Post

Navigating the Global Maze of Cyber Incident Reporting: An Indian Perspective

Navigating the Global Maze of Cyber Incident Reporting: An Indian Perspective

As of mid-2026, organisations operating globally face a complex and often divergent landscape of cybersecurity incident reporting obligations. For Indian businesses, general counsels, and Data Protection Officers (DPOs), understanding these nuances is critical, especially with India’s own Digital Personal Data Protection Act (DPDPA) 2023 now in force and existing frameworks like the CERT-In Directions maturing. This analysis anchors on the Indian regime, comparing it against the European Union’s NIS2 Directive and the U.S. Securities and Exchange Commission (SEC) cyber rules.

Diverse Reporting Triggers and Timelines

India’s cybersecurity incident reporting regime, primarily driven by the Indian Computer Emergency Response Team (CERT-In) Directions issued under Section 70B of the Information Technology Act, 2000, stands out for its stringent timelines. These directions mandate that all service providers, data centres, body corporates, and government organisations report a wide array of cyber incidents, including data breaches, system compromises, and ransomware attacks, within six hours of becoming aware of them. For other specified incidents, reporting is required “as soon as possible.” This six-hour window is among the tightest globally. Complementing this, the Reserve Bank of India (RBI) Master Direction on IT Governance, Risk, Controls, and Operations imposes similar six-hour reporting requirements for significant cyber incidents on regulated financial entities. Furthermore, under the DPDPA 2023, Section 22 requires Data Fiduciaries to notify the Data Protection Board of India (DPBI) and affected Data Principals of a personal data breach “without undue delay,” with specific timelines expected to be prescribed in forthcoming rules, likely aligning with or being stricter than the 72-hour benchmark seen in other jurisdictions.

In contrast, the EU’s NIS2 Directive (Directive (EU) 2022/2555), which Member States were required to transpose by October 2024, adopts a two-stage reporting approach for “significant incidents” (Article 23). An “early warning” is due within 24 hours of becoming aware of a significant incident, followed by an “incident notification” within 72 hours, updating the initial assessment. A final report is then required within one month. The U.S. SEC’s rules, effective since late 2023, require publicly traded companies to disclose “material cybersecurity incidents” on Form 8-K within four business days of determining the incident’s materiality (Item 1.05 of Form 8-K). This timeline is significantly longer than India’s and is contingent on a subjective materiality assessment.

Scope and Thresholds for Incident Reporting

The scope of incidents requiring reporting also varies considerably. CERT-In’s Directions cover a broad spectrum of technical incidents, from targeted scanning and attacks on servers to data breaches and phishing attacks, without an explicit “materiality” or “significance” threshold for initial reporting to the authority. The DPDPA 2023, however, specifically focuses on “personal data breaches” where there is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

NIS2 focuses on “significant incidents” that have caused or are capable of causing severe operational disruption, financial loss, or affecting other entities. This introduces a threshold of impact that must be met before reporting is triggered. The SEC rules are even more explicit about a materiality threshold: an incident must be reported only if it is determined to be material to the company’s business, operations, or financial condition. This determination, guided by Regulation S-K Item 106, can involve a subjective judgment and potentially delay public disclosure. Consequently, India’s CERT-In regime is generally stricter by requiring reporting for a wider array of technical incidents without a high impact threshold, whereas NIS2 and SEC rules introduce elements of significance or materiality that can limit reporting obligations.

Public Disclosure vs. Regulator Notification

A key divergence lies in the primary recipient and nature of the disclosure. Under CERT-In Directions and RBI guidelines, the obligation is primarily to notify the respective government authority or regulator. While these authorities may aggregate or publish anonymised data, direct public disclosure of specific incidents by the reporting entity is not the immediate or primary requirement unless it involves a personal data breach under DPDPA. In such cases, the DPDPA mandates notification to affected Data Principals, similar to the EU’s GDPR.

The SEC rules, conversely, are fundamentally about public disclosure to investors. The Form 8-K filing makes the incident publicly known to the market. While this promotes transparency for investors, it allows companies to omit certain technical details or remediation steps if disclosure would impede remediation or investigation, especially if concurred by the Department of Justice. NIS2 primarily requires notification to national CSIRTs or competent authorities, with public disclosure generally only mandated if the incident is likely to cause substantial public concern or adversely affect public services, or if the authority deems it necessary.

Information Specificity and Remediation

The information required in incident reports also reflects the different objectives of these frameworks. CERT-In requires detailed technical information, including indicators of compromise, impact, and actions taken, facilitating a coordinated national cybersecurity response. NIS2 also demands comprehensive details on the nature, severity, impact, and cross-border implications of the incident, with updates as more information becomes available.

The SEC rules, while requiring disclosure of the nature, scope, timing, and material impact, allow for less technical specificity in public filings. This flexibility is intended to prevent further harm or compromise ongoing investigations, a trade-off for the public nature of the disclosure. Indian entities operating under multiple regimes must therefore be prepared to provide varying levels of detail to different stakeholders, from highly technical reports to CERT-In to more impact-focused disclosures for investors under SEC rules.

Practical Takeaway

For Indian businesses, GCs, and DPOs, navigating this global reporting landscape necessitates a robust, multi-layered incident response framework. The stringent six-hour reporting window under CERT-In and RBI norms means that rapid detection, assessment, and internal escalation capabilities are paramount. Companies must develop clear internal protocols for determining incident type, assessing potential impact (including DPDPA-relevant personal data breaches), and identifying the appropriate reporting authority and timeline. For those with global operations, integrating these diverse requirements into a unified incident response plan is crucial. This involves understanding the different thresholds (e.g., CERT-In’s broad technical scope vs. SEC’s materiality), the nature of disclosure (regulator vs. public), and the specific information required by each jurisdiction to ensure compliance and mitigate legal and reputational risks.

This post is licensed under CC BY 4.0 by the author.