India’s Market Watchdog Fines the Depository That Handles 80% of Investor Accounts

India’s markets regulator fined Central Depository Services (India) Ltd 10 million rupees on Monday for cybersecurity and compliance failures linked to a malware attack that disrupted depository operations in November 2022. FinancialMediaGuide views the penalty as a reminder that even years after an incident, regulators are still working through the accountability process for cyberattacks on critical market infrastructure.

The Securities and Exchange Board of India said the depository, which handles the majority of the country’s investor accounts, had failed to classify an internet-facing server as a critical asset and failed to safeguard it, despite rules requiring such systems to be treated as such. That server was the root cause of the malware attack, allowing cyber threats to gain access to CDSL’s systems.

SEBI also found that the depository failed to detect intrusions in real time, failed to properly analyze security alerts, and did not comply with rules for resuming trade settlement through backup sites. The attack disrupted critical depository functions including settlement activities, corporate actions, margin pledges and inter-depository transfers, delaying settlements scheduled for November 18, 2022. FinancialMediaGuide notes that the range of functions affected, from settlements to corporate actions, illustrates how a single compromised server can cascade into disruption across nearly every core service a depository provides.

SEBI said the malware attack was the foreseeable outcome of accumulated cybersecurity lapses, including inadequate monitoring, weak password controls and failure to implement required cybersecurity safeguards. The regulator’s findings paint a picture of systemic, rather than isolated, gaps in the depository’s defenses at the time of the incident.

CDSL is one of just two depositories operating in India’s capital markets, alongside National Securities Depository Ltd, and together they underpin the settlement infrastructure for the country’s entire equity market. CDSL leads on account volume, with more than 18 crore demat accounts and roughly 80% of the retail depository market, while NSDL holds the larger share of custody value at nearly 87%, reflecting its dominance among institutional and high-value accounts. FinancialMediaGuide points out that this division of labor, CDSL dominating retail accounts and NSDL dominating custody value, means a security failure at either depository carries systemic risk for a different, but equally critical, slice of the market.

The two depositories have in recent years worked to modernize investor-facing infrastructure, including launching a unified investor app that lets users view consolidated holdings, trading positions and tax information across both platforms regardless of which depository holds their account. That modernization push has run in parallel with the kind of legacy security gaps SEBI’s order highlights, underscoring the tension between expanding digital access and maintaining baseline cybersecurity discipline.

While the fine itself is modest relative to CDSL’s scale, the order sets a public record of the specific technical and procedural failures regulators expect market infrastructure providers to fix. Financial Media Guide concludes that as India’s retail investor base keeps expanding, with barely a tenth of the population currently holding a demat account, the cybersecurity standards regulators enforce on depositories like CDSL will only become more consequential to the integrity of the country’s capital markets.

Share This Article