Cybersecurity 2026

INDIA Law and Practice Contributed by: Anoop Narayanan, Priyanka Gupta and Harshita Sakarya, ANA Law Group

• description of affected data categories; • description of affected data subjects; • proposed or implemented mitigation steps; and • contact details of the CISO or DPO. Notifications are submitted to CERT-In via the official incident reporting template by email or 24/7 helpdesk, to NCIIPC through channels established in the enti - ty’s Cyber Crisis Management Plan, and to the DPBI through its online portal or mobile application. CERT-In assigns a tracking number, analyses the incident, and provides guidance on containment and recovery. Entities are expected to provide updates as more information becomes available, and Protected Systems are generally required to prepare post-inci - dent reports, including root-cause analysis, corrective measures, and, in some cases, third-party audits to verify remediation. System logs and related techni - cal records must be maintained locally for 180 days to facilitate investigation, compliance and regulatory follow-up. 2.4 State Responsibilities and Obligations The National Cyber Security Policy, 2013, lays down the protection and resilience of CII, building a secure and resilient cyberspace, creating mechanisms for security threat early warning, vulnerability manage - ment, and response to security threats as some of the primary responsibilities of the government. The policy prescribes that the government should work towards rapid identification, information exchange, investigation and co-ordinated response and reme - diation, which can effectively mitigate the damage caused by malicious cyberspace activity. CERT-In is the main authority responsible for analys - ing trends and patterns in intruder activities, determin - ing the scope, priority and threat of a cyber incident and developing preventive strategies against cyberse - curity incidents. With the aim of identifying cybersecu - rity vulnerabilities and promoting resilience, CERT-In follows a “Responsible Vulnerability Disclosure and Co-ordination Policy”, in terms of which it collects, analyses and mitigates co-ordination with research - ers/finders and vendors leading to the public disclo -

sure of newly identified cybersecurity vulnerabilities and threats. Upon receiving any information regarding a cyberse - curity vulnerability, CERT-In will examine and validate the vulnerability report and communicate to the dis - closer whether or not the report will be co-ordinated by CERT-In. Upon successful validation, CERT-In will initiate co-ordination with the relevant product ven - dor, discloser and other stakeholders (if required) for the remediation and closure of the issue. CERT-In will endeavour to get the issue resolved within 120 days from initial vendor contact date. Under the proposed National Cybersecurity Strate - gy, states are expected to establish dedicated State Cybersecurity Cells tasked with monitoring, co-ordi - nating and responding to cyber threats at the regional level. These cells work in close co-ordination with the National Cyber Co-ordination Centre (NCCC), CERT-In and the NCIIPC to ensure a unified response to cyber incidents. 3. Operational Resilience in the Financial Sector 3.1 Scope of Financial Sector Operational Resilience Regulation India’s financial sector operational resilience frame - work is principally articulated through regulator-issued guidance and framework. The RBI’s Guidance Note on Operational Risk Man - agement and Operational Resilience (the “Guidance Note”) issued in April 2024, is a key development in this area, which applies to Regulated Entities (REs) including all commercial banks, primary (Urban) Co- Operative Banks/State Co-Operative Banks/Central Co-Operative Banks, All-India Financial Institutions and All Non-Banking Financial Companies including Housing Finance Companies. RBI’s Guidance Note intends to promote and further improve the effectiveness of Operational Risk Man - agement of the REs, and enhance their Operational Resilience in view of the interconnections and inter - dependencies, within the financial system, that result

198 CHAMBERS.COM

Powered by