Threat & Exposure

Dark-Web Monitoring and Breach Reporting Clocks

Separate CERT-In reporting and DPDP breach-notification triggers, understand dark-web monitoring limits, and prepare an evidence-led alert response workflow.

Security alert desk with two clocks representing separate reporting triggers.
In this article 7 sections
ShareLinkedInWhatsAppEmail

Dark-web monitoring can reveal exposed credentials or data that an organisation has not yet found internally. Its value depends on what happens next: prompt triage, evidence preservation and a reporting process with a named owner.

Finding an incident and containing it are different milestones. Reporting can be due while the investigation is still underway. Existing safeguards and logging duties also matter before any alert arrives.

When does the six-hour clock actually start?

For covered entities, the CERT-In Directions require reporting within six hours of noticing a reportable incident or being informed of it. Read Annexure I together with the official FAQs: FAQ 30 provides reporting criteria and allows available information to be submitted first, with further information supplied later. CERT-In Directions and reporting trigger

Build escalation around the facts already known, not the date a final forensic report will arrive. See our CERT-In reporting overview for the wider operational context.

What second clock does the DPDP Act add?

DPDP Rules 1 and 7 place these breach-notification duties in the May 2027 commencement phase. When applicable, a Data Fiduciary must inform affected individuals and the Board without delay after becoming aware of a personal data breach. Fuller information goes to the Board within 72 hours of awareness, unless the Board allows longer following a written request. DPDP Rules 1 and 7

This is a separate duty with its own scope and trigger. The initial notification is not postponed until the fuller report is ready. Our DPDP overview explains the broader preparation work.

Why separate detection from containment?

IBM’s 2025 India report put the average breach lifecycle at 263 days, including identification and containment/restoration. That is not 263 days before discovery. Its 2026 India release reports an average total breach cost of ₹25.5 crore. These are different annual datasets, not a combined estimate for one incident. IBM India 2025 report: identification and containment lifecycle

Neither figure tells you how long your organisation would take or whether most costs occur before detection. Measure your own awareness, escalation and containment timestamps. Prevention, internal detection and rehearsed response remain part of the same programme.

What does this mean for payment environments?

Payment-environment scoping is a separate discipline. Keep its systems and owners current so incident triage reaches the right people. The linked PCI DSS scope article explains that review; a scope calendar does not replace incident reporting.

Where does dark-web monitoring fit?

Treat a listing as a lead to investigate. It may contain old, duplicated or misattributed material; private channels may be outside a monitoring service’s coverage. An external signal can complement internal detection, but cannot guarantee earlier discovery or prove that no breach exists.

Use a short operational sequence: preserve the alert and its source; establish which assets or people it concerns; record awareness timestamps; assign incident and reporting owners; assess applicable duties; and continue containment alongside required reports. Document why the team escalated or closed the alert.

Give each trigger an owner and evidence trail

  • Alert triage owner: preserve the source and establish what the material actually supports. Record uncertainty about freshness, attribution and completeness without circulating exposed personal data unnecessarily.
  • Incident lead: record the relevant noticing and awareness facts, open the incident timeline and coordinate containment. Do not substitute the final investigation date for an earlier reporting trigger.
  • Reporting owner: assess each applicable duty independently with the authorised legal or compliance contact. Record the report, recipient, submission time and information still outstanding; an external monitoring provider should not silently become the accountable decision-maker.
  • Exercise reviewer: use an old credential listing and a credible current data exposure as separate scenarios. Test whether the team can distinguish them, escalate uncertainty and provide an initial report while technical investigation continues.

Sources and further guidance

Regulatory applicability depends on the organisation and the provisions in force. Check the linked primary sources before acting.

Related reading and capabilities

Frequently asked questions

Does dark-web monitoring replace breach notification?

No. It can provide an additional signal of exposure. Assess what the signal establishes, preserve evidence and follow the reporting duties that apply; monitoring itself does not fulfil a notification requirement.

Must every security alert be reported within six hours?

Assess the incident against the CERT-In Directions, Annexure I and applicable guidance. The six-hour rule concerns reportable incidents, not every raw alert. Do not delay a required initial report while waiting for a complete investigation.

Do the two reporting clocks always start together?

No. Noticing a reportable cyber incident and becoming aware of a personal data breach may happen at different times. Record the relevant facts and timestamps for each duty rather than assuming one universal trigger.