Prime Infoserv Prime Infoserv

What the regulator asks for

Start here

Six practices, one lifecycle: advise, assess, comply, protect, monitor, respond. Most engagements begin with an assessment and stay for the monitoring.

All services

Prime can sign the audit report your regulator will accept.

Scope an engagement

Audit & testing

Certification & privacy

Arrived with a deadline rather than a question? Every page above states the scope, the evidence produced and the typical duration.

All requirements

Data-intensive

Each industry page names the specific obligations that apply — SEBI CSCRF for market infrastructure, CEA guidelines for utilities, DPDP for everyone holding personal data.

All industries

New CERT-In Regulation Mandates Organizations for Notifying Cyber Breaches Within 6 Hours

The Ministry of Electronics and Information Technology (Meity), Government of India declared that organizations such as service providers, data centers and even government entities should report incidents of cyber security breaches to the CERT-In wit

Article

Cyber Security30 April 20223 min read

PP By Prime

New CERT-In Regulation Mandates Organizations for Notifying Cyber Breaches Within 6 Hours
The Ministry of Electronics and Information Technology (Meity), Government of India declared that organizations such as service providers, data centers and even government entities should report incidents of cyber security breaches to the CERT-In within 6 hours. The announcement has been made on 28th April, 2022 to further strengthen the present cyber environment. According to the cyber security guidelines published by the union government, this process would ensure Indicators of Compromise (IoC) related to cyber security incidents are available for immediately carrying out detailed investigation procedures and in-depth analysis of the said incidents.

CERT-In Mandates New Guidelines for Cyber Security Assessment

The government has also issued several new guidelines and directions that need to be followed so that the country’s cyber security system becomes stronger.
  • Every services provider and other organizations should be connected to National Physical Laboratory (NPL) or Network Time Protocol (NTP) server of National Informatics Center (NIC) for ICT system clock synchronization.
  • Organizations should also provide information related to cyber security incidents as well as conduct other activities to assist CERT-In for security mitigation and cyber awareness.
  • Data centers and VPN providers should maintain records of subscribers or customers for a minimum period of 5 years after cancellation or withdrawal of subscriptions.
  • Service providers related to virtual asset exchange and custodian wallet should mandatorily maintain information of KYC as well as records of every financial transaction for 5 years for ensuring cyber security.
According to the Union Ministry of Electronics and Information Technology, these guidelines would ensure a safe as well as trusted cyber environment by further enhancing overall cyber security infrastructure.

Different Types of Cyber Security Incidents According to CERT-In

The report also provides a detailed list of different types of cyber security incidents which need to be mandatorily reported within 6 hours of detection. A total of 20 types of security incidents are mentioned which are all recognized as serious cyber security threats by CERT-In. The security incidents are as follows:
  1. Targeted scanning of systems
  2. Critical systems and information compromise
  3. Unauthorized access
  4. Website intrusion
  5. Malicious code and malware attacks
  6. Server attacks
  7. Phishing and identity theft
  8. DoS and DDoS attacks
  9. Attack on SCADA and critical infrastructure
  10. Attack on E-Governance and E-Commerce
  11. Data Breaching
  12. Data Leaking
  13. IoT attacks
  14. Attack on digital payment systems
  15. Attacks from mobile apps
  16. Dummy mobile applications
  17. Unauthorized access on social media
  18. Attacks on cloud infrastructure
  19. Attacks on virtual assets, blockchain, etc
  20. Attacks on AI and ML applications
CERT-In is responsible for analysis and mitigation of cyber incidents and therefore, cyber attacks related to the above mentioned types should be mandatorily reported within 6 hours. However, it will create a challenge for some organizations due to lack of additional staff and management time. We, a CERT-In empanelled agency, is the most preferred cyber security advisor that supports key public as well as private sector enterprises in the industry delivering state-of-the-art solutions on vulnerability and penetration testing (VAPT), managed security services, web application audit, NoC, SoC, SIEM/SOAR and many more. Our Anti-Ransomware Readiness (ARR) Audit is a combination of active and passive non-intrusive techniques that delivers a strong technical process to an organization to mitigate ransomware threats. Do check our website www.primeinfoserv.com for more details or write us at info@primeinfoserv.com or contact us at +913340085677 for queries.
  • cybersecurity
  • Assessment
  • Cert In
  • cyber security guidelines
  • New Guidelines of Cyber Security
  • Security breaches

awareness27 Aug 2026

Don’t Just Protect Your Siblings—Protect Their Data Too!

Raksha Bandhan celebrates one of the most cherished bonds—one built on love, trust, and protection. But in today’s digital world, protection means more than being there for your sibling. It also means helping them protect their personal data, digital

Read more

Tell us the deadline, not the acronym.

Thirty minutes with a practitioner rather than a salesperson. If the requirement somebody has handed you does not match what you actually need, that is a more useful thing to find out now than in week nine.

Talk to an expert

Or reach the incident line directly on +91 9147712576, monitored 24×7 from Kolkata.