When the incident happens
A cyber incident in India is a regulated event. CERT-In Rule 3 mandates reporting within 6 hours. The DPDP Act requires DPB India notification for personal data breaches. RBI-regulated entities have additional 2-hour and 6-hour reporting obligations. SEBI-regulated entities have their own framework.
A traditional incident response engagement starts with a call and ends with a report. Bachao.AI's IR engagement starts with containment and ends with regulatory closure.
This page describes how we handle incidents.
Engagement modes
Emergency response (no prior relationship):
- First responder on the call within 30 minutes (24×7)
- Engagement letter signed via DocuSign in real time
- Containment actions begin within 60 minutes
- Suitable when an active incident is happening NOW
- Pre-signed engagement letter, runbooks pre-shared
- First responder paged within 15 minutes
- Containment actions begin within 30 minutes
- Monthly retainer covers 4 hours of proactive readiness work (tabletops, runbook updates)
The 6-phase response
Phase 1: Containment (Hour 0–4)
The named incident commander takes the call. Within the first 30 minutes:
- Severity assessment
- Containment actions agreed with the customer's IT lead
- Evidence preservation (forensic image captured before any remediation)
- Customer notification draft started in parallel
CERT-In Rule 3 mandates initial reporting within 6 hours. Bachao.AI's CERT-In submission template is pre-filled with the customer's CSP/UID/registration. We submit the initial report from our side with the customer's approval — typically within 4 hours.
Phase 3: Investigation (Hour 4–48)
Forensic team works on the captured evidence:
- Initial access vector identification
- Lateral movement timeline reconstruction
- Affected data scope determination
- Persistence and exfiltration assessment
Phase 4: Customer + regulator notification (Hour 24–72)
DPDP Section 8(6) requires DPB India notification for personal data breaches within 72 hours. We draft the notification; the customer's legal counsel reviews; we submit.
If customers (data principals) are affected, we draft the customer notification. Customer's CMO/Legal review; we send.
Phase 5: Remediation (Day 3–14)
The remediation depends on the incident:
- Credential reset and rotation
- Identified initial access vector closure
- Lateral movement path closure
- Persistence mechanism removal
- Detection rule deployment for the observed TTPs
Phase 6: Lessons learned + regulatory closure (Day 14–30)
- Post-incident review with customer executive team
- Root cause analysis document
- Updated runbook for similar future incidents
- Final CERT-In closure report
- Final DPB India update if required
- Documentation package for the customer's auditors
Know your vulnerabilities before attackers do
Run a free VAPT scan — takes 5 minutes, no signup required.
Book Your Free ScanWhat the incident commander does
The named Bachao.AI incident commander is your single point of contact through the engagement. They:
- Run the war-room channel (Slack/Teams)
- Coordinate Bachao.AI's forensic + comms teams
- Speak to your CEO/board on update calls
- Speak to CERT-In/DPB India officials with you
- Speak to your audit firm if SOC 2 / ISO 27001 involved
- Sign off the final report
Common incident types we handle
| Type | Typical duration | Critical actions |
|---|---|---|
| Ransomware (operational impact) | 5–14 days | Backup integrity check, decision on payment, restore + harden |
| Credential compromise (no data loss) | 1–3 days | Reset, rotate, lateral movement check, regulatory notification |
| Customer data breach | 3–14 days | Scope determination, customer notification, DPB India filing |
| Insider data exfiltration | 7–21 days | Forensic recovery, HR/legal coordination, custodial discovery |
| Business email compromise | 2–7 days | Funds recovery attempt, recipient list audit, MFA enforcement |
| Supply chain attack (third-party SaaS) | 7–14 days | Affected scope mapping, third-party coordination, regulator filings |
How to start (retainer)
A retainer engagement starts with a 90-minute scoping workshop. We capture:
- Critical asset inventory
- Notification contacts (CEO, CFO, CISO, legal counsel, PR)
- Pre-approved containment authority
- Runbook references
Schedule the IR retainer scoping call →
How to start (emergency)
Call the 24×7 IR hotline. First responder on the call within 30 minutes. Engagement letter signed via DocuSign during the call. Containment begins inside 60 minutes.
Related: Case Study: Chennai NBFC Ransomware Contained in 4 Hours · CERT-In 6-Hour Reporting Explained
