Tipsheet
What matters at India’s listed companies
SEBI · Enforcement · High

SEBI penalises CDSL, ex-CISO, ex-CTO over 2022 malware attack that delayed settlements

SEBI's adjudication order holds CDSL and its former cybersecurity heads accountable for a November 2022 malware attack that forced a two-day settlement delay.

19 Jul 2026 Affects: CDSL and its former CISO Rajesh Nadkarni and former CTO Amit Mahajan; also sets a precedent for individual accountability of cybersecurity officers at market infrastructure institutions.

What changed

  • SEBI issued an adjudication order against CDSL, ex-CISO Rajesh Nadkarni, and ex-CTO Amit Mahajan for cybersecurity lapses in the Nov 2022 attack.
  • The attack disabled servers and end-user computers, delaying settlements due Nov 18 to Nov 20, 2022.
  • The order alleges violations of SEBI's cybersecurity framework and the Depositories and Participants Regulations.

The read

A malware attack on CDSL on November 18, 2022 knocked out servers and end-user computers, forcing the depository to rebuild on a clean VLAN and delaying settlements by two days. SEBI's adjudication order holds CDSL, its former CISO Rajesh Nadkarni, and former CTO Amit Mahajan personally responsible for failing to comply with the mandated cybersecurity and remote-access framework. The order applies existing rules, but its real sting is individual accountability. For market infrastructure institutions, the message is clear: cybersecurity lapses that disrupt settlement operations will be pursued against the officers in charge.

CDSLRajesh NadkarniAmit Mahajan

Primary source: official circular (PDF)