IT & ITES security compliance · IndiaWhoever notices the incident owns the clock.

CERT-In’s six-hour duty falls on whoever spots it — and no contract can hand it to someone else.

Services

A bank client’s RBI clock starts at your detection.

Product

Your platform owes CERT-In the same six hours.

One incident · 7 clocks it can start

  • 6 hoursCERT-Into CERT-In
  • 6 hoursRBI outsourcingto the RBI, via your bank client
  • 24 hoursNIS2to the national CSIRT (early warning)
  • 24 hoursEU CRAto ENISA’s single reporting platform
  • 72 hoursDPDPto the Data Protection Board
  • ≤ 60 daysHIPAAto your covered-entity client
  • No delayGDPRto your client, the controller
6 hours or less24–72 hoursLonger“Without undue delay”
Two businesses, one industry

Which half are you?

Pick one and the rest of the page follows you. Plenty of firms are both.

Services

We run systems for clients

IT services · BPM & contact centres · MSPs & MSSPs · engineering R&D · GCCs

The industry, FY2026E: $315bn revenue, ~78% exported, 59.5 lakh employees. Services: $149bn IT services · $63bn Engineering R&D · $59bn BPM · 2,117 GCCs, 2.36 million staff. Product: $23bn Software products · ~1,600 SaaS firms funded, 2017–22 (Bain) · $12–13bn Indian SaaS ARR, 2022 (Bain). NASSCOM Strategic Review 2026 as reported by PTI; NASSCOM–Zinnov India GCC Landscape 2026; Bain India SaaS Report 2022 (the latest with a public method); DSCI Indian Cybersecurity Product Landscape 3.0.

What binds you?

Free · no email · shareable
  1. 1What do you do? — Pick everything that is true
  2. 2Who are your clients or customers? — Including your parent, if you are a GCC
  3. 3Anything else true? — These change the answer

Binds every firm — before you pick anything

5obligations
2reporting clocks
9controls

The clocks one incident starts

CERT-In · 6 hoursDPDP · 72 hours
Get a shortlist for this profile →

Indicative, based on the published texts as we read them on the dates shown against each obligation. General information, not legal advice — confirm applicability with your counsel.

Threat patterns

How firms like yours actually get breached

8 patterns, each drawn as the attacker walks it. Every incident is sourced.

The help desk resets the attacker’s password

Services
  1. Caller poses as staff
  2. Desk resets password + MFA
  3. Attacker signs in
Clorox v. Cognizant2023 incident; suit filed July 2025

Clorox alleges its outsourced help desk reset passwords and MFA for callers without verifying them, and is seeking $380 million.

Cognizant: it was hired for “a narrow scope of help desk services which Cognizant reasonably performed” and “did not manage cybersecurity for Clorox”. These are allegations in litigation.

The Record ↗
+ 2 more cases: Co-op (UK), CISA advisory AA23-320A
Co-op (UK)April 2025

Attackers called the IT help desk impersonating employees to obtain password resets; data on all 6.5 million members was taken.

LBC, citing BleepingComputer ↗
CISA advisory AA23-320ARevised July 2025

The group behind these attacks “targets large companies and their contracted information technology (IT) help desks”.

CISA ↗

Your remote tool becomes their remote tool

Services
  1. Remote tool exposed
  2. Console taken over
  3. Pushed to every client
Kaseya VSAJuly 2021

A zero-day in the RMM tool MSPs use pushed ransomware through fewer than 60 MSPs to fewer than 1,500 downstream businesses.

The Record ↗
+ 2 more cases: Wipro, CISA advisory AA25-163A
Wipro2019

KrebsOnSecurity reported that phished employee accounts were used to target customers, with a remote-access tool seeded on more than 100 endpoints.

Wipro: “We detected a potentially abnormal activity in a few employee accounts on our network due to an advanced phishing campaign.”

KrebsOnSecurity ↗
CISA advisory AA25-163AJune 2025

Ransomware actors used an unpatched SimpleHelp RMM at a software provider to reach that provider’s downstream customers.

CISA ↗

The build pipeline ships the breach

Product
  1. CI server reached
  2. Secrets harvested
  3. Customers hit downstream
Codecov2021

A tampered uploader script sent customers’ CI environment variables — tokens and keys — to the attacker for two months.

Codecov ↗
+ 2 more cases: C-Edge Technologies, CircleCI
C-Edge TechnologiesJuly 2024

Ransomware at the banking-technology provider disrupted payments at about 300 small Indian banks; analysts reported it began at a misconfigured Jenkins server at a partner.

CSO Online ↗
CircleCIDecember 2022

Malware that antivirus missed stole an engineer’s MFA-backed session; every customer was told to rotate every secret.

CircleCI incident report ↗

The code you didn’t write

Product
  1. Dependency backdoored
  2. Pulled into your build
  3. Shipped to customers
xz-utilsMarch 2024

A maintainer persona built trust over years, then hid a backdoor targeting SSH authentication; it was caught just before wide distribution.

Tarlogic ↗
+ 2 more cases: Shai-Hulud npm worm, Zoho ManageEngine (CVE-2022-47966)
Shai-Hulud npm wormSeptember and November 2025

A self-replicating worm compromised hundreds of npm packages and stole developer and cloud credentials; CISA told developers to require phishing-resistant MFA on GitHub and npm.

CISA ↗
Zoho ManageEngine (CVE-2022-47966)Disclosed January 2023

A bundled Apache Santuario library about a decade old left many on-premise ManageEngine products open to unauthenticated code execution; it was exploited in the wild.

Flashpoint ↗

The token in the integration

Product
  1. Long-lived token found
  2. Replayed via integration
  3. Customer data pulled
Salesloft DriftAugust 2025

Stolen OAuth tokens for the Drift integration were used to pull data from Salesforce instances at 700+ organisations; the intrusion began in Salesloft’s GitHub account months earlier.

SecurityWeek ↗
+ 1 more case: GitGuardian, State of Secrets Sprawl
GitGuardian, State of Secrets Sprawl2026 report

29 million new hardcoded secrets reached public GitHub in 2025, up 34% — the largest jump recorded.

GitGuardian ↗

The contractor’s laptop is the way in

Both
  1. Personal use, work device
  2. Infostealer takes sessions
  3. Signs in to clients
Snowflake customer tenants2024

About 165 organisations were hit with stolen credentials on accounts without MFA. Mandiant: the infostealers ran “on contractor systems that were also used for personal activities, including gaming and downloads of pirated software”.

Google Cloud (Mandiant) ↗
+ 1 more case: Okta / Sitel
Okta / SitelJanuary 2022

A support contractor’s workstation was taken over through remote desktop; Okta’s final finding was 25 minutes of control and two customer tenants accessed.

Infosecurity Magazine ↗

The hire isn’t who they say — or the leaver never left

Both
  1. Fake or stale identity
  2. Gets real access
  3. Data or systems taken
North Korean IT workersJune 2025

The US Justice Department found North Korean IT workers had obtained jobs at more than 100 US companies using stolen identities.

US Department of Justice ↗
+ 1 more case: KiranaPro
KiranaProMay 2025

Servers and code were wiped through a former employee’s access that had never been revoked.

Outlook Business ↗
The bill

What a breach costs here

  • ₹35.7 crBoth
    Average cost of a breach in India’s technology sector — second only to financial servicesIBM Cost of a Data Breach, India 2026 ↗
  • 15%Both
    Share of Indian breaches that began with a supply-chain compromiseIBM Cost of a Data Breach, India 2026 ↗
  • $17.5MServices
    Infosys McCamish’s class-action settlement after 6.08 million people were notified, agreed without admission of liabilityBankInfoSecurity ↗
  • $50–70MServices
    Revenue Cognizant expected to lose from 2020 ransomware — some clients disconnected from it as a precautionThe Week ↗
  • $2bn+Product
    Market value Okta lost in the days after disclosing that its support system had been breached (October 2023)NBC / CNBC ↗
  • 144Product
    Class actions MOVEit’s maker, Progress Software, faced by mid-2024 — plus letters from 38 customers, some seeking indemnificationCybersecurity Dive ↗

Seen enough to know where you stand?

A 30-minute call. We come with a vendor-neutral shortlist, priced in INR with GST.

How we help

Send us the security questionnaire you were just handed.

Whichever half you are in, the bar arrives as a questionnaire. We turn it into a shortlist.

  1. 01

    You send the questionnaire

    A client’s vendor assessment, a customer’s SOC 2 request, an RFP annexure.

  2. 02

    We map it to the 29 controls

    Which questions you already answer, and which ones you can’t yet.

  3. 03

    You get a shortlist that closes the gaps

    Vendor-neutral, priced in INR with GST, implemented if you want us to.

  • 25/29controls our catalogue answers
  • 170vendors researched
  • 977product pages, limits stated
  • 25obligations, sourced
Map my questionnaire →
Myths & gaps

What the market gets wrong — and where we are thin

  • “Your client reports the incident, not you.”
    CERT-In says whoever notices it reports it, and the duty cannot be contracted away.
  • “DPDP is in force now.”
    Only the Board is. The operational duties start on 13 May 2027; a proposal to bring that forward has not been notified.
  • “Processors face DPDP penalties directly.”
    The penalty schedule targets Data Fiduciaries. Processors are bound through the contract.
  • “CERT-In logs must physically stay in India.”
    CERT-In’s FAQ allows storage abroad if logs can be produced in reasonable time. RBI, IRDAI and SEBI clients can be stricter.
  • “Our contracts follow the RBI’s 2023 IT-outsourcing Master Direction.”
    It was repealed on 28 November 2025. The Managing Risks in Outsourcing Directions 2025 replaced it.
  • “Our insurer clients follow IRDAI’s 2023 cyber guidelines.”
    IRDAI reissued them on 6 April 2026, replacing the 2023 edition.
All 14 myths, each checked →

Where our catalogue is thin

We’d rather tell you than let a gap look like a recommendation.
Questions people ask

IT & ITES compliance, answered

Short answers, each backed by the source on the obligations page.

If an IT services vendor detects a cyber incident in a client's environment, who reports it to CERT-In?

Whoever notices it. CERT-In's FAQ on its 2022 Directions says any entity which notices the incident shall report it within six hours, and that the obligation is neither transferable nor indemnifiable by contract.

When does a bank's six-hour RBI reporting clock start if its IT vendor detects the incident?

At the vendor's detection. The RBI's Managing Risks in Outsourcing Directions 2025 require the service provider to report to the bank without undue delay so that the bank reports to the RBI within six hours of detection by the service provider.

Do CERT-In's reporting rules apply to Indian SaaS companies?

Yes. CERT-In's 2022 Directions bind every body corporate, so an incident on a SaaS platform must be reported within six hours of noticing it, and logs kept for 180 days. Under DPDP, a SaaS company is also a Data Fiduciary for its own users' data, with the operational duties applying from 13 May 2027.

What does CERT-In require for log retention?

Logs of all ICT systems for a rolling 180 days, producible to CERT-In on demand. CERT-In's FAQ allows them to be stored outside India if they can be produced in reasonable time. The DPDP Rules add at least one year for logs of personal-data processing.

Are IT services firms Data Fiduciaries or Data Processors under the DPDP Act?

Usually processors for their clients' data, bound through the contract — the penalties fall on the Data Fiduciary. But every firm is a Data Fiduciary for its own employees' data. The operational duties apply from 13 May 2027.

Is ISO 27001:2013 still valid for Indian IT and SaaS companies?

No. The transition to ISO/IEC 27001:2022 ended on 31 October 2025, so a 2013-edition certificate has lapsed. ISO 27001 is not law, but it is the baseline ask in nearly every client RFP.

Does the EU Cyber Resilience Act apply to Indian software companies?

If they sell installable software, apps or agents in the EU, yes. Its reporting obligations — a 24-hour early warning for actively exploited vulnerabilities and severe incidents — apply from 11 September 2026, with full application from 11 December 2027. Pure SaaS is generally outside it.

Where software is the answer, and where it is not

25 of the 29 controls are answered by software we can shortlist, price in INR with GST, and implement. The other 4 are a procedure, a hiring process, a runbook and a contract — and we say so.

Every obligation carries its source and the date we verified it, on the obligations page. Incident accounts are quoted as their sources state them; where a company disputed a link, its own statement is shown. General information, not legal advice — confirm applicability and current status with your counsel.