+91 98726 60544 hello@mitstech.co Mon–Sat · 09:00–18:30 IST

CERT-In's six-hour breach reporting rule

Security By Mits Engineering Team 3 min read
CERT-In's six-hour breach reporting rule

CERT-In Direction No. 20(3)/2022, issued on 28 April 2022 and effective sixty days later, requires organisations to report specified cyber incidents within six hours of noticing them, or of being made aware of them. Six hours is the number everyone remembers and almost nobody has planned for. It is shorter than a working day, shorter than most escalation chains, and considerably shorter than the time an engineering team typically spends establishing whether something is an incident at all.

That is the real difficulty. The clock starts at noticing, not at confirming. A team that waits for root cause before reporting will miss the window every time, because root cause on a serious incident is a multi-day exercise. The organisations that comply are the ones that decided in advance that a named person can file a report on partial information, and that filing early and updating later is the expected behaviour rather than an admission of incompetence. That is a management decision made on a calm day, not a technical one made at two in the morning.

The direction carries obligations beyond reporting, and these are the ones that get missed because they are infrastructure rather than incident response. All ICT systems must synchronise their clocks to the Network Time Protocol server of the National Informatics Centre or the National Physical Laboratory. This sounds trivial until you try to reconstruct a timeline across a dozen services whose clocks disagree by seconds — at which point it is the difference between an investigation and a guess.

Logs must be enabled and maintained securely for a rolling period of 180 days, and they must be kept within Indian jurisdiction. Both halves matter. Many teams retain thirty days because that is the default on their logging vendor's plan, and many teams retain them in whichever region the vendor defaulted to. Neither is a decision anyone made deliberately, and both are non-compliant. Fixing retention is usually a billing conversation; fixing jurisdiction is sometimes a migration.

Providers of VPN, cloud and data centre services carry a heavier obligation: registration details and accurate subscriber information must be retained for five years, or longer where other law requires it, after a customer cancels. Virtual asset service providers must maintain KYC documentation and records of financial transactions for the same five-year period, aligned to the RBI's 2016 KYC Directions, the SEBI circular of 24 April 2020 and the DoT notice of 21 September 2021.

Non-compliance may invite punitive action under sub-section (7) of Section 70B of the Information Technology Act, 2000, alongside any other applicable law. In our experience the enforcement risk is not the main argument for getting this right, though. The main argument is that an organisation which can report accurately within six hours is one that knows what its systems are doing — and that capability pays for itself in every incident, reportable or not.

If you want a practical starting point: name the person who can file, write down the two or three facts they need before filing, confirm your NTP source, and check what your logging retention and log storage region actually are today rather than what you believe them to be. That is an afternoon's work and it covers most of the gap.

Need help with this? Explore our Cybersecurity & Compliance services. Learn more Back to all news

Keep reading

More on Security