Industry

    Security for Government & Public Sector

    Citizen data platforms, e-governance portals, and critical public infrastructure run on long-lived systems that cannot simply be taken offline to patch.

    01
    6 hrs

    CERT-IN'S MANDATORY WINDOW TO REPORT A CYBER INCIDENT

    02
    180 days

    OF SYSTEM LOGS CERT-IN REQUIRES BE RETAINED WITHIN INDIA

    Securing a public sector estate means gaining visibility across systems nobody has fully inventoried, hardening citizen-facing portals against the internet, and building detection and reporting workflows that can meet CERT-In's timelines. It requires working within procurement realities and around services that cannot take downtime.

    Why it matters

    Public Systems, Public Consequences

    A government breach is not just a data incident. It disrupts services citizens depend on, exposes records that can never be reissued, and plays out in full public view. Meanwhile the estate spans decades-old systems, third-party integrators, and infrastructure designated as nationally critical.

    • 01

      Legacy Systems, Modern Attackers

      Departments run software far past vendor support because replacing it means interrupting a public service. Attackers target exactly these unpatched, internet-reachable systems.

    • 02

      Reporting Clocks Start Immediately

      CERT-In gives you six hours from noticing an incident to reporting it. Without prepared detection and escalation paths, that deadline passes during triage.

    • 03

      Critical Infrastructure Raises the Stakes

      Systems designated critical by NCIIPC carry obligations well beyond ordinary IT security, and an outage there reaches power, transport, or health services directly.

    Regulatory landscape, India

    Compliance built for Indian government & public sector

    Every engagement is aligned to the regulations that actually apply to your sector in India, so your security programme satisfies auditors and regulators, not just a checklist.

    • 01

      CERT-In Directions (2022)

      Six-hour incident reporting, 180 days of logs retained in India, and synchronised NTP across the estate.

    • 02

      NCIIPC

      Additional protection obligations for systems designated as Critical Information Infrastructure.

    • 03

      DPDP Act, 2023

      Duties over citizen personal data held by government bodies, including breach notification.

    • 04

      MeitY & NIC Guidelines

      Security policy, hosting, and audit expectations for government applications and cloud services.

    FAQ

    Common questions

    01Can you work within our existing empanelment and procurement process?

    Yes. We scope engagements to fit departmental procurement routes and coordinate with your existing system integrators rather than replacing them.

    02Our systems cannot be taken offline. Can you still test them?

    Yes. We run non-disruptive assessment against production and reserve intrusive testing for staging or agreed maintenance windows.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us