The 72-Hour Challenge: Building DPDP-Ready Incident Response Capabilities for Organizations
As DPDP reshapes breach response expectations, Indian enterprises must rethink incident readiness, manage dual regulatory timelines and build resilient response capabilities.

Data breaches today are no longer a question of "if" but "when." For Indian enterprises, the challenge lies in building the capability to detect, contain and respond before a breach becomes a business crisis. Statistics point out that organizations in India face an average of 3,195 cyber attacks per week, which is 62% higher than the global average. Incidents take an average of 263 days to identify and contain.
The DPDP Act introduces a new dimension to this challenge. Organizations are no longer evaluated only on their ability to prevent cyber incidents, but also on their ability to respond effectively when personal data is compromised. Under the Act, failure to meet breach-related requirements, may result in significant financial penalties, with certain violations carrying penalties of up to ₹250 crore.
However, beyond financial penalties, the real operational challenge for organizations is the race against reporting time.
Stricter breach management expectations require organizations to assess and respond to personal data breaches quickly. Organizations are expected to provide an initial notification without delay and submit detailed breach information within the prescribed timelines to the Data Protection Board of India (DPBI) and affected Data Principals.
If an organization’s incident response capability is designed only for technical investigation and containment, it may no longer be sufficient for the regulatory environment emerging in India. Hence, organizations must redesign their response models right from the earliest stages of an incident.
The Two Regulatory Clocks Organizations Must Manage During a Breach
When a breach occurs, organizations are not responding against a single timeline. They must manage two parallel regulatory expectations, each focused on a different aspect of the incident.
The CERT-In Security Clock
CERT-In reporting requirements operate from a broader cyber security perspective. Under the CERT-In directions issued under the Information Technology Act, certain categories of incidents must be reported within prescribed timelines, including the six-hour reporting requirement for specified incidents after noticing them.
This focuses on the broader technical characteristics of the event, including unauthorized access, ransomware, data breaches and other cyber threats.
The DPDP Privacy Clock
DPDP introduces defined timelines for breach-related notifications, requiring organizations to rapidly assess the nature and impact of personal data breaches and communicate relevant information within 72 hours.
Unlike CERT-In requirements, which focus on broader cyber security incidents, DPDP obligations focus specifically on protecting personal data and affected individuals.
This dual-clock system means organizations can no longer wait for the perfect report to communicate about the incident. They must simultaneously investigate, contain, assess impact and prepare regulatory communications.
What Constitutes a Breach Under the Indian Regulatory Landscape?
To respond effectively, organizations must first understand what triggers these obligations.
Under the DPDP framework, a personal data breach broadly refers to unauthorized processing, disclosure, alteration, loss or compromise of personal data.
CERT-In requirements operate from a broader cyber security perspective and cover a wider range of security incidents beyond personal data breaches.
Understanding the difference between cyber security incidents and personal data breaches is critical because the response requirements, stakeholders involved and reporting obligations may differ.
When Does the Regulatory Clock Actually Start?
A critical challenge for organizations is determining when an incident becomes a reportable event.
The response timeline begins when the organization becomes aware, or reasonably believes, that a personal data breach may have occurred.
For example:
- If a database administrator discovers a misconfigured Amazon S3 bucket containing customer phone numbers exposed to the public internet, the regulatory clock starts ticking.
- If an employee falls victim to a phishing attack and their credentials are used to access active HR databases, the regulatory clock starts ticking.
This makes early detection, clear escalation criteria and well-defined incident ownership essential components of DPDP readiness. Your incident response playbook must establish a clear threshold for what constitutes "awareness" so that triage begins immediately, rather than after lengthy internal discussions.
How Can Indian Organizations Manage the Critical 72-Hour DPDP Reporting Window?
An effective DPDP-ready Incident Response plan must define exactly how teams respond during this critical window. It must remove uncertainty, establish ownership and ensure that every function understands its role before an incident occurs.
Hours 0 to 12: Triage, Containment, and CERT-In Response
- Isolate and Contain
Immediately block compromised accounts, revoke API keys, isolate affected servers and restrict network traffic.
- Establish Incident Response Coordination
Assemble the core response team, including the CISO, DPO, legal counsel, compliance teams and other relevant business stakeholders.
- CERT-In Filing
File the required security incident report with CERT-In within the applicable timeline.
Hours 12 to 36: Impact Assessment and Root Cause Analysis
- Analyze the Impact
Determine exactly what personal data has been compromised. Examples include Aadhaar numbers, financial information, health records or basic contact details.
- Estimate the Scope
Assess how many Data Principals may be impacted and determine whether the data was encrypted, hashed or exposed in plain text.
- Conduct Forensic Investigation
Deploy forensic teams to identify the vulnerability exploited and understand the root cause of the incident.
Hours 36 to 60: Preparing Notifications
- Prepare DPBI Notification
Prepare detailed breach information covering:
- Nature of the breach
- Number of affected users
- Likely consequences
- Mitigation measures taken
- Prepare Data Principal Communication
Develop notifications for affected individuals using clear and simple language while avoiding unnecessary jargons.
Hours 60 to 72: Execution and Filing
- Final Review and Approval
Complete legal, compliance and executive reviews.
- Submit Required Notifications
Submit the required breach information to the DPBI within the prescribed timeline and notify affected Data Principals through approved communication channels.
Rewriting The Incident Response Playbook: Four Critical Changes For Organizations
Meeting DPDP timelines requires more than updating breach notification procedures. Organizations must redesign how incident response is coordinated and tested.
1. Shift Legal From "Approver" to "Active Responder"
Historically, many incident response models involved legal teams only after technical investigation was complete. Under a 72-hour response requirement, this approach is no longer effective.
The Change:
Legal and compliance officers must be embedded into the response process from the beginning. They must work alongside security teams to provide timely guidance and support faster decision-making.
2. Create Pre-Approved Notification Templates
Organizations cannot afford to develop communication strategies during an active crisis.
The Change:
Create and maintain approved templates for regulatory reporting and customer communications. These should include placeholders for critical information such as:
- Number of affected records
- Types of personal data involved
- Recovery timelines
This allows teams to focus on accurate assessment rather than building communication processes from scratch.
3. Standardize Data Inventory
Organizations cannot protect or report on data they do not know exists. Doing a readiness assessment as part of your compliance activities can be helpful. If security teams spend the first 24 hours of a breach trying to identify where affected personal data is stored, meeting regulatory timelines becomes more difficult.
The Change:
Implement data discovery and classification capabilities. Maintain an updated data map connecting personal data assets with business owners and systems to accelerate impact assessment.
4. Define Tiered Vendor SLA Requirements
Many breaches originate from third-party platforms, SaaS providers, marketing vendors or cloud providers. If a vendor takes several days to notify an organization about a breach, the organization may already face compliance challenges.
The Change:
Review third-party agreements and establish clear breach notification requirements. Ensure processors notify security teams of suspected personal data breaches within defined timelines.
The Culture Shift: Practicing Under Pressure
A documented incident response plan is not the same as operational readiness. Organizations must transition from theoretical checklists to realistic simulation exercises.
Conduct regular tabletop exercises that simulate a dual-regulatory crisis, where teams must balance:
- A live incident scenario
- CERT-In reporting expectations
- DPDP breach response requirements
Measure how quickly teams identify "awareness," how effectively stakeholders coordinate, and where response bottlenecks exist.
Closing Note
The DPDP Act represents a fundamental shift in how India approaches personal data protection. It requires organizations to move beyond simply preventing breaches and toward building the capability to respond with transparency, accountability and precision.
In this era, resilience will not be measured only by how well organizations prevent incidents but by how confidently they respond when prevention fails.
Frequently Asked Questions
What is the India Digital Personal Data Protection Act (DPDP Act)?
The DPDP Act is India's first comprehensive framework governing the processing of digital personal data. It balances the right of individuals to protect their personal data with the need to process such data for lawful purposes. Unlike previous patchwork regulations, the DPDP Act sets a high bar for consent-based processing, data minimization, and accountability for any entity—known as a Data Fiduciary—that determines the purpose of data collection.
Which organizations and individuals does the India DPDP Act impact?
The Act has a broad reach, applying to all private and public sector entities that process digital personal data within India. It also has extraterritorial jurisdiction, meaning it applies to foreign companies offering goods or services to individuals in India.
Internally, it impacts every level of your organization. Whether it is HR handling employee records, Marketing managing customer leads, or IT overseeing data architecture, every staff member who interacts with "Data Principals" (individuals) must comply with the law’s strict mandates on transparency and security.
What are the penalties for breaching the DPDP Act, and what are some examples?
The Data Protection Board of India (DPBI) enforces significant financial penalties that are designed to be deterrent rather than just symbolic. Penalties are levied per violation and can reach:
- ₹250 Crore for failure to take reasonable security safeguards to prevent data breaches.
- ₹200 Crore for failure to notify the Board and affected individuals of a breach.
- ₹150 Crore for non-compliance with additional obligations of Significant Data Fiduciaries (SDFs).
Common breach scenarios include failing to secure cloud databases leading to data leaks, processing children’s data without verifiable parental consent, or failing to implement a robust grievance redressal mechanism for users.
What are the top cyber threats currently facing Indian businesses?
India is currently one of the most targeted regions for cyber warfare and financial crime. Key threats in the 2026 landscape include:
- AI-Enhanced Phishing: Hyper-personalized social engineering attacks using Deepfakes and AI-generated scripts to target finance and HR departments.
- Double-Extortion Ransomware: Where attackers not only lock systems but also threaten to leak sensitive data, triggering immediate DPDP Act penalties.
- Supply Chain Attacks: Exploiting vulnerabilities in third-party vendors to gain access to the primary organization’s data.
- Credential Harvesting: Targeted attacks on employee login portals to bypass traditional perimeter security.
Request a demo
Reduce human cyber and compliance risks with targeted training.
Get a guided walkthrough — at a time that suits your timezone.
