Threat data · disclosure check

Has this company disclosed a cyber incident?

Enter a listed company's legal name.

What the check reads

The company's own letters to the National Stock Exchange under Regulation 30 of the SEBI listing regulations: the first disclosure, every update, any clarification the exchange asked for and the reply. Each answer links the filing itself. The time of filing is NSE's dissemination time, to the second. The time of the incident is whatever the letter says, in its words, and nothing else — not a press report, not a later estimate.

Most letters don't say when the incident happened. They say the company “has become aware” or “has detected” it. In that case the answer says so, and the gap isn't measured.

What the filings show

Since 1 January 2023, 50 companies listed on NSE have disclosed 53 cyber incidents between them. 19 of those letters give a date for the incident or for when the company learnt of it, and 4 give a time. Where a date is given, the median gap to the first filing is one day. In 3 cases the exchange itself asked the company for a clarification.

YearIncidents disclosed
202315
202414
202512
202612
Cyber incidents disclosed to NSE, by year of first filing
VerticalIncidents disclosed
Manufacturing16
Healthcare/Wellness7
Technology6
Finance5
Tourism/Hospitality5
Energy/Resources4
Insurance2
Real Estate2
Business Services1
Education1
Engineering1
Food Production1
Retail1
Transportation1
Cyber incidents disclosed to NSE, by scorecard vertical

No company is named in these counts, here or anywhere else in the scorecard. The check names only the company you ask about, from its own filing.

The clock is twelve hours, not twenty-four

Regulation 30(6) sets three limbs. A cyber incident emanates from within the listed entity, so it falls in limb (ii): disclosure within twelve hours. The twenty-four hours usually quoted is limb (iii), for events that arise outside the company.

  • The clock runs from occurrence. Where a letter states only when the company became aware, detected or confirmed the incident, the check says which, and measures from that.
  • Separately, Regulation 27(2)(ba) puts cyber incidents, breaches and loss of data into the quarterly corporate governance report with no materiality test, so an incident judged immaterial for Regulation 30 is still reported there.

Work out your own deadlines with the incident reporting clock, or read the LODR cyber disclosure obligations in full.

NSE corporate announcements, swept and read on , refreshed with each monthly edition of the scorecard. Regulation 30(6) and 27(2)(ba) as read from the consolidated SEBI LODR Regulations.

This report counts other people. Find out what yours says.

Your organisation already has a security rating, calculated from signals anyone can see — including the suppliers in the verticals above. Request the complimentary Cyber Risk Rating Report and find out what it says — as little as 45 minutes for publicly listed entities, up to 48 hours for all others. No agent, no system access, no questionnaire.

Request my rating →See supplier monitoring