Incident Response8 min readAugust 2026

Dual-Clock Breach Reporting: Navigating CERT-In 6-Hour and DPDPA 72-Hour Mandates

How Indian security and incident response teams must coordinate CERT-In and Data Protection Board incident notification timelines without creating regulatory exposure.

Vikram Malhotra

Vikram Malhotra

Chief Information Security Architect • PrivacyOS Global Research Desk

Dual-Clock Breach Reporting: Navigating CERT-In 6-Hour and DPDPA 72-Hour Mandates

The Incident Response Dilemma in India

When a security incident occurs in India, security and legal teams face two distinct clocks running concurrently:
  • CERT-In Mandate (Cybersecurity Focus): Mandatory reporting within 6 hours of noticing cybersecurity incidents, ransomware attacks, or system intrusions.
  • DPDPA Section 8(6) (Personal Data Focus): Mandatory reporting of personal data breaches to the Data Protection Board of India (DPBI) and all impacted Data Principals within 72 hours.
  • Failing either clock exposes the enterprise to severe regulatory sanctions from MeitY and financial penalties from the Board.

    ---

    Dual-Clock Incident Workflow Matrix

    | Hour | Action Item | Target Authority | Lead Team | | :--- | :--- | :--- | :--- | | 0–2 Hours | Incident detection, containment, and initial triage | Internal IR Team | SOC / InfoSec | | Hour 6 | Submit initial technical incident report | CERT-In (cyber) | CISO / SecOps | | 6–24 Hours | Automated Data Discovery & PII blast-radius scoping | Internal Vault | DPO / Security | | 24–48 Hours | Identify affected Data Principals and severity classification | Legal Counsel | DPO / Legal | | Hour 72 | Submit statutory breach disclosure & principal notifications | DPBI & End-Users | DPO / Executive |

    ---

    Why Automated Breach Scoping is Essential

    Manual database queries cannot determine personal data exposure within 24 hours. PrivacyOS integrates with data lakes and databases to calculate instantaneous blast-radius reports—identifying exact Aadhaar, PAN, and phone records impacted by compromised systems.
    Tags:#Breach Response#CERT-In#DPBI#Cybersecurity
    STAY AHEAD OF DPDPA RULES

    Prepare Your Systems For The 2027 DPBI Enforcement

    Evaluate consent banners, DSR portals, vendor DPAs, and data discovery with an interactive PrivacyOS platform walkthrough.