INDIA Law and Practice Contributed by: Anoop Narayanan, Priyanka Gupta and Harshita Sakarya, ANA Law Group
broader enterprise risk management and IT govern - ance frameworks. Telecommunications sector Telecommunications operators are regulated by the Department of Telecommunications (DoT). Licensed telecoms service providers are required to ensure network security, protect the confidentiality of com - munications and conduct ongoing monitoring, audits and compliance assessments. The Telecom Cyberse - curity Rules, 2024, mandate infrastructure protection measures, intrusion and attack monitoring facilities and incident reporting to relevant authorities, reflect - ing the critical role of telecoms networks as founda - tional digital infrastructure. Telecoms entities are also subject to CERT-In report - ing obligations, in addition to sector-specific licence conditions and operational directions. In 2025, the amended Telecom Cybersecurity Rules introduced verification and reporting obligations for non-telecoms entities that are using telecoms identifiers to provide The Central Electricity Authority (CEA) provides a comprehensive cybersecurity framework for all enti - ties managing Operational Technology (OT) and IT infrastructure in the power sector under the Cyber Security in Power Sector Guidelines, 2021. The Power Computer Security Incident Response Team (CSIRT), set up in 2024, is the central agency responsible for reporting and responding to cyber security incidents, and co-ordinating with other agencies. Additionally, the CEA introduced the draft Central Electricity Authority (Cyber Security in Power Sector) Regulations, in October 2025, which includes provi - sions regarding incident reporting obligations, annual security audits, additional cybersecurity requirements, etc. Securities sector The Securities and Exchange Board of India (SEBI) introduced a comprehensive Cybersecurity and Cyber Resilience Framework (CSCRF) in August 2024, appli - cable to all SEBI-regulated entities. This includes stock exchanges, clearing corporations, deposito - their services. Power sector
ries, brokers, asset managers, credit rating agencies, mutual funds, investment advisers, KYC registration agencies and other market intermediaries. The CSCRF sets out standards for anticipation, detec - tion, response to, containment of and recovery from cyber incidents. It requires SEBI-regulated entities to develop and implement cybersecurity governance structures, establish Security Operations Centres (SOCs) or equivalent monitoring arrangements, con - duct regular vulnerability assessments and audits, report cyber incidents within prescribed timelines, and manage third-party risk effectively. 1.2 Cybersecurity Laws Cybersecurity and cyber-risk management in India are governed through legislation, delegated rules, binding executive directions and sector-specific standards. This framework applies horizontally across sectors, with enhanced obligations for critical infrastructure and regulated entities. IT Act (2000) and IT Rules (2021) The IT Act forms the core statutory basis for cyberse - curity regulation in India. Its subject matter includes cyber offences, unauthorised access, damage to computer resources, intermediary liability, intercep - tion powers and the protection of CII. The IT Act applies to all persons and entities using computer systems or networks in India, including companies, intermediaries, service providers and government bodies. It has extraterritorial application where a computer system or network located in India is involved, regardless of the nationality or location of the offender. The Act empowers the central government to issue binding directions and designate authorities responsi - ble for incident response and infrastructure protection, providing the statutory basis for CERT-In and NCIIPC. The IT Rules further establish a regulatory frame - work for social media intermediaries, requiring them to observe enhanced due diligence obligations. The Rules also regulate content published by online pub - lishers of news and current affairs, as well as providers of curated audio-visual content, and prescribe obli -
193 CHAMBERS.COM
Powered by FlippingBook