Overview
In simple terms… Cyber Security Advisory means helping a business protect its systems, data and legal position — and proving afterwards that it did so.
Every business now runs on digital records, cloud tools, customer databases, employee devices, payment rails, APIs and third-party vendors. When any of those fail, the consequences are rarely confined to the IT department. They arrive as reporting deadlines, customer complaints, insurance questions, investor diligence findings and, occasionally, regulatory proceedings.
The work divides into two halves. Before an incident: mapping data, closing control gaps, writing policies, fixing vendor contracts and building a reporting workflow. After an incident: containing it, preserving evidence, meeting the clock and documenting the response. The first half is what makes the second half survivable.
Quick Answer
Cyber Security Advisory is not a licence. It is legal, technical and compliance advisory work for managing cyber risk and information security obligations.
There is no single master direction covering all businesses. Obligations come from the IT Act and the SPDI Rules, the CERT-In Directions, the DPDP framework as it commences, sectoral regulator circulars and your own customer and vendor contracts. Which of those bite depends on your entity type, sector, data and counterparties.
What Is Actually In Force Today
Most public writing on Indian data protection describes the DPDP Act as though it were fully operative. It is not yet. The DPDP Rules, 2025 were notified on 13 November 2025 with a deliberately staggered commencement, and the obligations most businesses care about begin on 13 May 2027. Meanwhile the IT Act, the SPDI Rules and the CERT-In Directions apply right now. Getting this sequence wrong leads businesses to over-invest in provisions that have not commenced while missing the ones that have.
| Instrument | Status as at September 2026 |
|---|---|
| IT Act, 2000 | In force |
| CERT-In Directions, 28 April 2022 | In force since 27 June 2022 — six-hour reporting and 180-day log retention apply now |
| IT Act Section 43A and SPDI Rules, 2011 | Still in force; omitted only with effect from 13 May 2027 |
| DPDP Act, 2023 | Enacted, commencing in phases alongside the Rules |
| DPDP Rules 1, 2 and 17–21 | In force from 13 November 2025 — Data Protection Board constitution and procedure |
| DPDP Rule 4 — Consent Manager registration | In force from 13 November 2026 |
| DPDP Rules 3, 5–16, 22 and 23 | Commence 13 May 2027 — notice, security safeguards, breach intimation, retention, children’s data, Significant Data Fiduciary duties and Data Principal rights |
| Bharatiya Sakshya Adhiniyam, 2023 | In force — governs electronic records and digital evidence |
The practical reading is straightforward. Your CERT-In and IT Act obligations are live and enforceable today. Your DPDP obligations are dated, not optional, and the preparation work — data inventory, consent design, vendor re-papering, retention controls — runs to months rather than weeks. May 2027 is the compliance deadline, not the start date.
Regulatory Framework
| Particular | Applicable framework |
|---|---|
| Main cyber law | Information Technology Act, 2000 |
| Incident response authority | CERT-In, under Section 70B of the IT Act |
| Incident reporting directions | Cyber Security Directions under Section 70B(6), dated 28 April 2022 |
| Sensitive personal data, current regime | IT Act Section 43A read with the SPDI Rules, 2011 |
| Personal data law | Digital Personal Data Protection Act, 2023 |
| Operative rules | Digital Personal Data Protection Rules, 2025 |
| Data protection authority | Data Protection Board of India |
| Critical infrastructure | NCIIPC framework under Section 70A |
| Intermediaries and platforms | IT Rules and the intermediary due diligence framework, where applicable |
| Sector regulators | RBI, SEBI, IRDAI, IFSCA, PFRDA, UIDAI, TRAI and MeitY, depending on sector |
| Evidence | Bharatiya Sakshya Adhiniyam, 2023 |
| Criminal law | Bharatiya Nyaya Sanhita, 2023 and the IT Act cyber offence provisions |
| Contractual layer | Customer contracts, vendor agreements, DPAs and confidentiality clauses |
Key Provisions
| Law | Provision | Practical relevance |
|---|---|---|
| IT Act, 2000 | Section 43 | Compensation for unauthorised access, data extraction or damage to computer systems |
| IT Act, 2000 | Section 43A | Compensation for failure to protect sensitive personal data — in force until 13 May 2027 |
| IT Act, 2000 | Section 65 | Tampering with computer source documents |
| IT Act, 2000 | Section 66 | Computer-related offences involving dishonest or fraudulent acts |
| IT Act, 2000 | Section 66C | Identity theft |
| IT Act, 2000 | Section 66D | Cheating by personation using a computer resource |
| IT Act, 2000 | Section 66E | Violation of privacy |
| IT Act, 2000 | Section 67C | Preservation and retention of information by intermediaries |
| IT Act, 2000 | Sections 69, 69A and 69B | Interception and monitoring directions, blocking, and traffic data monitoring |
| IT Act, 2000 | Sections 70, 70A and 70B | Protected systems, NCIIPC and the CERT-In framework |
| IT Act, 2000 | Sections 72 and 72A | Breach of confidentiality, and disclosure in breach of lawful contract |
| CERT-In Directions, 2022 | Direction under Section 70B(6) | Six-hour incident reporting, 180-day log retention and time synchronisation |
| DPDP Act, 2023 | Sections 4 to 6 | Grounds for processing, notice to the Data Principal and the consent framework |
| DPDP Act, 2023 | Section 8 | General obligations of a Data Fiduciary, including reasonable security safeguards |
| DPDP Act, 2023 | Sections 9 and 10 | Children’s personal data and Significant Data Fiduciary obligations |
| DPDP Act, 2023 | Sections 11 to 14 | Rights of the Data Principal |
| DPDP Act, 2023 | Sections 16, 18, 29 and 33 | Processing outside India, the Board, appeals to the Appellate Tribunal, and penalties |
| Bharatiya Sakshya Adhiniyam, 2023 | Sections 61 to 63 | Admissibility of electronic and digital records |
| Companies Act, 2013 | Board governance and director duties | Board-level cyber risk oversight and internal controls |
What the Advisory Covers
| Area | What it means in practice |
|---|---|
| Cyber risk assessment | Identifying technology, data and process vulnerabilities |
| Legal compliance review | Mapping IT Act, CERT-In, DPDP and sectoral obligations to your actual operations |
| Data protection readiness | Building notice, consent, breach and rights processes ahead of commencement |
| Incident response planning | A written plan with owners and escalation, prepared before it is needed |
| VAPT coordination | Scoping technical testing and tracking remediation to closure |
| Policy drafting | Cyber security, access, password, BYOD, retention and incident policies |
| Vendor risk review | Cloud, SaaS and outsourcing controls, plus the contract clauses behind them |
| Board reporting | Management-level cyber risk reporting that stands up in diligence |
| Evidence preservation | Logs, tickets, emails and digital proof kept in admissible form |
| Regulatory reporting | CERT-In and DPDP breach reporting workflows |
| Training support | Employee awareness on phishing, fraud and data handling |
| Cyber due diligence | Risk review during investment, M&A or vendor onboarding |
Who Needs It
| Entity | Why |
|---|---|
| Fintech company | Handles financial, KYC and customer data |
| NBFC | IT governance, outsourcing and cyber risk controls expected by the regulator |
| Payment business | Transaction fraud and data breach exposure |
| Insurance intermediary | Customer, health and policy data, plus system audit expectations |
| Ecommerce platform | Payment, customer and vendor information |
| SaaS company | Customer business data held on cloud infrastructure |
| Healthcare business | Sensitive health and patient records |
| Education platform | Children’s and student data, with heightened DPDP obligations coming |
| HR and recruitment platform | CVs, salary, identity and employee records |
| Accounting or legal firm | Confidential client records |
| BPO and call centre | Customer communication data and broad agent access |
| Startup | Early-stage policies and investor-ready controls |
| Regulated entity | Sector-specific cyber governance and audit readiness |
| Any business mid-incident | Immediate response, reporting and evidence preservation |
When to Take Advice
| Trigger | Why it matters now |
|---|---|
| A website or app goes live | Customer data and login systems become externally exposed |
| You start collecting personal data | DPDP preparation should begin well before May 2027 |
| You adopt cloud or SaaS tools | Vendor access and contract terms need review |
| You handle payment or KYC data | Fraud and breach exposure is materially higher |
| An incident has occurred | Reporting clocks, evidence and response must be managed immediately |
| Ransomware or phishing has hit | System isolation and legal response run in parallel |
| Customer data has leaked | Breach assessment and a reviewed communication plan are required |
| Investor diligence is approaching | Policies, VAPT status and incident history will be examined |
| A regulator asks for an IT audit | Documentation and technical reports must already exist |
| A vendor gains access to data | Processing terms and security clauses need to be in place first |
| Employees work remotely | Device, access and BYOD controls become material |
CERT-In Reporting Readiness
The CERT-In Directions of 28 April 2022, effective from 27 June 2022, are the obligation most often discovered too late. They require covered entities to report specified cyber incidents to CERT-In within six hours of noticing them or being made aware of them. Where complete information is not available in that window, available information should be provided within it and supplemented afterwards.
Two supporting obligations matter as much as the reporting itself. ICT system logs must be maintained securely for a rolling period of 180 days within Indian jurisdiction, and system clocks must be synchronised to the prescribed time sources so that logs from different systems can actually be correlated. An organisation that reports on time but cannot produce correlated logs has met the letter of one obligation and failed the purpose of both.
| Readiness area | Control to have in place |
|---|---|
| Incident classification | A documented test for whether an event is reportable |
| Internal escalation | IT, legal, management and compliance escalation matrix with named owners |
| Reporting workflow | Who drafts, who approves and who files, inside six hours |
| Log retention | 180 days, secure, within Indian jurisdiction |
| Time synchronisation | Systems synchronised to the prescribed time sources |
| Incident register | A maintained record of cyber incidents and responses |
| Forensic readiness | Devices, logs, screenshots and emails preserved, not overwritten |
| Vendor coordination | Cloud, SOC, SIEM and hosting support reachable out of hours |
| Customer communication | Legally reviewed templates prepared in advance |
| Post-incident review | Root cause, remediation and a management report |
DPDP Readiness
Where an organisation processes digital personal data, the DPDP framework will govern how it does so. The obligations below commence on 13 May 2027, which makes this a preparation exercise rather than a filing exercise — but one with a fixed deadline and a long lead time.
| DPDP area | What preparation involves |
|---|---|
| Notice | A clear, itemised notice covering what is collected and why |
| Consent | Free, specific, informed and unambiguous consent, with records kept |
| Purpose limitation and minimisation | Collecting only what is needed, using it only as stated |
| Security safeguards | Reasonable technical and organisational controls under Section 8 |
| Breach intimation | Intimate the Board without delay, then a detailed report within 72 hours; affected Data Principals must also be informed |
| Data Principal rights | Access, correction, erasure, nomination and grievance redressal processes |
| Children’s data | Verifiable parental consent and restrictions on tracking and targeted advertising |
| Significant Data Fiduciary | Additional obligations including a Data Protection Officer and audits, once notified |
| Vendor processing | Processor contracts with security and breach-reporting obligations |
| Retention and deletion | Defined retention periods and actual deletion capability |
| Cross-border transfer | Transfers outside India subject to Section 16 restrictions |
| Grievance contact | A published escalation channel that is actually monitored |
Two clocks, not one. A personal data breach at a CERT-In covered entity can trigger both the six-hour CERT-In report and the DPDP intimation to the Board. They are separate obligations with different recipients and timelines, and the six-hour clock is the tighter of the two. Build one workflow that satisfies both, and decide the reporting call before the incident rather than during it.
Where Businesses Actually Get Hit
| Risk | Practical impact |
|---|---|
| Phishing | Employee credentials stolen, often the entry point for everything else |
| Ransomware | Systems locked, data encrypted, operations halted |
| Data breach | Customer, employee or vendor data exposed |
| Weak passwords and no MFA | Account takeover, the most preventable failure on this list |
| Poor vendor controls | A third-party breach that lands on you |
| No logs | Investigation becomes guesswork and CERT-In compliance fails |
| No backup | Data cannot be restored after an attack |
| No incident plan | The team reacts late, inconsistently and on the record |
| Misconfigured cloud | Private data publicly exposed without any attack at all |
| API vulnerability | Customer or transaction data exposed at scale |
| Insider threat | Employee misuse or data theft, often at exit |
| Unpatched systems | Known vulnerabilities exploited long after a fix existed |
| No retention rules | Data you no longer need enlarging every breach you have |
How the Engagement Runs
| Step | Activity | Output |
|---|---|---|
| 1 | Initial consultation | Business model, data and system overview |
| 2 | Risk mapping | Legal, technical and operational cyber risks identified |
| 3 | Data inventory | Personal data, business data and systems mapped |
| 4 | Regulatory mapping | IT Act, CERT-In, DPDP, sectoral rules and contractual obligations |
| 5 | Control gap review | Access, logs, backups, vendors, policies and response |
| 6 | VAPT and audit coordination | Technical testing scoped and coordinated |
| 7 | Policy drafting | Cyber security and data protection policy set |
| 8 | Incident response plan | Breach SOP, escalation matrix and reporting workflow |
| 9 | Vendor contract review | Security, confidentiality, indemnity and breach clauses |
| 10 | Employee awareness | Phishing, password, data handling and reporting training |
| 11 | Management reporting | Board cyber risk note |
| 12 | Implementation tracker | Corrective action, owner and deadline |
| 13 | Compliance monitoring | Periodic review and update support |
Documents Required
| Document | Purpose |
|---|---|
| Company profile | Business and sector understanding |
| System architecture | Technology and access review |
| Data flow diagram | Personal and business data mapping |
| Website and app details | External exposure review |
| Cloud and hosting vendor details | Vendor risk review |
| Existing cyber security policy | Gap review |
| Privacy policy and terms of use | Notice, consent and liability review |
| Vendor agreements and DPAs | Security and breach obligation review |
| Employee device and access policy | Endpoint and permission review |
| Access control list | Who can reach what |
| Incident logs and register | Past breach and response assessment |
| VAPT reports | Technical vulnerability status |
| ISO, SOC or audit reports | Existing control maturity |
| Backup and log retention policy | Recovery readiness and CERT-In compliance |
| Customer complaint records | Breach or misuse allegations |
| Cyber insurance policy | Coverage, conditions and exclusions |
| Regulator notices | Live regulatory exposure |
| Board minutes and risk reports | Governance review |
Policies We Prepare
| Document | Purpose |
|---|---|
| Cyber Security Policy | Overall governance framework |
| Information Security Policy | Information classification and protection |
| Access Control Policy | User permissions and approval matrix |
| Password and MFA Policy | Credential security |
| Incident Response Policy | Breach response and reporting workflow |
| Data Breach Response SOP | Step-wise action plan against the clock |
| Acceptable Use Policy | Employee use of company systems |
| BYOD and Remote Work Policy | Personal device and off-site controls |
| Email Security Policy | Phishing and spoofing protection |
| Vendor Security Policy | Third-party risk management |
| Data Retention Policy | Retention and deletion rules |
| Backup and Recovery Policy | Restoration after an incident |
| Privacy Policy and Cookie Policy | User-facing notice and consent |
| Data Processing Agreement | Processor obligations |
| Cyber Incident Register | Incident logging and response evidence |
| Board Cyber Risk Note | Governance reporting |
Regulated Entities
Regulated entities carry a heavier documentation burden, because regulators generally expect board oversight, demonstrable controls and an audit trail rather than assurances.
| Sector | Advisory focus |
|---|---|
| NBFC | IT governance, outsourcing, incident handling and customer data |
| Payment aggregator or PSP | Transaction security, fraud risk, data storage and incident response |
| Insurance broker or ISNP | System audit, user access, logs, security architecture and insurer interfaces |
| SEBI intermediary | Cyber resilience, client data, trading systems and vendor risk |
| IFSCA entity | IFSC compliance, outsourcing and information security governance |
| AIF or investment manager | Investor data, fund records and access controls |
| Healthcare | Patient data, health records and breach response |
| EdTech | Children’s data, consent and the heightened DPDP position |
| Ecommerce | Payment, customer and seller data security |
| SaaS and IT | Cloud controls, customer data and SOC or ISO readiness |
| BPO and call centre | Customer data, recording and agent access controls |
Cyber Due Diligence
Cyber posture is now a standard diligence workstream in investment, M&A, vendor onboarding and licensing. What gets reviewed is rarely the firewall; it is the paperwork behind it.
| Area | What is reviewed |
|---|---|
| Data inventory | What is collected, where it is stored and for how long |
| System architecture | Where data and applications are hosted |
| Access rights | Who can reach critical systems, and who should not |
| Vendor risk | Cloud, SaaS and outsourced IT controls and contracts |
| Incident history | Past breaches, complaints and how they were handled |
| VAPT reports | Findings, and whether they were remediated or filed |
| Policy framework | Cyber and privacy policies, and evidence they are followed |
| DPDP readiness | Consent, notice, breach and rights processes |
| CERT-In readiness | Reporting workflow and log retention |
| Backup and recovery | Business continuity after an attack |
| Contractual liability | Customer and vendor cyber clauses and caps |
| Insurance | Coverage, conditions precedent and exclusions |
| Board oversight | Governance and risk reporting |
Common Gaps We Fix
| Gap | Risk it creates | How we close it |
|---|---|---|
| No incident response plan | Improvised decisions during an attack | Breach response SOP and escalation matrix |
| No log retention | CERT-In non-compliance and forensic dead ends | 180-day retention design and checklist |
| Privacy notice not DPDP-ready | Rework against a fixed 2027 deadline | Notice redraft and readiness gap review |
| Vendor contracts without security clauses | Third-party breach liability sits with you | DPA and security clause drafting |
| Personal devices in use | Uncontrolled data leakage | BYOD and remote-work policy |
| No MFA | Account takeover | Access control recommendations with a tracker |
| VAPT report not acted on | A known vulnerability left open and documented | Remediation tracker to closure |
| No retention rules | Every breach is larger than it needed to be | Retention and deletion policy |
| Incident not documented | Weak defence and a contested insurance claim | Incident register and evidence file |
| Regulator asks for a system audit | Submission delay and follow-up scrutiny | Audit-readiness checklist |
| No board-level reporting | Governance gap visible in diligence | Management cyber risk note |
Cost of Ignoring It
| Omission | Consequence |
|---|---|
| No incident reporting capability | CERT-In and sectoral non-compliance |
| No DPDP preparation | A fixed 2027 deadline met in a rush, or not at all |
| No logs | Investigation and legal defence both weakened |
| Weak vendor contracts | Liability cannot be allocated or recovered |
| No access control | Unauthorised employee or vendor access |
| No backup | Recovery depends on the attacker |
| No employee training | Phishing remains the open door |
| No audit trail | Board and regulator questions cannot be answered |
| No breach communication plan | Reputational damage compounded by the response |
Our Services
| Service | What we do |
|---|---|
| Cyber risk assessment | Identify legal, technical and operational risk |
| IT Act and SPDI review | Map current-regime obligations, including Section 43A |
| CERT-In readiness | Six-hour reporting workflow, logs and escalation |
| DPDP readiness | Notice, consent, safeguards, rights and breach process ahead of 2027 |
| Cyber policy drafting | The full policy set, tailored to your operations |
| Incident response planning | Escalation matrix and breach SOP |
| VAPT coordination | Scoping, vendor selection and remediation tracking |
| Vendor risk review | Cloud, SaaS and outsourcing risk and contracts |
| Data flow mapping | Personal data and system flow inventory |
| Employee training material | Cyber awareness and phishing content |
| Cyber due diligence | Investor, M&A and vendor onboarding review |
| Regulated entity support | RBI, SEBI, IRDAI, IFSCA and ISNP-linked documentation |
| Breach response support | Evidence preservation, reporting and communication review |
| Contract clause review | Confidentiality, security, indemnity and breach terms |
| Board cyber governance | Risk notes and management reporting |
| Ticket-based tracking | Gaps, owners, remediation and closure |
FAQs
1. What is Cyber Security Advisory?
A professional service that helps a business identify and reduce legal, regulatory, operational and technical risk connected with cyber threats, data breaches and information security. It sits between the IT function and the legal function, which is exactly where most gaps live.
2. Is it a licence?
No. It is not a licence or a registration. It is advisory and compliance support. That said, the underlying obligations — incident reporting, log retention, security safeguards — can themselves be mandatory depending on the entity and sector.
3. Which laws apply to cyber security in India?
The Information Technology Act, 2000 and the CERT-In Directions of 28 April 2022 are the operative baseline today. The SPDI Rules, 2011 still govern sensitive personal data. The Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 layer on top, with most substantive obligations commencing 13 May 2027.
4. Is DPDP compliance mandatory right now?
Not in full. The DPDP Rules, 2025 were notified on 13 November 2025 with a phased commencement. The Data Protection Board provisions came into force at once and consent-manager registration opened after twelve months, but the operative obligations — notice, security safeguards, breach intimation, retention limits, children’s data, Significant Data Fiduciary duties and Data Principal rights — commence on 13 May 2027.
5. So can we wait until 2027?
That would be a mistake. The 13 May 2027 date is the deadline to be compliant, not the date to begin. Data inventories, consent re-papering, vendor contract amendments and retention controls take months, and the IT Act, SPDI Rules and CERT-In obligations already apply today regardless.
6. Is Section 43A of the IT Act still in force?
Yes. Section 43A and the SPDI Rules, 2011 remain in force and are omitted only with effect from 13 May 2027, when the corresponding DPDP provisions commence. Treating them as already repealed is a live compliance risk.
7. What is CERT-In?
The Indian Computer Emergency Response Team, the national nodal agency for cyber incident response under Section 70B of the IT Act.
8. Is cyber incident reporting mandatory?
For specified cyber incidents, yes. The CERT-In Directions require covered entities to report specified incidents within six hours of noticing them or being made aware of them.
9. What if we do not have all the details within six hours?
Report what you have. The Directions contemplate providing available information within the window and supplementing it afterwards. A late complete report is worse than a prompt partial one.
10. How long must logs be kept?
The CERT-In Directions require ICT system logs to be maintained securely for a rolling period of 180 days, within Indian jurisdiction. Log retention is the single most commonly failed item we see.
11. What is VAPT?
Vulnerability Assessment and Penetration Testing — technical testing that identifies weaknesses in systems, applications and networks.
12. Is VAPT mandatory?
It depends on the entity, regulator, certification and customer contracts. For regulated entities, system audits and security testing are commonly expected. For everyone else, it is usually a contractual rather than statutory requirement.
13. What is the DPDP breach intimation timeline?
When the relevant rules commence, a Data Fiduciary must intimate the Data Protection Board without delay with an initial description, followed by a detailed report within seventy-two hours, unless the Board allows longer on written request. Affected Data Principals must also be informed.
14. Does a CERT-In report cover the DPDP obligation as well?
No. They are separate obligations with separate recipients, thresholds and timelines. A personal data breach at a covered entity can trigger both, and the six-hour clock is the tighter one.
15. What is an incident response plan?
A step-wise plan for identifying, containing, reporting, investigating and recovering from a cyber incident, with named owners and an escalation matrix. Written before the incident, not during it.
16. What should we do immediately after an attack?
Isolate affected systems, preserve evidence, convene the response team, assess reporting obligations against the clock and coordinate technical support. Do not delete logs, do not wipe devices and do not have anyone improvise a customer statement.
17. Why does evidence preservation matter so much?
Because a breach is usually followed by a regulator, an insurer, a customer or a litigant asking what happened. Electronic records are governed by the Bharatiya Sakshya Adhiniyam, 2023, and evidence that was not preserved properly is hard to rely on later.
18. What is vendor cyber risk?
The risk arising when cloud providers, SaaS platforms, IT vendors or consultants can access your systems or data. A vendor breach is still your regulatory and customer problem, which is why contract clauses and access controls matter.
19. What is a data processing agreement?
A contract defining how a vendor processes data on your behalf, what it must protect, how quickly it must report a breach to you, and where liability sits.
20. Do small businesses need this?
Yes, proportionately. A small business still holds customer data, payment records and employee information, and attackers do not filter by turnover. The controls should be scaled, not skipped.
21. What do investors look at?
Data inventory, policies, VAPT reports and remediation status, incident history, vendor contracts, DPDP readiness and board oversight. Cyber gaps surface in diligence and affect terms.
22. What is the most common mistake?
Treating cyber security as purely an IT problem. The technical controls are only half of it; the other half is documentation, contracts, reporting readiness, evidence and board accountability.
23. What documents should a business maintain?
Cyber security policy, privacy notice, access control register, incident register, VAPT reports with a remediation tracker, vendor contracts and DPAs, data inventory, backup policy and a breach response SOP.
24. How often should this be reviewed?
Periodically, and on every trigger — a new product or app, a new vendor, a new data flow, a regulatory change, an incident, or an investor process starting.
25. Can Estabizz help during a live incident?
Yes. We support legal response, reporting readiness against the six-hour and seventy-two-hour clocks, evidence preservation, breach communication review and corrective-action tracking. Forensic and remediation work is done with technical partners.
Expert Insight
“Cyber security advice fails when it stops at the firewall. What decides the outcome after an incident is whether the logs exist, whether the reporting call was already decided, whether the vendor contract allocates the loss, and whether anyone can show the board knew. Those are legal questions, and they are cheap to answer in advance.”
— CS Devyani Khambhati, Compliance Expert
Disclaimer
This guide is general information, not entity-specific legal or technical advice. Commencement dates, applicability thresholds and sectoral obligations change, and which obligations apply to you depends on your entity type, sector, data and contracts. Statutory positions stated here are as at September 2026 and parts of this guide remain under professional review. Estabizz provides compliance mapping, documentation, policy drafting and coordination support; technical testing is performed by specialist partners and court appearance is through enrolled advocates. Confirm the current position before acting.