July 23, 2026
The 6-Hour Clock: Why Most Organizations Aren’t Ready for Incident Reporting
That knot in your stomach when you discover a potential breach? It’s worse when you realize the clock is already ticking.
By Innovations Arm
2 min read
That knot in your stomach when you discover a potential breach? It's worse when you realize the clock is already ticking.
Six hours. That's the window you have to report a cybersecurity incident to CERT-In. And if you're a SEBI-regulated entity, the pressure is even higher.
When you discover a potential breach, that 6-hour window can feel like 6 minutes. It's stressful. It's urgent. And it's easy to panic.
Here's the thing. Panic is the enemy of good reporting.
Think of it like an emergency triage center. When someone arrives with a critical injury, you don't perform complex surgery on the spot. You triage. You stabilize. You communicate clearly to the right people.
The same applies to cybersecurity reporting. Your incident reporting process should be a triage, not a full investigation.
The Problem: Two Regulators, One Incident
Here's what makes incident reporting complicated for regulated entities in India.
CERT-In requires reporting within 6 hours of detection. SEBI CSCRF also requires incident reporting, but with a different focus — market integrity, investor confidence, and operational stability.
Most incidents that trigger CERT-In reporting will also trigger SEBI CSCRF reporting. But they use different formats and have different expectations.
Organizations that haven't prepared for this dual-reporting requirement often find themselves scrambling — submitting incomplete reports, missing deadlines, or duplicating effort across teams.
The Solution: A Reporting Playbook
The difference between panic and control is having a playbook. A structured approach to incident reporting helps you stay calm and communicate clearly when it matters most.
Here's a simple framework:
Hour 1 — Detection Immediately notify your incident response team. Don't wait for confirmation. Start the clock.
Hour 2 — Triage Gather initial information. Determine if what you've detected is an event or a reportable incident.
Hour 3 — Verification Collect evidence. Document everything. Regulators want to know what happened, when, and what you're doing.
Hours 4–5 — Reporting Draft and submit notifications to CERT-In and SEBI using prescribed templates.
Hour 6+ — Follow-Up Assign a coordinator to provide updates and handle regulator questions promptly.
The "False Alarm" Trap
Here's a question we hear a lot: "What if I report something that turns out to be nothing?"
Here's the reality. Over-reporting is better than under-reporting.
Regulators aren't penalizing organizations for reporting incidents that turn out to be false alarms. They're penalizing organizations that fail to report — or report too late.
The 6-hour window isn't a deadline to confirm everything. It's a deadline to start the communication process.
Three Things You Can Do This Week
-
Define Your Reporting Team Who has decision-making authority? Who will draft the reports? Who will communicate with regulators? Define these roles now, before an incident occurs.
-
Draft Your Notification Templates Don't write a report from scratch under pressure. Prepare templates for both CERT-In and SEBI reporting. Include placeholders for incident details, affected systems, and actions taken.
-
Conduct a 6-Hour Simulation The best way to test your readiness is to practice. Run a tabletop exercise that simulates a breach and tests your ability to detect, triage, and report within 6 hours.
Read the Full Guide
We go deep on how to prepare for the 6-hour reporting window, including:
- The exact differences between CERT-In and SEBI reporting requirements
- A step-by-step reporting playbook
- How to avoid common reporting mistakes
- What to do if you're unsure whether an incident is reportable
- How to coordinate dual reporting to both regulators
Book a cybersecurity consultation with ARM Innovations.
📞 +91 9910422411 📧 support@arm-innovations.com 🌐 www.arm-innovations.com
🛡️ Stay Informed. Stay Prepared. Stay Secure.