13.06.2023

  1. Reference is drawn to para 3.5 ‘Notification to Regulatory Authorities’ under policy no. 2.10 ‘Incident and Problem Management’ in IRDAI Information and Cyber Security Guidelines, 2023 dated 24th Apr, 2023, wherein it is stated that “Organization shall mandatorily report cyberincidents to Cert-In within 6 hours of noticing or being brought to notice about such incidents with a copy to IRDAI and other concerned regulators / authorities.”
  2. In this connection, it is observed that the Regulatory Entities are not adhering to the above mentioned timelines and also not keeping the Authority in loop in their communications to CertIn.
  3. In view of the above, all Regulated Entities are directed to scrupulously follow the provisions regarding reporting of incident to IRDAI and Cert-In. Further, Regulated Entities are required to submit available details of Cyber Security Incident to the Authority in an enclosed format within 24 hrs of intimation of the incident.
  4. Further, the details in the reporting format needs to be updated with flow of information from the forensic analysis as and when obtained and submitted to the Authority as subsequent version(s) within 24 hrs of such information being made available.
Series Navigation<< Insurance claims relating to Cyclone Biparjoy

Author

This entry is part 19 of 19 in the series July 2023 - Insurance Times

Byadmin

Leave a Reply

Your email address will not be published. Required fields are marked *