Tool 1

What an NBFC must report after a ransomware attack

Work out every regulatory notification an Indian entity owes after a cyber incident, as wall-clock IST deadlines — CERT-In, the seven RBI Directions, SEBI CSCRF and LODR, IRDAI and NCIIPC, each with the clause it comes from.

In short
An Indian entity that notices a cyber incident owes CERT-In a report within six hours. RBI regulated entities file on DAKSH within six hours of detection; SEBI entities file to SEBI and CERT-In within six hours, then the portal within twenty-four. IRDAI is six hours, with no second step. A listed entity owes the exchanges twelve hours. DPDP does not commence until 13 May 2027.

What this case turns on

An NBFC files under RBI/DoS/2026-27/461, not the Commercial Banks Directions at 410 — the single most common citation error in this area. Which chapter applies turns on the scale-based layer, and it decides whether a DAKSH filing is owed at all: a Base Layer NBFC below ₹500 crore carries no such clause, while CERT-In’s six hours binds it regardless. Ransomware falls squarely inside CERT-In Annexure I as a malicious code attack.

InstrumentWhat you fileWindowStarts from
CERT-In Directions, 2022Report the incident to CERT-In6 hours from noticing, or being brought to noticeNoticing, or being brought to notice
RBI Cyber Directions, 2026 — Non-Banking Financial CompanyReport the cyber incident on the DAKSH platform6 hours from detectionDetection
DPDP Act, 2023 and DPDP Rules, 2025Intimation to affected Data Principals, and a two-stage report to the Data Protection BoardNot in force
Every filing owed on this scenario, with the window each one runs for.

Adjust it to your own facts

The tool below opens on this scenario. Change anything that does not match your entity, and add the moment you noticed to turn the windows into wall-clock IST deadlines.

Your entity
When you noticed
2filings owed — windows from each trigger
InstrumentWhat you fileWindowGoes to
CERT-In Directions, 2022No. 20(3)/2022-CERT-InReport the incident to CERT-Inwithin 6 hours of noticing such incidents or being brought to notice about such incidents6 hours from noticing, or being brought to noticefrom: noticing, or being brought to noticeCERT-Inincident@cert-in.org.in · 1800-11-4949
RBI Cyber Directions, 2026 — Non-Banking Financial CompanyRBI/DoS/2026-27/461 · Chapter V, para 141Report the cyber incident on the DAKSH platformshall report cyber incidents within six hours of detection on DAKSH platformOne of seven parallel Directions issued on 31 July 2026, one per entity class. Quote this instrument and its own paragraph number — the numbering differs between them.6 hours from detectionfrom: detectionReserve Bank of Indiadaksh.rbi.org.in
DPDP Act, 2023 and DPDP Rules, 2025G.S.R. 846(E) · Rule 7 · G.S.R. 843(E), section 8Intimation to affected Data Principals, and a two-stage report to the Data Protection BoardNot in force. Rule 7 falls in the eighteen-month tranche under Rule 1(4), and section 8 commences on the same date — 13 May 2027. There is no DPDP breach clock running on an incident today. Plan and rehearse against it; do not file against it.Not in forceData Principals and the Data Protection Board of India

Indicative, and not legal advice. Whether an instrument applies to a particular entity, and whether an event is a reportable incident, are determinations for your compliance and legal team. Verify every citation against the published text before a notification is filed.

Take this away as an escalation pack

Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, the owner columns your incident file needs, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.

For the full picture — every clock, how they overlap, and the standing obligations that decide how the first six hours go — see the complete incident reporting clock.

This page is indicative and is not legal advice. Whether an instrument applies to your entity, and whether an event is a reportable incident, are determinations for your compliance and legal team. Every instrument cited here was verified against the issuing regulator's own notification on .

Questions this page answers

How long do you have to report a cyber incident in India?
Six hours to CERT-In, from noticing the incident or being brought to notice of it. Most sectoral clocks are also six hours: RBI regulated entities report on DAKSH within six hours of detection, SEBI regulated entities notify SEBI and CERT-In within six hours, and insurers report to CERT-In within six hours copied to IRDAI. A listed entity separately owes its stock exchanges a disclosure within twelve hours where the incident is material.
Does the six-hour clock start when an incident is confirmed?
No. The CERT-In Directions run from noticing the incident or being brought to notice of it, which means a vendor, a researcher or a regulator telling you starts the clock exactly as your own alerting does. The RBI Directions run from detection. In neither case does an incomplete investigation pause the clock — draft on what is known, mark the unknowns as under investigation, and file the update.
Is the SEBI LODR deadline for a cyber incident 12 hours or 24 hours?
Twelve hours. Regulation 30(6) sets twelve hours for an event emanating from within the listed entity and twenty-four for an event arising outside it. A ransomware event, data breach or IT outage originates within the entity, so it falls in the twelve-hour limb. The twenty-four hour figure is the one most commonly repeated, and quoting it puts the disclosure twelve hours late.
Does the DPDP Act require breach notification within 72 hours today?
No. Rule 7 of the DPDP Rules, 2025 and section 8 of the Act both commence eighteen months after the Rules were notified on 13 November 2025, which is 13 May 2027. There is no DPDP breach-intimation clock running on an incident today. The regime is worth planning and rehearsing against, but a notification filed against it now is filed against an obligation that has not commenced.
How long does a GIFT City entity have to report a cyber incident?
Six hours from detection, to the Authority at cyber-incidents@ifsca.gov.in with a copy to the CISO, IFSCA, under the IFSCA Guidelines on Cyber Security and Cyber Resilience of 10 March 2025. The obligation then continues: an interim report at three days, mitigation measures at seven, and a detailed root cause analysis at thirty. An IFSC licence displaces the mainland regulator, so a GIFT City banking unit does not file under the RBI Directions — but CERT-In still binds it.
Which RBI Direction applies to an NBFC after a cyber incident?
RBI/DoS/2026-27/461, the Non-Banking Financial Companies instrument — not the Commercial Banks Directions at 410. Its chapters are graded: a Base Layer NBFC below ₹500 crore sits under Chapter III, which carries no six-hour DAKSH clause at all, while Chapter IV covers Base Layer at ₹500 crore and above and Chapter V covers the Middle, Upper and Top Layers. CERT-In’s six hours binds every one of them.

This tool is one skill out of sixteen.

What runs on this page is the browser-sized version of incident-notify, a skill in BitScoreCoWork — our MIT-licensed Claude plugin. The full version runs against your own Bitsight tenancy and works from your measured attack surface rather than a form. The source is public, so you can read exactly what it does before you run it.

Read the source The Applied AI practice

Knowing the rule is the easy half.

This page tells you what you owe. It cannot tell you what an attacker already sees. Your organisation has a security rating calculated from signals visible from outside — request the complimentary Cyber Risk Rating Report and find out what it says. No agent, no system access, no questionnaire.

Request my rating All free tools