Resources
Guides, templates, and educational content about this site may be hacked.
Downloads
Free, no obligation. We email a confirmation link, then the file.
The First 72 Hours
An hour-by-hour action pack for the first three days of a cyber incident in India — what to do before the evidence is gone, who to wake, and the filing that is due at hour six.
The India Incident Reporting Pack
What a regulated Indian entity owes in the first six hours, and in the forty-five days after — the CERT-In Directions of 28 April 2022, the RBI Directions of 31 July 2026 and the SEBI CSCRF, side by side with the clause behind each row.
The Eight Questions You Will Be Asked at Hour One
A readiness assessment built backwards from a live incident: eight questions somebody will ask in the first hour, where each answer has to already live, and the clause that puts it there.
Guides and templates
Business email compromise — the money left this morning
A payment went to an account that was not your supplier's. The instinct is to chase the money, and that is right — but a BEC is a mailbox intrusion first and a fraud second, and the two run on different clocks. What to do in the first hours, in what order, and why the mailbox investigation cannot wait for the recovery attempt.
How they got in — and why your logs decide whether you can answer
The morning after, the question is how. A short list of entry classes, each confirmed from a different record — and every one of those records is a log with a retention window set by whoever runs the infrastructure. Where that window is shorter than the intrusion, the honest finding is 'root cause undetermined' — and this is how to write one.
Website defacement, or a Google warning on your site: the first hour
A replaced homepage, or a Chrome warning on your site. What to copy before you touch the server, and the CERT-In clause that puts a defaced site on a six-hour clock.
What the ransom decision actually turns on
By the time the question reaches you it is usually framed as pay or don't. It is really five separate findings, and four of them can be established in the first two days: which strain it is, whether a decryptor already exists, whether your backups actually restore, and whether data left the building. The six-hour CERT-In filing is due either way.
Preserve it before you rebuild
Powering the machine off, restoring from backup, re-imaging, and quietly cleaning up: four reasonable instincts, each of which destroys something no technique recovers afterwards. What each one takes with it, and a preservation sequence a system owner can work through with what they already have — before anyone with a forensics kit arrives.
The six-hour report: what actually gets sent, and who else you owe
You noticed at 09:40. CERT-In is due by 15:40. What goes in the six-hour report, who sends it, and which other regulators are owed a filing too.
The first hour, and the first seventy-two
The order to work in from the moment you find out: what to stop doing, what to preserve, who to call, and what CERT-In's Direction (ii) of 28 April 2022 requires within six hours of noticing an incident or being brought to notice about it. Preservation comes before remediation — a rebuilt server is an answer nobody can reconstruct.