A cybersecurity incident can disrupt business operations, compromise confidential information and cause significant financial and reputational damage. For organisations operating in India, responding to such incidents is not merely a technical exercise. Businesses must also understand their regulatory obligations, maintain appropriate security processes and ensure that incidents are reported and managed within prescribed timelines.
The Indian Computer Emergency Response Team (CERT-In) is India’s national agency for responding to computer security incidents. Under Section 70B of the Information Technology Act, 2000, CERT-In is responsible for functions including analysing cyber incidents, coordinating incident response, issuing security guidance and taking emergency measures for handling cybersecurity incidents.
What Is Incident Response?
Incident response refers to the structured process through which an organisation identifies, investigates, contains and recovers from a cybersecurity incident.
A comprehensive incident-response lifecycle generally involves four stages: preparation; detection and analysis; containment and eradication; and recovery and lessons learned. CERT-In’s guidance emphasises that preparation is critical to ensuring that an organisation can respond effectively when an incident occurs.
Organisations should therefore have a documented incident-response plan before an attack takes place. The plan should establish responsibilities, escalation mechanisms, communication procedures and the technical steps required to contain and recover from an incident.
Reporting Cyber Incidents to CERT-In
One of the most important organisational obligations arises under the CERT-In Cyber Security Directions dated 28 April 2022.
Covered entities are required to report specified cyber incidents to CERT-In within six hours of noticing the incident or being brought to notice of it. The framework covers incidents such as data breaches and data leaks, ransomware, phishing, attacks on critical systems and other specified categories.
The six-hour requirement makes early detection and internal escalation particularly important. Organisations should have clearly defined procedures for determining when an incident should be escalated to their cybersecurity, legal, compliance and senior-management teams.
Maintaining Logs and Evidence
Effective incident response depends heavily on the availability of reliable technical information. The CERT-In Directions require covered entities to maintain ICT system logs securely for a rolling period of 180 days.
Businesses should therefore ensure that logs are appropriately generated, synchronised, protected against unauthorised alteration and readily available when an incident needs to be investigated.
Organisations should also take care not to destroy or improperly alter potential evidence during an investigation. Proper evidence preservation can be important for determining the cause of an incident, assessing its impact and supporting regulatory or legal proceedings.
Internal Organisational Responsibilities
Incident response should not be treated as the sole responsibility of the IT department. A serious cyber incident can involve legal, regulatory, contractual, operational and reputational consequences.
Organisations should establish a cross-functional response structure involving IT and cybersecurity teams, legal and compliance personnel, senior management, communications teams and relevant business functions.
CERT-In’s guidance for government entities recommends a dedicated cybersecurity capability under appropriate leadership and emphasises coordination with relevant stakeholders and authorities.
Post-Incident Obligations
Incident response does not end once systems are restored. Organisations should conduct a post-incident review to determine the root cause, identify control failures and implement corrective measures.
CERT-In’s incident-response guidance specifically highlights recovery and lessons learned as an important phase of incident management.
Businesses should document what happened, how the incident was handled, what information was compromised and what measures will prevent recurrence.
Conclusion
Effective incident response requires organisations to combine technical preparedness with regulatory compliance and organisational coordination.
Businesses should maintain an updated incident-response plan, monitor their systems, preserve appropriate logs, establish clear escalation procedures and understand their CERT-In reporting obligations. Where a serious incident occurs, timely reporting, evidence preservation and coordinated containment can significantly reduce its impact.
Cybersecurity resilience is ultimately built before an incident occurs. Organisations that regularly test their response plans, train employees and learn from previous incidents are better positioned to protect their systems, comply with applicable requirements and maintain stakeholder trust.
