The Insurance Regulatory and Development Authority of India (IRDAI) on June 13, 2023, issued a notification regarding the Reporting of Cyber Security Incidents by Regulated Entities.
The following has been stated namely: -
• Organization shall mandatorily report cyber incidents to Cert-In within 6 hours of noticing or being brought to notice about such incidents with a copy to IRDAI and other concerned regulators/authorities.
• It is observed that the Regulatory Entities are not adhering to the above-mentioned timelines and also not keeping the Authority in the loop in their communications to Cert-In.
• All Regulated Entities are directed to scrupulously follow the provisions regarding the reporting of incidents to IRDAI and Cert-In.
• Regulated Entities are required to submit available details of Cyber Security Incidents to the Authority in an enclosed format within 24 hrs of intimation of the incident.
• The details in the reporting format need to be updated with the flow of information from the forensic analysis as and when obtained and submitted to the Authority as a subsequent version(s) within 24 hrs of such information being made available
[Notification No. IRDAI/GA&HR/CIR/MISC/128/06/2023]