The Incident Response Dilemma in India
When a security incident occurs in India, security and legal teams face two distinct clocks running concurrently:
CERT-In Mandate (Cybersecurity Focus): Mandatory reporting within 6 hours of noticing cybersecurity incidents, ransomware attacks, or system intrusions.
DPDPA Section 8(6) (Personal Data Focus): Mandatory reporting of personal data breaches to the Data Protection Board of India (DPBI) and all impacted Data Principals within 72 hours.Failing either clock exposes the enterprise to severe regulatory sanctions from MeitY and financial penalties from the Board.
---
Dual-Clock Incident Workflow Matrix
| Hour | Action Item | Target Authority | Lead Team |
| :--- | :--- | :--- | :--- |
|
0–2 Hours | Incident detection, containment, and initial triage | Internal IR Team | SOC / InfoSec |
|
Hour 6 | Submit initial technical incident report |
CERT-In (cyber) | CISO / SecOps |
|
6–24 Hours | Automated Data Discovery & PII blast-radius scoping | Internal Vault | DPO / Security |
|
24–48 Hours | Identify affected Data Principals and severity classification | Legal Counsel | DPO / Legal |
|
Hour 72 | Submit statutory breach disclosure & principal notifications |
DPBI & End-Users | DPO / Executive |
---
Why Automated Breach Scoping is Essential
Manual database queries cannot determine personal data exposure within 24 hours. PrivacyOS integrates with data lakes and databases to calculate instantaneous blast-radius reports—identifying exact Aadhaar, PAN, and phone records impacted by compromised systems.