top of page

Cyber Incident Disclosure by Listed Indian Companies

  • 16 hours ago
  • 11 min read

Introduction : There are multiple disclosure obligations, with multiple clocks, multiple audiences, and multiple statutes, that apply to a listed Indian company in the event of a cyber incident. The Securities and Exchange Board of India ("SEBI") mandates that material events be disclosed to stock exchanges in hours and the Indian Computer Emergency Response Team ("CERT-In") mandates that specified cyber incidents be reported to the government within 6 hours of an entity being aware of the incident; the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Rules notified under it in November 2025 require notification to the Data Protection Board of India and to the affected individuals; and the company's own commercial contracts frequently include separately negotiated breach-notification obligations with customers, vendors and insurers. The obligations do not occur in order, rather they occur concurrently, and, in many cases, prior to the facts each regime requires a company to disclose.


This means that for boards and general counsel there is a real structuring issue in how to comply with each disclosure regime while not disclosing prematurely, not destroying an ongoing forensic investigation and not getting the facts wrong in a rush to meet the disclosure requirements. This article looks at the concept of overlapping disclosure for listed Indian companies, the conflicting timelines and materiality issues, an investigation privilege over the “work product” of forensic and incident response, and the dangers of premature or incomplete disclosure, before ending with a board-approved disclosure protocol for an incident


Legal Analysis


The many and varied triggers for disclosures -


Each of the disclosure triggers for a listed company that suffers a cyber incident could have a different clock, a different recipient, and different disclosure requirements.


The CERT-In has outlined a time limit of 6 hours for reporting a specified Cyber incident to the CERT-In even if there is no material impact on the securities market. This report is confidential to the government and no report is a public disclosure on its own.


In contrast, SEBI has a willfully two-track approach. Every cyber incident, breach or loss of data, regardless of its magnitude, shall be disclosed in the Corporate Governance Report of the listed entity for the quarter in which it happens, under the proposed Regulation 27(2)(ba) which was included in the Consultation Paper only because SEBI's own discussion in 2022 with the listed entities while introducing the track understood that such a requirement would leave entities exposed to follow-on attacks while they are still ongoing. However, if the incident independently meets the materiality test in Regulation 30(4) (either by reference to quantitative thresholds or to the probability that the information will affect a decision by a reasonable investor, or by reference to its quantitative thresholds based on turnover, net worth and profitability), disclosure is required under Regulation 30(6), which mandates disclosure to be made within 30 minutes after a board action on the subject or 12 hours after the information is disseminated if it comes from within the company, or 24 hours if from sources outside the company.


Also, the DPDP Act and the Rules in 2025 introduce a third, distinct, requirement, which does not depend on the materiality to the investors but rather on the actual occurrence of a personal data breach. Under Rule 7, an initial notification to the Data Protection Board must be sent "without undue delay," a detailed report is due in 72 hours and notification to those affected must be sent "without delay" but with no outer limit similar to the 72-hour rule for the Board. Layered on top of all three statutory regimes, contractual notification windows often exist around the time the discovery is made, typically 24 to 72 hours, that trigger indemnity, audit, or termination rights that are independent of the notification windows imposed by SEBI, CERT-in and the Data Protection Board.


The practical problem is that these obligations are not only different in terms of when the company must learn the information before it shares it, they are also different in terms of what the company is expected to learn. The six-hour window is CERT-In's assumption that an incident has happened, but not necessarily that it is known. The materiality test adopted by SEBI assumes the company can, within a few hours, evaluate the likely financial or operational repercussions, assessment which may not be reliably possible for a legitimate intrusion until a forensic investigation is well into its course. The DPDP framework assumes that in a similarly short time, the company can determine which customers' data has actually been breached. If a company tries to disclose the provisional information and then later adjust it in accordance with both regimes, it is more likely to be subject to regulatory scrutiny than a company that discloses the information at a measured pace.


Investigation Privilege - Forensic Work Product


One of the oft-overlooked considerations in structuring a question is whether the forensic investigation report, often the most detailed and most damaging document the company will create about what went wrong in the aftermath of an incident, is privileged, and therefore not subject to compelled production to a regulator, litigant, or to an adversary in subsequent proceedings.


Section 132 of the Bharatiya Sakshya Adhiniyam, 2023 (which replaces Section 126 of the former Indian Evidence Act, 1872) provides for such privilege. This privilege applies to communications in the process of or in connection with obtaining legal services. It does not necessarily apply to a report prepared by a third party forensic or cyber security entity hired directly by the IT or information security function of the company in the ordinary course of incident response, as such a report would not, on its own, be a communication between the company and its legal adviser, but rather would be an operational document prepared for remediation.


There is, at present, no extensive precedent for such structuring of the relationship between the forensic firm and the company and the same has not been tested in the Indian courts and regulators as extensively as it has been tested in other countries around the world, where the relationship is commonly engaged with the outside legal counsel and not directly with the forensic firm such that the resulting report is prepared to enable the legal counsel to provide legal advice, which has become a standard approach internationally. If a company adopts this structure in India, it should consider it to be a prudent and reasonable precaution rather than an absolute safeguard, mark all such work product as privileged and confidential, pass the instructions to the forensic firm through counsel and keep a contemporaneous record of the operational (or non-privileged) incident apart from counsel's assessment of privilege, in order to have some contemporaneous factual recording of the incident which cannot be challenged if a claim should ever be raised that the work product was not privileged and confidential.


Investor Communications overlap with Insider Trading.


The disclosure of a cyber incident is connected to the SEBI (Prohibition of Insider Trading) Regulations, 2015, where it is determined that the incident is material. This information about a significant cyber incident, prior to its release in the public market, can constitute UPSI, and trading windows for individuals who have knowledge of the incident must be considered, while any communication to analysts or institutional investors or to the media before the formal stock exchange disclosure is likely to be deemed as selective disclosure. As with other such events that cause UPSI, communication with investors should be handled in a similar way following a cyber incident, by issuing a single public statement, with any additional investor questions being referred back to that statement instead of fielded informally. Leading to risk of premature or incomplete disclosure. Whether a regime wants to move quickly or take their time in a thorough forensic investigation presents an actual risk on both sides of the timing issue.


By disclosing prematurely, without understanding the scope of an incident, this could lead to provisional or incorrect information being made public, which, when later corrected, might be perceived by regulators or investors as an initial attempt to downplay the severity of the incident, or incompetence, inviting scrutiny under the general disclosure-accuracy obligations in Regulation 4(1) of the SEBI LODR and, in more severe instances, under SEBI's framework for fraud and market-manipulation. Public disclosure of a specific vulnerability exploited or systems affected, before a vulnerability is contained, can also help the attacker and may make it difficult to remediate an incident, which is why SEBI chose to inform the public of routine cyber incidents in a quarterly Corporate Governance Report instead of requiring immediate disclosure of all incidents. From the privacy point of view, informing people before the firm has a reliable way of knowing who was the victim of the breach could cause them undue worry, and a string of sequential messages is likely to discredit the firm's ability to secure its privacy policies. From the privacy side, informing people before the firm has a reliable way of knowing who was the victim of the breach will cause them undue worry, while a string of sequential messages is bound to be a discredit to the firm's ability to secure its privacy policies.


On the other hand, the well-known side effects of revealing incompletely and in a late stage apply. In the case of Central Depository Services (India) Limited, instead of penalizing for the cyberattack itself, SEBI imposed a cumulative penalty of ₹1 crore (₹90 lakh under SEBI Act, 1992 and ₹10 lakh under the Depositories Act, 1996) on the entity for its failure to appropriately classify a critical internet-facing server, to subject it to the necessary vulnerability assessment and penetration tests, and to adhere to its own cybersecurity protocols in the run-up to the incident. The order highlights that the quantum and quality of the disclosure made after a cyber incident is not the only aspect which SEBI focuses upon while monitoring the cyber incident; it also gives attention to the quantum and quality of the governance and control framework that existed prior to the cyber incident, which is relevant for the disclosure readiness as a part of cybersecurity governance.


Practical Implications


The overlapping disclosure framework has specific implications of governance for listed Indian companies. First, it is clear that cyber incident response is not an IT-led, purely technical activity anymore, and as the CDSL order notes, SEBI takes the same view on the adequacy of governance and control frameworks as it does on the adequacy of disclosure following a cyber incident, and oversight of cybersecurity is a disclosure-ready issue as well as an operational one for the board. Second, the timelines of the reporting of confidentiality to CERT-In (six hours), disclosure to SEBI (within materiality) (12/24 hours) and disclosure to DPDP (without undue delay/72 hours) means that companies will need a pre-built compliance calendar against each regime, rather than build one during the active incident. Third, the uncertainty about the privilege that attaches to the forensic investigation reports in India, counsels caution, and it is advisable to conduct forensic engagements through counsel, which, again, is not tried before Indian courts. Fourth, the meeting with the requirements of insider-trading regulations should be treated as concurrent, not sequential, assessments of the materiality requirement under Regulation 30 and the UPSI requirements and trading window implications.


In the long term, listed entities and market infrastructure institutions are likely to experience more convergence between governance and disclosure committees as SEBI's enforcement action (as seen in the CDSL order) is likely to lead to the review of governance and disclosure practices, and cyber-incident response is likely to become a standing, board-approved protocol, rather than an ad hoc response that is assembled after an incident.


Board-Approved Incident Disclosure Protocol


The cyber incident disclosure protocol outlined below is proposed as a model for a board-approved cyber incident disclosure procedure that should be adopted before an incident occurs and rehearsed through periodic simulations:


  1. Incident Command Formation. On a detected suspicious cyber incident, call a standing Incident Response Committee comprised of the Chief Information Security Officer, General Counsel or a senior legal representative, the Company Secretary or Compliance Officer, and the Chief Financial Officer, along with a designated board member or Audit Committee representative, who has the authority to convene within hours, not days.

  2. Immediate Containment, Confidential Reporting. Immediately focus on technical containment, while simultaneously putting together and submitting the CERT-In report within the 6-hour period, with available information, and indicating that more information will come in as the investigation proceeds, in keeping with CERT-In's other guidance allowing for phased reporting.

  3. Enlist the assistance of Forensic Counsel, under Privilege. Use external forensic and incident-response experts as directed by outside legal counsel, not by the information-security function, to ensure the best possible claim of privilege to the investigation report and to keep a separate, non-privileged incident containment and remediation log.

  4. Materiality Assessment in relation to the Board Approved Policy. Assign the Incident Response Committee a preliminary materiality assessment of the incident in the context of the company's Board approved Materiality Policy, noting this is a provisional assessment, and, where the incident seems reasonably likely to materialize, prepare a holding disclosure to stock exchanges that includes the fact and nature of the incident and the company's response, but not promises as yet to be verified quantitative impact figures.

  5. Trading Window Controls and UPSI. Determine if the incident constitutes UPSI, include the incident in structured digital database, and limit trading by persons designated as having knowledge of the incident, the doing of which will occur concurrently with the Regulation 30 'materiality' assessment, but should not be an after-thought.

  6. Institutional Recognized Public and Regulatory Disclosure. Timing the SEBI disclosure within the required time limits under Regulation 30(6); making an initial notification to the Data Protection Board under the DPDP Act within the "without undue delay" period, but with discretion in mind that this period should not be extended to ensure compliance with the "without delay" requirement; withholding notification to individual Data Principals whose information has been compromised or misused, until they can be identified by the company with reasonable certainty, while keeping in mind that this period should not be extended in order to comply with the "without delay" requirement.

  7. Contractual Notification Review. Ensure that legal counsel cross-check all material commercial, vendor and insurance contracts against a notification obligation register which is already kept in order, and that contractual notification deadlines (which may be earlier than statutory deadlines) are not missed.

  8. Centralised Investor Communication. Communicate with investors and analysts through a single, designated spokesperson and through a single public disclosure, with regular updates as material facts are known, rather than allowing several functions of the company to give incremental or informal statements.

  9. Disclosure Reconciliation - Post Incident Review. After containment, do a formal post-incident review and identify and resolve any inconsistencies, which should be brought to the notice of the next periodic review of the Board-approved protocol.


Conclusion


Today, there is no single rulebook for the disclosure of cyber incidents by listed Indian companies, rather an overlapping framework of securities, cyber-security and data-protection laws, each with a different timeframe and disclosure and notification obligations. The problem with this is not the lack of law to apply, but the lack of verified fact in the moment of an actual incident to please any of these regimes. It is well to remember that those who "work it out" as the incident unfolds are the ones who are most likely to end up disclosing prematurely, inconsistently or too late, let the example of SEBI's enforcement action against CDSL be a reminder. The best way to make this disjointed compliance program a coordinated, defensible response is to establish a board-approved, pre-tested incident disclosure protocol based on a single incident command structure, privilege-aware investigation practice and a strategic, sequential process for every regulatory and contractual deadline.


Author: Mahathi Iyer in case of any queries please contact/write back to us via email to content@khuranaandkhurana.com or at  Khurana & Khurana, Advocates and IP Attorney.


Endnotes


  1. Securities and Exchange Board of India, Securities and Exchange Board of India (Listing Obligations and Disclosure Requirements) Regulations, 2015, as amended up to 22 January 2026, especially Regulations 27 and 30, read with the applicable materiality and disclosure framework for listed entities. The Regulations specifically provide for disclosure of details of cybersecurity incidents, breaches, or loss of data/documents in the corporate governance reporting framework.

    SEBI LODR Regulations, 2015 – Updated Text

  2. Indian Computer Emergency Response Team (CERT-In), Directions under section 70B(6) of the Information Technology Act, 2000 relating to information security practices, procedure, prevention, response and reporting of cyber incidents for Safe & Trusted Internet, dated 28 April 2022, requiring specified cyber incidents to be reported to CERT-In within six hours of noticing the incident or being brought to notice of such incident.

    CERT-In Cyber Security Directions

  3. Digital Personal Data Protection Act, 2023, section 8(6), read with the Digital Personal Data Protection Rules, 2025, Rule 7, concerning intimation of personal data breaches to affected Data Principals and the Data Protection Board, including the requirement to furnish prescribed detailed information within 72 hours, or such longer period as permitted by the Board. The commencement notification should also be considered because the DPDP framework follows a phased enforcement timeline.

    Digital Personal Data Protection Rules, 2025 – MeitY

  4. Bharatiya Sakshya Adhiniyam, 2023, sections 132–134, governing professional communications, the non-waiver of privilege merely through voluntary evidence, and confidential communications with legal advisers. These provisions provide the statutory basis for legal professional privilege; however, whether privilege extends to a particular third-party forensic report will depend on the facts, purpose and structure of the engagement.

    Bharatiya Sakshya Adhiniyam, 2023 – Official Text

  5. Securities and Exchange Board of India (Prohibition of Insider Trading) Regulations, 2015, as last amended on 12 March 2025, particularly the provisions governing unpublished price sensitive information, its communication and handling, together with SEBI's framework concerning structured digital databases and fair disclosure. A significant cyber incident may require a fact-specific assessment of whether the information is UPSI before it becomes generally available.



Recent Posts

See All
Smart Contracts in IPR Paradigm

Smart Contracts, a concept that was proposed in 1994, with the intention to execute contractual obligations using computer codes has...

 
 
 
Smart Contract In The Indian Crucible

Smart Contracts- First Impressions Few words have caused as much bewilderment in the Indian setup as “blockchain” and “smart contracts” have. Much excitement has been generated by the coverage of cryp

 
 
 

Comments


bottom of page