Skip to main content
Finin2minBatch 08 · Source checked 14 Aug 2026
Cyber Security & ResilienceUpdated 5 October 2026

Third-Party Cyber Incident Affecting a Government Service: Vendor, CERT-In and Contract-Evidence Map

By Ravi Sisodia · Reviewed by CA Divyanshu Sengar · Updated 5 October 2026

India-first finance, audit and risk workflow with primary-source anchors.

2-minute summary

Current position

A third-party compromise affecting a Government service requires a joint evidence and coordination file. The vendor supplies technical facts and recovery evidence; the service owner separately determines citizen, transaction, data and regulatory impact and records its CERT-In / sector-reporting conclusions.

Control and decision map

#Control / decision step
1Trigger the joint incident bridge and identify vendor / customer decision owners.
2Collect vendor timeline, affected assets, data scope, indicators and containment evidence.
3Map the vendor incident to the Government service’s citizen / transaction impact.
4Assess CERT-In, sector and contractual notification separately.
5Reconcile restored transactions / records before normal closure.
6Enforce post-incident RCA, remediation and contractual service-credit / risk actions where applicable.

Evidence pack

Worked example

A managed-service provider reports ransomware on the database tier supporting a Government portal. The vendor restores from backup, but the customer does not close the incident until it reconciles the citizen transactions processed around the outage, confirms whether personal data was affected and records the CERT-In / regulator assessment.

Common mistakes

  1. Accepting “service restored” as complete incident closure.
  2. Allowing a vendor to decide all customer reporting duties.
  3. Failing to contract for log and forensic access.
  4. Ignoring sub-processors involved in the affected service.

Frequently asked questions

Can the customer rely entirely on the vendor report?

No. The customer must assess its own service, data and reporting impact.

What is the minimum vendor evidence?

Timeline, affected systems / data, containment, recovery, indicators and RCA support.

Why reconcile transactions after recovery?

Availability restoration does not prove transaction or data integrity.

Official sources

Disclaimer: Educational and informational content only. Apply the current law, instrument, contract, facts and professional judgement before acting.

Disclaimer

Educational and professional reference only; confirm the current law, rates and the facts of your case before relying on this page.

Educational and professional reference only — not financial, tax or legal advice. Verify the current official position from the primary source before relying on any figure, rate, provision or deadline.