India's incident reporting regime is one of the strictest clocks in global cyber regulation: under CERT-In's directions of April 2022, specified cyber incidents must be reported within six hours of noticing them. Four years on, plenty of organisations still discover the requirement during their first real incident — the most expensive possible moment.
Who and what is covered
The directions apply broadly: service providers, intermediaries, data centres, body corporates, and government organisations. The list of reportable incidents is long and more inclusive than teams expect — beyond major breaches, it includes items such as website defacement, malware and ransomware attacks, identity theft and spoofing, unauthorized access to systems and data, and attacks on critical infrastructure. The practical reading: if it would make your incident channel light up, check the list before assuming it isn't reportable.
The obligations beyond the clock
- 180-day logs: ICT system logs must be maintained for 180 days and kept within India, to be produced when directed. Centralized, tamper-resistant logging stops being a nice-to-have.
- Time synchronization: system clocks must sync to approved NTP sources — mundane until a cross-system forensic timeline depends on it.
- Customer records for infrastructure providers: VPS, VPN, and cloud service providers must maintain subscriber and customer records for five years.
Building a runbook that survives contact
Six hours is not enough time to decide who decides. A workable runbook settles that in advance: a definition of "noticing" (the timer should start at triage confirmation, and your process should prove when that was), an incident classification matrix mapped to the reportable list, a pre-filled reporting template with your organisation's standing details, named owners with deputies, and the reporting channel details kept where an on-call engineer can find them at 3 a.m. Then rehearse it once — a thirty-minute tabletop exposes more gaps than a quarter of policy writing.