CERT-In Says Organisations Must Report Cybersecurity Breaches Within 6 Hours

CERT-In has asked all government and private agencies, including Internet service providers, social media platforms and data centres, to mandatorily report cyber security breach incidents to it within six hours of noticing them.

Advertisement
By Press Trust of India | Updated: 28 April 2022 18:08 IST
Highlights
  • The log should be provided to CERT-In
  • The move will help in fighting cybercrime more effectively
  • Some companies continued to ignore alerts

There have been several incidents of data breach in Indian entities that led to leak of personal data

CERT-In has asked all government and private agencies, including Internet service providers, social media platforms, and data centres, to mandatorily report cybersecurity breach incidents to it within six hours of noticing them.

The new circular, issued by the Indian Computer Emergency Response Team (CERT-In), mandates all service providers, intermediaries, data centres, corporates, and government organisations to mandatorily enable logs of all their ICT (Information and Communication Technology) systems and maintain them securely for a rolling period of 180 days, and the same shall be maintained within the Indian jurisdiction.

Advertisement

The log should be provided to CERT-In along with reporting of any incident or when directed by the computer emergency response team.

The move will help in fighting cybercrime more effectively, minister of state for electronics and IT Rajeev Chandrasekhar said in a tweet, asking all companies and enterprises "must mandatorily report cyber incidents to IndianCERT".

Advertisement

CERT-In is empowered under section 70B of the Information Technology Act to collect, analyse, and disseminate information on cybersecurity incidents.

CERT-In said that during the course of handling cyber incidents and interactions with the constituency, it has identified certain gaps causing hindrance in the analysis of breach incidents.

Advertisement

"To address the identified gaps and issues so as to facilitate incident response measures, CERT-In has issued directions relating to information security practices, procedure, prevention, response, and reporting of cyber incidents under the provisions of sub-section (6) of section 70B of the Information Technology Act, 2000. These directions will become effective after 60 days," Cert-In said.

According to the latest order, data centres, virtual private server (VPS) providers, cloud service providers, and virtual private network service (VPN Service) providers need to register the accurate information related to subscriber names, customer hiring the services, ownership pattern of the subscribers etc, and maintain them for five years or longer duration as mandated by the law.

Advertisement

"Many times during LEA (Law Enforcement Agency) requests and investigations, we have seen cases of non-storage or availability of data and proper records with intermediaries and service providers. These guidelines will streamline the date records to be maintained and proper reporting of security incidents to CERT-In," said Jiten Jain, Voyager Infosec director of digital lab.

There have been several incidents of data breach in Indian entities that have led to leak of personal data of crores of individuals.

Some companies continued to ignore alerts by cybersecurity researchers and acted only after the data was made public.

"End-user has the right to know if their data is loaded so that an individual can protect himself from fraud transactions, fake loans, ID misuse etc. Government should also force companies to inform their users within 24 hours of the incident. Neither CERT-In nor companies inform users. We saw a lot of data breaches last year. None of them informed their users. As a result, cybercrime, financial frauds and ID misuse have spiked," cybersecurity researcher Rajshekhar Rajaharia said.

He said that users are still unaware if their KYC (Know Your Customer) and financial data is safe or not.


Are affordable smartwatches worth it? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: CERT In, Cybersecurity
Advertisement

Related Stories

Popular Mobile Brands
  1. All in One Monster: Galaxy M17e 5G Packs Serious Power for Everyday Users
  2. OTT Releases This Week: Border 2, Peaky Blinders: The Immortal Man, Chiraiya, and More
  3. Lenovo Legion Y700 Gen 5 Launched With Snapdragon 8 Elite Gen 5 SoC, 9,000mAh Battery
  4. Nothing Phone 4a Pro Review: A Big Leap
  5. Realme P4 Lite 5G Launched in India With These Specifications
  6. Xiaomi Watch S5 With a 1.48-Inch AMOLED Display Arrives at This Price
  7. Samsung Galaxy Forever Offers Easy Upgrade, Return Option in India
  8. Microsoft Pauses Automatic Rollout of Microsoft 365 Copilot App on Windows
  9. You Can Now Simply Tap to Pause Reels on Instagram
  10. Xiaomi Book Pro 14 Debuts With a 72Wh Battery at This Price
  1. Google Announces New Sideloading Rules for Android With Developer Verification, Security Delay
  2. Blue Origin Announces NEO Hunter Mission to Track and Deflect Dangerous Asteroids
  3. Xiaomi Watch S5 Launched With 1.48-Inch AMOLED Display, Up to 21 Days of Battery Life: Price, Features
  4. Xiaomi Book Pro 14 Launched With Up to Intel Core Ultra X7 358H Processor, 72Wh Battery: Price, Features
  5. Samsung Galaxy Forever Programme Launched in India for Easy Upgrade with EMI and Return Options
  6. Adobe Introduces Custom Models in Firefly, Expands Access to Project Moonlight
  7. AI Chatbots Tend to Validate Users’ Messages About Suicide and Violence: Study
  8. Polymarket Acquires DeFi Startup Brahma to Strengthen Infrastructure
  9. Meta’s New Facebook Initiative Offers TikTok, YouTube Creators Increased Reach and Guaranteed Pay
  10. Instagram Rolls Out Tap-to-Pause Feature for Reels With More Control Over Playback
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.