A data breach can expose sensitive customer information, employee records, financial information, credentials and other confidential data. With businesses increasingly dependent on digital systems, responding to a breach is no longer limited to containing the technical problem. Organisations must also understand their regulatory reporting and notification obligations.
In India, the Indian Computer Emergency Response Team (CERT-In) plays a central role in the reporting and management of cybersecurity incidents. Its Cyber Security Directions issued under Section 70B of the Information Technology Act, 2000 establish reporting requirements for specified cyber incidents, including data breaches and data leaks.
What is a Data Breach?
A data breach occurs when personal or confidential information is accessed, disclosed, altered, lost or obtained without proper authorisation. A breach may result from a successful cyberattack, ransomware, compromised credentials, insider activity, misconfigured cloud storage or even accidental disclosure.
For example, if an employee unintentionally sends a customer database to an unauthorised recipient, the incident may require investigation and appropriate reporting even though there was no deliberate cyberattack.
Reporting to CERT-In
Under the CERT-In Cyber Security Directions, covered entities are required to report specified cyber incidents to CERT-In within six hours of noticing the incident or being brought to notice of it. Data breaches and data leaks are specifically included among the incidents subject to this reporting requirement.
Importantly, an organisation does not necessarily need to wait until every detail of an incident has been established before making the initial report. CERT-In’s FAQs clarify that entities may provide the information available at the time of reporting and submit additional information subsequently within a reasonable period.
This makes early detection and internal escalation particularly important.
What Information Should Be Reported?
CERT-In’s incident-reporting framework contemplates information such as the time of occurrence, affected systems or networks, symptoms observed and relevant technical information, including security measures and actions taken to mitigate the incident.
Organisations should therefore maintain appropriate logs and incident records so that relevant information can be identified quickly when an incident occurs.
Notification to Affected Individuals
Regulatory reporting and communication with affected individuals are separate considerations.
CERT-In advisories concerning data breaches have recommended notifying affected users or customers promptly, explaining the information compromised, measures being taken to address the incident and protective steps that individuals can take.
Depending on the organisation, the nature of the data and the applicable legal framework, additional notification requirements may arise under privacy, sectoral or contractual obligations.
Preparing for a Data Breach
Businesses should not develop their breach-response process after an incident has already occurred. A documented incident response plan should establish who is responsible for identifying, investigating, containing and reporting a breach.
Organisations should also:
- maintain an updated inventory of critical systems and data;
- implement appropriate access controls and authentication;
- continuously monitor security logs;
- establish an internal escalation mechanism;
- preserve relevant evidence and logs;
- maintain contact details for regulatory reporting;
- conduct periodic incident-response exercises; and
- review contractual obligations relating to vendors and service providers.
CERT-In’s cybersecurity guidance also emphasises preparation, detection, containment, recovery and lessons learned as important stages of incident management.
Conclusion
A data breach requires both technical and legal response. Organisations must act quickly to contain the incident while simultaneously assessing applicable reporting and notification obligations.
For entities covered by the CERT-In Directions, the six-hour reporting requirement makes preparedness especially important. A well-designed incident-response framework, supported by effective monitoring, clear internal responsibilities and accurate record-keeping, can help businesses respond efficiently when a breach occurs.
Ultimately, effective breach management is not simply about recovering systems. It is about detecting incidents early, protecting affected individuals, complying with reporting obligations and learning from the incident to prevent recurrence.
