Cybersecurity 2026

INDIA Law and Practice Contributed by: Anoop Narayanan, Priyanka Gupta and Harshita Sakarya, ANA Law Group

• perform Vulnerability/Threat/Risk (V/T/R) Analysis whenever significant system upgrades occur, with results reported to the ISSC; • report cyber incidents to CERT-In within six hours of discovery; • maintain system logs for 180 days within India; • implement network segmentation, role-based access controls and multi-factor authentication for privileged users; • prioritise the use of validated and certified IT prod - ucts, including indigenously manufactured prod - ucts, where feasible for CII; • ensure accountability for data protection even where third-party processors are engaged, sup - ported by contractual security obligations and audit rights; • establish and periodically test a Cyber Crisis Management Plan (CCMP) in co-ordination with NCIIPC; and • validate Protected Systems at least once every two years to assess resilience against evolving threats. The CISO is required to maintain regular contact with the NCIIPC and is responsible for implementing the security measures suggested by NCIIPC using all available/appropriate ways of communication. Fur - ther, under the IT Act, any person who secures access or attempts to secure access to a Protected System in contravention of the provisions shall be punished with imprisonment which may extend to ten years and a fine. For entities designated as SDFs under the DPDPA, additional governance and accountability require - ments apply under Rule 13 of the DPDP Rules, includ - ing: • conducting periodic Data Protection Impact Assessments (DPIAs) addressing processing activities, risks, mitigation measures, algorithmic impacts and high-risk use cases; • updating DPIAs following system redesigns, adop - tion of new technologies or material changes in data flows • undergoing annual independent data protection audits;

• ensuring algorithmic transparency and safeguards where automated decision-making affects indi - vidual rights; • implementing enhanced protections for sensitive categories of data, including biometric, health, financial and children’s data; and • appointing a qualified Data Protection Officer (DPO) reporting directly to senior management. Under the DPDPA, security safeguard failures or fail - ure to notify data breaches to the DPBI may attract penalties of up to INR250 crore (1 crore equals 10 million) (USD27.2 million, approximately). 2.3 Incident Response and Notification Obligations Entities operating in India may be subject to paral - lel and multi-agency incident reporting obligations, depending on the nature of the incident and the sys - tems affected. CERT-In serves as the national nodal agency for all cybersecurity incident reporting, while the NCIIPC is the designated authority for Protected Systems and CII. The DPBI, operationalised in 2025 under the DPDP Act, handles personal data breaches. Sector- specific regulators, such as the RBI, SEBI, IRDAI and CEA impose additional reporting obligations on enti - ties in finance, securities, insurance and power. Reporting timelines are defined according to the type of incident: • general cybersecurity incidents, including unau - thorised access, malware infection, or critical system compromise, must be reported to CERT-In within six hours; • any incident affecting a Protected System or CII must be reported within six hours to both CERT-In and NCIIPC; and • personal data breaches, including unauthorised processing or loss of access to personal data, must be reported to the DPBI within 72 hours. Initial notifications must include the nature of the inci - dent, date and time of detection, affected systems or data, and immediate mitigation measures. Detailed reports may additionally require:

197 CHAMBERS.COM

Powered by