Cybersecurity threats are constantly evolving. Ransomware, phishing, software vulnerabilities, data breaches and attacks on cloud infrastructure can disrupt business operations and expose sensitive information. In India, the Indian Computer Emergency Response Team (CERT-In) plays a central role in coordinating responses to cyber incidents and providing organisations with guidance on preventing and managing cybersecurity threats.
Established under the Information Technology Act, 2000, CERT-In serves as India’s national agency for cyber incident response. Its statutory functions include collecting and analysing information on cyber incidents, issuing alerts, coordinating incident response and issuing guidelines, advisories, vulnerability notes and whitepapers relating to information security practices.
What Are CERT-In Advisories?
CERT-In regularly publishes advisories concerning emerging cybersecurity threats, vulnerabilities and recommended mitigation measures. These advisories may address specific software vulnerabilities, ransomware, phishing campaigns, emerging technologies or broader threats affecting organisations.
For example, CERT-In has issued advisories covering ransomware attacks, vulnerabilities in widely used software and emerging AI-driven cyber risks. Its advisories typically identify the threat, explain potential consequences and recommend practical security measures.
Businesses should therefore treat relevant CERT-In advisories as an important source of threat intelligence rather than waiting for an incident to occur before reviewing them.
CERT-In Cybersecurity Directions
In addition to advisories and guidelines, CERT-In has issued binding Cyber Security Directions under Section 70B of the Information Technology Act, 2000.
The Directions dated 28 April 2022 address information security practices, procedures for prevention and response, and reporting of specified cyber incidents. They apply to various categories of entities, including service providers, intermediaries, data centres, cloud service providers, VPS providers, VPN service providers, virtual asset service providers and government organisations, as applicable.
One of the important requirements is the reporting of specified cyber incidents to CERT-In within the prescribed timeframe. The Directions also require covered entities to maintain ICT logs securely for a rolling period of 180 days. Organisations should therefore ensure that their incident-response and logging practices are aligned with the applicable requirements.
Why Do CERT-In Guidelines Matter?
CERT-In’s guidelines provide organisations with practical recommendations for strengthening their cybersecurity posture. The guidance covers areas ranging from secure application development and cybersecurity audits to specific technologies and emerging threats.
For instance, CERT-In’s 2024 Secure Application Design, Development, Implementation & Operations Guidelinesprovide recommendations for building security into the application lifecycle. More recent guidance has addressed cybersecurity audits, smart-city infrastructure, software bills of materials and AI-related vulnerabilities.
CERT-In also publishes sector- and threat-specific guidance. Its 2025 advisory for businesses, for example, recommended measures including strong authentication, multi-factor authentication, role-based access controls, patch management, incident-response planning, continuous monitoring and employee cybersecurity training.
How Should Businesses Respond?
Businesses should establish a structured process for monitoring CERT-In advisories and determining which recommendations are relevant to their infrastructure.
Organisations should particularly focus on:
- regularly monitoring newly published CERT-In advisories;
- identifying vulnerabilities affecting their systems and software;
- applying security patches and updates promptly;
- maintaining appropriate access controls and MFA;
- preserving logs in accordance with applicable requirements;
- maintaining a documented cyber incident-response plan;
- conducting periodic security assessments and audits; and
- training employees to identify phishing, social engineering and other cyber threats.
Conclusion
CERT-In advisories and guidelines form an important part of India’s cybersecurity ecosystem. While an advisory may provide recommendations for addressing a particular threat, the CERT-In Cyber Security Directions establish specific obligations for covered entities.
Businesses should therefore distinguish between guidance, advisories and mandatory regulatory requirements while developing their cybersecurity programmes. Regular monitoring of CERT-In publications, combined with strong technical controls and an effective incident-response framework, can help organisations respond to emerging threats and strengthen their overall cyber resilience.
In today’s threat environment, cybersecurity compliance should not be treated as a one-time exercise. It requires continuous monitoring, timely action and ongoing improvement.
