India's incident reporting regime is one of the strictest clocks in global cyber regulation: under CERT-In's directions of April 2022, specified cyber incidents must be reported within six hours of noticing them. Four years on, plenty of organisations still discover the requirement during their first real incident — the most expensive possible moment.

Who and what is covered

The directions apply broadly: service providers, intermediaries, data centres, body corporates, and government organisations. The list of reportable incidents is long and more inclusive than teams expect — beyond major breaches, it includes items such as website defacement, malware and ransomware attacks, identity theft and spoofing, unauthorized access to systems and data, and attacks on critical infrastructure. The practical reading: if it would make your incident channel light up, check the list before assuming it isn't reportable.

The obligations beyond the clock

Building a runbook that survives contact

Six hours is not enough time to decide who decides. A workable runbook settles that in advance: a definition of "noticing" (the timer should start at triage confirmation, and your process should prove when that was), an incident classification matrix mapped to the reportable list, a pre-filled reporting template with your organisation's standing details, named owners with deputies, and the reporting channel details kept where an on-call engineer can find them at 3 a.m. Then rehearse it once — a thirty-minute tabletop exposes more gaps than a quarter of policy writing.

The six-hour rule is really a detection-and-decision test wearing a compliance costume. Teams that can answer "what happened, when did we know, who reports it" inside an hour find the deadline unremarkable.