By Securelay Research
Six hours is a reporting window—not a licence to guess.
CERT-In’s directions require specified cyber incidents to be reported within six hours of noticing the incident or being brought to notice. The accompanying FAQ recognises that the first report may contain only the information available at that time, with additional information supplied later.

Report early, then improve the facts
The first report should clearly separate confirmed facts, current scope, containment already performed, evidence still being collected, and the next update time. Waiting for perfect forensics can miss the deadline; presenting assumptions as facts creates a different risk. Build a process for progressive, attributable updates.
Design for fast scoping
Maintain a current data map, synchronized clocks, durable application and identity logs, request identifiers, processor contacts, and an incident decision log. Minimize where plaintext exists. If sensitive fields are replaced with opaque references on selected application paths, a database exposure on those paths may have a smaller data impact than an equivalent plaintext dump.
Say only what the evidence proves
A vault audit trail can show whether configured token reveal operations occurred through that vault during the investigated period. It cannot prove that no personal data left through an unmanaged export, an unintegrated service, a compromised endpoint, or another plaintext copy. Incident statements must preserve that boundary.
Run the six-hour drill
Choose a realistic data-leak scenario and time five actions: detect, preserve evidence, identify the reportable category, notify accountable leaders, and send the initial report. Capture gaps as engineering work. Repeat until the team can produce a defensible initial statement without inventing certainty.
