Security and Exchange Board of India
Stock market regulator SEBI has imposed a fine of Rs 1 crore on Central Depository Services (CDSL) for alleged negligence in cyber security. This action has been taken after investigating the malware attack that took place in November 2022. SEBI says that there were many serious flaws in the security system of CDSL, due to which the cyber attack could have such a big impact. According to SEBI order, due to malware attack, many important services of CDSL were affected for a long time. The settlement process was disrupted for about 46 hours and the inter-depository transfer system for about 54.5 hours. The regulator said that it is clear that the impact of this incident was not limited to CDSL only, but had an impact on the entire securities market.
Investigation also revealed that this attack did not happen suddenly. According to SEBI, relaxations given in cyber security rules from time to time, unimplemented regulatory instructions and lack of necessary security measures prepared the ground for this attack. It has been said in the order that the attackers had gained access to CDSL’s servers in November 2021 itself, but this intrusion was detected in November 2022. That is, there was a breach in the system for about a year and it could not be known.
These were also flaws
SEBI also found that CDSL had created an admin account in 2021, the password of which was set to never expire. Additionally, basic security settings like locking the account if the wrong password is entered three times in a row were also not implemented. According to the regulator, these shortcomings were rectified only after the malware attack. SEBI said in its order that depository systems are interconnected, hence weakness in cyber security of any one institution can become a big risk for the entire stock market. For this reason, a fine of ₹ 1 crore has been imposed on CDSL.
Also read- Did you get 8.25% interest in your PF account? Learn the easy way to check balance
