Tool 6

Rehearse an incident against the clocks that actually run

A ninety-minute tabletop script whose injects are timed against the real Indian filing deadlines — CERT-In at six hours, your sectoral regulator alongside it, the exchanges at twelve — each citing the instrument it comes from.

In short
A cyber incident tabletop is only as useful as its clock. Generic templates run on invented timings, while an Indian entity’s first six hours are governed ones — CERT-In from noticing, the sectoral regulator from detection, the exchanges from a materiality determination made by a named person. Rehearsing against the real deadlines is what surfaces who is missing from the room.

Build your exercise

Tell it who you are and what happened. The script below places the injects you would expect of any tabletop alongside the filings you actually owe, positioned where they genuinely fall due rather than summarised at the end — which is the whole difference between rehearsing an incident and reading about one.

Your entity
The scenario
3statutory deadlines fall inside this exercise. 90 minutes of room time covering 12 hours of incident time — the jumps are marked.
  1. T+0
    Inject
    A core system is unavailable, and nobody knows why yet.

    Operations report it first, then the contact centre. The service desk has an open ticket from forty minutes ago that was never escalated.

    Who in this room declares an incident — and what exact time do we write down?

  2. T+10m
    Stop the clock
    Stop, and fix the moment of noticing in writing.

    Every clock in this exercise runs from it. It is the first thing every regulator asks, the hardest thing to reconstruct afterwards, and the cheapest thing in the whole incident to get right. Write the time, and write how you came to notice.

  3. T+25m
    Inject
    A ransom note is found on a file server.

    Ransomware is a malicious code attack in CERT-In’s Annexure I, so the six-hour obligation has been running since T+0 — not since this moment. Nothing about the note changed what was owed; it only changed what you know.

    Does anything about who we notify change now? Should it have?

  4. T+50m
    Inject
    Someone outside the organisation asks you about it.

    A journalist, a large customer, or an account on social media with screenshots. Nothing has been filed with anyone yet, and no holding statement exists.

    Who speaks? And does answering before we have filed create a problem for us?

  5. T+2h30mjump forward
    Stop the clock
    Draft the filing now, on what is known.

    Take ten minutes and write it. An incomplete investigation does not pause any clock — the instruments expect what is known, with the unknowns marked as under investigation and an update to follow. Rooms that discover this at T+5h file late.

  6. T+3h
    Inject
    The authorised KMP has to determine whether this is material.

    The investigation is nowhere near finished, and the determination cannot wait for it. The disclosure window runs from the incident rather than from the decision, so a slow determination spends the window rather than extending it.

    Who is the authorised KMP, and are they reachable right now?

  7. T+5hjump forward
    Inject
    Someone asks whether affected individuals have to be told.

    Today, no — Rule 7 of the DPDP Rules and section 8 of the Act do not commence until 13 May 2027, so no DPDP clock is running on this incident. From that date every affected Data Principal is intimated with no threshold for size or severity, plus a report to the Data Protection Board within seventy-two hours.

    If that duty applied today, could we produce the list of affected individuals at all?

  8. T+6hjump forward
    Deadline — 2 filings, in parallel
    CERT-In Directions, 2022Report the incident to CERT-In

    To CERT-In (incident@cert-in.org.in · 1800-11-4949). Runs from noticing the incident or being brought to notice of it.

    No. 20(3)/2022-CERT-In
    RBI Cyber Directions, 2026 — Commercial bankReport the cyber incident on the DAKSH platform

    To Reserve Bank of India (daksh.rbi.org.in). Runs from detection. One of seven parallel Directions issued on 31 July 2026, one per entity class. Quote this instrument and its own paragraph number — the numbering differs between them.

    RBI/DoS/2026-27/410 · Ch. V, §Z.1, para 182

    None of these discharges any of the others.

  9. T+12hjump forward
    Deadline
    SEBI LODR, Reg. 30(6)Market disclosure of the event, if the KMP determines it is material

    To Stock exchanges. Runs from occurrence. Twelve hours, not twenty-four. A ransomware event, data breach or IT outage emanates from within the listed entity, which is limb (ii). Limb (iii)’s twenty-four hours is for events arising outside it. Materiality is the authorised KMP’s determination, not a technical one.

    SEBI LODR Regulations, 2015, as amended 14 July 2026

Who has to be in the room

  • The person who can declare an incident. Everything downstream runs from the moment they do, and from the time they write down.
  • The registered CERT-In point of contact. CERT-In directs all communications to the registered PoC. Check the name on the Annexure II form is someone who still works here.
  • The owner of the DAKSH filing, and their deputy. Six hours from detection is not long enough to work out who files.
  • The authorised KMP, and the Company Secretary. The materiality determination is the KMP’s alone, and the exchange filing is the Company Secretary’s.
  • Whoever can say which individuals are affected. Not required today, and required from 13 May 2027. Finding out now whether it is answerable at all is free.
  • Someone who can approve spending. Forensics and external counsel are engaged mid-incident, not procured.

What to have to hand before you start

  • Logs, 180 rolling days, within Indian jurisdiction. All ICT system logs enabled, maintained securely for a rolling 180 days and held within Indian jurisdiction. They must be provided to CERT-In with an incident report or when directed.
  • Clock synchronisation to NIC or NPL. All ICT system clocks synchronised to the NTP servers of NIC or NPL, or to servers traceable to them. An incident timeline assembled from unsynchronised clocks is very hard to defend.
  • A registered CERT-In point of contact. A designated PoC registered with CERT-In in the Annexure II format and kept current. CERT-In directs all communications to the PoC.

The exercise collapses every clock to a single T+0. Real triggers differ — CERT-In runs from noticing, the RBI Directions from detection — and the gap between them is itself one of the things a tabletop is for discovering.

Take this away as a print-ready facilitator pack

Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, the owner columns your incident file needs, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.

How to run it

90 minutes in a room, covering about twelve hours of incident time. The compression is the only artificial thing about it, and it works provided you announce the jumps rather than letting people quietly lose the thread.

  • Hand out the injects one at a time. A script everyone can read ahead of is a discussion about the script. Print the cards, deal them at the offsets, and let the room react to what it has rather than to what is coming.
  • Make someone write the time down. The first pause exists because the moment of noticing is what every clock runs from and the hardest thing to reconstruct afterwards. If the room cannot agree on it in an exercise, it will not agree on it at three in the morning.
  • Have them draft the filing on incomplete facts. Ten minutes, at the two-and-a-half hour mark, on what is known. This is the single most useful thing a tabletop produces, and it is the step most often skipped.
  • Record decisions, not findings. Who decided, at what time, on what information. The technical detail is the easy part to reconstruct later; the decision trail is not.

What usually goes wrong

Four failures recur, and none of them is technical. The room cannot say who declares an incident. Nobody can name the registered CERT-In point of contact, or the name on the form belongs to someone who has left. The filing waits for the investigation, on the assumption that a clock pauses while you work — none of them does. And for a listed entity, the authorised KMP who has to determine materiality is unreachable, which spends the twelve-hour window rather than extending it.

For the deadlines themselves, resolved to wall-clock IST times from a moment you supply, use the incident reporting clock. For which instrument binds you in the first place, which regulation applies.

Indicative, and not legal advice. The injects are authored; every deadline in the script is resolved from the same register the incident reporting clock uses, and each cites the instrument it comes from. Every instrument cited here was verified against the issuing regulator's own notification on .

Worked examples

The same calculator, run for a specific entity — with the thresholds and clocks that apply to it, and the instrument each one comes from.

Questions this page answers

How do you run a cyber incident tabletop exercise in India?
Ninety minutes in a room, covering roughly twelve hours of incident time, with the jumps announced. Start from a moment of noticing that the room fixes in writing, hand out injects one at a time rather than reading a narrative, and place the statutory deadlines where they actually fall — CERT-In at six hours from noticing, the sectoral filing alongside it, and for a listed entity the exchanges at twelve. The value is in the decisions the room cannot make, not in the technical detail.
When does the six-hour clock start in a tabletop exercise?
At the moment of noticing, which is the first thing the exercise should force the room to fix in writing. CERT-In runs from noticing the incident or being brought to notice of it, so an injected phone call from a customer or a regulator starts the clock exactly as internal alerting would. Rooms routinely assume the clock starts when the incident is confirmed, and discovering that assumption in an exercise costs nothing.
Who should attend a cyber incident tabletop?
Whoever the clocks name. The person who can declare an incident, the CISO, the registered CERT-In point of contact, the owner of the sectoral filing and their deputy, and — for a listed entity — the authorised KMP who makes the materiality determination together with the Company Secretary who files with the exchanges. Add someone who can approve spending, because forensics and external counsel are engaged mid-incident rather than procured.
Does an incomplete investigation delay a regulatory filing?
No. Every Indian instrument in this area expects a filing on what is known, with the unknowns marked as under investigation and an update to follow. No clock pauses while an investigation continues. A room that discovers this at the five-hour mark files late, which is why a good exercise makes the participants draft the filing at about two and a half hours on deliberately incomplete facts.
Do DPDP breach obligations apply during an incident today?
Not yet. Rule 7 of the DPDP Rules, 2025 and section 8 of the Act commence on 13 May 2027, so no DPDP clock runs on an incident today. It is still worth an inject, because from that date every affected Data Principal is intimated with no threshold for size or severity and the Data Protection Board gets a full report within seventy-two hours — and the question of whether you could even produce the list of affected individuals is answerable now, for free.

This tool is one skill out of sixteen.

What runs on this page is the browser-sized version of incident-notify, a skill in BitScoreCoWork — our MIT-licensed Claude plugin. The full version runs against your own Bitsight tenancy and works from your measured attack surface rather than a form. The source is public, so you can read exactly what it does before you run it.

Read the source The Applied AI practice

Knowing the rule is the easy half.

This page tells you what you owe. It cannot tell you what an attacker already sees. Your organisation has a security rating calculated from signals visible from outside — request the complimentary Cyber Risk Rating Report and find out what it says. No agent, no system access, no questionnaire.

Request my rating All free tools