Why Cybersecurity Law Matters Economically
Cyberattacks are no longer isolated IT problems. A single data breach can trigger regulatory fines, loss of customer trust, and operational downtime, all of which carry direct economic cost. India’s regulatory response has therefore expanded well beyond the original Information Technology Act, 2000 (IT Act), which was India’s first comprehensive law on electronic records, digital signatures, and cybercrime.
Key Statutes Governing Indian Cyber Law
1. Information Technology Act, 2000 (amended 2008) The foundational statute. It criminalizes hacking, identity theft, and data theft, and gives legal recognition to electronic contracts and digital signatures. Section 43 covers civil liability for unauthorized access to computer systems, while Section 66 criminalizes computer-related offences with imprisonment of up to three years.
2. IT (Reasonable Security Practices and Sensitive Personal Data or Information) Rules, 2011 Often called the Privacy Rules, these require companies handling sensitive personal data, such as financial information, health records, or passwords, to maintain documented security practices.
3. CERT-In Directions, 2022 Issued under Section 70B of the IT Act, these directions created the current incident-reporting regime. The Indian Computer Emergency Response Team (CERT-In) is the national nodal agency for cybersecurity incident response. Organizations must report specified categories of incidents within six hours of noticing them, and maintain system logs for 180 days.
4. Digital Personal Data Protection Act, 2023 (DPDP Act) India’s dedicated data protection law, which became operational through the DPDP Rules, 2025, notified in November 2025. It governs how “data fiduciaries” (entities that decide how personal data is processed) collect and use the data of “data principals” (individuals). The rollout is phased: the Data Protection Board of India began functioning immediately, the Consent Manager framework takes effect in November 2026, and core obligations around breach notification and data principal rights become enforceable from May 2027.
5. Bharatiya Nyaya Sanhita, 2023 (BNS) The criminal code that replaced the Indian Penal Code carries forward and updates offences relevant to online fraud, cheating, and identity misuse.
6. Sector-specific frameworks The Reserve Bank of India, the Securities and Exchange Board of India, and the Insurance Regulatory and Development Authority of India each maintain their own cybersecurity directions for banks, market intermediaries, and insurers respectively, layered on top of the general law.
Frequently Asked Questions
The Information Technology Act, 2000 remains the primary statute, supported by the DPDP Act, 2023 and CERT-In Directions.
Yes, the six-hour reporting mandate applies broadly and is not limited to large enterprises.
CERT-In lists around twenty categories, including data breaches, ransomware attacks, and unauthorized access to critical systems.
No, it is being rolled out in phases through 2027, though the Data Protection Board is already operational.
It may face penalties under both the IT Act for non-reporting to CERT-In and the DPDP Act for failing to notify affected individuals.
Want the deeper dive? Grab the reference book.