Finin2minBatch 08

Cyber Security & Resilience: Batch 08 Action Guides

10 distinct application pages. The established Finin2min hub remains the canonical source/law layer.

Open canonical hub →

India Recorded 29.44 Lakh Cyber Security Incidents in 2025: Enterprise Risk and Board-Reporting Guide

For **India Recorded 29.44 Lakh Cyber Security Incidents in 2025**, first fix **incident classification** and the governing date. Reconcile **threat-intelligence correlation** to the **SIEM/EDR log**, then complete the operational step only when **notification/escalation** and the evidence agree. If the source is a draft, consultation or strategy report, do not convert it into an operative legal requirement.

P0 — latest/current

CERT-In Incident Response for a Government-Connected Vendor: Notification, Evidence and Coordination Checklist

For **CERT-In Incident Response for a Government-Connected Vendor**, first fix **containment and service continuity** and the governing date. Reconcile **vulnerability remediation** to the **CERT-In/advisory record**, then complete the operational step only when **recovery evidence** and the evidence agree. If the source is a draft, consultation or strategy report, do not convert it into an operative legal requirement.

P0 — latest/current

National Cyber Coordination Centre Threat Intelligence: Enterprise SOC Intake and Escalation Workflow

For **National Cyber Coordination Centre Threat Intelligence**, first fix **threat-intelligence correlation** and the governing date. Reconcile **notification/escalation** to the **vulnerability report**, then complete the operational step only when **incident classification** and the evidence agree. If the source is a draft, consultation or strategy report, do not convert it into an operative legal requirement.

P0 — latest/current

NCIIPC Critical Information Infrastructure Alerts: CII Entity Risk and Vulnerability-Response File

For **NCIIPC Critical Information Infrastructure Alerts**, first fix **vulnerability remediation** and the governing date. Reconcile **recovery evidence** to the **vendor/system evidence**, then complete the operational step only when **containment and service continuity** and the evidence agree. If the source is a draft, consultation or strategy report, do not convert it into an operative legal requirement.

P0 — latest/current

Cyber Swachhta Kendra for Corporate Devices: Botnet Detection, Malware Cleanup and Evidence Checklist

For **Cyber Swachhta Kendra for Corporate Devices**, first fix **notification/escalation** and the governing date. Reconcile **incident classification** to the **recovery and post-incident report**, then complete the operational step only when **threat-intelligence correlation** and the evidence agree. If the source is a draft, consultation or strategy report, do not convert it into an operative legal requirement.

P0 — latest/current

Sectoral CSIRT Coordination After a Cyber Incident: Regulator, CERT-In and Service-Provider Workflow

For **Sectoral CSIRT Coordination After a Cyber Incident**, first fix **recovery evidence** and the governing date. Reconcile **containment and service continuity** to the **incident timeline**, then complete the operational step only when **vulnerability remediation** and the evidence agree. If the source is a draft, consultation or strategy report, do not convert it into an operative legal requirement.

P0 — latest/current

Cyber Incident Playbook for Citizen-Facing Digital Platforms: Availability, Data and Recovery Controls

For **Cyber Incident Playbook for Citizen-Facing Digital Platforms**, first fix **incident classification** and the governing date. Reconcile **threat-intelligence correlation** to the **SIEM/EDR log**, then complete the operational step only when **notification/escalation** and the evidence agree. If the source is a draft, consultation or strategy report, do not convert it into an operative legal requirement.

P0 — latest/current

Vulnerability Assessment for Public-Facing Portals: Remediation Priority and Closure Evidence

For **Vulnerability Assessment for Public-Facing Portals**, first fix **containment and service continuity** and the governing date. Reconcile **vulnerability remediation** to the **CERT-In/advisory record**, then complete the operational step only when **recovery evidence** and the evidence agree. If the source is a draft, consultation or strategy report, do not convert it into an operative legal requirement.

P0 — latest/current

Cyber Security Incident Trend from 15.93 Lakh to 29.44 Lakh: CFO Budget and Control-Capacity Review

For **Cyber Security Incident Trend from 15.93 Lakh to 29.44 Lakh**, first fix **threat-intelligence correlation** and the governing date. Reconcile **notification/escalation** to the **vulnerability report**, then complete the operational step only when **incident classification** and the evidence agree. If the source is a draft, consultation or strategy report, do not convert it into an operative legal requirement.

P0 — latest/current

Third-Party Cyber Incident Affecting a Government Service: Vendor, CERT-In and Contract-Evidence Map

For **Third-Party Cyber Incident Affecting a Government Service**, first fix **vulnerability remediation** and the governing date. Reconcile **recovery evidence** to the **vendor/system evidence**, then complete the operational step only when **containment and service continuity** and the evidence agree. If the source is a draft, consultation or strategy report, do not convert it into an operative legal requirement.

P0 — latest/current