The regulator said CDSL had failed to classify an internet-facing server as a critical asset and had not addressed cybersecurity deficiencies flagged months before the attack.
The regulator said CDSL had failed to classify an internet-facing server as a critical asset and had not addressed cybersecurity deficiencies flagged months before the attack.