Six practices, one lifecycle: advise, assess, comply, protect, monitor, respond. Most engagements begin with an assessment and stay for the monitoring.
Each industry page names the specific obligations that apply — SEBI CSCRF for market infrastructure, CEA guidelines for utilities, DPDP for everyone holding personal data.
New CERT-In Regulation Mandates Organizations for Notifying Cyber Breaches Within 6 Hours
The Ministry of Electronics and Information Technology (Meity), Government of India declared that organizations such as service providers, data centers and even government entities should report incidents of cyber security breaches to the CERT-In wit
The Ministry of Electronics and Information Technology (Meity), Government of India declared that organizations such as service providers, data centers and even government entities should report incidents of cyber security breaches to the CERT-In within 6 hours. The announcement has been made on 28th April, 2022 to further strengthen the present cyber environment. According to the cyber security guidelines published by the union government, this process would ensure Indicators of Compromise (IoC) related to cyber security incidents are available for immediately carrying out detailed investigation procedures and in-depth analysis of the said incidents.
CERT-In Mandates New Guidelines for Cyber Security Assessment
The government has also issued several new guidelines and directions that need to be followed so that the country’s cyber security system becomes stronger.
Every services provider and other organizations should be connected to National Physical Laboratory (NPL) or Network Time Protocol (NTP) server of National Informatics Center (NIC) for ICT system clock synchronization.
Organizations should also provide information related to cyber security incidents as well as conduct other activities to assist CERT-In for security mitigation and cyber awareness.
Data centers and VPN providers should maintain records of subscribers or customers for a minimum period of 5 years after cancellation or withdrawal of subscriptions.
Service providers related to virtual asset exchange and custodian wallet should mandatorily maintain information of KYC as well as records of every financial transaction for 5 years for ensuring cyber security.
According to the Union Ministry of Electronics and Information Technology, these guidelines would ensure a safe as well as trusted cyber environment by further enhancing overall cyber security infrastructure.
Different Types of Cyber Security Incidents According to CERT-In
The report also provides a detailed list of different types of cyber security incidents which need to be mandatorily reported within 6 hours of detection. A total of 20 types of security incidents are mentioned which are all recognized as serious cyber security threats by CERT-In. The security incidents are as follows:
Targeted scanning of systems
Critical systems and information compromise
Unauthorized access
Website intrusion
Malicious code and malware attacks
Server attacks
Phishing and identity theft
DoS and DDoS attacks
Attack on SCADA and critical infrastructure
Attack on E-Governance and E-Commerce
Data Breaching
Data Leaking
IoT attacks
Attack on digital payment systems
Attacks from mobile apps
Dummy mobile applications
Unauthorized access on social media
Attacks on cloud infrastructure
Attacks on virtual assets, blockchain, etc
Attacks on AI and ML applications
CERT-In is responsible for analysis and mitigation of cyber incidents and therefore, cyber attacks related to the above mentioned types should be mandatorily reported within 6 hours. However, it will create a challenge for some organizations due to lack of additional staff and management time.
We, a CERT-In empanelled agency, is the most preferred cyber security advisor that supports key public as well as private sector enterprises in the industry delivering state-of-the-art solutions on vulnerability and penetration testing (VAPT), managed security services, web application audit, NoC, SoC, SIEM/SOAR and many more. Our Anti-Ransomware Readiness (ARR) Audit is a combination of active and passive non-intrusive techniques that delivers a strong technical process to an organization to mitigate ransomware threats.
Do check our website www.primeinfoserv.com for more details or write us at info@primeinfoserv.com or contact us at +913340085677 for queries.
Raksha Bandhan celebrates one of the most cherished bonds—one built on love, trust, and protection. But in today’s digital world, protection means more than being there for your sibling. It also means helping them protect their personal data, digital
The deadline is fixed. The implementation window is shrinking. Is your organisation ready for India’s Digital Personal Data Protection (DPDP) regime? As of 24 August 2026, 262 days remain until 13 May 2027, when the principal operational provisions o
Thirty minutes with a practitioner rather than a salesperson. If the requirement somebody has handed you does not match what you actually need, that is a more useful thing to find out now than in week nine.