CybersecurityCERT-InIT ActIndia
AMLEGALS / Services / Cybersecurity
Cybersecurity · CERT-In · IT Act

Cybersecurity compliance and incident response advisory

CERT In 6 hour reporting compliance, incident response framework, IT Act obligations, data breach coordination with DPDPA requirements and cyber insurance programme advisory.

Counsel that connects the technical, the commercial, and the legal, across ten offices in India.
CERT-In
6 Hour Reporting
IT Act
2000 (Amended 2008)
DPDPA
Breach Sync
10
Offices
01

CERT In directions and mandatory reporting

  • CERT In Directions of 28 April 2022: mandatory 6 hour incident reporting for 20 defined cyber incident categories.
  • Synchronised clock, log retention (180 days rolling) and VPN/cloud provider obligations.
  • Designated point of contact registration, incident report format and escalation.
  • CERT In interaction management and follow up compliance.
02

Incident response framework and playbook

  • Cyber incident response plan (CIRP) design: identification, containment, eradication, recovery and post incident review.
  • Legal privilege strategy for forensic investigation reports and internal communications.
  • Parallel DPDPA breach notification: Data Protection Board intimation without unreasonable delay under Rule 7.
  • Regulatory notification coordination: CERT In, Data Protection Board, sectoral regulator (RBI, SEBI, IRDAI) and law enforcement.
03

IT Act compliance and liability

  • Section 43A: body corporate liability for failure to implement reasonable security practices and procedures.
  • Section 72A: punishment for disclosure of information in breach of lawful contract.
  • Information Technology (Reasonable Security Practices and Procedures) Rules, 2011 and IS/ISO/IEC 27001 certification.
  • Intermediary guidelines compliance under IT Act Section 79 and IT Rules 2021 for platforms.
04

How AMLEGALS assists

  • Cybersecurity compliance framework design aligned with CERT In, IT Act and DPDPA.
  • Incident response retainer: on call legal support for breach scenarios.
  • Regulatory notification drafting and regulator interaction management.
  • Cyber insurance programme review, policy wording analysis and claims coordination.
Answers

What clients ask before they commit.

Short, direct, on the record.

01What incidents must be reported to CERT In within 6 hours?

The 2022 CERT In Directions require mandatory 6 hour reporting for 20 categories including targeted scanning, compromise of critical systems, malicious code attacks, attacks on servers and databases, identity theft, spoofing and phishing, data breach, data leak, attacks on IoT devices and systems, attacks on digital payment systems, and unauthorised access to social media accounts.

02How does CERT In reporting interact with DPDPA breach notification?

They are parallel obligations. CERT In reporting covers the cybersecurity incident itself (6 hour timeline). DPDPA breach notification covers the personal data breach aspect and must be made to the Data Protection Board without unreasonable delay. The scope and content of each notification differ, and both must be managed simultaneously.

03What is the liability under Section 43A of the IT Act?

A body corporate that is negligent in implementing and maintaining reasonable security practices and procedures, resulting in wrongful loss or gain to any person, is liable to pay damages by way of compensation to the affected person. There is no statutory cap on the compensation amount.

04Is cyber insurance mandatory in India?

Cyber insurance is not currently mandatory for all entities, though certain regulated sectors (banking, insurance) have sectoral requirements or strong regulatory expectations around cyber risk transfer. CERT In compliance, DPDPA obligations and contractual requirements are driving voluntary adoption.

Engage AMLEGALS

Discuss cybersecurity compliance or incident response

Share the industry sector, current compliance state and the specific incident or regulatory concern for a confidential assessment.

Get in Touch[email protected]
Engagements are conducted under attorney work product and privilege.