📞 Call Now 💬 WhatsApp 📋 Report
⚖️
SIRI Law LLP
● Typically replies within 30 min
👋 Hi! How can SIRI Law LLP help you today?

We offer expert legal and cybersecurity advisory. Tap below for a confidential chat.
SIRI Law · Now
💬  Start Chat on WhatsApp
Ransomware & Crisis Legal Response in India | 24/7 Emergency Line — SIRI Law LLP
Active ransomware incident right now? Call the 24/7 emergency line: +91 79819 12046
Ransomware & Crisis Legal Response · Hyderabad, India · 24/7

Ransomware & crisis legal response in India — when ransomware hits, you need a lawyer before you need IT.

India's only dedicated ransomware legal response practice — attorney-client privilege from minute one, negotiation authority, CERT-In notification, forensic evidence preservation, regulatory representation, and insurance claim support. Retainer clients get a 2-hour response SLA.

6 hrsCERT-In's mandatory notification deadline — clock starts at awareness
2 hrsSIRI Shield retainer client response SLA
₹2,500 CrScale of a June 2026 ED action on unauthorised crypto transfers under FEMA
24/7Emergency line, every day of the year
Why speed is the whole game
Live tracking · the deadlines that actually govern a breach
Deadline
6 hrs
CERT-In notification deadline from awareness of the incident — not from when a lawyer is engaged.
Statute
FEMA §3
Prohibits dealing in foreign exchange with unauthorised persons — directly relevant to any ransom paid abroad or in crypto.
Statute
FEMA §10
Requires accurate disclosure of the purpose of any remittance through authorised channels — a ransom payment rarely fits cleanly.
Precedent
17 JUN 2026
Enforcement Directorate action across six Bengaluru premises over ₹2,500 Cr in unauthorised stablecoin transfers, prosecuted under FEMA.
Cross-border
OFAC
US sanctions can attach to a ransom payment on a strict-liability basis if the recipient is a designated entity — relevant wherever US-linked financial rails are involved.
Position
GoI stance
The Indian government has stated it does not support ransom payments to cybercriminals, viewing them as encouraging further attacks.

The decision nobody wants to make under pressure

Paying a ransom is not simply illegal in India — but the mechanics of paying almost always are.

There is no single Indian statute that says "paying a ransomware demand is a crime." That gap gets misread constantly, including by IT teams and boards under pressure to just make the problem go away. The real exposure isn't in the act of paying — it's in how the payment actually moves.

Most ransom demands are payable only in cryptocurrency, and most require moving value out of India. That routing is where the law bites. Section 3 of FEMA prohibits dealing in foreign exchange with unauthorised persons, and Section 10 requires an accurate declared purpose for any remittance through authorised channels — a ransom payment satisfies neither by its nature. This isn't a theoretical concern: in June 2026, the Enforcement Directorate raided six premises across Bengaluru linked to crypto payment companies over an alleged ₹2,500 crore in unauthorised stablecoin transfers, prosecuted specifically under FEMA rather than money-laundering statutes. That is the exact legal instrument that would apply to a mishandled ransom payment.

Two separate sanctions regimes, not one
A ransom payment can create exposure under Indian FEMA rules for the cross-border movement itself, and separately under US OFAC sanctions if the recipient turns out to be a designated entity — a strict-liability standard that applies even if the payer had no way of knowing who was on the other end. Any payment routed through US-linked financial infrastructure inherits this second layer of risk regardless of where the victim organisation is based.

This is precisely why the decision to pay — or not — needs to sit with an attorney assessing sanctions and FEMA exposure in real time, not with an IT team focused purely on data recovery. The technical urgency of a ransomware event is real, but it doesn't override the legal analysis; it makes the legal analysis more time-critical, not less relevant.

SIRI Law LLP crisis response team during an active incident

The forensics question that decides everything later

IT forensics findings can be subpoenaed. Legal-directed forensics generally cannot.

Our crisis response process

What happens in the first six hours

When ransomware hits, the first six hours are the most critical — legally, technically, and regulatorily. This is exactly when SIRI is deployed.

0–30 min
Immediate response

Attorney-client privilege established

Legal retainer activated. All communications, forensic findings, and incident documentation are immediately positioned to be protected from regulatory subpoena and third-party discovery.

Hour 1
Hour one

Legal triage & evidence preservation

Forensic evidence collection begins under legal oversight. Attorney directs preservation strategy to build toward court-admissible evidence while minimising operational disruption.

Hour 4
Four hours

CERT-In notification filed

India's mandatory 6-hour breach notification obligation met with two hours to spare. Notification drafted by attorneys to minimise regulatory exposure while fulfilling all disclosure requirements.

Hour 6
Six hours

Ransom decision assessment complete

Legal analysis of payment legality under FEMA, sanctions screening against relevant lists, negotiation strategy, and threat actor assessment completed — with legal authority to proceed or decline.

Additional response services

What continues after the first six hours

A ransomware incident doesn't end when the notification is filed — the legal exposure runs for months afterward, across insurance, regulators, and affected individuals.

01

Insurance Claim Support

Cyber insurance policy review, claim documentation preparation, insurer liaison, coverage dispute representation, and policy compliance validation during incident response.

02

Regulatory Representation

Ongoing representation before CERT-In, SEBI, RBI, TRAI, and other sector regulators following a breach — managing enforcement risk and negotiating outcomes.

03

Data Subject Notification

Legal drafting and oversight of all customer and employee data breach notifications — minimising litigation risk while meeting DPDPA and international notification obligations.

04

Board & C-Suite Advisory

Direct advisory to board and executive team on legal exposure, D&O liability, disclosure obligations, and crisis communications strategy during active incidents.

05

Post-Incident Litigation

If litigation follows, we represent you with the complete incident record already protected by privilege — from regulatory proceedings to civil claims against threat actors where identifiable.

06

Retainer Preparedness

Pre-incident retainer clients receive IR plan drafting, tabletop exercises, playbook preparation, and priority response within 2 hours of incident declaration.

Evidence, not guesswork

What actually governs a ransom payment decision

Most guidance on this topic is written for a US audience and leans entirely on OFAC. Here is the fuller picture relevant to an Indian organisation.

Legal regime What it governs Practical trigger
FEMA Section 3 Dealing in foreign exchange with unauthorised persons Any ransom paid to an entity outside authorised banking channels
FEMA Section 10 Accurate declared purpose for remittances Misrepresenting or omitting the true purpose of a cross-border payment
US OFAC sanctions Transactions with designated (SDN-listed) entities or jurisdictions Strict liability — applies even without knowledge the recipient is sanctioned
CERT-In Direction (IT Act) Mandatory 6-hour incident notification Awareness of the incident, independent of the payment decision
Government of India policy stance No formal criminal prohibition, but explicit non-support Not a binding legal bar, but shapes regulatory and reputational risk

Sources: Foreign Exchange Management Act 1999, Sections 3 and 10; US Treasury OFAC ransomware advisory guidance; Enforcement Directorate action reported June 2026; CERT-In Direction 20(3)/2022. This table is general legal information, not a payment-legality determination for a specific incident — an active decision should be assessed by counsel against the specific facts and recipient in real time.

What speed and delay actually cost

Four numbers that explain why the first hour matters most

6 hrs
CERT-In deadline

From awareness of the incident — the clock does not pause for internal deliberation, vendor scoping calls, or a search for outside counsel.

₹250 Cr
DPDP Act exposure

Maximum per-instance penalty for security safeguard failures, if the underlying incident also involves a personal data breach.

Strict
OFAC liability standard

US sanctions liability applies even without knowledge the ransom recipient was a designated entity — ignorance is not a defence.

2 hrs
Retainer client SLA

Response time for SIRI Shield retainer clients — legal response begins essentially simultaneously with technical response, not after it.

Why SIRI

Why you need an attorney before you call IT support

No other firm in India combines attorney-client privilege with technical execution across cybersecurity and emerging technology law — assessed inside the same crisis call, not coordinated across separate vendors under pressure.

SIRI Law LLP crisis response coordination
01 — Privilege

Privilege protects you

IT forensics findings can be subpoenaed. Legal-directed forensics generally cannot. Activating SIRI first means your worst findings stay protected — always, not just for the favourable ones.

02 — Deadline

The 6-hour CERT-In deadline is real

India's mandatory breach notification carries genuine regulatory consequences for non-compliance. SIRI files the notification correctly while you manage the technical response in parallel.

03 — Payment decision

Ransom payment is a legal decision

Paying ransomware has real legal consequences under FEMA and, separately, potential OFAC exposure. This requires an attorney assessing sanctions and foreign-exchange risk, not just an IT team focused on recovery.

04 — Readiness

24/7 retainer SLA

SIRI Shield ransomware retainer clients get a 2-hour response SLA. The moment an attack is detected, your legal response begins alongside your IT response, not after it.

Get ready before you need us

Don't wait for a ransomware attack to discover you need us

Get on SIRI's ransomware retainer before an incident occurs. We'll build your legal response playbook, test your incident procedures, and be ready to respond within 2 hours.

Most of what makes a crisis response fast is work that has to happen before the crisis — pre-agreed rules of engagement, a tested playbook, and legal points of contact who already understand your systems and vendor relationships. Organisations that call us for the first time during an active incident lose valuable minutes to basic scoping that retainer clients skip entirely.

What a ransomware retainer includes

  • 2-hour response SLA, 24/7
  • Pre-built incident response playbook
  • Tabletop exercise facilitation
  • Pre-agreed legal points of contact
  • Pre-vetted forensic and negotiation resources
  • Annual playbook review and update
See SIRI Shield plans

Frequently asked

Ransomware & crisis response, answered directly

Is it legal to pay a ransomware demand in India?

There is no blanket Indian law that criminalises paying a ransom outright, but the payment mechanics themselves create real legal exposure. If the payment involves foreign remittance or cryptocurrency, Section 3 of FEMA prohibits dealing in foreign exchange with unauthorised persons, and Section 10 requires accurate disclosure of the purpose of any remittance through authorised channels — a ransom payment rarely fits either requirement cleanly. The Indian government has also stated it does not support ransom payments, and separately, US OFAC sanctions can attach if the threat actor is a designated entity, which matters for any payment routed through US-linked financial infrastructure.

Why does the CERT-In 6-hour window matter so much?

CERT-In's Direction under the IT Act requires notification within 6 hours of becoming aware of a cybersecurity incident, and non-compliance carries real regulatory consequences. The clock starts at awareness, not at the moment legal counsel is engaged — which is exactly why the delay between detecting an incident and calling a lawyer is the most expensive delay in the entire response.

Why can't our IT team just handle the forensics?

Forensic findings produced without a legal engagement directing the work are generally not protected by attorney-client privilege, and can be compelled in a later regulatory investigation or civil claim. When forensics are conducted under attorney direction from the outset, the resulting findings are far more likely to be protected — a distinction that matters enormously if the investigation later reveals something the organisation would not want to become a matter of public record.

What does a ransomware retainer actually change during an incident?

A pre-incident retainer means the rules of engagement, response playbook, and legal points of contact are agreed before an attack happens, not negotiated during one. SIRI Shield retainer clients receive a 2-hour response SLA, meaning legal response begins essentially simultaneously with technical response rather than after a scoping call that eats into the CERT-In notification window.

What happens to our cyber insurance claim during an incident?

We review your policy alongside the incident as it unfolds — many policies impose their own notification deadlines and specific documentation requirements that run parallel to, and sometimes conflict with, regulatory obligations. Missing an insurer notification window can jeopardise coverage even when the underlying claim would otherwise be valid, which is why policy review happens inside the first response window, not after.

Do you negotiate directly with threat actors?

Where a client decides negotiation is the appropriate path after legal and sanctions assessment, we can conduct or oversee that negotiation under privilege, with the payment decision itself gated by the FEMA and sanctions screening described above. We do not initiate contact with a threat actor before that legal assessment is complete.

Ready when you are

Don't wait for a ransomware attack to discover you need us.

Get on SIRI's ransomware retainer before an incident occurs. We'll build your legal response playbook, test your incident procedures, and be ready to respond within 2 hours.

or call +91 79819 12046 — Mon–Sat, 9 AM – 7 PM IST · Emergency line 24/7

Visit or contact us

SIRI Law LLP — Hyderabad, India

Registered officeHITEC City, Madhapur, Hyderabad, Telangana 500081, India
Telephone+91 79819 12046
Emailinfo@sirilawllp.com
Other officesNew Delhi, India · Austin, Texas, USA · Online worldwide
HoursMon–Sat, 9:30 AM – 7:00 PM IST · Emergency line 24/7
© SIRI Law LLP · Hyderabad, Telangana

This page is provided for general informational purposes and does not constitute legal advice, and nothing here is a determination of the legality of any specific ransom payment. References to FEMA, OFAC, CERT-In, and enforcement actions reflect publicly available information as of publication and remain subject to change; a live incident should always be assessed by counsel against its specific facts. No lawyer-client relationship is formed by viewing this page. SIRI Law LLP is a registered law firm under the Limited Liability Partnership Act 2008, practising under the Advocates Act 1961; complaints regarding professional conduct may be directed to the Bar Council of Telangana.

Scroll to Top