CERT In 6 hour reporting compliance, incident response framework, IT Act obligations, data breach coordination with DPDPA requirements and cyber insurance programme advisory.
Short, direct, on the record.
The 2022 CERT In Directions require mandatory 6 hour reporting for 20 categories including targeted scanning, compromise of critical systems, malicious code attacks, attacks on servers and databases, identity theft, spoofing and phishing, data breach, data leak, attacks on IoT devices and systems, attacks on digital payment systems, and unauthorised access to social media accounts.
They are parallel obligations. CERT In reporting covers the cybersecurity incident itself (6 hour timeline). DPDPA breach notification covers the personal data breach aspect and must be made to the Data Protection Board without unreasonable delay. The scope and content of each notification differ, and both must be managed simultaneously.
A body corporate that is negligent in implementing and maintaining reasonable security practices and procedures, resulting in wrongful loss or gain to any person, is liable to pay damages by way of compensation to the affected person. There is no statutory cap on the compensation amount.
Cyber insurance is not currently mandatory for all entities, though certain regulated sectors (banking, insurance) have sectoral requirements or strong regulatory expectations around cyber risk transfer. CERT In compliance, DPDPA obligations and contractual requirements are driving voluntary adoption.
Share the industry sector, current compliance state and the specific incident or regulatory concern for a confidential assessment.