File 0001— CRISIS PROTOCOLS
Unclassified // Cleared for releaseThe First 48 Hours: the statutory clocks behind a corporate crisis in India
An Indian company that discovers a serious cyber incident may have six hours before its first legal deadline, and every public statement it makes has to fit the reports it files in the same hours.
- File
- PPR-001
- Kind
- paper
- Date filed
- Reading time
- 13 min
File 0002The paper
Key points
- The legal clock starts when the company first notices an incident or is told of it, which can be hours before the board hears.
- A listed cyber incident must be reported to CERT-In within six hours, and banks, payment system operators and insurers have six-hour rules of their own.
- A listed company must tell the stock exchange before the press: within 12 hours for a material event arising inside the company and 24 hours for one arising outside.
- The duty to tell the Data Protection Board and every affected person about a personal data breach is expected to start in mid-May 2027, with a detailed report due within 72 hours.
- A holding statement should carry only what is confirmed, because it can be read beside the reports filed with regulators in the same hours.
Prepared by ARKA's desk from public sources, not by lawyers. General information, not legal advice.
This paper sets out each deadline, who it binds and what starts it, and then what a company can say in public while the facts are still incomplete.
The clock starts before the board knows
The legal deadlines in a crisis start before the first press call, when the company first notices the incident or is told of it. CERT-In counts its six hours from the time a company notices an incident or has it brought to its notice [1]. The data protection rules, once in force, count from the moment the company becomes aware of a breach [2]. SEBI's guidance for listed companies goes furthest. An event that needs no approval, such as a disruption, has occurred when the company becomes aware of it, or as soon as an officer "has, or ought to have reasonably come into possession" of the information in the course of his duties, and an officer here includes a promoter [3].
The time that matters later may therefore be when an employee or a vendor first raised the alarm, which can be hours before the managing director heard. Which moment counts in law is a question for counsel, so record each one. CERT-In already requires synchronised system clocks and a rolling 180 days of logs, which helps the sequence to be reconstructed [1].
Six hours: CERT-In and the sector regulators
CERT-In's directions of 28 April 2022, issued under section 70B(6) of the Information Technology Act, 2000, apply to service providers, intermediaries, data centres, bodies corporate and government organisations. The twenty types of incident in Annexure I, among them data breaches, data leaks, ransomware, website defacement and unauthorised access to social media accounts, must be reported within six hours [1]. CERT-In's FAQ, which says of itself that it is not a legal document, applies the six-hour limit to listed incidents that are severe and hit public information infrastructure, are data breaches or leaks, are large in scale or among the most frequent, or affect human safety [4]. A hijacked brand handle is on the list; whether it meets that test is a call for counsel, inside the six hours.
Six hours is rarely enough to know what happened, and the FAQ accepts this: a company reports what it has and sends the rest within a reasonable time. The duty to report also overrides any confidentiality clause in a contract [4]. Failure to comply is punishable under section 70B(7) with up to a year's imprisonment, a fine, or both, and since 30 November 2023 the fine can reach one crore rupees [5]. The FAQ says the power will be used reasonably, where non-compliance is deliberate [4].
Regulated sectors have six-hour rules of their own.
- A commercial bank must report a cyber incident on the Reserve Bank's DAKSH platform within six hours of detection and notify CERT-In as well, under RBI directions of 31 July 2026. The directions also require communication plans for escalating incidents to the board, senior management and, as required, customers [6].
- An authorised non-bank payment system operator must report unusual incidents to the RBI within six hours of detection, under directions of 30 July 2024. These include outages of critical systems, internal fraud and settlement delays as well as cyber attacks. Small operators have until 1 April 2028 to comply [7].
- An insurer or other IRDAI-regulated entity must report a cyber incident to CERT-In within six hours of noticing it or being told of it, with a copy to IRDAI, under IRDAI's Information and Cyber Security Guidelines as revised in April 2026 [8]. An IRDAI circular of 24 March 2025 told regulated entities to empanel forensic auditors in advance [9]. The April 2026 guidelines do not repeat that requirement, so confirm with the insurer's compliance officer that it still stands.
Small finance banks, non-banking finance companies and market intermediaries have their own directions, which were not checked for this note.
Twelve and twenty-four hours: the listed company
Regulation 30 of SEBI's listing regulations requires a listed company to disclose a material event to the stock exchange as soon as reasonably possible. The outer limits are 30 minutes from the close of the board meeting that decided the matter, 12 hours if the event arose inside the company, and 24 hours if it arose outside. Since December 2024 a board meeting that closes after trading hours, and more than three hours before the next session opens, has three hours [10].
SEBI's table of timelines, carried in its master circular of 30 January 2026, gives 24 hours for fraud or default by the company, its promoter, a director, key managerial personnel, senior management or a subsidiary, for the arrest of a promoter, director, key managerial person or senior manager, and for a search or seizure by an authority. A disruption of operations by natural calamity, strike or lockout also has 24 hours if it is material [3]. A cyber incident is not named in the table, so whether one needs immediate disclosure turns on materiality. Separately, since July 2023 details of cyber security incidents, breaches and loss of data or documents have had to be disclosed with the quarterly corporate governance report [10].
Two points bear on communications. The regulation says the exchange must be told first, so the filing comes before the press release [10]. And under entry 18 of the table, if a director, promoter, key managerial person or senior manager announces material information on social media or in the mainstream media before the company has made it public, the company must disclose it within 24 hours, which means an unscripted post by a promoter during a crisis can create a filing duty [3].
The 250 largest listed companies by market capitalisation are also bound by the rumour rule, in force for the top 100 since 1 June 2024 and for the next 150 since 1 December 2024 [3]. When a mainstream media report of a specific impending event is followed by a material movement in the share price, the company must confirm, deny or clarify the report within 24 hours of that movement, and a confirmation must state the current stage of the event [10].
Without delay and seventy-two hours: personal data
The Digital Personal Data Protection Act, 2023 requires a Data Fiduciary to inform both the Data Protection Board and each affected person of a personal data breach. The definition is wide: it covers unauthorised processing, accidental disclosure, and loss of access to personal data that compromises its availability [11]. On a plain reading that takes in a ransomware attack that locks records without copying them.
Rule 7 of the Digital Personal Data Protection Rules, 2025 sets the timing. On becoming aware of a breach, the company must tell each affected person without delay, in a concise, clear and plain manner. The notice has five parts: a description of the breach, the consequences likely for her, what the company is doing to reduce the risk, what she can do to protect herself, and a business contact who can answer questions. The Board gets a first description without delay and a detailed report within 72 hours of the company becoming aware, unless it allows longer on a written request [2].
The rule has no threshold: it speaks of any breach and each affected person [2]. The Act's Schedule sets a penalty of up to ₹200 crore for failing to give notice [11].
The duty is not yet in force. The Rules are dated 13 November 2025 and rule 7 comes into force eighteen months after their publication in the Gazette, which points to mid-May 2027; the Rules give a period and no calendar date [2]. On 12 August 2026 the Government told the Lok Sabha that breach notification falls in the third phase, within eighteen months [12]. In January 2026 Business Standard reported, on unnamed sources, that the ministry was considering a cut to twelve months for key provisions [13]. So far as we could find, no such amendment had been notified by early October 2026. If one is, the duty starts sooner, so the date needs checking again before it is relied on.
Until rule 7 starts, a data breach still has to be reported to CERT-In within six hours [1]. After that the two duties run side by side. The Act applies in addition to other laws [11], and neither it nor the Rules treats a report to CERT-In as notice to the Board [2][11].
The clocks in one table
| Window | Who is bound | What must happen | Source |
|---|---|---|---|
| 30 minutes, or 3 hours after trading hours | Listed companies | File a material board decision with the exchange, from the close of the meeting | [10] |
| 6 hours | Bodies corporate, service providers, intermediaries, data centres, government organisations | Report a listed cyber incident to CERT-In | [1][4] |
| 6 hours | Commercial banks, non-bank payment system operators, IRDAI-regulated entities | Report to the RBI, or copy the CERT-In report to IRDAI | [6][7][8] |
| 12 hours | Listed companies | File a material event that arose inside the company | [10] |
| 24 hours | Listed companies | File a material event that arose outside; also fraud, arrest, search or seizure, and a material disruption | [3][10] |
| 24 hours from a material price movement | Top 250 listed companies | Confirm, deny or clarify a specific media report | [3][10] |
| Without delay (expected from mid-May 2027) | Data Fiduciaries | Tell each affected person and give the Board a first description | [2] |
| 72 hours (expected from mid-May 2027) | Data Fiduciaries | Detailed report to the Board | [2] |
The order of telling
The deadlines settle most of the sequence. The incident lead and the company's lawyers come first, to fix the time of awareness and decide which clocks apply. The six-hour reports to CERT-In and any sector regulator follow, with whatever is known, and the board is told in the same window. For a listed company, a board meeting that decides anything material starts the 30-minute clock when it closes, and the exchange is told ahead of any press statement [10].
Employees should hear shortly before the public statement goes out. They will be asked, and need a paragraph they can repeat and the name of the company's spokesperson. Affected customers should be told directly. Once rule 7 is in force that will be a legal duty with prescribed contents [2], and until then it is still better that they hear it from the company than read it elsewhere. Lenders, insurers and large counterparties may have notice clauses in their contracts, to be read on the first day. The press and the wider public come last, though these later steps often fall close together.
What a holding statement may and may not say
A holding statement can say that an incident was detected and when, which service or site is affected, and what has been done: systems isolated, specialists engaged, authorities informed, if each of those is true. It should tell affected people what to do now, give the time of the next update and name a contact for questions.
It should leave out the cause and the culprit until forensic work supports them. A line such as "no customer data was affected" belongs in a statement only once it has been verified, and the same holds for any number. Blaming a vendor or an employee by name invites a dispute before the facts are known.
Every public sentence in the first 48 hours can later be read beside the reports filed with regulators in the same hours.
Under rule 7 the detailed report to the Board must include a report on the notices given to affected people [2], so once the rule is in force customer notices become part of the regulatory record.
The cost of speculation and of silence
CERT-In accepts that a first report will be incomplete [4], and rule 7 is built on a first description followed by a detailed report [2]. A confident public claim made on the same partial facts has to be corrected in public, and the correction becomes a second story.
Silence has statutory costs. A top-250 listed company cannot stay quiet beyond 24 hours once its share price has moved materially on a specific report [10]. Under the data protection Act, failing to give notice is a separate breach, and in fixing a penalty the Board must weigh whether the company acted to limit the damage and how quickly [11]. There is an ordinary cost too: when a company says nothing, customers and reporters work from whatever else is circulating.
The position between the two is to say early what is confirmed and what is not yet known, then name the time of the next update and keep to it.
Where a communications desk fits
ARKA's Overwatch desk works on the communications side of this map: holding statements, the order of telling, stakeholder and media briefing, and monitoring. It does not give legal advice or make statutory filings. Those belong to the company and its counsel.
What to do with this
A board can adopt these as a one-page protocol.
- Define who can declare an incident and where the time of awareness is recorded.
- Keep a register of every clock that applies to the company, with the form, the portal and the named person who files.
- Confirm that the company's point of contact with CERT-In is registered and current [1].
- Authorise named officers to file the six-hour reports without waiting for a board meeting.
- If the company is listed, seat the compliance officer in the crisis team and tell directors and promoters that their public remarks can trigger a disclosure.
- Hold pre-drafted texts with blanks: a holding statement, an employee note, and a customer notice built on the five parts in rule 7.
- Retain a forensic firm and outside counsel in advance.
- Keep one time-stamped log of every filing and every external statement, and check each new statement against it.
- Rehearse once a year against the clock. Put mid-May 2027 in the board calendar for the data breach rules, and check each quarter whether the date has been brought forward.
Sources
- Directions under sub-section (6) of section 70B of the Information Technology Act, 2000 relating to information security practices, procedure, prevention, response and reporting of cyber incidents for Safe & Trusted Internet (No. 20(3)/2022-CERT-In) (opens in a new tab)
Indian Computer Emergency Response Team (CERT-In), Ministry of Electronics and Information Technology
Dated 28 April 2022 // Read 2026-10-04
- Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)) (opens in a new tab)
Ministry of Electronics and Information Technology, Gazette of India
Dated 13 November 2025 // Read 2026-10-04
- Master Circular for compliance with the provisions of the Securities and Exchange Board of India (Listing Obligations and Disclosure Requirements) Regulations, 2015 by listed entities (HO/49/14/14(7)2025-CFD-POD2/I/3762/2026): Section V-AA, Annexure 18A and Annexure 19 (opens in a new tab)
Securities and Exchange Board of India
Dated 30 January 2026 // Read 2026-10-04
- Frequently Asked Questions on Cyber Security Directions of 28.04.2022 (opens in a new tab)
Indian Computer Emergency Response Team (CERT-In)
Dated May 2022 // Read 2026-10-04
- Office Memorandum F. No. 2(1)/2022-CL: Gazette notifications regarding the date on which the provisions of the Jan Vishwas (Amendment of Provisions) Act, 2023 relating to the Information Technology Act, 2000 come into force (with section 70B(7) as amended) (opens in a new tab)
Ministry of Electronics and Information Technology, Government of India
Dated 3 November 2023 // Read 2026-10-04
- Reserve Bank of India (Commercial Banks - Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 (RBI/DoS/2026-27/410) (opens in a new tab)
Reserve Bank of India
Dated 31 July 2026 (updated as on 1 October 2026) // Read 2026-10-04
- Master Directions on Cyber Resilience and Digital Payment Security Controls for non-bank Payment System Operators (RBI/DPSS/2024-25/123) (opens in a new tab)
Reserve Bank of India
Dated 30 July 2024 // Read 2026-10-04
- IRDAI Information and Cyber Security Guidelines, Version 2.0 (opens in a new tab)
Insurance Regulatory and Development Authority of India (copy hosted at medianama.com)
Dated April 2026 // Read 2026-10-04
- Regarding Cyber Incident or Crisis Preparedness (Ref No: IRDAI/GA&HR/CIR/MISC/49/03/2025) (opens in a new tab)
Insurance Regulatory and Development Authority of India
Dated 24 March 2025 // Read 2026-10-04
- Securities and Exchange Board of India (Listing Obligations and Disclosure Requirements) Regulations, 2015 [Last amended on July 14, 2026]: regulations 27(2)(ba), 30(6) and 30(11) (opens in a new tab)
Securities and Exchange Board of India
Dated 14 July 2026 // Read 2026-10-04
- The Digital Personal Data Protection Act, 2023 (No. 22 of 2023) (opens in a new tab)
Ministry of Law and Justice, Gazette of India (copy on meity.gov.in)
Dated 11 August 2023 // Read 2026-10-04
- Lok Sabha Unstarred Question No. 3943: Implementation of Rules under DPDP Act, 2023 (opens in a new tab)
Ministry of Electronics and Information Technology, Government of India (Lok Sabha)
Dated 12 August 2026 // Read 2026-10-04
- Meity may cut compliance timeline for key DPDP rules to 12 months (opens in a new tab)
Business Standard
Dated 22 January 2026 // Read 2026-10-04
This note is general information as of the date it was filed. It is ARKA's reading of public sources, prepared by a communications and advisory firm and not by lawyers. It is not legal, tax or investment advice; take advice on your own facts from a qualified professional.
File 0003— Open a channel
Discuss this paper
Sending an enquiry does not bind you to anything. It opens a confidential conversation.