We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Free · Incident first-response

Think you’ve been breached? Start here.

The first hour decides how bad it gets. Pick what’s happening and get the exact first steps — contain, preserve evidence, and meet India’s 6-hour CERT-In reporting clock and your DPDP obligations.

Active incident right now? Contain first (below), preserve evidence, and get expert help immediately — CyberSigma’s CERT-In empanelled responders can join within the reporting window. Request response →
What’s happening?
Your sector (tailors who you report to)

🔓 Data breach / data exposure

⏱ First 60 minutes — contain & preserve
1Contain the exposure — revoke leaked credentials/keys, disable the affected account or endpoint, and close the exposed service or bucket.
2Preserve evidence before you clean up — snapshot systems and export logs; do not wipe or rebuild yet.
3Assemble your incident team and start a written timeline (who found it, when, what was seen).
🔎 Investigate & assess
1Determine what data was exposed — personal data, cardholder data, credentials, IP — and roughly how many records and individuals.
2Establish the entry point and whether the attacker still has access.
3Decide severity and whether it is a reportable personal-data breach.
📢 Reporting obligations
CERT-In (mandatory, India)
Report the incident to CERT-In within 6 hours of noticing it, via incident@cert-in.org.in or the CERT-In portal. This applies to a broad list of incident types under the CERT-In Directions, 28 Apr 2022.
DPDP Act 2023 (if personal data is affected)
A personal-data breach must be notified to the Data Protection Board of India and to each affected Data Principal, in the manner and timeline set out in the DPDP Rules. Do not delay assessment.
Customers & contracts
Check your customer contracts and DPAs for breach-notification clauses — many require notice within 24–72 hours. Notify affected customers and, where relevant, your cyber-insurer.
Do NOT
  • Pay a ransom, wipe/rebuild systems, or talk to attackers before responders are engaged.
  • Delete logs or the original malicious email / ransom note — that’s your evidence.
  • Publicly comment before scope and your legal position are clear.

General first-response guidance — confirm the exact regulatory timelines for your entity. This is guidance, not legal advice.

Get CERT-In empanelled responders on it now

Share your details and a senior CyberSigma responder will call you back to help contain the incident, preserve evidence and meet your CERT-In and DPDP reporting obligations. For an active incident, mark it urgent below.

Prepare before it happens: draft an Incident Response Policy, check which rules apply to you, or explore our services.