One incident.Three clocks start at once.
CERT-In counts in hours. The RBI has its own reporting. DPDPA adds the Board and every affected customer.
In one line: A cyber incident may need reporting to CERT-In under its 2022 directions, and a personal data breach must also be intimated to the Data Protection Board and each affected Data Principal under DPDPA and the Rules. Sectoral reporting to the RBI may apply as well.
The breach is one event. The reporting is three exams, sat at the same time.
The scene
The alert came at 2am. By 8am the CISO had told CERT-In, as the 2022 directions require within six hours. By noon the RBI team had filed their incident report. At four in the afternoon someone asked whether the forty thousand customers whose statements were exposed had been told. Nobody had been asked to do that.
Where the thinking breaks
Designing one playbook
Map the three regimes side by side: trigger, recipient, timeline, content. Where they overlap, draft once. Where they differ, assign an owner. Rehearse the whole thing against a single scenario, with a stopwatch.
Monday morning
- 01Put CERT-In, RBI and DPDPA timelines on one page.
- 02Pre-draft the customer notice in English and one regional language.
- 03Run a two-hour drill where all three clocks start together.
Questions, answered plainly
Does a bank need to report a data breach to both CERT-In and the Data Protection Board?
A cyber incident may need reporting to CERT-In under its 2022 directions, and a personal data breach must also be intimated to the Data Protection Board and each affected Data Principal under DPDPA and the Rules. Sectoral reporting to the RBI may apply as well.
What is the CERT-In reporting timeline?
CERT-In's April 2022 directions require specified cyber security incidents to be reported within six hours of noticing them.
Tell us where your data sits.We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner