IT & ITES security compliance · IndiaWhoever notices the incident owns the clock.
CERT-In’s six-hour duty falls on whoever spots it — and no contract can hand it to someone else.
A bank client’s RBI clock starts at your detection.
Your platform owes CERT-In the same six hours.
One incident · 7 clocks it can start
- 6 hoursCERT-Into CERT-In
- 6 hoursRBI outsourcingto the RBI, via your bank client
- 24 hoursNIS2to the national CSIRT (early warning)
- 24 hoursEU CRAto ENISA’s single reporting platform
- 72 hoursDPDPto the Data Protection Board
- ≤ 60 daysHIPAAto your covered-entity client
- No delayGDPRto your client, the controller
One incident. Up to 7 clocks. Filing one doesn’t discharge another.
Three lines from the primary texts that most contracts in this industry were not written for.
“Any entity which notices the cyber security incident, shall report to CERT-In. The obligation of reporting of cyber incident is neither transferrable nor indemnified or dispense with.”
So: Asked about exactly the outsourcing case. It binds a SaaS platform just the same.
RBI Outsourcing Directions 2025 · para 56Incidents are reported to the bank by the service provider “so that an incident is reported by the bank to the RBI within six hours of detection by the service provider”.
So: Your detection starts your bank client’s regulatory clock.
EU Cyber Resilience Act · Article 14Actively exploited vulnerabilities and severe incidents: an early warning within 24 hours, a notification within 72 — from 11 September 2026.
So: For installable software sold in the EU. 2027 is full application, not the clock.
Which half are you?
Pick one and the rest of the page follows you. Plenty of firms are both.
We run systems for clients
IT services · BPM & contact centres · MSPs & MSSPs · engineering R&D · GCCs
We build and sell software
SaaS · installable software · platforms sold worldwide
The industry, FY2026E: $315bn revenue, ~78% exported, 59.5 lakh employees. Services: $149bn IT services · $63bn Engineering R&D · $59bn BPM · 2,117 GCCs, 2.36 million staff. Product: $23bn Software products · ~1,600 SaaS firms funded, 2017–22 (Bain) · $12–13bn Indian SaaS ARR, 2022 (Bain). NASSCOM Strategic Review 2026 as reported by PTI; NASSCOM–Zinnov India GCC Landscape 2026; Bain India SaaS Report 2022 (the latest with a public method); DSCI Indian Cybersecurity Product Landscape 3.0.
What binds you?
Free · no email · shareableBinds every firm — before you pick anything
The clocks one incident starts
Indicative, based on the published texts as we read them on the dates shown against each obligation. General information, not legal advice — confirm applicability with your counsel.
How firms like yours actually get breached
8 patterns, each drawn as the attacker walks it. Every incident is sourced.
The help desk resets the attacker’s password
Services- Caller poses as staff
- Desk resets password + MFA
- Attacker signs in
Clorox alleges its outsourced help desk reset passwords and MFA for callers without verifying them, and is seeking $380 million.
Cognizant: it was hired for “a narrow scope of help desk services which Cognizant reasonably performed” and “did not manage cybersecurity for Clorox”. These are allegations in litigation.
The Record ↗+ 2 more cases: Co-op (UK), CISA advisory AA23-320A− fewer
Attackers called the IT help desk impersonating employees to obtain password resets; data on all 6.5 million members was taken.
LBC, citing BleepingComputer ↗The group behind these attacks “targets large companies and their contracted information technology (IT) help desks”.
CISA ↗Your remote tool becomes their remote tool
Services- Remote tool exposed
- Console taken over
- Pushed to every client
A zero-day in the RMM tool MSPs use pushed ransomware through fewer than 60 MSPs to fewer than 1,500 downstream businesses.
The Record ↗+ 2 more cases: Wipro, CISA advisory AA25-163A− fewer
KrebsOnSecurity reported that phished employee accounts were used to target customers, with a remote-access tool seeded on more than 100 endpoints.
Wipro: “We detected a potentially abnormal activity in a few employee accounts on our network due to an advanced phishing campaign.”
KrebsOnSecurity ↗Ransomware actors used an unpatched SimpleHelp RMM at a software provider to reach that provider’s downstream customers.
CISA ↗The insider is paid
Services- Agent is bribed
- Records copied out
- Data sold on
Coinbase disclosed that support agents outside the US were bribed to pull customer data, and put its costs at $180–400 million. Reuters reported an India-based TaskUs employee photographing her screen.
The Register ↗The build pipeline ships the breach
Product- CI server reached
- Secrets harvested
- Customers hit downstream
A tampered uploader script sent customers’ CI environment variables — tokens and keys — to the attacker for two months.
Codecov ↗+ 2 more cases: C-Edge Technologies, CircleCI− fewer
Ransomware at the banking-technology provider disrupted payments at about 300 small Indian banks; analysts reported it began at a misconfigured Jenkins server at a partner.
CSO Online ↗Malware that antivirus missed stole an engineer’s MFA-backed session; every customer was told to rotate every secret.
CircleCI incident report ↗The code you didn’t write
Product- Dependency backdoored
- Pulled into your build
- Shipped to customers
A maintainer persona built trust over years, then hid a backdoor targeting SSH authentication; it was caught just before wide distribution.
Tarlogic ↗+ 2 more cases: Shai-Hulud npm worm, Zoho ManageEngine (CVE-2022-47966)− fewer
A self-replicating worm compromised hundreds of npm packages and stole developer and cloud credentials; CISA told developers to require phishing-resistant MFA on GitHub and npm.
CISA ↗A bundled Apache Santuario library about a decade old left many on-premise ManageEngine products open to unauthenticated code execution; it was exploited in the wild.
Flashpoint ↗The token in the integration
Product- Long-lived token found
- Replayed via integration
- Customer data pulled
Stolen OAuth tokens for the Drift integration were used to pull data from Salesforce instances at 700+ organisations; the intrusion began in Salesloft’s GitHub account months earlier.
SecurityWeek ↗+ 1 more case: GitGuardian, State of Secrets Sprawl− fewer
29 million new hardcoded secrets reached public GitHub in 2025, up 34% — the largest jump recorded.
GitGuardian ↗The contractor’s laptop is the way in
Both- Personal use, work device
- Infostealer takes sessions
- Signs in to clients
About 165 organisations were hit with stolen credentials on accounts without MFA. Mandiant: the infostealers ran “on contractor systems that were also used for personal activities, including gaming and downloads of pirated software”.
Google Cloud (Mandiant) ↗+ 1 more case: Okta / Sitel− fewer
A support contractor’s workstation was taken over through remote desktop; Okta’s final finding was 25 minutes of control and two customer tenants accessed.
Infosecurity Magazine ↗The hire isn’t who they say — or the leaver never left
Both- Fake or stale identity
- Gets real access
- Data or systems taken
The US Justice Department found North Korean IT workers had obtained jobs at more than 100 US companies using stolen identities.
US Department of Justice ↗+ 1 more case: KiranaPro− fewer
Servers and code were wiped through a former employee’s access that had never been revoked.
Outlook Business ↗What a breach costs here
- ₹35.7 crBothAverage cost of a breach in India’s technology sector — second only to financial servicesIBM Cost of a Data Breach, India 2026 ↗
- 15%BothShare of Indian breaches that began with a supply-chain compromiseIBM Cost of a Data Breach, India 2026 ↗
- $17.5MServicesInfosys McCamish’s class-action settlement after 6.08 million people were notified, agreed without admission of liabilityBankInfoSecurity ↗
- $50–70MServicesRevenue Cognizant expected to lose from 2020 ransomware — some clients disconnected from it as a precautionThe Week ↗
- $2bn+ProductMarket value Okta lost in the days after disclosing that its support system had been breached (October 2023)NBC / CNBC ↗
- 144ProductClass actions MOVEit’s maker, Progress Software, faced by mid-2024 — plus letters from 38 customers, some seeking indemnificationCybersecurity Dive ↗
Seen enough to know where you stand?
A 30-minute call. We come with a vendor-neutral shortlist, priced in INR with GST.
What you actually have to do
29 controls. Most bind both halves — the map shows which are only yours.
- Detect and respond inside six hours
- Logs kept, and producible
- Phishing-resistant sign-in
- Access that ends when the job does
- Managed devices only
- Email security and phishing training
- Backups the attacker cannot reach
- Vulnerability management and VAPT
- Audit evidence: ISO 27001, SOC 2
- Privacy operations for DPDP
- Your own suppliers, managed
- Client and customer data, encrypted and found
- Verifying the caller before a reset
- Knowing who you hired
- The six-hour runbook
- The clauses you sign
- 1Report to CERT-In within six hours
- 2Keep 180 days of logs
- 3Sync clocks to NIC / NPL time
- 4Back up your books daily, in India
- 5Protect employees’ data (DPDP, 2027)
Send us the security questionnaire you were just handed.
Whichever half you are in, the bar arrives as a questionnaire. We turn it into a shortlist.
- 01
You send the questionnaire
A client’s vendor assessment, a customer’s SOC 2 request, an RFP annexure.
- 02
We map it to the 29 controls
Which questions you already answer, and which ones you can’t yet.
- 03
You get a shortlist that closes the gaps
Vendor-neutral, priced in INR with GST, implemented if you want us to.
- 25/29controls our catalogue answers
- 170vendors researched
- 977product pages, limits stated
- 25obligations, sourced
What the market gets wrong — and where we are thin
- “Your client reports the incident, not you.”CERT-In says whoever notices it reports it, and the duty cannot be contracted away.
- “DPDP is in force now.”Only the Board is. The operational duties start on 13 May 2027; a proposal to bring that forward has not been notified.
- “Processors face DPDP penalties directly.”The penalty schedule targets Data Fiduciaries. Processors are bound through the contract.
- “CERT-In logs must physically stay in India.”CERT-In’s FAQ allows storage abroad if logs can be produced in reasonable time. RBI, IRDAI and SEBI clients can be stricter.
- “Our contracts follow the RBI’s 2023 IT-outsourcing Master Direction.”It was repealed on 28 November 2025. The Managing Risks in Outsourcing Directions 2025 replaced it.
- “Our insurer clients follow IRDAI’s 2023 cyber guidelines.”IRDAI reissued them on 6 April 2026, replacing the 2023 edition.
Where our catalogue is thin
We’d rather tell you than let a gap look like a recommendation.- Vulnerability management and VAPTThe two VAPT services in our catalogue are not CERT-In-empanelled. If a client needs an empanelled auditor, that is a separate engagement.
- Audit evidence: ISO 27001, SOC 2Only three of these automate SOC 2 / ISO 27001 evidence collection; the others are enterprise GRC platforms.
- Your own suppliers, managedThin: two products in our catalogue. Most firms this size run supplier risk in their GRC platform.
- Isolated client workspacesVirtual desktops in our catalogue are Citrix only.
- Contact-centre and BPO operationsThin: our contact-centre coverage is Zendesk and Zoom, and nothing we list does DTMF masking for card payments.
- Secrets and signing keys out of the codeCode signing is thin: one dedicated product, plus PKI from Entrust and eMudhra.
- Customer identity and account protectionThin: three products in our catalogue.
IT & ITES compliance, answered
Short answers, each backed by the source on the obligations page.
If an IT services vendor detects a cyber incident in a client's environment, who reports it to CERT-In?
Whoever notices it. CERT-In's FAQ on its 2022 Directions says any entity which notices the incident shall report it within six hours, and that the obligation is neither transferable nor indemnifiable by contract.
When does a bank's six-hour RBI reporting clock start if its IT vendor detects the incident?
At the vendor's detection. The RBI's Managing Risks in Outsourcing Directions 2025 require the service provider to report to the bank without undue delay so that the bank reports to the RBI within six hours of detection by the service provider.
Do CERT-In's reporting rules apply to Indian SaaS companies?
Yes. CERT-In's 2022 Directions bind every body corporate, so an incident on a SaaS platform must be reported within six hours of noticing it, and logs kept for 180 days. Under DPDP, a SaaS company is also a Data Fiduciary for its own users' data, with the operational duties applying from 13 May 2027.
What does CERT-In require for log retention?
Logs of all ICT systems for a rolling 180 days, producible to CERT-In on demand. CERT-In's FAQ allows them to be stored outside India if they can be produced in reasonable time. The DPDP Rules add at least one year for logs of personal-data processing.
Are IT services firms Data Fiduciaries or Data Processors under the DPDP Act?
Usually processors for their clients' data, bound through the contract — the penalties fall on the Data Fiduciary. But every firm is a Data Fiduciary for its own employees' data. The operational duties apply from 13 May 2027.
Is ISO 27001:2013 still valid for Indian IT and SaaS companies?
No. The transition to ISO/IEC 27001:2022 ended on 31 October 2025, so a 2013-edition certificate has lapsed. ISO 27001 is not law, but it is the baseline ask in nearly every client RFP.
Does the EU Cyber Resilience Act apply to Indian software companies?
If they sell installable software, apps or agents in the EU, yes. Its reporting obligations — a 24-hour early warning for actively exploited vulnerabilities and severe incidents — apply from 11 September 2026, with full application from 11 December 2027. Pure SaaS is generally outside it.
Where software is the answer, and where it is not
25 of the 29 controls are answered by software we can shortlist, price in INR with GST, and implement. The other 4 are a procedure, a hiring process, a runbook and a contract — and we say so.
Every obligation carries its source and the date we verified it, on the obligations page. Incident accounts are quoted as their sources state them; where a company disputed a link, its own statement is shown. General information, not legal advice — confirm applicability and current status with your counsel.