Tool 6

Vendor compromise tabletop for an insurer

A ninety-minute tabletop script whose injects are timed against the real Indian filing deadlines — CERT-In at six hours, your sectoral regulator alongside it, the exchanges at twelve — each citing the instrument it comes from.

In short
A cyber incident tabletop is only as useful as its clock. Generic templates run on invented timings, while an Indian entity’s first six hours are governed ones — CERT-In from noticing, the sectoral regulator from detection, the exchanges from a materiality determination made by a named person. Rehearsing against the real deadlines is what surfaces who is missing from the room.

What this case turns on

The hardest question in this scenario is whose clock started when. Your provider knew yesterday; you know now; the obligation runs from your being brought to notice, and their filing under their own obligations discharges nothing of yours. The 2026 Guidelines are a single six-hour step with no twenty-four hour follow-up — the removal is real, and the 2023 figure still circulates because IRDAI’s own page for the superseded version carries no notice.

Compromise at a service provider falls in CERT-In's Annexure I as “Unauthorised access of IT systems or data”, for irdai regulated — insurer, intermediary or the iib.

InstrumentWhat you fileWindow
CERT-In Directions, 2022Report the incident to CERT-In6 hours from noticing, or being brought to notice
IRDAI Information and Cyber Security Guidelines, 2026Report the incident to CERT-In, copied to IRDAI6 hours from noticing, or being brought to notice
Every filing this exercise puts in play

Run it for your own entity

The generator below opens on this scenario. Change the entity or the incident to see which clocks come into play, and take the result away as a pack you can print.

Your entity
The scenario
2statutory deadlines fall inside this exercise. 90 minutes of room time covering 6 hours of incident time — the jumps are marked.
  1. T+0
    Inject
    A service provider tells you they have had an incident.

    The email is vague, arrived at a shared mailbox, and does not say whether your data or your access is involved. It is dated yesterday.

    Whose clock started when — theirs, or ours? And what does our contract say they owed us?

  2. T+10m
    Stop the clock
    Stop, and fix the moment of noticing in writing.

    Every clock in this exercise runs from it. It is the first thing every regulator asks, the hardest thing to reconstruct afterwards, and the cheapest thing in the whole incident to get right. Write the time, and write how you came to notice.

  3. T+25m
    Inject
    Their access into your environment was live throughout.

    Unauthorised access of IT systems or data is an Annexure I category, and a filing by your provider under their own obligations discharges nothing of yours.

    Who can revoke that access right now, and how long would it take?

  4. T+50m
    Inject
    Someone outside the organisation asks you about it.

    A journalist, a large customer, or an account on social media with screenshots. Nothing has been filed with anyone yet, and no holding statement exists.

    Who speaks? And does answering before we have filed create a problem for us?

  5. T+2h30mjump forward
    Stop the clock
    Draft the filing now, on what is known.

    Take ten minutes and write it. An incomplete investigation does not pause any clock — the instruments expect what is known, with the unknowns marked as under investigation and an update to follow. Rooms that discover this at T+5h file late.

  6. T+5hjump forward
    Inject
    Someone asks whether affected individuals have to be told.

    Today, no — Rule 7 of the DPDP Rules and section 8 of the Act do not commence until 13 May 2027, so no DPDP clock is running on this incident. From that date every affected Data Principal is intimated with no threshold for size or severity, plus a report to the Data Protection Board within seventy-two hours.

    If that duty applied today, could we produce the list of affected individuals at all?

  7. T+6hjump forward
    Deadline — 2 filings, in parallel
    CERT-In Directions, 2022Report the incident to CERT-In

    To CERT-In (incident@cert-in.org.in · 1800-11-4949). Runs from noticing the incident or being brought to notice of it.

    No. 20(3)/2022-CERT-In
    IRDAI Information and Cyber Security Guidelines, 2026Report the incident to CERT-In, copied to IRDAI

    To CERT-In, copied to IRDAI and other concerned regulators. Runs from noticing the incident or being brought to notice of it. One step, not two. The 24-hour follow-up widely quoted for IRDAI is from the superseded 2023 Guidelines and has no counterpart in the 2026 text.

    IRDAI/GA&HR/CIR/MISC/51/4/2026 · Guidelines §3.6

    None of these discharges any of the others.

Who has to be in the room

  • The person who can declare an incident. Everything downstream runs from the moment they do, and from the time they write down.
  • The registered CERT-In point of contact. CERT-In directs all communications to the registered PoC. Check the name on the Annexure II form is someone who still works here.
  • Whoever can say which individuals are affected. Not required today, and required from 13 May 2027. Finding out now whether it is answerable at all is free.
  • Someone who can approve spending. Forensics and external counsel are engaged mid-incident, not procured.

What to have to hand before you start

  • Logs, 180 rolling days, within Indian jurisdiction. All ICT system logs enabled, maintained securely for a rolling 180 days and held within Indian jurisdiction. They must be provided to CERT-In with an incident report or when directed.
  • Clock synchronisation to NIC or NPL. All ICT system clocks synchronised to the NTP servers of NIC or NPL, or to servers traceable to them. An incident timeline assembled from unsynchronised clocks is very hard to defend.
  • A registered CERT-In point of contact. A designated PoC registered with CERT-In in the Annexure II format and kept current. CERT-In directs all communications to the PoC.

The exercise collapses every clock to a single T+0. Real triggers differ — CERT-In runs from noticing, the RBI Directions from detection — and the gap between them is itself one of the things a tabletop is for discovering.

Take this away as a print-ready facilitator pack

Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, the owner columns your incident file needs, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.

For how to run the exercise, what usually goes wrong, and every other entity class, see the full tabletop generator.

Indicative, and not legal advice. The injects are authored; every deadline is resolved from the register and cites the instrument it comes from. Every instrument cited here was verified against the issuing regulator's own notification on .

Other worked examples

The same calculator, run for a specific entity — with the thresholds and clocks that apply to it, and the instrument each one comes from.

Questions this page answers

How do you run a cyber incident tabletop exercise in India?
Ninety minutes in a room, covering roughly twelve hours of incident time, with the jumps announced. Start from a moment of noticing that the room fixes in writing, hand out injects one at a time rather than reading a narrative, and place the statutory deadlines where they actually fall — CERT-In at six hours from noticing, the sectoral filing alongside it, and for a listed entity the exchanges at twelve. The value is in the decisions the room cannot make, not in the technical detail.
When does the six-hour clock start in a tabletop exercise?
At the moment of noticing, which is the first thing the exercise should force the room to fix in writing. CERT-In runs from noticing the incident or being brought to notice of it, so an injected phone call from a customer or a regulator starts the clock exactly as internal alerting would. Rooms routinely assume the clock starts when the incident is confirmed, and discovering that assumption in an exercise costs nothing.
Who should attend a cyber incident tabletop?
Whoever the clocks name. The person who can declare an incident, the CISO, the registered CERT-In point of contact, the owner of the sectoral filing and their deputy, and — for a listed entity — the authorised KMP who makes the materiality determination together with the Company Secretary who files with the exchanges. Add someone who can approve spending, because forensics and external counsel are engaged mid-incident rather than procured.
Does an incomplete investigation delay a regulatory filing?
No. Every Indian instrument in this area expects a filing on what is known, with the unknowns marked as under investigation and an update to follow. No clock pauses while an investigation continues. A room that discovers this at the five-hour mark files late, which is why a good exercise makes the participants draft the filing at about two and a half hours on deliberately incomplete facts.
Do DPDP breach obligations apply during an incident today?
Not yet. Rule 7 of the DPDP Rules, 2025 and section 8 of the Act commence on 13 May 2027, so no DPDP clock runs on an incident today. It is still worth an inject, because from that date every affected Data Principal is intimated with no threshold for size or severity and the Data Protection Board gets a full report within seventy-two hours — and the question of whether you could even produce the list of affected individuals is answerable now, for free.

This tool is one skill out of sixteen.

What runs on this page is the browser-sized version of incident-notify, a skill in BitScoreCoWork — our MIT-licensed Claude plugin. The full version runs against your own Bitsight tenancy and works from your measured attack surface rather than a form. The source is public, so you can read exactly what it does before you run it.

Read the source The Applied AI practice

Knowing the rule is the easy half.

This page tells you what you owe. It cannot tell you what an attacker already sees. Your organisation has a security rating calculated from signals visible from outside — request the complimentary Cyber Risk Rating Report and find out what it says. No agent, no system access, no questionnaire.

Request my rating All free tools