Board Accountability for Cybersecurity Failures in India
Introduction : Cybersecurity is now no longer an information technology (IT) issue, but a corporate governance and board accountability issue. A major incident in the cyber world can result in the ability to disrupt the business, loss of confidential or personal information, financial loss, loss of confidence in the market, and legal, contractual and regulatory exposure to a company. Rather than just a question of whether a company was attacked, the question is whether a company's board was exercising appropriate oversight over a known and significant business risk.This responsibility is triggered by a combination of corporate law, securities regulation, data protection obligations and sector specific cybersecurity obligations in India.
The Companies Act 2013 sets out statutory duties of the directors which include obligations to act in good faith and to demonstrate the exercise of proper care, skill and diligence. Risk management and internal controls are also stressed in the corporate governance framework. The SEBI (Listing Obligations and Disclosure Requirements) Regulations 2015 ('LODR') and SEBI's Cybersecurity and Cyber Resilience Framework ('CSCRF') were introduced in 2024 and introduce further expectations on the part of listed entities and securities-market participants with respect to their cybersecurity governance, resilience, reporting and oversight.
But a cyberattack doesn't necessarily mean a governance failure. It's not fair to hold a director responsible for every cyber threat. The question that should be asked is whether the board had set up proportionate procedures to detect and monitor cyber risks, whether material warnings and vulnerabilities were brought up, whether management was adequately supervised and whether the company complied with relevant regulatory and disclosure obligations.Listed entities have disclosure requirements which are especially important. Disclosure of material events/information within prescribed timelines is regulated by Regulation 30 read with Schedule III of the LODR and quarterly reporting in relation to specified cybersecurity incidents/breaches and loss of data/documents is regulated by Regulation 27(2)(ba). The Digital Personal Data Protection Act 2023 also imposes obligations on reasonable security safeguards and a serious statutory penalty regime, once it enters into force and applies.A key aspect of board-level risk management is insurance.
The purpose of D&O insurance and of standalone cyber liability insurance is different, and the availability of coverage is dependent on the exact wording, exclusions and facts of the insurance policies. Therefore, boards should take a comprehensive approach to cybersecurity risk by addressing it in addition to financial, operational, legal and reputational risk, not as a technical problem.This article explores when poor oversight of cyber-risk can constitute a material failure of governance by a board, the duties and regulatory requirements placed on a board, relevant Indian case law, insurance considerations and practical steps boards can take to improve their cybersecurity governance.
Legal Provisions
Companies Act 2013 : The Companies Act 2013 provides the foundational framework for directors’ accountability. Section 166 requires directors to act in good faith, exercise due and reasonable care, skill and diligence, and exercise independent judgment. They come into play when the company faces a reasonably foreseeable and substantial risk of a cybersecurity incident. In accordance with section 134(3)(n), the Board's Report must include details of the development and implementation of a risk-management policy concerning risk factors which could affect the company's continued operations. Section 134 is also part of the overall internal-control and legal-compliance regime. The Act does not explicitly place a duty on the director to prevent cyberattacks, but a lack of identifying, escalating or addressing the significant cyber risks could be taken into account when determining whether the director has fulfilled his or her statutory duties.
SEBI LODR Regulations : The SEBI (Listing Obligations and Disclosure Requirements) Regulations 2015 ('LODR') prescribe further governance and disclosure requirements for listed entities. Board responsibilities and oversight of risk management are covered in Regulation 17. Note that Regulation 27(2)(ba) obligates reporting of specified cybersecurity incidents or breaches and lost data or documents quarterly. Regulation 30, when read with Schedule III, is applicable to disclosure of material events or information, including applicable timelines for qualifying events, separately. Therefore, a listed entity must evaluate a cyber incidence on its own merits, not only for periodic reporting, but also to determine whether the incident constitutes material information that should be disclosed as soon as possible.
SEBI Cybersecurity and Cyber Resilience Framework : In August 2024, SEBI's Cybersecurity and Cyber Resilience Framework ('CSCRF') considerably enhances cybersecurity governance of SEBI-regulated entities. It covers governance, cybersecurity policies, asset and risk management, vulnerability assessment, incident response, cyber audits, data security, outsourcing and resilience. Its aims are to prepare for, resist, manage, recover from and learn from cyber incidents. The requirements applicable to a specific regulated entity should also be inferred from later SEBI clarifications and other communications regarding the implementation of these requirements. The CSCRF reaffirms the notion that cyber-security should be included in a formal enterprise-risk management framework, and that it is not just an IT problem.
Information Technology Act 2000 and CERT-In Directions
The Information Technology Act 2000, particularly sections 43A and 70B, remains relevant to corporate cybersecurity and incident response. Section 70B establishes CERT-In as the national agency for cyber incident response. The CERT-In directions issued under section 70B impose specified obligations concerning cybersecurity incidents, reporting and log retention. Non-compliance may therefore contribute to regulatory exposure and, depending on the circumstances, the assessment of management and board oversight.
Digital Personal Data Protection Act 2023
The Digital Personal Data Protection Act 2023 ('DPDP Act') establishes obligations concerning protection of digital personal data. Section 33 read with Schedule 1 provides the penalty framework, including a maximum penalty of ₹250 crore for failure to take reasonable security safeguards to prevent personal data breaches. Its application must, however, be considered in light of the commencement of the relevant provisions and rules. Boards should therefore distinguish between enacted provisions and obligations presently operational.
Insurance and Risk Transfer
Cyber risk should also be addressed through appropriate insurance planning. D&O insurance is a different product than standalone cyber liability insurance and coverage will be dependent on the specific policy wording, exclusions, policy definitions and the nature of the claim. Boards should not rely on D&O coverage for cyber losses being automatic. Cyber insurance might cover certain first-party and third party exposures; D&O policies might respond to certain claims against directors based on the terms of the policies. Insurance should therefore complement, not substitute for effective cyber-risk governance.
Legal Analysis
Directors' Fiduciary Duty of Care : The Companies Act stipulates a duty of care, skill and diligence to be exercised by directors in the best interests of the company. With the rise of technology in today's economy, cybersecurity is becoming part of corporate risk, and courts and regulators are stepping in to hold companies accountable.Courts and regulators are increasingly looking at cybersecurity as a part of the corporate risk profile in today's digital economy and holding companies accountable. Although there have been no cases in India that have held a director personally liable for a data breach, it is established that directors cannot be held automatically liable for any organizational misconduct without evidence of any fault in them. In Shiv Kumar Jatia v. State of NCT of Delhi (2019), the Supreme Court set aside criminal charges against company officers since “accountability in the absence of any concrete evidence of their personal negligence or criminal intent” was not enough. If a board member is responsible for a cyber incident, that person must have demonstrated a failure to take reasonable steps to monitor or a conscious failure to see red flags.
Best practice (and emerging law) however, holds that where an entity fails to provide appropriate “cyber” security and management is a failure of the fiduciary duty. In recent years, courts around the world have shifted their attitude toward the requirement for adequate cybersecurity measures to become a part of what a director should consider in good faith when assessing corporate risk. In India, under the Companies Act §166, penalties are imposed on individual directors when they fail in their duties (₹100,000 – ₹500,000). These penalties are personal, but aren't very big. Furthermore, Section 245 (class actions) of the Act provides shareholders with the right to pursue damages against directors for any “fraudulent, unlawful or wrongful act or omission” which can include gross negligence in cyber oversight.
Regulation and disclosure obligations : The Listing Regulations of SEBI require the board to have obligations in respect of cyber security. Reg. 17(9) requires boards to set up risk management procedures and continuously review them. Boards shall be advised of cyber risks and remediation plans by either Boards' Risk Management Committee (if established) or the full board). Under Reg. 27(2)(ba), any cyber “incident or breach or loss of data” is to be reported to the stock exchanges in the quarterly report. More urgently, Reg. 30 read with schedule III is for submitting intimation about “material events” in time. This rule may be triggered if there is a material impact on the business or share value due to a cyber-attack.
The 30(2) regulation stipulates “as soon as possible” and at any rate 24 hours after, disclosure of the occurrence. All material events, caused by internal sources, must be disclosed no later than 12 hours after they occur. Therefore, a cyber incident of material size (an incident that impacts customers or is harmful to operations, for instance) requires virtually instantaneous notification to regulators and investors. Otherwise it would be a major compliance lapse, which may even constitute a failure in governance.
Failure of Material : A cyber incident is a material failure in the governance if it is a result of a failure in either the board's oversight or the internal controls. These could be: (a) a large volume of data breached in which the board failed to follow through with required security audits; (b) a ransomware attack that caused significant business disruption; or (c) loss of critical systems from the failure to take action on vulnerability reports. In both instances, the regulators and courts would examine if the board had adequate policies (such as incident response plans, periodic audits of cybersecurity conducted by auditors on the CERT-In panel) in place and how it responded when cybersecurity issues came up. The directors' failure to “anticipate, withstand, contain or recover” themselves from cyber threats (the CSCRF's goals) as a result of an incident could be considered to be a material governance failure.
Insurance Considerations : Many companies have Directors & Officers (D&O) insurance but this type of insurance is usually limited to cover general acts of fraud and does not cover privacy breaches or cyber incidents. With respect to practice, a major cyber incident may not be insured by a D&O policy. The board should take steps to ensure that separate cyber liability insurance is in place. The coverage would respond to first-party losses (forensic investigation, notification, business interruption, regulatory fines) that a D&O coverage would not respond to.
Case Laws
There is a dearth of case law on cybersecurity law in India, and the general principles are applicable. In the case of Sunil Bharti Mittal v. CBI (2015), the Supreme Court stated that a corporate director does not have any personal liability for a company's offence unless there is evidence that he participated in the offence and had a personal motive. In the absence of an explicit statute on vicarious liability, the Court did not presume that the managing director is liable for the company's wrongdoings. In Shiv Kumar Jatia v. State of Delhi (2019), the Court reiterated the same: it set aside the charges against a company's director on the ground that no allegation had been made against him regarding his active negligence causing the harm. These cases are a reminder that India's Courts demand “tangible fault” on the part of the director before holding the director criminally liable.
Similarly, if a Cyber-Breach leads to a civil or regulatory response, directors would not be held liable until it could be demonstrated that they were aware that they neglected or otherwise violated any legal obligations. Penalties, for example, are generally applicable to the company or the “service provider” who processes the data under Sections 43A or 72A of the IT Act. No criminal conviction for a sole failure of the Corporate Data Breach under IT Act for a Director. Directors are unlikely to be personally liable if they can establish they took “reasonable security measures” and had no reason to suspect the breach.
Where directors can demonstrate that they took “reasonable security measures” and had no reason to suspect the breach, they will likely avoid personal liability. In the commercial litigation arena, the plaintiffs can try to invoke a director’s duty of care (Sec. 166) against the corporation or allege any breaches of its duty of care and argue for relief under shareholder oppression remedies (Sec. 166), but no Indian litigation has tested those remedies in the cyber context. In general, Sunil Bharti Mittal and Shiv Kumar Jatia impart that the liability is based on the director's culpability and not just his position.
Practical Implications
For Indian businesses and boards, the above legal framework has several implications:
Board Cybersecurity Agenda : Boards need to proactively incorporate cyber risk into their governance. This involves setting clear policies and holding management responsible for frequent vulnerability assessments and ensuring that everyone is aware of the importance of cyber-awareness. Some areas explored include the designation of a Chief Information Security Officer (CISO), reporting on threat metrics by management, and auditing incident response plans. Boards are encouraged to establish a committee or task force on cybersecurity or technology or assign the responsibility to the audit/risk committee.
Regulatory and Disclosure Practices : Companies need to keep abreast of reporting requirements. Management should inform CERT-In under IT Act and meet all the requirements of sectoral regulators, if there is any significant breach. The incident is considered material to investors and should be disclosed in view of the requirements of SEBI's LODR rules. Boards need to ensure that disclosure by management is timely and complete to prevent penalties and investor confidence loss due to delays or inadequate disclosure.
Insurance and Liability Mitigation : The board should annually review the insurance coverage. A cyber liability and directors-and-officers policy evaluation can help identify whether existing policies are adequate. Indian law does not require such insurance, but experience all over the world has demonstrated that failures to obtain this insurance frequently result in costly claims; it is a wise application of risk-management policy to have such insurance in place.
Investor and Market Reactions : The trend of investors seeing cyber as a critical component of the ESG (Environmental, Social, Governance) factor is gaining momentum. Large asset managers could raise specific questions regarding the management of a company's cyber governance. If not handled properly, a grave breach may lead to shareholder activism or to rating downgrades. Boards should directly dialogue with investors about cyber strategy and gain their trust.
Emerging Trends : Securities regulators, such as the U.S. SEC, have started holding boards and CEOs accountable for cybersecurity reporting. Although India has not yet caught up with enforcement, the trend indicates that directors can be subject to court action in the future if there is lax enforcement of cyber rules. Boards should thus record their work on cyber-governance. The concept of "reasonable security measures" may refer to industry standards, such as ISO 27001, NIST and CERT-In Best Practices. Experts in governance say that it is now considered best practice for directors to be trained and for the board to have regular discussions about cyber.
Conclusion
Cybersecurity is truly in the boardroom of India. Directors should be aware that cybersecurity risk is not an “IT problem,” but rather a material risk to the business. Under the Companies Act and SEBI regulations, there are general obligations on boards for risk-management, and new legislation (such as the DPDP Act) is increasing the cost of non-compliance. In the Indian context, a major cyber-incident is likely to be deemed as significant as per the Indian law. If directors of Indian organizations are held liable for breaches under cyber laws in India, it remains to be seen but boards should be mindful that if such a breach is a result of a failure to monitor, it will be investigated. Boards should thus pursue an aggressive approach to cyber-governance: establish strong security policies, conduct regular security audits, mandates management to report on cyber-risk and provide sufficient insurance. Improving these governance processes could make companies better equipped to deal with cyber threats and provide assurance to regulators and investors that the board has discharged its responsibility for cybersecurity.
Author: Raghav Goyal in case of any queries please contact/write back to us via email to content@khuranaandkhurana.com or at Khurana & Khurana, Advocates and IP Attorney
References
Companies Act, 2013, § 134(3)(n) (India) (board report must include risk management policy).
Companies Act, 2013, § 166(3) (India) (duty of care, skill and diligence of directors).
Securities and Exchange Board of India (Listing Obligations and Disclosure Requirements) Regulations, 2015, Reg. 17(9)(b) (board responsible for risk-management plan).
Securities and Exchange Board of India (Listing Obligations and Disclosure Requirements) Regulations, 2015, Reg. 27(2)(ba) (disclosure of cyber incidents).
Information Technology Act, 2000, § 70B (India) (powers of CERT-In to direct cyber incident reporting).
Information Technology Act, 2000, § 43A (India) (liability for negligent security practices).
Information Technology Act, 2000, § 72A (India) (penalties for disclosure of personal data).
Digital Personal Data Protection Act, 2023 (India) (data fiduciary security and breach reporting requirements).
Apoorva Saxena & Amrita Rathi, Role of Directors in Corporate Cybersecurity: A Critical Analysis, 7 Indian J. L. & Legal Res. 4350 (2025).
Dhruv Kaushal & Aniket Ghosh, DPDP Act 2023: Director Liability, Board Responsibilities and Data Privacy Compliance for Indian Companies, Legal500 (India) (July 2, 2023).
Aisha Begum Ansari, Cyber security incidents to be reported quarterly to stock exchanges, Vinod Kothari (Oct. 4, 2023).
Lt. Gen. Surinder Nath, Cyber Security in Boardrooms, Director Today (Institute of Directors, India) (Jul. 2, 2024).
Sunil Bharti Mittal v. Central Bureau of Investigation, (2015) 10 SCC 189 (India).
Shiv Kumar Jatia v. State of Delhi, (2019) 16 SCC 609 (India).




Comments