions of Indian retail investors. Every transaction that should have settled on November 18 sat in uncertainty for two days. The entire securities market settlement chain, which runs on the assumption that clearing and settlement infrastructure is always available, had that assumption removed.
On July 20, 2026, nearly four years after the attack, SEBI’s adjudicating officer issued the enforcement order. SEBI imposed a total penalty of ₹1 crore on CDSL after finding that its failure to implement prescribed cybersecurity measures enabled the 2022 LockBit ransomware attack.
The penalty amount is not the most important thing in this order. The finding is.
“The malware attack was a foreseeable outcome of lapses built up over time, including unwarranted policy deviations, unimplemented regulatory directions, and the absence of certain cybersecurity measures.” MEDIANAMA
That sentence is the most consequential thing SEBI has written about cybersecurity in India’s capital markets. Not because of what it says about CDSL, but because of the standard it establishes for every other regulated entity operating in India’s financial infrastructure.
The Attacker Had Been Inside for One Year
This is the detail that should land hardest for every CISO and IT head in India’s capital markets.
The attacker had gained access to the servers of CDSL in November 2021, while the attack was discovered in November 2022. MEDIANAMA
Three hundred and sixty-five days. The attacker was inside CDSL’s network for a full year before the ransomware was activated. For twelve months, CDSL’s monitoring systems, its security reviews, its compliance exercises, its audit processes — none of them surfaced a persistent, active intruder operating inside the network.
The six-hour CERT-In notification window begins when detection occurs. But detection can be measured in days, months, or as the CDSL case demonstrates, years. The six-hour clock started on November 18, 2022. The actual exposure had already been running since November 2021.
This dwell time is not unusual in the global ransomware landscape. Mandiant’s M-Trends research consistently shows median attacker dwell times of days or weeks before detection. For critical infrastructure that has become an attractive ransomware target, the pattern of gaining access early and waiting for the right moment to activate is well documented. What the CDSL case adds to that global pattern is the specific regulatory consequence: when the dwell time is long because the detection capability was insufficient, and that insufficiency is traceable to known, unaddressed security gaps, SEBI will call the eventual attack foreseeable.
The Four Failures SEBI Named
SEBI’s adjudicating officer identified specific failures that individually and collectively contributed to the breach. Reading them together, what emerges is not a picture of a sophisticated attack that defeated strong defences. It is a picture of accumulated, known, documented gaps that were not addressed.
- Failure 1: The ADFS server was not classified as critical.
SEBI found that the internet-facing Active Directory Federation Services server should have been classified as a critical asset and subjected to the same cybersecurity controls as other critical infrastructure. Because CDSL did not classify it as such, it also failed to identify threats and vulnerabilities associated with the server and did not deploy adequate security controls. ScanX
Active Directory Federation Services manages identity federation and single sign-on. It is the system that tells other systems which users are authenticated and what they are authorised to do. An internet-facing ADFS server is, by its nature, a high-value target. Classifying it as non-critical was not a subtle judgment call. It was a documented deviation from what the framework required.
- Failure 2: VAPT excluded the most exposed system.
CDSL carried out VAPT exercises in mid-2022, but the ADFS server was excluded despite being internet-facing. The adjudicating officer concluded that this omission meant CDSL had failed to comply with SEBI’s requirement that VAPT cover all critical assets and infrastructure components like servers, networking systems, and security devices. ScanX
A VAPT that excludes the system that will become the attack entry point is not a VAPT. It is documentation of a VAPT with a gap that happens to coincide exactly with the breach vector. SEBI’s adjudicating officer declined to accept CDSL’s argument that the May 2022 circular allowed discretion in identifying critical assets, concluding that SEBI’s mandate was intentionally expansive to ensure all internet-facing systems were treated as critical.
- Failure 3: An admin account with a password set to never expire.
CDSL created an admin account in 2021 whose password was set to never expire, and its relaxation regarding the lockout threshold to three failed attempts was not addressed until the malware attack. MEDIANAMA
An administrative account with a non-expiring password is a known, documented security risk. Every cybersecurity framework, every VAPT methodology, every security audit checklist flags non-expiring passwords on privileged accounts as a high-priority finding. This was not an obscure misconfiguration that required specialist expertise to identify. It was a standard password policy gap that sat unaddressed from 2021 until the ransomware attack made it impossible to ignore.
- Failure 4: The disaster recovery site was already infected.
CDSL argued that it could not shift operations to the DR site because the primary Active Directory system had already been compromised and migrating workloads risked infecting the recovery environment. However, the adjudicating officer relied on forensic evidence showing that the ransomware had already spread to the recovery environment, suggesting DR planning was inadequate. ScanX
The disaster recovery framework failed during the disaster it was built to address. This is the most fundamental DR failure there is: a recovery environment that cannot be used because it shares the same vulnerability as the primary environment. The separation between primary and DR systems that is the entire point of DR architecture had not been maintained in a way that protected against the specific threat that materialised.
The One Phrase That Changes Everything
SEBI’s language in this order is precise, and its most important word is foreseeable.
A foreseeable outcome, in regulatory and legal terms, is one that a reasonable party in the same position could have anticipated and prevented. When SEBI describes the CDSL ransomware attack as a foreseeable outcome of accumulated lapses, it is establishing that CDSL was in possession of the information that should have led it to prevent the attack.
The ADFS server was identified as internet-facing. The admin account’s non-expiring password was a known policy deviation. The VAPT in 2022 happened before the attack was discovered. The DR architecture decisions were made internally. None of these failures were imposed on CDSL from outside. They were the result of internal decisions, deviations, and omissions.
SEBI also explicitly rejected the argument that post-incident remediation could excuse prior failures. While the order acknowledged that CDSL had taken extensive remedial measures after the incident, it repeatedly stressed that post-incident corrective action could not excuse earlier regulatory failures. ScanX
This is the sentence that should be read most carefully by compliance and legal teams across India’s capital markets. Fixing things after a breach is good. It does not reverse the regulatory finding that the breach was foreseeable. The regulatory clock runs from the moment the gap existed, not from the moment it was exploited.
What Foreseeable Means as a Legal Standard in 2026
The CDSL adjudication order has established, through a formal regulatory proceeding, a specific standard of assessment for cybersecurity failures at Indian capital market institutions.
The questions SEBI will now ask in any cybersecurity enforcement proceeding are the same questions the adjudicating officer asked about CDSL.
Were the prescribed regulatory controls in place? Not approximately in place. Not substantially compliant. Specifically, for each enumerated requirement, were the controls implemented as prescribed?
Were any deviations from prescribed controls documented and addressed? Or did they accumulate over time as policy deviations that nobody resolved?
Did the VAPT cover every required system? Not a broad selection. Every system the framework required.
Was the asset inventory current and accurate in its classification of critical assets? Were internet-facing systems treated as critical assets regardless of business-operational judgments about their importance?
Was the disaster recovery framework tested in a way that would have revealed the specific failure it experienced?
The CDSL order is not guidance for how to avoid a SEBI investigation. It is a description of what SEBI found in its investigation and why it imposed a penalty. The same framework will be applied to the next investigation.
The Market Infrastructure Risk Nobody Talked About Enough in 2022
SEBI noted that the interconnectedness and interdependency of the depositories pose broader implications for cyber risk. MEDIANAMA
This observation matters beyond CDSL. India’s capital market infrastructure is deeply interconnected. Exchanges, depositories, clearing corporations, registrars and transfer agents, and the payment systems that settle securities transactions all depend on each other’s availability. A 46-hour settlement disruption at CDSL is not an isolated operational problem. It is a system-wide event that affects every participant in India’s securities market.
LockBit 3.0 did not target CDSL because of a specific intelligence assessment about CDSL’s importance. LockBit operates industrially, targeting any organisation with the combination of valuable data, poor segmentation, and willingness to pay or sufficient disruption potential to generate a ransom return. CDSL met that profile, and the lapses that made it vulnerable were the same lapses that make dozens of other capital market participants vulnerable today.
The SEBI order’s explicit observation about interconnectedness is a signal. Regulators are aware that cybersecurity failures at systemically important institutions have consequences that extend far beyond the immediate victim. That awareness will translate into escalating supervisory attention on the cybersecurity posture of market infrastructure institutions.
What Every SEBI-Regulated Entity Must Do
The CDSL order identifies specific gaps that led to regulatory consequences. For every SEBI-regulated entity reading this, these are the operational priorities the order establishes.
- Classify every internet-facing system as a critical asset, regardless of business function assessment. SEBI’s adjudicating officer explicitly rejected the argument that business-operational judgments about importance should determine critical asset classification. If a system faces the internet, it is critical for cybersecurity purposes. Asset inventories and classification frameworks must reflect this.
- Include every critical system in VAPT scope, and document why any system was excluded. A VAPT scope that excludes internet-facing systems is not VAPT compliance. Before any VAPT exercise, confirm that every internet-facing server, every authentication system, every critical API endpoint, and every network device is in scope. Any exclusion requires documented justification that can withstand regulatory scrutiny.
- Audit every privileged account for password policy compliance. Non-expiring passwords on administrative accounts are a documented, well-known risk that SEBI will treat as evidence of policy deviation. Run an immediate audit. Identify every account with a non-expiring password. Remediate within a defined window. Document the exercise and its completion.
- Test whether the DR site is actually separate from the primary environment against the threat scenarios relevant to your organisation. For ransomware specifically, the test must confirm that ransomware which has compromised the primary Active Directory cannot propagate to the DR environment during a failover attempt. If the answer is uncertain, the DR architecture needs assessment.
- Document every deviation from prescribed regulatory controls and track its resolution. The CDSL order repeatedly returns to the concept of unaddressed policy deviations. A deviation that is documented, escalated, and resolved is a different regulatory finding from a deviation that accumulated over time without attention. Build a deviation register. Track resolution. Report to the Board.
- Do not rely on post-incident remediation as a compliance defence. SEBI made clear that CDSL’s extensive remediation after the 2022 attack did not change the finding that the attack was foreseeable from pre-incident lapses. Compliance must be demonstrated before an incident, not after one.
- Commission an independent gap assessment against SEBI’s cybersecurity circular requirements. The CDSL case demonstrates that SEBI’s examination of cybersecurity frameworks looks at specific, enumerated requirements, not general posture. Conduct a systematic assessment of your entity’s compliance against each requirement of the applicable SEBI cybersecurity circular, document the gaps, and build a remediation plan with dates and ownership.
The Timing No One Should Miss
SEBI issued this adjudication order on July 20, 2026. The RBI’s new Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions came into effect on July 31, 2026. Both arrived within eleven days of each other.
The two events are not coordinated, but they are directionally consistent. India’s two most significant financial regulators have both escalated their cybersecurity expectations for regulated entities in July 2026, one through enforcement and one through prescriptive rules.
For any CTO or CISO who has been treating cybersecurity compliance as a periodic exercise, July 2026 is the clearest possible signal that the regulatory environment has moved on. SEBI has now demonstrated that it will investigate cybersecurity incidents, apply a foreseeable outcome standard, and impose penalties. RBI has established a mandatory, prescriptive framework that banks must comply with paragraph by paragraph.
The question every regulated entity in India needs to answer is not whether they will face regulatory scrutiny of their cybersecurity posture. They will. The question is what their current posture will look like when that scrutiny arrives.
Final Thought
CDSL is not a careless organisation. It holds the demat accounts of millions of Indian investors. It processes tens of thousands of transactions every working day. The people who ran it in 2021 and 2022 were not indifferent to security.
What the SEBI order describes is something more familiar and more uncomfortable than carelessness. It describes accumulated drift. An admin account created in 2021 with a non-expiring password. A server classified as non-critical because the business team assessed it that way. A VAPT scope that reflected that classification. A DR architecture that had not been stress-tested against the specific threat it needed to handle.
Each deviation was arguably defensible when it was made. Together, across the timeline SEBI examined, they were foreseeable.
That word is the most important thing this order contributes to India’s cybersecurity governance landscape. Not the penalty. Not even the specific findings. The standard.
When SEBI investigators examine a cybersecurity incident at any regulated entity, they will now be asking: was this foreseeable? Were there accumulated deviations from prescribed controls? Were there known gaps that the organisation chose not to address?
If the answers are yes, the outcome is no longer uncertain. The CDSL order has made the regulatory consequence of that answer visible.
Note: This blog is based on the SEBI Adjudication Order in the matter of Central Depository Services India Limited dated July 20, 2026, reference Order/JS/RJ/2026-27/32498-32500, available at sebi.gov.in. The findings and language cited are drawn directly from the official order and verified reporting from Business Standard, MediaNama, and LiveLaw. This blog is for awareness and educational purposes only. It does not constitute legal or compliance advice. Consult your legal, compliance, and cybersecurity teams for entity-specific guidance on SEBI cybersecurity obligations.
At Skeletos IT Services, we help Indian organisations across BFSI, capital markets, and manufacturing assess their cybersecurity posture against regulatory requirements, identify gaps before an inspector does, and build the governance documentation that demonstrates compliance. If you want to understand how your current security posture compares to SEBI or RBI requirements, we can help you find out.

