Cyber Incident Reporting Timelines: IIBF Exam Guide 2026
Every bank employee preparing for the Prevention of Cyber Crime paper eventually runs into one deceptively simple exam question: how fast must a breach be reported? Understanding cyber incident reporting timelines is not just an exam requirement — it is the backbone of how Indian banks stay compliant with CERT-In and RBI supervisory expectations after any security event. This guide breaks down the reporting clock, the escalation chain inside a bank, and the exact facts examiners love to test.
Most candidates memorise isolated facts about phishing or ransomware but forget that every one of those incidents eventually funnels into the same reporting pipeline. If the clock is missed, even a well-handled technical response can still turn into a regulatory failure. That is why cyber incident reporting timelines deserve their own dedicated study session rather than a passing mention inside a broader chapter.
🔐 Why Reporting Timelines Exist
Cyber incidents rarely stay contained to one system. A single compromised credential can move laterally across core banking, ATM switches, and payment gateways within minutes. Regulators built strict reporting timelines precisely because delay compounds damage — both to the affected bank and to the wider financial system it is connected to through NPCI, RTGS, and interbank settlement rails. A late report means CERT-In and the RBI's supervisory teams cannot coordinate a sector-wide response, issue advisories to other banks, or block a fraud pattern before it spreads.
The logic mirrors fire-safety regulation: the rule is not really about paperwork, it is about giving a central authority enough lead time to contain a spreading risk. For exam purposes, remember that reporting obligations apply regardless of whether customer money was actually lost — detection and materiality trigger the clock, not confirmed loss. Read the Introduction To Cyber Crimes chapter for the foundational classification of incidents that feed into this reporting duty.
💡 Exam Tip: Timelines are measured from the moment of detection or notice, not from the moment the root cause is confirmed — a common examiner trap.
📜 CERT-In's Six-Hour Rule
India's CERT-In (Indian Computer Emergency Response Team) directions require regulated entities, including banks, to report specified categories of cyber incidents within six hours of detection or of the incident being brought to their notice. This is one of the strictest reporting windows globally and is frequently tested because candidates confuse it with the 24-hour or 72-hour windows used in some international frameworks (such as GDPR's 72-hour rule, which does not apply here).
The reportable categories are broad: unauthorised access to IT systems, data breaches, ransomware, DDoS attacks, defacement of banking portals, and compromise of critical infrastructure all qualify. Banks typically maintain a standing template pre-approved by their information security team so that the initial report can be filed within the window even while forensic investigation is still ongoing — a preliminary report followed by a detailed one is standard practice. This connects directly to how banks classify attack vectors, covered in Channels Of Cyber Crimes.
⚠️ Common Mistake: Candidates often answer "24 hours" by confusing CERT-In's window with unrelated data-breach norms from other jurisdictions — the correct figure for India is 6 hours.

🏦 RBI's Cyber Security Framework and Bank-Level Response
Layered on top of CERT-In's directions, the Reserve Bank of India expects every bank to run a 24x7 Security Operations Centre (SOC) capable of continuous monitoring, detection, and first-response containment. The RBI framework requires banks to have a documented Cyber Crisis Management Plan (CCMP) that defines exactly who declares an incident, who notifies CERT-In and the RBI, and how customer-facing communication is handled in parallel. External authoritative guidance on these expectations is published by the Reserve Bank of India's cyber security framework circular, which examiners frequently reference for factual accuracy.
Inside the bank, incident management is a coordinated exercise: the SOC detects and triages, the CISO's office validates severity, compliance drafts the regulatory report, and corporate communications manages customer disclosure where personal data or funds were affected. This full lifecycle — detection to closure — is detailed in the Incident Management chapter, which pairs well with this article for scenario-based questions.
📌 Remember: A missed reporting deadline is treated as a compliance failure in its own right, independent of how well the technical incident itself was ultimately resolved.
⚖️ Legal Backing Under the IT Act and Related Provisions
The reporting duty is not just a circular-level instruction — it draws statutory weight from India's information technology law, which defines unauthorised access, data theft, and system damage as punishable offences and empowers CERT-In to function as the national nodal agency for incident response coordination. Banks that fail to report as required can face supervisory action from the RBI in addition to any liability arising under the underlying statute.
This is also where candidates should connect the dots between technical failure modes and legal consequence: a poorly-secured endpoint that enables unauthorised access (see Computer Insecurity) is not just an IT problem, it is the trigger event for the entire reporting chain described above. Similarly, card-present and card-not-present compromises covered under Electronic Card Frauds fall under the same six-hour clock the moment they are classified as a security incident rather than an isolated customer dispute.
For a broader view of how banks structure their overall fraud response programme — of which incident reporting is one piece — see our companion guide on fraud management in banking.

🧭 Building an Exam-Ready Response Checklist
For exam purposes, it helps to reduce the entire topic to a sequence: detect, classify severity, notify internally (SOC to CISO to compliance), file the preliminary CERT-In report within six hours, run the RBI-mandated CCMP playbook, complete forensic root-cause analysis, and file a closure report. Each stage has a designated owner, and questions often test whether a candidate can correctly sequence these steps rather than just recall the six-hour figure in isolation.
It is also worth revising how reporting timelines interact with specific attack types you have already studied — a ransomware event, for instance, still follows the same six-hour clock even though containment (isolating infected systems) may take considerably longer. Our detailed walkthrough of ransomware attack prevention is a useful companion read, as is the guide on social engineering tactics in banking, since human-triggered incidents follow identical reporting obligations once detected.

📊 CERT-In vs RBI Expectations: A Quick Comparison
| Parameter | Regulatory Requirement | Bank Practice |
|---|---|---|
| Incident reporting window | Report significant incidents to CERT-In within 6 hours of detection | ✅ SOC auto-triggers preliminary report on confirmed severity |
| Low-severity event logging | Not mandatorily reportable, but must be logged internally | ❌ Skipping the log entry because it "wasn't serious" |
| Root cause analysis (RCA) | Detailed RCA to be submitted in the prescribed follow-up period | ✅ RCA filed with supporting forensic evidence |
| Customer notification | Required where customer data or funds are impacted | ❌ Delaying disclosure until after internal review closes |
🧠 Practice MCQs: Cyber Incident Reporting Timelines
Q1. Under CERT-In's directions, a bank must report a significant cyber incident within how many hours of detection? (a) 24 hours (b) 6 hours (c) 72 hours (d) 48 hours
Answer: (b) — CERT-In's directions mandate reporting of specified cyber incidents within 6 hours of detection or of being brought to notice.
Q2. Which agency is the designated national nodal authority for receiving mandatory cyber incident reports from Indian banks? (a) SEBI (b) IRDAI (c) CERT-In (d) TRAI
Answer: (c) — CERT-In (Indian Computer Emergency Response Team) is the statutory nodal agency for cyber incident reporting and coordination.
Q3. What is the primary role of a 24x7 Security Operations Centre (SOC) under the RBI's cyber security expectations for banks? (a) Marketing analytics (b) Continuous monitoring and detection of cyber incidents (c) HR onboarding (d) Loan disbursal tracking
Answer: (b) — The SOC provides round-the-clock monitoring, detection, and first-response triage of security events.
Q4. Which section of India's information technology law deals with penalties for unauthorised access to a computer or computer system? (a) Section 43 (b) Section 12 (c) Section 90 (d) Section 130
Answer: (a) — Section 43 prescribes penalties for damage to a computer or computer system, including unauthorised access.
Q5. Missing CERT-In's mandated reporting window for a cyber incident primarily exposes a bank to: (a) A tax rebate (b) Regulatory and reputational risk (c) Bonus interest income (d) Lower audit scrutiny
Answer: (b) — A missed deadline is treated as a compliance lapse, inviting supervisory action and reputational damage independent of the technical outcome.
Want chapter-wise mock tests with 100+ MCQs? Start practising free →
What is the CERT-In mandated timeline for reporting cyber incidents?
Banks and other regulated entities must report significant cyber incidents to CERT-In within 6 hours of detecting the incident or of it being brought to their notice.
Why do cyber incident reporting timelines matter for exam candidates?
They are a frequently tested factual point that links CERT-In directions, the RBI's cyber security framework, and statutory provisions together in scenario-based questions.
What happens if a bank misses the reporting deadline?
The bank faces regulatory scrutiny and possible supervisory action from the RBI, in addition to reputational risk, regardless of how the underlying technical incident was resolved.
How does incident management fit into the broader cyber security framework?
Incident management is the operational process — detection, escalation, reporting, and closure — through which a bank fulfils the reporting obligations set out by CERT-In and the RBI.
Cyber incident reporting timelines sit at the intersection of technology, law, and regulatory compliance — exactly the kind of cross-cutting topic IIBF examiners favour. Lock in the six-hour rule, the SOC-to-compliance escalation chain, and the statutory backing behind it, then test your recall with a full mock set on iibf.store/tests or continue structured prep through the CAIIB course. For more exam-ready reads across every subject, browse the iibf.store blog or explore every article tagged under Prevention of Cyber Crime.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.