The Eight Questions
You Will Be Asked at Hour One
A regulator, a board member, a customer’s security team, or the engineer trying to work out what happened. Five of the eight can be answered late, by waking the right person. The other three have an answer that must already exist by the time the question arrives, and cannot be created afterwards at all. This is the assessment built backwards from a live incident, to be worked on a quiet afternoon.
The Eight Questions You Will Be Asked at Hour One
Enter your work email for the printable assessment — the eight questions with a column for where yours lives, the 180-day log test by system class, the backup and restore fields, the time-synchronisation checklist, the filings table, the filing rehearsal, and the weighted score you take to whoever funds the work.
Check your inbox
We've emailed you a link to download The Eight Questions You Will Be Asked at Hour One.
The link expires in 48 hours. If it hasn't arrived in a few minutes, check your spam folder.
We couldn't send the download link. Please try again, or contact us and we'll email you The Eight Questions You Will Be Asked at Hour One.
The argument
Five can be assembled under pressure. Three cannot be assembled at all
Five of the eight can be answered late, badly, at 02:00, by waking the right person. The other three have a property those five do not: the answer is made of something that had to exist before the incident began, and the hour it is asked in is too late to start.
The designated Point of Contact
Row 1.3 · fifteen of the hundred points
A Point of Contact designated at hour two is a designation made late. What section 1 asks for is an Annexure II record already sent to info@cert-in.org.in, with the date of the last update beside it.
The retention window
Row 1.4 · twenty of the hundred points
A retention window that has already rolled past the start of an intrusion cannot be extended backwards. Section 2 asks how many days are actually held by system class, rather than the number the policy states.
The agreed clock
Row 1.6 · ten of the hundred points
Clocks synchronised on the morning after do not retrospectively agree about last month. It carries ten because it is a configuration change: a score of 0 here can become a 4 in an afternoon, which is true of none of the other five.
Section 7 weights the six scored areas accordingly, and asks you to score each one twice: as it is today, and as it will be once the gaps you have just written down are closed. The second column is the one to put in front of whoever funds the work. Read the result as a diagnostic rather than a grade — any criterion at 0 or 1 is worth more attention than the total.
What it asks
Read the middle column first: where the answer must already live
The question is not the point. The point is whether the answer exists somewhere before anybody asks it, and who would have to be woken to find it. In the document each of these carries a fourth column, and it is the one you write in: where yours lives, and who holds it.
1.1
When did you notice, and how?
A record made at the moment of noticing, separate from the record of detection. Where somebody else told you, the two are different moments and the gap can be days.
Why it is asked. Direction (ii) runs from “noticing such incidents or being brought to notice about such incidents”. The RBI clock runs from detection.
1.2
Which type of incident is it?
Annexure I’s twenty types, printed and to hand. Work the list and tick every one that describes the incident.
Why it is asked. Direction (ii) requires any service provider, intermediary, data centre, body corporate and Government organisation to report cyber incidents as mentioned in Annexure I to CERT-In within 6 hours.
1.3
Who is your Point of Contact for CERT-In?
An Annexure II record already sent to info@cert-in.org.in, with the date of the last update.
Why it is asked. Direction (iii): “The service providers, intermediaries, data centres, body corporate and Government organisations shall designate a Point of Contact to interface with CERT-In”, in the format at Annexure II, “updated from time to time”.
1.4
How many days of logs do you hold, by system?
A retention register naming each system class and the number of days actually held — not the number in the policy.
Why it is asked. Direction (iv): “All service providers, intermediaries, data centres, body corporate and Government organisations shall mandatorily enable logs of all their ICT systems and maintain them securely for a rolling period of 180 days”, within the Indian jurisdiction. Section 2.
1.5
Which restore point is known-good, and when was that last tested?
A restore test record with a date on it.
Why it is asked. Section 3. This row rests on the other seven: each of them assumes a recovery is possible, and the restore test is the only thing that establishes it.
1.6
Do your clocks agree?
The NTP configuration, and the date it was last verified.
Why it is asked. Direction (i): synchronisation of all ICT system clocks to NIC or NPL, or to servers traceable to them. Section 4.
1.7
Who can take production offline, right now?
A named person and a named deputy, with out-of-hours contact details.
Why it is asked. Section 6, set against row 1.2’s six-hour clock — an approval path slower than the clock is what spends it.
1.8
Which regulators do you owe, and by when?
A one-line record of your entity class and the paragraph that governs it.
Why it is asked. Section 5. For an RBI-regulated entity the DAKSH paragraph differs by class; for a SEBI RE, Annexure-O part B clause 1 and Table 36.
Contents
Nine sections, seven of them things you fill in
It is a working document, not a guide. Sections 1 to 7 are the afternoon’s work, section 8 is where every clause in it came from, and section 9 is the only page on which we describe what we do.
1. The eight questions
The eight above, set as a table with a fourth column you fill in: where yours lives, and who holds it. Read the middle column first — the question is not the point.
2. Log availability: the 180-day test
Thirteen system classes taken from CERT-In’s own answer at FAQ Q 37, five blank lines for the ones you add, and four columns per row: days actually held, where stored, who produces it and how fast, and whether failures are recorded as well as successes.
3. Backup integrity: the test, and its date
One question in five parts, and “we have backups” is not an answer to any of them. The date a restore was last performed and the restored data opened; what was restored and to where; retention depth; reachability and credentials; who owns the decision.
4. Time synchronisation
Direction (i) and the reason CERT-In gives for it, then a five-item checklist with a write-in on every line — including the systems outside the synchronised estate and their known offset.
5. Which filings you owe, recorded in advance
Five rows, each scoped by who it addresses: CERT-In, the DAKSH paragraph for your RBI class, the National Housing Bank for a Housing Finance Company, SEBI and its portal, and the exchange or depository for a broker or DP. Write your own paragraph number in.
6. The filing rehearsal
Eight fields: who drafts, who approves and what they need to see, who sends and from which mailbox, who signs off outside working hours, the destinations from section 5, who can take production offline, the segmentation you would rely on, and the date this was last rehearsed end to end.
7. Scoring
Six weighted criteria totalling 100, scored twice — as things are today, and as they will be once the gaps you have just written down are closed. A 0–4 scale anchored to observable states of your own estate.
8. Sources
Five instruments with their reference and the sections that use each: the CERT-In Directions of 28 April 2022, the May 2022 FAQs, the CERT-In Rules 2013, the RBI Directions of 31 July 2026 and the SEBI CSCRF.
9. Working with Security Brigade
The one page where we describe what we do — what an engagement covers, what it produces, and which of the six scored areas need no firm at all.
Where each answer comes from
Every row says what it rests on
Six of the eight questions name an instrument by Direction, paragraph or clause, quoted in the regulator’s own words. The other two rest on other rows of the pack, and say so: the restore test at 1.5 rests on the other seven questions, each of which assumes a recovery is possible, and the containment authority at 1.7 rests on 1.2’s six-hour clock, because an approval path slower than the clock is what spends it.
CERT-In Directions
Shall Direction (ii) · No. 20(3)/2022-CERT-In, 28 April 2022Direction (ii) requires any service provider, intermediary, data centre, body corporate and Government organisation to report cyber incidents as mentioned in Annexure I to CERT-In within 6 hours. It runs from “noticing such incidents or being brought to notice about such incidents”, which is why question 1.1 asks for a record of the moment of noticing kept separately from the record of detection: where a third party told you, those are two different moments.
CERT-In Directions
Shall Direction (iii) and Annexure IIThe service providers, intermediaries, data centres, body corporate and Government organisations “shall designate a Point of Contact to interface with CERT-In”, in the format at Annexure II, “updated from time to time”. The same Direction provides that where CERT-In issues an order or direction for cyber incident response, it “may include the format of the information that is required (up to and including near real-time), and a specified timeframe in which it is required, which should be adhered to and compliance provided to CERT-In, else it would be treated as non-compliance of this direction”. A requisition can therefore arrive with a timeframe attached, and it arrives at the Point of Contact — which is why section 6 rehearses the approval path rather than only the first filing.
CERT-In Directions
Shall mandatorily Direction (iv)“All service providers, intermediaries, data centres, body corporate and Government organisations shall mandatorily enable logs of all their ICT systems and maintain them securely for a rolling period of 180 days and the same shall be maintained within the Indian jurisdiction.” Section 2 turns that into a table you fill in against what you hold, and on shared hosting or a managed platform the answer belongs to somebody else — which is a ticket you can raise this afternoon.
CERT-In FAQs on Cyber Security Directions
Should May 2022 · Q 37CERT-In’s own answer begins “The logs that should be maintained depend on the sector that the organisation is in, such as Firewall logs, Intrusion Prevention Systems logs, SIEM logs, web / database/ mail / FTP / Proxy server logs, Event logs of critical systems, Application logs, ATM switch logs, SSH logs, VPN logs etc.”, and records that “this list of logs is not exhaustive but has been mentioned to provide flavour of logs to be maintained by the relevant teams”. Those thirteen classes are the rows of section 2, with blank lines for the ones you add. The answer also carries the sentence the table’s last column is built on: “From the incident response and analysis perspective both successful as well as unsuccessful events shall be recorded.”
CERT-In Directions
Shall Direction (i) · with FAQ Q 39, Q 40 and Q 43Direction (i) requires all service providers, intermediaries, data centres, body corporate and Government organisations to “connect to the Network Time Protocol (NTP) Server of National Informatics Centre (NIC) or National Physical Laboratory (NPL) or with NTP servers traceable to these NTP servers, for synchronisation of all their ICT systems clocks”. Entities whose ICT infrastructure spans multiple geographies “may also use accurate and standard time source other than NPL and NIC, however it is to be ensured that their time source shall not deviate from NPL and NIC”. CERT-In gives the reason at FAQ Q 39: “A typical cyber incident involves multiple computer systems within as well as across entities. Without an accurate time stamp it is extremely challenging to re-create accurate sequence of events thus causing serious hindrance while handling cyber incidents.” Q 43 names samay1.nic.in, samay2.nic.in and time.nplindia.org; Q 40 adds that “The time zone information shall also be recorded along-with time to facilitate accurate conversion at the time of need.”
IT (CERT-In and Manner of Performing Functions and Duties) Rules, 2013
May seek G.S.R. 20(E) · Rules 14(1), 14(3) and 12(1)Rule 14(1) provides that any officer of CERT-In not below the rank of Deputy Secretary to the Government of India may seek information from service providers, intermediaries, data centres, body corporate and any other person for carrying out the functions provided in sub-section (4) of section 70B of the Act, and Rule 14(3) adds that the information sought is to be submitted “within the duration and in the format provided alongwith the communication sent for seeking the information”. Rule 12(1) puts the CERT-In Incident Response Help Desk “on 24 hours basis on all days including Government and other public holidays”. Section 6 asks the matching question about your own approval path.
RBI Directions, 31 July 2026
Shall /410 ¶182 · /419 ¶181 · /428 ¶181 · /437 ¶88 · /461 ¶28 or ¶141 · /470 ¶177A Commercial Bank as /410 ¶3 defines that term, a Small Finance Bank, Payments Bank, Urban Co-operative Bank, Credit Information Company, an NBFC in the Base Layer with asset size ₹500 crore and above, or an NBFC in the Middle, Upper or Top Layer other than a Core Investment Company or a Housing Finance Company reports cyber incidents within six hours of detection on the DAKSH platform. A Housing Finance Company reports cyber incidents to the National Housing Bank, per the note at /461 ¶141. Establishing which of those describes you is a reading exercise, and section 5 is where you write the paragraph number down.
SEBI CSCRF
Shall Annexure-O part B clause 1 · Table 36 · 20 August 2024, v1.0A SEBI regulated entity whose incident falls under the CERT-In Cybersecurity directions notifies SEBI and CERT-In within 6 hours of noticing or detecting it, or being brought to notice — SEBI at mkt_incidents@sebi.gov.in — and files on the SEBI Incident Reporting Portal within 24 hours; any other cybersecurity incident goes to SEBI, CERT-In and NCIIPC, as applicable, within 24 hours. A stock broker or depository participant also reports to its stock exchange or depository inside the same 6 hours. Table 36 then dates what follows: an interim report at 3 days, mitigation at 7, root cause analysis at 30 and a VAPT at 45, each running from the date the incident was reported or you were brought to notice of it.
Section 8 of the document lists all five sources with their full reference and the sections that use each. Several of these apply by entity class, and which class describes you decides which paragraph number goes in your copy of section 5 — confirm that against the instrument itself before it reaches a board paper.
What it is, and what it is not
Four of the six scored areas need no firm at all
Designating a Point of Contact is eight fields and an email. Asking your host how many days of logs they keep is one ticket. Running a restore test is an afternoon. Putting the estate on samay1.nic.in is a configuration change. Do those first. Three of them — the Point of Contact, the log retention and the time source — are the rows that cannot be created once an incident has started; the restore test is simply cheaper to run today than to discover on the night. This pack is worth more to you filled in than any conversation with us.
Where it turns into work you want help with, Security Brigade responds to live incidents 24/7 on +91 22 4164 2220 and has been CERT-In empanelled since 2008. We take full ownership of CERT-In six-hour incident notification as part of an engagement; the statutory obligation stays with your entity, because FAQ Q 13 puts it there and it is “neither transferrable nor indemnified”. If what you want instead is the clause-by-clause map of every filing you owe across CERT-In, RBI and SEBI, that is The India Incident Reporting Pack, free on this site.
Scored yourself and found a 0?
Tell us which of the six areas you scored lowest and which entity class describes you. Those two decide what has to exist before an incident and what can be assembled during one.
Describe your estate