Pages

Tuesday, July 21, 2026

SEBI means business when it comes to cybersecurity and Data Security

 The CDSL Cyber Attack: What SEBI Adjudication Order Reveals About Hidden Vulnerabilities in Our Markets


The recent news of CDSL getting pulled up for cybersecurity issues gained importance.
SEBI penalises CDSL for cybersecurity lapses behind 2022 malware attack, imposes Rs 1 crore penalty.

https://www.moneycontrol.com/news/business/markets/sebi-penalises-cdsl-for-cybersecurity-lapses-behind-2022-malware-attack-imposes-1-crore-penalty-13978860.html

When and How!

If you trade or invest in Indian stocks, you probably remember the sheer panic of Friday, November 18, 2022.

Early that morning, Central Depository Services India Ltd, the powerhouse holding demat accounts for the vast majority of retail investors, suddenly went pitch black. Broking apps could not verify holdings, investors could not sell stocks, and a multi billion rupee settlement system froze solid.

At the time, CDSL put out a brief statement about detecting malware and isolating systems as a precaution. But the full story has finally blown wide open. SEBI recently dropped an exhaustive 88 page adjudication order on the incident, slapping CDSL with a 1 crore penalty, which breaks down to 90 lakh under the SEBI Act and 10 lakh under the Depositories Act.

The fine is small for a market giant like CDSL, but the forensic autopsy detailed in the SEBI report is an absolute eye opener. It exposes a classic corporate tragedy: cutting corners on basic IT security until a minor oversight triggers a massive systemic crisis.

Let us unpack exactly what happened behind the scenes, why the regulator cracked down so hard, and what this tells us about the structural fragility of our financial plumbing.

 The Digital Vaults: Why Cyber Norms Are Not Just Bureaucracy

To understand why SEBI went into enforcement mode, you have to look at what CDSL actually does.

In market lingo, depositories are Market Infrastructure Institutions. If stock exchanges are the engine of the market, depositories are the digital vaults and plumbing. CDSL controls roughly 70 percent of the market share for demat accounts in India. Every single time you execute a trade, transfer a share, or pledge stock to get trading margin, CDSL systems handle the transaction.

Because these institutions are completely hyper connected, a breach at one does not just hurt its internal operations, it threatens to collapse the entire market system.

This is exactly why SEBI maintains a strict Cybersecurity and Cyber Resilience Framework. It is not a checklist of friendly suggestions, it lays down non negotiable rules as follows.

  •  Critical Asset Inventory

Every single server, database, or network path facing the public internet must be cataloged as a Critical Asset.

  • Mandatory VAPT Audits

These critical assets must undergo relentless Vulnerability Assessment and Penetration Testing to catch security loops before hackers weaponize them.

  • Privileged Identity Management

Rigid control over administrative access, mandatory password rotation cycles, and tight lockout thresholds to stop automated brute force attacks.

  • Security Log Monitoring

Ingesting all system logs into a central platform for real time anomaly detection.

Under the law, failing to follow these guidelines exposes a depository to direct penalties. And as the SEBI investigation discovered, CDSL broke almost every single one of them.

The Anatomy of the 2022 Freeze

It all kicked off around 3:00 AM on November 18, 2022. Just as the IT team wrapped up day end processing, operational servers and corporate desktops started dropping fast. A destructive malware payload was actively tearing its way across the corporate network.

To protect its primary data vault from being wiped out or held for ransom, CDSL took the emergency step of pulling the plug on their entire network, disconnecting from the outside world. While this saved the core data, it triggered an immediate gridlock across the broader market:

 Infected Servers: 135 out of 547 operational servers were completely infected by the malware.

 Encrypted Endpoints:  177 out of 506 corporate desktops and laptops were encrypted or disabled.

 Subsidiary Contagion: The virus jumped the fence into CDSL Ventures Limited, resulting in a permanent loss of operational data within the KYC registry.

 Inter Depository Freeze: Inter depository transfers were paralyzed for 54.5 hours. If you needed to move securities between CDSL and NSDL over that weekend, you were completely stuck. Core market settlement systems were knocked offline for 46 hours.

The Inconvenient Truths Uncovered by SEBI

When the SEBI cybersecurity committee audited the wreckage, they found that this was not an unavoidable, ultra sophisticated hack. It was an accumulation of basic security failures.

1. The Ignored Gateway

The hackers broke in through an Active Directory Federation Services server, which handles corporate user logins. CDSL tried to defend itself by claiming that because this server did not host core demat ledger data, it was not a vital asset.

SEBI rejected this argument. The server was connected to the public internet and validated user logins; it was a wide open front door into the internal network. Yet, CDSL had left it off their Critical Asset list, meaning it completely skipped regular security drills, logging, and administrative access controls.

2. The One Year Guest Pass

The most alarming revelation in the order is the timeline. The hackers did not break in on November 18. Forensic analysis showed they breached the unmonitored server back in November 2021.

The attackers lived inside the CDSL network for an entire year, completely undetected, quietly mapping out the architecture, collecting administrative credentials, and planning their execution without anyone noticing.

3. Ignoring Early Warnings

Three months before the attack, in August 2022, SEBI ran an inspection and explicitly warned CDSL about gaps in their external perimeter defense. Instead of patching them immediately, CDSL tech management brushed it off, relying on an older audit report to argue that everything was fine.

4. The Pandemic Backdoor

During the remote work shifts of the pandemic, CDSL created a master administrator account and explicitly set its password policy to Never Expire. They also loosened account lockout rules. Long after staff returned to the office, this massive vulnerability was left live, giving the attackers a permanent master key to move laterally across the network.

The Reality Check: How to Fix Market Infrastructure

SEBI dropping the hammer on CDSL is a stark reminder for every financial player in India. To prevent our market infrastructure from becoming a soft target, the industry needs to rethink its approach to security:

  •  Public Facing Means Critical

You cannot exclude a server from security testing just because it does not house your primary database. If it touches the internet or authenticates identities, it needs to be tested relentlessly.

  • Abolish Permanent Admin Credentials

The existence of a Never Expire admin password in a system handling national assets is unacceptable. Organizations must implement Just In Time access, where administrative privileges automatically expire after a few hours.

  • Build Hard Network Fences

The fact that malware easily leaked from CDSL to its subsidiary proves that perimeter defense alone is not enough. Parent companies and subsidiaries must maintain completely isolated network zones so a breach in one does not drag down the other.

  •  Transition to Active Threat Hunting

Running automated antivirus scans is useless when attackers sit silently in your network for 12 months. Security teams need to deploy behavioral monitoring tools that actively search for long term internal movements.

  • Failover in Minutes Not Days

A 54 hour market outage is completely unacceptable in a modern financial economy. Infrastructure institutions must have real time backup sites running concurrently, so that operations can failover immediately without manual cleanups.

The Bottom Line

The 1 crore fine on CDSL is not a financial crisis for the depository, but it is a massive reputational wake up call for boardrooms across India.

When an institution operates the digital back end for over 80 million retail investments, cybersecurity ceases to be a simple IT issue, it becomes a matter of national economic stability. If you are going to build a hyper connected, digital first market, you have to make sure the plumbing is secure.


Five salient points of this SEBI ruling


1. Omission of Internet-Facing Assets from Vulnerability Scans

CDSL failed to classify its public-facing Active Directory Federation Services (ADFS) server as a Critical Asset. Consequently, this server was excluded from mandatory Vulnerability Assessment and Penetration Testing (VAPT), lacked two-factor authentication (2FA), and was not integrated into central monitoring systems (SIEM/PIM). This inadequately secured entry point served as the root cause for the attack.


2. A "Silent" Breach Remained Undetected for Nearly a Year

Forensic investigations revealed that threat actors had breached the unmonitored server as early as November 2021—a full year before triggering the destructive malware payload in November 2022. The long dwell time allowed attackers to gather credentials and map out internal network architecture without generating any alerts.


3. Ignored Pre-Attack Regulatory Warnings

SEBI had explicitly flagged perimeter defense gaps to CDSL management during an inspection in August 2022 (three months prior to the incident). Instead of patching the vulnerabilities immediately, CDSL relied on older, flawed audit reports, leaving the vulnerability open.


4. Risky Administrative Credential Practices

The investigation highlighted persistent policy deviations originally created for remote work during the pandemic, including a privileged administrator account with a password policy set to "Never Expire" and missing basic lockout or multi-factor protections. These legacy settings gave attackers a persistent master key across internal networks.


5. Institutional Accountability Over Individual Scapegoating

While SEBI penalized CDSL ₹90 lakh under the SEBI Act and ₹10 lakh under the Depositories Act, it disposed of charges against former individual technology executives (ex-CISO and ex-CTO) without monetary fines. SEBI noted that critical asset classification and cybersecurity governance are collective, institutional responsibilities involving board committees (such as the Systems and Technology Committee), rather than individual isolated failures.


Disclaimer 

Source: Internet

(This is an article generated using AI based on reports of SEBI imposing fine on CDSL for cybersecurity lapses)

Wednesday, May 17, 2017

It's become like a warcry in last five days.. #wannacry, #wannacry.. I  really wanna cry. Why.. Because time and again it has been proven that we as user fail to learn and remain ostrich. Even now it's not too late
1. Do not open any email if it's suspicious, don't fall for lucrative offers.. Check for URL and also see details of sender.. If u don't  know the sender, don't open the link
2. Take backup of your laptop or pc data
3. Update Antivirus definitions.
4. If you are still using Windows Xp, download latest updates from MS
5. Upgrade to latest OS, choice is your depending upon your budget, requirements and preference. Better would be to upgrade to Linux.. Now is the time to take helping hand of TUX
6. Lastly you will find lots of advices and DIY links offering you assistance in case you have been infected.. Word of advice PROCEED WITH CAUTION.. Follow some reputed blogger or stick to well known security research companies for information.
Happy hunting
Follow my link on facebook
https://www.facebook.com/groups/3tips/

Thursday, March 23, 2017

Fuzzy Thoughts.. Are they really Scary!!!

Otherday when I just closed my eyes.... (Bcoz There are so many eye openers that you tend to get confused many times whether you are daydreaming with open eyes).. Just imagining how our lives have been changed over the years.. In fact more so in last decade.
Isn't this exactly what we get to hear from all historians...
.. Jokes apart
Now I am just typing this on my Smart Phone that more memory than my office laptop and it can have more apps.. And the operating system ie OS takes space identical to Windows 10 and Ubuntu on my PC or Laptop.. I realized that I no longer need the distant cousins of my *Smartphone*.. I can use it to get notified for emails received, open it, read it and then if required reply it or forward it to intended recipients or simply push back button twice on my smartphone to come out to home screen.
Now you would say what's special about it

Think the scenario in Year 2000...

We have just come out of fear of doom.. Of Y2K bug
Dialup modems have just started to gather speed
Blackberry has gained momentum with iPhone giving all competitors a good lead

Still sensing and recent email was a ritual


Cut to 2017
Now we are talking of Iot, Cloud computing, Machine Learning (never thought that machine can also learn), AI (Intelligence becoming Artificial?) Elastic Search, Quantum Computing, networked Home.. Office, Car becoming intelligent
And what's at the backbone for it.. High speed Internet

Yes.. The Moores law is not applicable here.. Neither is Murphys law
So we r going towards hi-tech super automated world..

But wait let me open my eyes now

What I'd I forget the password to my Smartphone.. What if it crashes.. What if it's been hacked and all my confidential information is stolen..
How's responsible for maintaining secrecy..
Keeping me secure
Of course.. Anyone but me
It's government duty
Peculiar problem
.. Ain't it

Not me

I have to reap the benefits and let government be damned if I get hacked... To be continued.. Fuzzy thoughts

Saturday, December 17, 2016

Who doesn't like to b a creator of something new..
Who doesn't want play God and feel devine
Well here is chance to play your own role as God while working on your computer.
Check out the God mode in MS Windows.  This feature has been available with all versions of MS Windows 7 onwards.. We will how it's done in Windows 10.. Follow the link given below
https://fossbytes.com/how-to-enable-godmode-windows/

Saturday, November 12, 2016

There have been frustrating times for coder and students and general Linux users while taking down notes ot just jotting  down their thought that they wish they had something simpler yet powerful notepad like tool.. Well there are a list of apps which augment features of notepad and features like Evernote..
Check these out
http://www.makeuseof.com/tag/top-notepad-apps-linux-can-sync/

Saturday, November 5, 2016

The emphasis on ensuring safety of your digital assets,  data included cannot go overboard ever.  This is one such field that would always remain Achilles heal for management and sore point of discussion in boardroom meetings whenever financial allocations are being carried out.. Check this out.. A primer

http://www.bizlibrary.com/article/cybersecurity-training-team-sport/

Saturday, October 29, 2016

  *Though a dated,  old article but give lots of basic information about different image formats that comes with tips on what format to be used and when..
This is a detailed summary of all popular image formats with comparisons also..  Handy reference
 Happy hunting

Ref http://blog.hubspot.com/insiders/different-types-of-image-files


(All copyrights of respective owners) 

Wednesday, August 10, 2016

Is Human factor weakest link in security?

Human factor: Weakest Link!
  • It has been always been a strong point of debate  whenever it is discussed for implementation of Cyber Security..  Who is the Weakest Link? Identification has never been difficult for Security team and they  have be univocally supported by both, Executives and /management…THE USER.
  • The User.. is known by many other names
    • Client
    • End user
    • field agents
    • office staff
    • non developers
  • Since ages the human link is taken as “Weakest Link” in security be it Physical or now “Cyber”.
  • However This fact has been overlooked more often that not that very same “HUMAN” factor is major contributor in implementing the ROBUST SECUTIY ARCHITECTURE.
  • Awareness : What Lets one down is the “Lack Of Awareness Training”..The basics are forgotten..what is the main factor to plug this?.. Create Awareness… How? Training is the best way of creating awareness.
    • It can be integral part of appraisals process.
    • Divide into various levels of training
      • Beginners ..for freshers and new recruits
      • Middle level…for those having completed some time in the company and those who are due for appraisal
      • Advanced and Refresher courses… At the time of change of any major policy or revision as well as on introduction of new equipment
  • Thus we can say its always the Onus on the Security Professionals as well as the Management
  • A detailed study carried out by eforensics magazine highlights such issues https://eforensicsmag.com/human_factor/

Saturday, April 25, 2015

Cost of data loss: How realistic we are about finances of data breaches?

  1. The data breach and subsequent loss of records for transactions and confidential details of customers are always a matter of concern for any company. However it becomes very difficult to put exact or near exact cost per record loss due to the breach.
  2. Verizone has tried to breach this barrier and to put cost per record and it comes out to be..... Dollars 0.58 . Amazingly low. Another research firm puts this between 188 to 210 dollars per record.
  3. Check out the details https://m.facebook.com/l.php?u=https%3A%2F%2Ffortune.com%2F2015%2F04%2F24%2Fdata-breach-cost-estimate-dispute&h=jAQHhn8X8

Monday, April 6, 2015

Facebook Thugging... new era of cyber threats

Ever heard of a term Cyber Bullying. Normally its associated with children being threatened by criminals, paedophiles etc online in chat rooms etc.
However a case of intimidating a facebook user by displaying a gun pointed towards camera with menacing smile has lead to arrest of a lady for "Facebook Thugging".
As per the details available, the lady posted a pic of herself pointing gun towards the camera that was followed by a comment something to the effect that "That's what you will get if you come lookin for me".
Though she took off the pic later on admitting that she thought it was intimidating, police arrested her on the charges of threatening on facebook.
Therefore be careful what you post and how I is going to be visualised by others.
Don't be impulsive. Think before you act.
http://www.techworm.net/2015/04/woman-arrested-for-facebook-thugging.html

Proud Blogger

Powered By Blogger