Legal Cyber and Data Protection

Cyber Security Advisory

A cyber incident is a legal event as much as a technical one. A phishing compromise, an exposed database, a ransomware attack or a vendor breach can trigger reporting obligations measured in hours, alongside customer claims, regulatory scrutiny and contractual liability. Estabizz assists companies, fintechs, NBFCs, insurance intermediaries, payment businesses, ecommerce platforms, SaaS providers, healthcare and education entities with cyber risk assessment, IT Act and SPDI compliance, CERT-In reporting readiness, DPDP preparation, policy drafting, VAPT coordination, vendor risk review, cyber due diligence and board-level governance.

📅 2026
|
⏱️ 16 min read
|
👁️ Regulatory Guide
Focus: Cyber Security Advisory
CERT-In reporting
Within 6 hours
Log retention
180 days, in India
DPDP main obligations
From 13 May 2027
IT Act s.43A
Still in force

Overview

In simple terms… Cyber Security Advisory means helping a business protect its systems, data and legal position — and proving afterwards that it did so.

Every business now runs on digital records, cloud tools, customer databases, employee devices, payment rails, APIs and third-party vendors. When any of those fail, the consequences are rarely confined to the IT department. They arrive as reporting deadlines, customer complaints, insurance questions, investor diligence findings and, occasionally, regulatory proceedings.

The work divides into two halves. Before an incident: mapping data, closing control gaps, writing policies, fixing vendor contracts and building a reporting workflow. After an incident: containing it, preserving evidence, meeting the clock and documenting the response. The first half is what makes the second half survivable.

Quick Answer

Cyber Security Advisory is not a licence. It is legal, technical and compliance advisory work for managing cyber risk and information security obligations.

There is no single master direction covering all businesses. Obligations come from the IT Act and the SPDI Rules, the CERT-In Directions, the DPDP framework as it commences, sectoral regulator circulars and your own customer and vendor contracts. Which of those bite depends on your entity type, sector, data and counterparties.

What Is Actually In Force Today

Most public writing on Indian data protection describes the DPDP Act as though it were fully operative. It is not yet. The DPDP Rules, 2025 were notified on 13 November 2025 with a deliberately staggered commencement, and the obligations most businesses care about begin on 13 May 2027. Meanwhile the IT Act, the SPDI Rules and the CERT-In Directions apply right now. Getting this sequence wrong leads businesses to over-invest in provisions that have not commenced while missing the ones that have.

InstrumentStatus as at September 2026
IT Act, 2000In force
CERT-In Directions, 28 April 2022In force since 27 June 2022 — six-hour reporting and 180-day log retention apply now
IT Act Section 43A and SPDI Rules, 2011Still in force; omitted only with effect from 13 May 2027
DPDP Act, 2023Enacted, commencing in phases alongside the Rules
DPDP Rules 1, 2 and 17–21In force from 13 November 2025 — Data Protection Board constitution and procedure
DPDP Rule 4 — Consent Manager registrationIn force from 13 November 2026
DPDP Rules 3, 5–16, 22 and 23Commence 13 May 2027 — notice, security safeguards, breach intimation, retention, children’s data, Significant Data Fiduciary duties and Data Principal rights
Bharatiya Sakshya Adhiniyam, 2023In force — governs electronic records and digital evidence

The practical reading is straightforward. Your CERT-In and IT Act obligations are live and enforceable today. Your DPDP obligations are dated, not optional, and the preparation work — data inventory, consent design, vendor re-papering, retention controls — runs to months rather than weeks. May 2027 is the compliance deadline, not the start date.

Regulatory Framework

ParticularApplicable framework
Main cyber lawInformation Technology Act, 2000
Incident response authorityCERT-In, under Section 70B of the IT Act
Incident reporting directionsCyber Security Directions under Section 70B(6), dated 28 April 2022
Sensitive personal data, current regimeIT Act Section 43A read with the SPDI Rules, 2011
Personal data lawDigital Personal Data Protection Act, 2023
Operative rulesDigital Personal Data Protection Rules, 2025
Data protection authorityData Protection Board of India
Critical infrastructureNCIIPC framework under Section 70A
Intermediaries and platformsIT Rules and the intermediary due diligence framework, where applicable
Sector regulatorsRBI, SEBI, IRDAI, IFSCA, PFRDA, UIDAI, TRAI and MeitY, depending on sector
EvidenceBharatiya Sakshya Adhiniyam, 2023
Criminal lawBharatiya Nyaya Sanhita, 2023 and the IT Act cyber offence provisions
Contractual layerCustomer contracts, vendor agreements, DPAs and confidentiality clauses

Key Provisions

LawProvisionPractical relevance
IT Act, 2000Section 43Compensation for unauthorised access, data extraction or damage to computer systems
IT Act, 2000Section 43ACompensation for failure to protect sensitive personal data — in force until 13 May 2027
IT Act, 2000Section 65Tampering with computer source documents
IT Act, 2000Section 66Computer-related offences involving dishonest or fraudulent acts
IT Act, 2000Section 66CIdentity theft
IT Act, 2000Section 66DCheating by personation using a computer resource
IT Act, 2000Section 66EViolation of privacy
IT Act, 2000Section 67CPreservation and retention of information by intermediaries
IT Act, 2000Sections 69, 69A and 69BInterception and monitoring directions, blocking, and traffic data monitoring
IT Act, 2000Sections 70, 70A and 70BProtected systems, NCIIPC and the CERT-In framework
IT Act, 2000Sections 72 and 72ABreach of confidentiality, and disclosure in breach of lawful contract
CERT-In Directions, 2022Direction under Section 70B(6)Six-hour incident reporting, 180-day log retention and time synchronisation
DPDP Act, 2023Sections 4 to 6Grounds for processing, notice to the Data Principal and the consent framework
DPDP Act, 2023Section 8General obligations of a Data Fiduciary, including reasonable security safeguards
DPDP Act, 2023Sections 9 and 10Children’s personal data and Significant Data Fiduciary obligations
DPDP Act, 2023Sections 11 to 14Rights of the Data Principal
DPDP Act, 2023Sections 16, 18, 29 and 33Processing outside India, the Board, appeals to the Appellate Tribunal, and penalties
Bharatiya Sakshya Adhiniyam, 2023Sections 61 to 63Admissibility of electronic and digital records
Companies Act, 2013Board governance and director dutiesBoard-level cyber risk oversight and internal controls

What the Advisory Covers

AreaWhat it means in practice
Cyber risk assessmentIdentifying technology, data and process vulnerabilities
Legal compliance reviewMapping IT Act, CERT-In, DPDP and sectoral obligations to your actual operations
Data protection readinessBuilding notice, consent, breach and rights processes ahead of commencement
Incident response planningA written plan with owners and escalation, prepared before it is needed
VAPT coordinationScoping technical testing and tracking remediation to closure
Policy draftingCyber security, access, password, BYOD, retention and incident policies
Vendor risk reviewCloud, SaaS and outsourcing controls, plus the contract clauses behind them
Board reportingManagement-level cyber risk reporting that stands up in diligence
Evidence preservationLogs, tickets, emails and digital proof kept in admissible form
Regulatory reportingCERT-In and DPDP breach reporting workflows
Training supportEmployee awareness on phishing, fraud and data handling
Cyber due diligenceRisk review during investment, M&A or vendor onboarding

Who Needs It

EntityWhy
Fintech companyHandles financial, KYC and customer data
NBFCIT governance, outsourcing and cyber risk controls expected by the regulator
Payment businessTransaction fraud and data breach exposure
Insurance intermediaryCustomer, health and policy data, plus system audit expectations
Ecommerce platformPayment, customer and vendor information
SaaS companyCustomer business data held on cloud infrastructure
Healthcare businessSensitive health and patient records
Education platformChildren’s and student data, with heightened DPDP obligations coming
HR and recruitment platformCVs, salary, identity and employee records
Accounting or legal firmConfidential client records
BPO and call centreCustomer communication data and broad agent access
StartupEarly-stage policies and investor-ready controls
Regulated entitySector-specific cyber governance and audit readiness
Any business mid-incidentImmediate response, reporting and evidence preservation

When to Take Advice

TriggerWhy it matters now
A website or app goes liveCustomer data and login systems become externally exposed
You start collecting personal dataDPDP preparation should begin well before May 2027
You adopt cloud or SaaS toolsVendor access and contract terms need review
You handle payment or KYC dataFraud and breach exposure is materially higher
An incident has occurredReporting clocks, evidence and response must be managed immediately
Ransomware or phishing has hitSystem isolation and legal response run in parallel
Customer data has leakedBreach assessment and a reviewed communication plan are required
Investor diligence is approachingPolicies, VAPT status and incident history will be examined
A regulator asks for an IT auditDocumentation and technical reports must already exist
A vendor gains access to dataProcessing terms and security clauses need to be in place first
Employees work remotelyDevice, access and BYOD controls become material

CERT-In Reporting Readiness

The CERT-In Directions of 28 April 2022, effective from 27 June 2022, are the obligation most often discovered too late. They require covered entities to report specified cyber incidents to CERT-In within six hours of noticing them or being made aware of them. Where complete information is not available in that window, available information should be provided within it and supplemented afterwards.

Two supporting obligations matter as much as the reporting itself. ICT system logs must be maintained securely for a rolling period of 180 days within Indian jurisdiction, and system clocks must be synchronised to the prescribed time sources so that logs from different systems can actually be correlated. An organisation that reports on time but cannot produce correlated logs has met the letter of one obligation and failed the purpose of both.

Readiness areaControl to have in place
Incident classificationA documented test for whether an event is reportable
Internal escalationIT, legal, management and compliance escalation matrix with named owners
Reporting workflowWho drafts, who approves and who files, inside six hours
Log retention180 days, secure, within Indian jurisdiction
Time synchronisationSystems synchronised to the prescribed time sources
Incident registerA maintained record of cyber incidents and responses
Forensic readinessDevices, logs, screenshots and emails preserved, not overwritten
Vendor coordinationCloud, SOC, SIEM and hosting support reachable out of hours
Customer communicationLegally reviewed templates prepared in advance
Post-incident reviewRoot cause, remediation and a management report

DPDP Readiness

Where an organisation processes digital personal data, the DPDP framework will govern how it does so. The obligations below commence on 13 May 2027, which makes this a preparation exercise rather than a filing exercise — but one with a fixed deadline and a long lead time.

DPDP areaWhat preparation involves
NoticeA clear, itemised notice covering what is collected and why
ConsentFree, specific, informed and unambiguous consent, with records kept
Purpose limitation and minimisationCollecting only what is needed, using it only as stated
Security safeguardsReasonable technical and organisational controls under Section 8
Breach intimationIntimate the Board without delay, then a detailed report within 72 hours; affected Data Principals must also be informed
Data Principal rightsAccess, correction, erasure, nomination and grievance redressal processes
Children’s dataVerifiable parental consent and restrictions on tracking and targeted advertising
Significant Data FiduciaryAdditional obligations including a Data Protection Officer and audits, once notified
Vendor processingProcessor contracts with security and breach-reporting obligations
Retention and deletionDefined retention periods and actual deletion capability
Cross-border transferTransfers outside India subject to Section 16 restrictions
Grievance contactA published escalation channel that is actually monitored

Two clocks, not one. A personal data breach at a CERT-In covered entity can trigger both the six-hour CERT-In report and the DPDP intimation to the Board. They are separate obligations with different recipients and timelines, and the six-hour clock is the tighter of the two. Build one workflow that satisfies both, and decide the reporting call before the incident rather than during it.

Where Businesses Actually Get Hit

RiskPractical impact
PhishingEmployee credentials stolen, often the entry point for everything else
RansomwareSystems locked, data encrypted, operations halted
Data breachCustomer, employee or vendor data exposed
Weak passwords and no MFAAccount takeover, the most preventable failure on this list
Poor vendor controlsA third-party breach that lands on you
No logsInvestigation becomes guesswork and CERT-In compliance fails
No backupData cannot be restored after an attack
No incident planThe team reacts late, inconsistently and on the record
Misconfigured cloudPrivate data publicly exposed without any attack at all
API vulnerabilityCustomer or transaction data exposed at scale
Insider threatEmployee misuse or data theft, often at exit
Unpatched systemsKnown vulnerabilities exploited long after a fix existed
No retention rulesData you no longer need enlarging every breach you have

How the Engagement Runs

StepActivityOutput
1Initial consultationBusiness model, data and system overview
2Risk mappingLegal, technical and operational cyber risks identified
3Data inventoryPersonal data, business data and systems mapped
4Regulatory mappingIT Act, CERT-In, DPDP, sectoral rules and contractual obligations
5Control gap reviewAccess, logs, backups, vendors, policies and response
6VAPT and audit coordinationTechnical testing scoped and coordinated
7Policy draftingCyber security and data protection policy set
8Incident response planBreach SOP, escalation matrix and reporting workflow
9Vendor contract reviewSecurity, confidentiality, indemnity and breach clauses
10Employee awarenessPhishing, password, data handling and reporting training
11Management reportingBoard cyber risk note
12Implementation trackerCorrective action, owner and deadline
13Compliance monitoringPeriodic review and update support

Documents Required

DocumentPurpose
Company profileBusiness and sector understanding
System architectureTechnology and access review
Data flow diagramPersonal and business data mapping
Website and app detailsExternal exposure review
Cloud and hosting vendor detailsVendor risk review
Existing cyber security policyGap review
Privacy policy and terms of useNotice, consent and liability review
Vendor agreements and DPAsSecurity and breach obligation review
Employee device and access policyEndpoint and permission review
Access control listWho can reach what
Incident logs and registerPast breach and response assessment
VAPT reportsTechnical vulnerability status
ISO, SOC or audit reportsExisting control maturity
Backup and log retention policyRecovery readiness and CERT-In compliance
Customer complaint recordsBreach or misuse allegations
Cyber insurance policyCoverage, conditions and exclusions
Regulator noticesLive regulatory exposure
Board minutes and risk reportsGovernance review

Policies We Prepare

DocumentPurpose
Cyber Security PolicyOverall governance framework
Information Security PolicyInformation classification and protection
Access Control PolicyUser permissions and approval matrix
Password and MFA PolicyCredential security
Incident Response PolicyBreach response and reporting workflow
Data Breach Response SOPStep-wise action plan against the clock
Acceptable Use PolicyEmployee use of company systems
BYOD and Remote Work PolicyPersonal device and off-site controls
Email Security PolicyPhishing and spoofing protection
Vendor Security PolicyThird-party risk management
Data Retention PolicyRetention and deletion rules
Backup and Recovery PolicyRestoration after an incident
Privacy Policy and Cookie PolicyUser-facing notice and consent
Data Processing AgreementProcessor obligations
Cyber Incident RegisterIncident logging and response evidence
Board Cyber Risk NoteGovernance reporting

Regulated Entities

Regulated entities carry a heavier documentation burden, because regulators generally expect board oversight, demonstrable controls and an audit trail rather than assurances.

SectorAdvisory focus
NBFCIT governance, outsourcing, incident handling and customer data
Payment aggregator or PSPTransaction security, fraud risk, data storage and incident response
Insurance broker or ISNPSystem audit, user access, logs, security architecture and insurer interfaces
SEBI intermediaryCyber resilience, client data, trading systems and vendor risk
IFSCA entityIFSC compliance, outsourcing and information security governance
AIF or investment managerInvestor data, fund records and access controls
HealthcarePatient data, health records and breach response
EdTechChildren’s data, consent and the heightened DPDP position
EcommercePayment, customer and seller data security
SaaS and ITCloud controls, customer data and SOC or ISO readiness
BPO and call centreCustomer data, recording and agent access controls

Cyber Due Diligence

Cyber posture is now a standard diligence workstream in investment, M&A, vendor onboarding and licensing. What gets reviewed is rarely the firewall; it is the paperwork behind it.

AreaWhat is reviewed
Data inventoryWhat is collected, where it is stored and for how long
System architectureWhere data and applications are hosted
Access rightsWho can reach critical systems, and who should not
Vendor riskCloud, SaaS and outsourced IT controls and contracts
Incident historyPast breaches, complaints and how they were handled
VAPT reportsFindings, and whether they were remediated or filed
Policy frameworkCyber and privacy policies, and evidence they are followed
DPDP readinessConsent, notice, breach and rights processes
CERT-In readinessReporting workflow and log retention
Backup and recoveryBusiness continuity after an attack
Contractual liabilityCustomer and vendor cyber clauses and caps
InsuranceCoverage, conditions precedent and exclusions
Board oversightGovernance and risk reporting

Common Gaps We Fix

GapRisk it createsHow we close it
No incident response planImprovised decisions during an attackBreach response SOP and escalation matrix
No log retentionCERT-In non-compliance and forensic dead ends180-day retention design and checklist
Privacy notice not DPDP-readyRework against a fixed 2027 deadlineNotice redraft and readiness gap review
Vendor contracts without security clausesThird-party breach liability sits with youDPA and security clause drafting
Personal devices in useUncontrolled data leakageBYOD and remote-work policy
No MFAAccount takeoverAccess control recommendations with a tracker
VAPT report not acted onA known vulnerability left open and documentedRemediation tracker to closure
No retention rulesEvery breach is larger than it needed to beRetention and deletion policy
Incident not documentedWeak defence and a contested insurance claimIncident register and evidence file
Regulator asks for a system auditSubmission delay and follow-up scrutinyAudit-readiness checklist
No board-level reportingGovernance gap visible in diligenceManagement cyber risk note
OmissionConsequence
No incident reporting capabilityCERT-In and sectoral non-compliance
No DPDP preparationA fixed 2027 deadline met in a rush, or not at all
No logsInvestigation and legal defence both weakened
Weak vendor contractsLiability cannot be allocated or recovered
No access controlUnauthorised employee or vendor access
No backupRecovery depends on the attacker
No employee trainingPhishing remains the open door
No audit trailBoard and regulator questions cannot be answered
No breach communication planReputational damage compounded by the response

Our Services

ServiceWhat we do
Cyber risk assessmentIdentify legal, technical and operational risk
IT Act and SPDI reviewMap current-regime obligations, including Section 43A
CERT-In readinessSix-hour reporting workflow, logs and escalation
DPDP readinessNotice, consent, safeguards, rights and breach process ahead of 2027
Cyber policy draftingThe full policy set, tailored to your operations
Incident response planningEscalation matrix and breach SOP
VAPT coordinationScoping, vendor selection and remediation tracking
Vendor risk reviewCloud, SaaS and outsourcing risk and contracts
Data flow mappingPersonal data and system flow inventory
Employee training materialCyber awareness and phishing content
Cyber due diligenceInvestor, M&A and vendor onboarding review
Regulated entity supportRBI, SEBI, IRDAI, IFSCA and ISNP-linked documentation
Breach response supportEvidence preservation, reporting and communication review
Contract clause reviewConfidentiality, security, indemnity and breach terms
Board cyber governanceRisk notes and management reporting
Ticket-based trackingGaps, owners, remediation and closure

FAQs

1. What is Cyber Security Advisory?

A professional service that helps a business identify and reduce legal, regulatory, operational and technical risk connected with cyber threats, data breaches and information security. It sits between the IT function and the legal function, which is exactly where most gaps live.

2. Is it a licence?

No. It is not a licence or a registration. It is advisory and compliance support. That said, the underlying obligations — incident reporting, log retention, security safeguards — can themselves be mandatory depending on the entity and sector.

3. Which laws apply to cyber security in India?

The Information Technology Act, 2000 and the CERT-In Directions of 28 April 2022 are the operative baseline today. The SPDI Rules, 2011 still govern sensitive personal data. The Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 layer on top, with most substantive obligations commencing 13 May 2027.

4. Is DPDP compliance mandatory right now?

Not in full. The DPDP Rules, 2025 were notified on 13 November 2025 with a phased commencement. The Data Protection Board provisions came into force at once and consent-manager registration opened after twelve months, but the operative obligations — notice, security safeguards, breach intimation, retention limits, children’s data, Significant Data Fiduciary duties and Data Principal rights — commence on 13 May 2027.

5. So can we wait until 2027?

That would be a mistake. The 13 May 2027 date is the deadline to be compliant, not the date to begin. Data inventories, consent re-papering, vendor contract amendments and retention controls take months, and the IT Act, SPDI Rules and CERT-In obligations already apply today regardless.

6. Is Section 43A of the IT Act still in force?

Yes. Section 43A and the SPDI Rules, 2011 remain in force and are omitted only with effect from 13 May 2027, when the corresponding DPDP provisions commence. Treating them as already repealed is a live compliance risk.

7. What is CERT-In?

The Indian Computer Emergency Response Team, the national nodal agency for cyber incident response under Section 70B of the IT Act.

8. Is cyber incident reporting mandatory?

For specified cyber incidents, yes. The CERT-In Directions require covered entities to report specified incidents within six hours of noticing them or being made aware of them.

9. What if we do not have all the details within six hours?

Report what you have. The Directions contemplate providing available information within the window and supplementing it afterwards. A late complete report is worse than a prompt partial one.

10. How long must logs be kept?

The CERT-In Directions require ICT system logs to be maintained securely for a rolling period of 180 days, within Indian jurisdiction. Log retention is the single most commonly failed item we see.

11. What is VAPT?

Vulnerability Assessment and Penetration Testing — technical testing that identifies weaknesses in systems, applications and networks.

12. Is VAPT mandatory?

It depends on the entity, regulator, certification and customer contracts. For regulated entities, system audits and security testing are commonly expected. For everyone else, it is usually a contractual rather than statutory requirement.

13. What is the DPDP breach intimation timeline?

When the relevant rules commence, a Data Fiduciary must intimate the Data Protection Board without delay with an initial description, followed by a detailed report within seventy-two hours, unless the Board allows longer on written request. Affected Data Principals must also be informed.

14. Does a CERT-In report cover the DPDP obligation as well?

No. They are separate obligations with separate recipients, thresholds and timelines. A personal data breach at a covered entity can trigger both, and the six-hour clock is the tighter one.

15. What is an incident response plan?

A step-wise plan for identifying, containing, reporting, investigating and recovering from a cyber incident, with named owners and an escalation matrix. Written before the incident, not during it.

16. What should we do immediately after an attack?

Isolate affected systems, preserve evidence, convene the response team, assess reporting obligations against the clock and coordinate technical support. Do not delete logs, do not wipe devices and do not have anyone improvise a customer statement.

17. Why does evidence preservation matter so much?

Because a breach is usually followed by a regulator, an insurer, a customer or a litigant asking what happened. Electronic records are governed by the Bharatiya Sakshya Adhiniyam, 2023, and evidence that was not preserved properly is hard to rely on later.

18. What is vendor cyber risk?

The risk arising when cloud providers, SaaS platforms, IT vendors or consultants can access your systems or data. A vendor breach is still your regulatory and customer problem, which is why contract clauses and access controls matter.

19. What is a data processing agreement?

A contract defining how a vendor processes data on your behalf, what it must protect, how quickly it must report a breach to you, and where liability sits.

20. Do small businesses need this?

Yes, proportionately. A small business still holds customer data, payment records and employee information, and attackers do not filter by turnover. The controls should be scaled, not skipped.

21. What do investors look at?

Data inventory, policies, VAPT reports and remediation status, incident history, vendor contracts, DPDP readiness and board oversight. Cyber gaps surface in diligence and affect terms.

22. What is the most common mistake?

Treating cyber security as purely an IT problem. The technical controls are only half of it; the other half is documentation, contracts, reporting readiness, evidence and board accountability.

23. What documents should a business maintain?

Cyber security policy, privacy notice, access control register, incident register, VAPT reports with a remediation tracker, vendor contracts and DPAs, data inventory, backup policy and a breach response SOP.

24. How often should this be reviewed?

Periodically, and on every trigger — a new product or app, a new vendor, a new data flow, a regulatory change, an incident, or an investor process starting.

25. Can Estabizz help during a live incident?

Yes. We support legal response, reporting readiness against the six-hour and seventy-two-hour clocks, evidence preservation, breach communication review and corrective-action tracking. Forensic and remediation work is done with technical partners.

Expert Insight

“Cyber security advice fails when it stops at the firewall. What decides the outcome after an incident is whether the logs exist, whether the reporting call was already decided, whether the vendor contract allocates the loss, and whether anyone can show the board knew. Those are legal questions, and they are cheap to answer in advance.”
— CS Devyani Khambhati, Compliance Expert

Disclaimer

This guide is general information, not entity-specific legal or technical advice. Commencement dates, applicability thresholds and sectoral obligations change, and which obligations apply to you depends on your entity type, sector, data and contracts. Statutory positions stated here are as at September 2026 and parts of this guide remain under professional review. Estabizz provides compliance mapping, documentation, policy drafting and coordination support; technical testing is performed by specialist partners and court appearance is through enrolled advocates. Confirm the current position before acting.

Prepare Before the Six-Hour Clock Starts

Nobody drafts an incident response plan well at 2 a.m. during a ransomware event. The reporting workflow, the log retention and the escalation matrix are cheap to build in advance and impossible to build under pressure.