The Economics of Cybercrime and Security
CERT-In and India's Cyber Rules
How India's cyber agency and laws govern incident reporting and data protection, including the 2022 six-hour reporting rule and the data protection law.
India has built a framework for cybersecurity.
CERT-In
The Indian Computer Emergency Response Team (CERT-In), under the IT ministry, handles cyber incidents and issues advisories.
2022 directions
In April 2022, CERT-In required organisations to:
- Report cyber incidents within 6 hours.
- Keep logs for 180 days.
- VPN providers to store user data.
Industry criticised the short deadline and data requirements; some VPN firms moved servers out of India.
Laws
- Information Technology Act, 2000: covers cyber offences.
- Digital Personal Data Protection Act, 2023: requires firms to protect personal data, with penalties up to 250 crore rupees for security failures. Rules were notified in 2025.
Critical infrastructure
NCIIPC protects critical sectors like power, banking and telecom.
Sector regulators
RBI, SEBI and IRDAI set cybersecurity rules for banks, markets and insurers.
Economic trade-off
Rules improve security and accountability, but compliance adds costs, especially for small firms.
A company detects a breach at 10 am. Under CERT-In rules, it must report by 4 pm, even before understanding the full scope.
CERT-In directions and the 2023 data law set requirements.
- CERT-In handles India's cyber incidents.
- 2022 rules require reporting within 6 hours.
- The 2023 data law allows penalties up to 250 crore rupees.
- Sector regulators add their own rules.
No recording for this one yet - EconReader can read it aloud for you.