Survive the six hours: a ransomware incident against the real clocks
A three-minute ransomware game played as a bank, NBFC, broker, insurer or listed manufacturer. Every decision spends incident time, and every filing deadline is the real one, cited to its instrument.
Play it
Pick who you are. Ransomware is noticed at T+0, and from then the clock runs at 2 incident minutes a second. Decisions arrive as it runs; each one spends incident time, and some cost a filing outright. When the last one is made, the filings go in — or the six hours run out first.
The filings you will owe
- Due T+6hCERT-In Directions, 2022 — Report the incident to CERT-In, to CERT-In. No. 20(3)/2022-CERT-In
- Due T+6hRBI Cyber Directions, 2026 — Commercial bank — Report the cyber incident on the DAKSH platform, to Reserve Bank of India. RBI/DoS/2026-27/410 · Ch. V, §Z.1, para 182
- Due T+12hSEBI LODR, Reg. 30(6) — Market disclosure of the event, if the KMP determines it is material, to Stock exchanges. SEBI LODR Regulations, 2015, as amended 14 July 2026
Take this away as a six-hour playbook for your entity
Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, an owner column against every action, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.
The decisions, and the instruments behind them
Every decision in the game, with the right call and the wording of the instrument it turns on. Read it after playing, not before.
- Operations report a core system down. A file server shows encrypted files. Declare an incident now and write the time down. The clock was already running. Fixing the moment in writing now is what every filing will be measured from. “within 6 hours of noticing such incidents or being brought to notice about such incidents” — CERT-In Directions, 2022, No. 20(3)/2022-CERT-In.
- Who is your registered CERT-In point of contact? The name on the Annexure II form, checked last quarter. The filing has an owner, and CERT-In will know who to call back. “A designated PoC registered with CERT-In in the Annexure II format and kept current. CERT-In directs all communications to the PoC.” — CERT-In Directions, 2022 — A registered CERT-In point of contact, No. 20(3)/2022-CERT-In.
- The RBI filing goes on DAKSH. Who can log in? The filing owner and a named deputy both hold access. The deputy logs in. Six hours is not long enough to discover who files. “shall report cyber incidents within six hours of detection on DAKSH platform” — RBI Cyber Directions, 2026 — Commercial bank, RBI/DoS/2026-27/410 · Ch. V, §Z.1, para 182. Drawn by: Listed commercial bank, NBFC in the Middle Layer or above.
- The forensic firm wants to scope the incident before anything is filed. Draft on what is known, and mark the unknowns as under investigation. The filing goes on what is known, with an update to follow. The deadline is on the report, not on the investigation. “within 6 hours of noticing such incidents or being brought to notice about such incidents” — CERT-In Directions, 2022, No. 20(3)/2022-CERT-In.
- Is this material? Under LODR that is the authorised KMP’s call. Reach the authorised KMP now for a determination. Twelve hours, not twenty-four. A ransomware event, data breach or IT outage emanates from within the listed entity, which is limb (ii). Limb (iii)’s twenty-four hours is for events arising outside it. Materiality is the authorised KMP’s determination, not a technical one. “twelve hours from the occurrence of the event or information” — SEBI LODR, Reg. 30(6), SEBI LODR Regulations, 2015, as amended 14 July 2026. Drawn by: Listed commercial bank, Listed manufacturer.
- The drafts are ready. Legal wants to review each filing before it goes. Legal reviews them together, and they go in parallel. Filed together. None of them discharges any of the others, so none of them waits for another. “within 6 hours of noticing such incidents or being brought to notice about such incidents” — CERT-In Directions, 2022, No. 20(3)/2022-CERT-In.
- Someone says the CERT-In filing covers SEBI too. File to SEBI and CERT-In under CSCRF, and to the exchanges and depositories. CSCRF’s six hours and CERT-In’s six hours are two filings, not one. Neither discharges the other. “shall be notified to SEBI and CERT-In within 6 hours of noticing/ detecting such incidents or being brought to notice about such incidents” — SEBI CSCRF, SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113. Drawn by: SEBI-registered stock broker.
- Someone suggests telling IRDAI first and letting it decide what happens next. Report to CERT-In, with a copy to IRDAI. One filing, to the recipient the Guidelines name, copied to the regulator. “shall mandatorily report cyber incidents to Cert-In within 6 hours of noticing or being brought to notice about such incidents with a copy to IRDAI” — IRDAI Information and Cyber Security Guidelines, 2026, IRDAI/GA&HR/CIR/MISC/51/4/2026 · Guidelines §3.6. Drawn by: Insurer.
- Someone says a manufacturer with no sector regulator owes nobody a filing. CERT-In binds any body corporate, so file. CERT-In’s Directions are deliberately wide. A sector regulator is not what brings you in. “Service providers, intermediaries, data centres, body corporates and government organisations. Cyber incidents reportable within six hours of noticing them.” — CERT-In Directions, 2022, No. 20(3)/2022-CERT-In. Drawn by: Listed manufacturer.
What is real and what is a game rule
The deadlines are real. Every filing comes from the same register the incident reporting clock uses, and every consequence quotes the instrument it comes from. No company is named, and the incident is generic.
The time each choice costs is a game rule. Waiting for forensics does not take exactly three hours in life; the costs are set so that one bad call leaves little room and two sink the filing, which is roughly how it goes.
Three minutes alone tells you what the clocks are. To find out who in your organisation is missing when they run, build a ninety-minute exercise with the incident tabletop.
Indicative, and not legal advice. Every deadline is resolved from the issuing regulator’s own text and cites the instrument it comes from. Every instrument cited here was verified against the issuing regulator's own notification on .
Questions this page answers
- How long does an Indian company have to report a ransomware attack?
- Six hours to CERT-In, from noticing the incident or being brought to notice of it, under the CERT-In Directions of 28 April 2022. Ransomware is a malicious code attack in Annexure I of those Directions. Most regulated entities owe a sectoral filing in parallel: an RBI entity files on DAKSH within six hours of detection, and a SEBI-regulated entity notifies SEBI and CERT-In within six hours under CSCRF.
- Does the CERT-In report cover the SEBI filing under CSCRF?
- No. CSCRF requires notification to SEBI and CERT-In within six hours of noticing the incident, and that is a separate filing from the one owed under the CERT-In Directions. A stock broker or depository participant also notifies the stock exchanges and depositories. None of these discharges any of the others.
- Can we wait for the forensic investigation before reporting a cyber incident?
- No. None of the Indian incident reporting clocks pauses while an investigation continues. The filing is made on what is known, with the unknowns marked as under investigation and an update to follow. Waiting for a forensic firm’s preliminary findings before filing is how a six-hour window gets spent.
- Who decides whether a cyber incident must be disclosed to the stock exchanges?
- The authorised key managerial personnel, under SEBI LODR. For an event originating within the listed entity, such as ransomware, the disclosure window under Regulation 30(6) is twelve hours from the occurrence, not twenty-four. The window runs from the event rather than from the determination, so a determination left for the next board meeting spends it.