Cyber / Breach Response

First 24 Hours After Breach

Respond to a personal-data breach through containment, evidence preservation, impact assessment, CERT-In review, communication, recovery and board oversight.

The first response should stop harm without destroying the evidence needed to understand what happened.

Quick View

Decision

Activate one incident command structure linking technology, legal, privacy, finance, communications and affected business owners.

First action

Open incident ticket.

Core evidence

Incident timeline.

Main warning

Deleting compromised accounts before capture.

Why It Matters

The final Digital Personal Data Protection Rules, 2025 were notified on 14 November 2025 with phased commencement. As of 25 June 2026, organisations should distinguish provisions already commenced from operational duties scheduled for later dates, while continuing to comply with the IT Act, CERT-In directions and sectoral rules already in force.

CERT-In’s 28 April 2022 directions already require covered entities to report specified cyber incidents within six hours of noticing or being informed of them, and to maintain ICT logs securely for a rolling 180 days in India.

DPDP breach-intimation duties follow the phased commencement schedule. The incident team should assess both present CERT-In and sectoral duties and future DPDP readiness.

Control Framework

AreaWhat to establishOperating rule
ContainAccounts, keys, devices and network paths.Preserve evidence first.
AssessData, systems, people and harm.Use facts, not guesses.
ReportCERT-In, sector regulator, police or users.Track separate triggers.
RecoverPatch, restore and monitor.Document decisions.

Action Checklist

  1. Open incident ticket.
  2. Preserve logs and system images.
  3. Contain compromised access.
  4. Create six-hour reporting assessment.
  5. Identify affected data and people.
  6. Brief management and record decisions.

Practical Example

An attacker exports customer records through a compromised admin account. The team resets every account but overwrites the access logs needed to identify the data taken.

Evidence to Keep

  • Incident timeline.
  • Logs and forensic images.
  • Access and configuration changes.
  • Reporting decisions.
  • Customer communication drafts.
  • Recovery and lessons report.

Warning Signs

  • Deleting compromised accounts before capture.
  • Waiting for perfect facts before CERT-In review.
  • One team communicating independently.
  • No vendor involvement plan.
  • No board notification threshold.

Detailed Review

Privacy governance should connect the personal data, individual, purpose, collection point, system, owner, recipient, access role, retention trigger and incident dependency. A policy that cannot be traced to this chain is difficult to operate.

Create a dated legal matrix rather than one status label. Record the DPDP provision, commencement date, present readiness action, current IT or sectoral obligation and the evidence owner.

Design controls in the product and system. A written rule cannot stop an SDK from firing, a shared folder from exposing payroll, or a vendor from retaining deleted users unless technology and operations enforce it.

Evidence should be generated during normal work: versioned notices, event logs, access approvals, request tickets, deletion reports, vendor registers, incident chronologies and management decisions.

Use proportionate identity and security checks. Excess verification creates more personal data, while weak verification can expose another person’s records or permit account takeover.

Synchronised clocks and durable logs are essential because incident reporting, transaction tracing and forensic conclusions depend on exact chronology.

The incident team should distinguish containment, evidence preservation, reporting, customer communication and recovery. Each has a different owner and deadline.

Control Test

Test the control using a real user journey from collection to deletion. Capture the notice shown, data stored, vendors called, employees with access, retention period and response if the user withdraws or complains.

Run a negative scenario: the vendor is breached, the user is a child, the employee exits, the phone is stolen, the data was inaccurate or the regulator asks for proof. Record which control fails.

Check that system records and public wording agree. Product forms, privacy notice, CRM fields, SDK behaviour, vendor contracts and support scripts should describe the same processing.

Assign a named owner and internal deadline for every gap. A risk register without funded action and closure evidence becomes an archive of known failures.

Retain the rejected alternatives and decision basis. This is especially important where the law is in phased commencement or a proportionate technical method is selected.

Escalation Route

Start with the system owner, privacy or security owner and the documented data flow. Preserve records before making changes, and separate current statutory reporting from future DPDP readiness.

For a breach, financial fraud, rights dispute, children’s-data issue or regulated-sector event, involve qualified legal, cyber, forensic and sector specialists and use the applicable official reporting or grievance channel.

Common Questions

Does every breach go to CERT-In?

The CERT-In directions list reportable incident categories; assess promptly.

What is the current CERT-In timeline?

Specified incidents must be reported within six hours of noticing or being informed.

Are DPDP breach notices fully operative?

Check the phased commencement schedule.

What should happen first?

Contain harm while preserving evidence and opening a documented chronology.

Official Sources

Use the latest commencement notifications, final Rules, CERT-In directions and sectoral regulator material. Applicability depends on dates, roles, systems, users and facts.

Disclaimer: This article is educational and does not provide personal legal, privacy, cyber-forensic, banking, insurance, employment or regulatory advice. Obtain qualified advice before implementing or reporting a material issue.