A cyber risk assessment for an Indian business should connect its systems, data flows, suppliers, contracts and incident duties in one usable review. The result is a prioritised record of legal and operational exposure, with clear actions to complete before a breach, complaint or regulatory request makes the gaps urgent.
What a cyber risk assessment should answer
A useful cyber risk assessment starts with decisions, not a list of security products. It should show which information the business holds, why it is collected, who can access it, where it moves, and which people or vendors can change or disclose it. It should also identify the business owner for each system and the evidence that proves a control is working.
A legal review does not replace a penetration test or a technical security audit. It adds a different question: what does the business need to do under the rules, contracts and notices that apply to its activity? A customer database, payroll system, payment flow, cloud account and employee device may create different risks. A report that treats them as one box will hide the decisions that management needs to make.
Map data, systems and third-party exposure
The first working session should draw the route from collection to deletion. Record the forms, applications, analytics tools, support desks, payment providers and storage locations that handle personal or confidential information. Then connect each step to an owner, a purpose, a retention rule and an access group. This gives the assessment a factual base instead of relying on policy wording alone.
- Identify sensitive routes. Record customer, employee, financial, authentication and business-confidential data, including copies created by exports, backups and support tickets.
- Review privileged access. Check administrator accounts, shared credentials, remote access, multi-factor controls, joiner and leaver processes, and logs for important actions.
- Test supplier boundaries. Read cloud, software, payroll, payment and support agreements for security duties, breach notice, audit rights, subcontracting and deletion obligations.
- Match public promises to practice. Compare privacy notices, consent screens, cookie notices and customer contracts with the actual collection and use of information.
The Digital Personal Data Protection Act, 2023 on India Code sets out a framework that includes processing grounds, notices, Data Fiduciary obligations, security safeguards, breach intimation and erasure duties. Its commencement schedule and the facts of a business matter, so the assessment should state which provisions are currently relevant instead of presenting every duty as automatically applicable.
Test incident readiness under Indian cyber rules
A risk register should explain what happens when an alert becomes an incident. The CERT-In incident reporting directions state that covered entities must report listed cyber incidents within six hours of noticing them or being informed about them. They also require covered organisations to keep ICT system logs securely for a rolling 180 days within Indian jurisdiction. The reportable categories include unauthorised access, ransomware, data breach, data leak, cloud incidents, digital payment incidents and certain virtual asset incidents.
That requirement makes preparation part of legal risk control. Decide who can declare that an incident has been noticed, who contacts CERT-In, who preserves devices and logs, who informs affected people or customers, and who manages the insurer, vendors and investigators. Keep a dated escalation record. A plan that names a contact but does not preserve evidence, authority and decision times will be difficult to use during the first hours of a crisis.
Turn findings into a prioritised risk register
Assessment findings become useful when each item leads to a named decision. The final risk register should separate an immediate exposure from a longer improvement project and should explain the evidence behind the rating.
- Describe the scenario. State the system, information, actor, access path and business process involved.
- Identify the rule or commitment. Link the risk to a statute, notification, contract, privacy promise, customer requirement or internal policy.
- Record the evidence gap. Say what is missing, such as a vendor clause, access log, retention schedule, incident record or approval.
- Assign an owner and date. Give the legal, technical, procurement or business owner authority to close the item.
- Set a verification step. Require a fresh test, signed record, sample review or tabletop exercise rather than marking the item complete on a promise.
For a broader control review, the site's Cyber Law Compliance Audit page is a related starting point. Its Cyber Laws and IT Act reference can provide additional background, but neither resource replaces an assessment of the particular systems and contracts in front of the adviser.
What the final assessment should contain
A board or founder should be able to read the first page and understand the highest risks, the reason for each rating and the action that needs funding or approval. Supporting sections can include the system and data map, third-party register, obligation matrix, evidence list, incident contacts, remediation plan and assumptions. Separate confirmed facts from items that still need technical testing or document review.
The assessment should also show what is out of scope. That boundary prevents a short review of one application from being mistaken for an opinion on every group company, vendor or location. Revisit the record after a new product launch, major supplier change, security incident, acquisition or material change to data use.
Request a cyber risk assessment consultation
If your business needs a cyber risk assessment, request a consultation with the relevant system map, vendor agreements, privacy notices, incident plan and any recent security findings. A focused first review can identify the legal questions, urgent evidence steps and practical owners for the next stage.
