On November 18, 2022, an order was passed to adjudicate the case of malware attack on CDSL. The order named the then Chief Information Security Officer Rajesh Nadkarni and the then Chief Technology Officer Amit Mahajan as notices. However, SEBI disposed of the action against the two former officials without imposing any monetary penalty.
SEBI under Section 15HB of the SEBI Act imposed on CDSL Rs. 90 lakhs and under Section 19G of the Depositories Act Rs. 10 lakh was imposed. The regulator said the penalty is commensurate with CDSL’s lapses and errors. The company has been directed to pay the amount within 45 days of receiving the order.
What happened in 2022
According to the order, CDSL observed on November 18, 2022 around 3 am, after completing end-of-day operations that some servers and end-user computers became inaccessible. On checking the cause, it was found to be a malware attack.
CDSL isolated server and end-user computers and disconnected its network to prevent the spread of malware. The attack affected complex systems connected to various depository processes. CDSL then created a separate virtual local area network with clean desktops and servers after scanning. The recovery exercise was completed on November 19, 2022, and settlements scheduled for November 18 were carried out on November 20.
Sebi said complex systems including settlement processing and inter-depository transfers were disrupted for 46 hours and 54.5 hours respectively. It said the disruption had a major spillover effect as settlement activities for the securities market also depended on the normal functioning of the CDSL systems.
Also Read: Complete Projects, Jindal Supreme gets SEBI nod to bring up IPO
At the heart of the case is the ADFS server
The regulator’s findings focused on CDSL’s Active Directory Federation Services, or ADFS server. Sebi said that the ADFS server is an Internet-facing application and should be treated as an important asset under the cyber security framework.
The final root cause analysis report found that an inadequately secured Internet-accessible ADFS server was the root cause of the incident, the order said. The server was not included in vulnerability assessment and penetration testing, and was not integrated with security information and event management and privileged identity management systems. Sebi said the loophole was used by a threat actor to access CDSL systems without generating alerts for malicious activity.
SEBI rejected CDSL’s contention that the ADFS server was not critical as it did not host business applications or sensitive investor data. Internet-facing applications are required to be included as critical assets under SEBI’s May 2022 cyber security circular, the regulator said.
The order also said that CDSL had accepted during the meetings of SEBI’s High Powered Steering Committee on Cyber Security in March and May 2023 that the ADFS server should be designated as a critical asset and subject to relevant audit.
Access control vulnerabilities
SEBI also found lapses in access control. The order states that the domain admin account on the ADFS server has a weak password that can be brute-forced through common dictionary attacks. It also said the password for the privileged account was set to “never expire,” which would have allowed the threat actor to retain access for a long period of time.
The regulator noted that the privileged identity management solution was not configured to control and monitor directory services. This allowed the threat actor to move laterally using privileged accounts regardless. SEBI also said that the threat actor was able to disable the endpoint detection and response solution on the endpoint machine by using system account privileges.
The regulator further stated that since ADFS server was not integrated with SIEM, logs were not available for audit and review. It also noted that some alerts related to possible data exfiltration, malware activity and beaconing were identified at CDSL’s head office and disaster recovery site, but the alerts were not acknowledged.
(Disclaimer: Recommendations, suggestions, opinions and views given by experts are their own. These do not represent the views of Economic Times)
(You can now subscribe to our ETMarkets WhatsApp channel)