IRDAI circular IRDAI/GA&HR/CIR/MISC/128/06/2023 · 13 Jun 2023
Official title
Circular on Reporting of Cyber Security Incident
Summary
Check the official recordThe Insurance Regulatory and Development Authority of India (IRDAI) has issued a directive to all regulated entities regarding the mandatory reporting of cyber security incidents. Entities must report incidents to CERT-In within 6 hours of discovery, while simultaneously copying the IRDAI. Furthermore, entities are required to submit detailed incident reports to the IRDAI in a specified format within 24 hours of the initial intimation. Subsequent updates based on forensic analysis must also be submitted to the Authority within 24 hours of such information becoming available. This circular addresses observed non-compliance with established reporting timelines and communication protocols.
What you must do
Key dates
Who is affected
भारतीय बीमा विनियामक और विकास प्राधिकरण INSURANCE REGULATORY AND DEVELOPMENT AUTHORITY OF INDIA
संदर्भ: आईआरडीएआई/जीए&एचआर/सीआईआर/विविध/128/06/2023 Ref: IRDAI/GA&HR/CIR/MISC/128/06/2023
13 जून, 2023 13th June, 2023
प्रति / To, सभी विनियमित संस्थाएँ / All Regulated Entities
विषय: विनियमित संस्थाओं द्वारा साइबर घटनाओं की रिपोर्टिंग Subject: Reporting of Cyber Security Incidents by Regulated Entities
Reference is drawn to para 3.5 ‘Notification to Regulatory Authorities’ under policy no. 2.10 ‘Incident and Problem Management’ in IRDAI Information and Cyber Security Guidelines, 2023 dated 24th Apr, 2023, wherein it is stated that “Organization shall mandatorily report cyber incidents to Cert-In within 6 hours of noticing or being brought to notice about such incidents with a copy to IRDAI and other concerned regulators / authorities.”
In this connection, it is observed that the Regulatory Entities are not adhering to the above mentioned timelines and also not keeping the Authority in loop in their communications to Cert-In.
In view of the above, all Regulated Entities are directed to scrupulously follow the provisions regarding reporting of incident to IRDAI and Cert-In. Further, Regulated Entities are required to submit available details of Cyber Security Incident to the Authority in an enclosed format within 24 hrs of intimation of the incident.
Further, the details in the reporting format needs to be updated with flow of information from the forensic analysis as and when obtained and submitted to the Authority as subsequent version(s) within 24 hrs of such information being made available.
(दीपक गायकवाड / Deepak Gaikwad) (सीआईएसओ/CISO)
सर्वे नं. 115/1, फाइनेंशियल डिस्ट्रिक्ट, नानकरामगुडा, हैदराबाद-500 032, भारत Survey No. 115/1, Financial District, Nanakramguda, Hyderabad-500 032, India : +91-40-20204000, वेबसाइट : www.irdai.gov.in : +91-40-20204000, Website : www.irdai.gov.in