Module 05 · Breach Management
The worst day, already rehearsed.
DPDPA asks for two things after a breach: tell the Board without delay, then file the full report within 72 hours. Neostra runs both clocks from the moment the incident is logged.
app.yourcompany.in
INC-118 · unauthorised access
Board intimation
Filed
72-hour report
11h left
1,204 principals2 systems4 controls mapped
Capabilities
Structure when it matters most.
Incident intake
One front door for suspected incidents, from the security team, support, or a vendor disclosure.
Dual-duty clocks
The immediate Board notification and the 72-hour report track separately, with escalation on both.
Severity scoring
Configurable scoring decides what is reportable, so the judgement call is made before the incident, not during it.
DPDPA control mapping
Incidents map automatically to the controls and obligations they touch, which shapes the report.
Notification templates
Board and data-principal notifications drafted from the incident record instead of from scratch at 2 a.m.
Immutable audit trail
Who knew what, when, and what was decided. The record that determines how the aftermath goes.
The dual duty
Two clocks, one record.
Section 8(6) requires notification to the Data Protection Board and to every affected data principal. The Rules set out the detail and the 72-hour window for the comprehensive report. Both obligations run from the same incident record, so the second one is never a scramble to reconstruct the first.
Incident logged: unauthorised access
Board notified
Comprehensive report filed
How it works
Live in days, not quarters.
1
Log
Anyone who spots something files it through one intake. Triage decides in minutes whether the clocks start.
2
Scope and notify
Pull the affected records from your data map, score severity and file the Board intimation from the record.
3
Report and learn
File within 72 hours, notify affected principals, and carry the remediation into your assessments.