Has this company disclosed a cyber incident?
Enter a listed company's legal name.
What the check reads
The company's own letters to the National Stock Exchange under Regulation 30 of the SEBI listing regulations: the first disclosure, every update, any clarification the exchange asked for and the reply. Each answer links the filing itself. The time of filing is NSE's dissemination time, to the second. The time of the incident is whatever the letter says, in its words, and nothing else — not a press report, not a later estimate.
Most letters don't say when the incident happened. They say the company “has become aware” or “has detected” it. In that case the answer says so, and the gap isn't measured.
What the filings show
Since 1 January 2023, 50 companies listed on NSE have disclosed 53 cyber incidents between them. 19 of those letters give a date for the incident or for when the company learnt of it, and 4 give a time. Where a date is given, the median gap to the first filing is one day. In 3 cases the exchange itself asked the company for a clarification.
| Year | Incidents disclosed |
|---|---|
| 2023 | 15 |
| 2024 | 14 |
| 2025 | 12 |
| 2026 | 12 |
| Vertical | Incidents disclosed |
|---|---|
| Manufacturing | 16 |
| Healthcare/Wellness | 7 |
| Technology | 6 |
| Finance | 5 |
| Tourism/Hospitality | 5 |
| Energy/Resources | 4 |
| Insurance | 2 |
| Real Estate | 2 |
| Business Services | 1 |
| Education | 1 |
| Engineering | 1 |
| Food Production | 1 |
| Retail | 1 |
| Transportation | 1 |
No company is named in these counts, here or anywhere else in the scorecard. The check names only the company you ask about, from its own filing.
The clock is twelve hours, not twenty-four
Regulation 30(6) sets three limbs. A cyber incident emanates from within the listed entity, so it falls in limb (ii): disclosure within twelve hours. The twenty-four hours usually quoted is limb (iii), for events that arise outside the company.
- The clock runs from occurrence. Where a letter states only when the company became aware, detected or confirmed the incident, the check says which, and measures from that.
- Separately, Regulation 27(2)(ba) puts cyber incidents, breaches and loss of data into the quarterly corporate governance report with no materiality test, so an incident judged immaterial for Regulation 30 is still reported there.
Work out your own deadlines with the incident reporting clock, or read the LODR cyber disclosure obligations in full.
NSE corporate announcements, swept and read on , refreshed with each monthly edition of the scorecard. Regulation 30(6) and 27(2)(ba) as read from the consolidated SEBI LODR Regulations.