← All field notes
Incident response · 6 minute read

By Securelay Research

Six hours is a reporting window—not a licence to guess.

CERT-In’s directions require specified cyber incidents to be reported within six hours of noticing the incident or being brought to notice. The accompanying FAQ recognises that the first report may contain only the information available at that time, with additional information supplied later.

Incident timeline separating confirmed facts from unknowns during the CERT-In reporting window.
Original Securelay editorial timeline based on the CERT-In directions dated 28 April 2022 and their official FAQ.
Primary source CERT-In Cyber Security Directions dated 28 April 2022Primary source CERT-In FAQ on the Cyber Security Directions

Report early, then improve the facts

The first report should clearly separate confirmed facts, current scope, containment already performed, evidence still being collected, and the next update time. Waiting for perfect forensics can miss the deadline; presenting assumptions as facts creates a different risk. Build a process for progressive, attributable updates.

Design for fast scoping

Maintain a current data map, synchronized clocks, durable application and identity logs, request identifiers, processor contacts, and an incident decision log. Minimize where plaintext exists. If sensitive fields are replaced with opaque references on selected application paths, a database exposure on those paths may have a smaller data impact than an equivalent plaintext dump.

Say only what the evidence proves

A vault audit trail can show whether configured token reveal operations occurred through that vault during the investigated period. It cannot prove that no personal data left through an unmanaged export, an unintegrated service, a compromised endpoint, or another plaintext copy. Incident statements must preserve that boundary.

Run the six-hour drill

Choose a realistic data-leak scenario and time five actions: detect, preserve evidence, identify the reportable category, notify accountable leaders, and send the initial report. Capture gaps as engineering work. Repeat until the team can produce a defensible initial statement without inventing certainty.

Put the control on the data path.Discuss an architecture review