Ransomware & crisis legal response in India — when ransomware hits, you need a lawyer before you need IT.
India's only dedicated ransomware legal response practice — attorney-client privilege from minute one, negotiation authority, CERT-In notification, forensic evidence preservation, regulatory representation, and insurance claim support. Retainer clients get a 2-hour response SLA.
The decision nobody wants to make under pressure
Paying a ransom is not simply illegal in India — but the mechanics of paying almost always are.
There is no single Indian statute that says "paying a ransomware demand is a crime." That gap gets misread constantly, including by IT teams and boards under pressure to just make the problem go away. The real exposure isn't in the act of paying — it's in how the payment actually moves.
Most ransom demands are payable only in cryptocurrency, and most require moving value out of India. That routing is where the law bites. Section 3 of FEMA prohibits dealing in foreign exchange with unauthorised persons, and Section 10 requires an accurate declared purpose for any remittance through authorised channels — a ransom payment satisfies neither by its nature. This isn't a theoretical concern: in June 2026, the Enforcement Directorate raided six premises across Bengaluru linked to crypto payment companies over an alleged ₹2,500 crore in unauthorised stablecoin transfers, prosecuted specifically under FEMA rather than money-laundering statutes. That is the exact legal instrument that would apply to a mishandled ransom payment.
This is precisely why the decision to pay — or not — needs to sit with an attorney assessing sanctions and FEMA exposure in real time, not with an IT team focused purely on data recovery. The technical urgency of a ransomware event is real, but it doesn't override the legal analysis; it makes the legal analysis more time-critical, not less relevant.
The forensics question that decides everything later
IT forensics findings can be subpoenaed. Legal-directed forensics generally cannot.
Our crisis response process
What happens in the first six hours
When ransomware hits, the first six hours are the most critical — legally, technically, and regulatorily. This is exactly when SIRI is deployed.
Attorney-client privilege established
Legal retainer activated. All communications, forensic findings, and incident documentation are immediately positioned to be protected from regulatory subpoena and third-party discovery.
Legal triage & evidence preservation
Forensic evidence collection begins under legal oversight. Attorney directs preservation strategy to build toward court-admissible evidence while minimising operational disruption.
CERT-In notification filed
India's mandatory 6-hour breach notification obligation met with two hours to spare. Notification drafted by attorneys to minimise regulatory exposure while fulfilling all disclosure requirements.
Ransom decision assessment complete
Legal analysis of payment legality under FEMA, sanctions screening against relevant lists, negotiation strategy, and threat actor assessment completed — with legal authority to proceed or decline.
Additional response services
What continues after the first six hours
A ransomware incident doesn't end when the notification is filed — the legal exposure runs for months afterward, across insurance, regulators, and affected individuals.
Insurance Claim Support
Cyber insurance policy review, claim documentation preparation, insurer liaison, coverage dispute representation, and policy compliance validation during incident response.
Regulatory Representation
Ongoing representation before CERT-In, SEBI, RBI, TRAI, and other sector regulators following a breach — managing enforcement risk and negotiating outcomes.
Data Subject Notification
Legal drafting and oversight of all customer and employee data breach notifications — minimising litigation risk while meeting DPDPA and international notification obligations.
Board & C-Suite Advisory
Direct advisory to board and executive team on legal exposure, D&O liability, disclosure obligations, and crisis communications strategy during active incidents.
Post-Incident Litigation
If litigation follows, we represent you with the complete incident record already protected by privilege — from regulatory proceedings to civil claims against threat actors where identifiable.
Retainer Preparedness
Pre-incident retainer clients receive IR plan drafting, tabletop exercises, playbook preparation, and priority response within 2 hours of incident declaration.
Evidence, not guesswork
What actually governs a ransom payment decision
Most guidance on this topic is written for a US audience and leans entirely on OFAC. Here is the fuller picture relevant to an Indian organisation.
| Legal regime | What it governs | Practical trigger |
|---|---|---|
| FEMA Section 3 | Dealing in foreign exchange with unauthorised persons | Any ransom paid to an entity outside authorised banking channels |
| FEMA Section 10 | Accurate declared purpose for remittances | Misrepresenting or omitting the true purpose of a cross-border payment |
| US OFAC sanctions | Transactions with designated (SDN-listed) entities or jurisdictions | Strict liability — applies even without knowledge the recipient is sanctioned |
| CERT-In Direction (IT Act) | Mandatory 6-hour incident notification | Awareness of the incident, independent of the payment decision |
| Government of India policy stance | No formal criminal prohibition, but explicit non-support | Not a binding legal bar, but shapes regulatory and reputational risk |
Sources: Foreign Exchange Management Act 1999, Sections 3 and 10; US Treasury OFAC ransomware advisory guidance; Enforcement Directorate action reported June 2026; CERT-In Direction 20(3)/2022. This table is general legal information, not a payment-legality determination for a specific incident — an active decision should be assessed by counsel against the specific facts and recipient in real time.
What speed and delay actually cost
Four numbers that explain why the first hour matters most
From awareness of the incident — the clock does not pause for internal deliberation, vendor scoping calls, or a search for outside counsel.
Maximum per-instance penalty for security safeguard failures, if the underlying incident also involves a personal data breach.
US sanctions liability applies even without knowledge the ransom recipient was a designated entity — ignorance is not a defence.
Response time for SIRI Shield retainer clients — legal response begins essentially simultaneously with technical response, not after it.
Why SIRI
Why you need an attorney before you call IT support
No other firm in India combines attorney-client privilege with technical execution across cybersecurity and emerging technology law — assessed inside the same crisis call, not coordinated across separate vendors under pressure.
Privilege protects you
IT forensics findings can be subpoenaed. Legal-directed forensics generally cannot. Activating SIRI first means your worst findings stay protected — always, not just for the favourable ones.
The 6-hour CERT-In deadline is real
India's mandatory breach notification carries genuine regulatory consequences for non-compliance. SIRI files the notification correctly while you manage the technical response in parallel.
Ransom payment is a legal decision
Paying ransomware has real legal consequences under FEMA and, separately, potential OFAC exposure. This requires an attorney assessing sanctions and foreign-exchange risk, not just an IT team focused on recovery.
24/7 retainer SLA
SIRI Shield ransomware retainer clients get a 2-hour response SLA. The moment an attack is detected, your legal response begins alongside your IT response, not after it.
Get ready before you need us
Don't wait for a ransomware attack to discover you need us
Get on SIRI's ransomware retainer before an incident occurs. We'll build your legal response playbook, test your incident procedures, and be ready to respond within 2 hours.
Most of what makes a crisis response fast is work that has to happen before the crisis — pre-agreed rules of engagement, a tested playbook, and legal points of contact who already understand your systems and vendor relationships. Organisations that call us for the first time during an active incident lose valuable minutes to basic scoping that retainer clients skip entirely.
What a ransomware retainer includes
- 2-hour response SLA, 24/7
- Pre-built incident response playbook
- Tabletop exercise facilitation
- Pre-agreed legal points of contact
- Pre-vetted forensic and negotiation resources
- Annual playbook review and update
Frequently asked
Ransomware & crisis response, answered directly
Is it legal to pay a ransomware demand in India?
There is no blanket Indian law that criminalises paying a ransom outright, but the payment mechanics themselves create real legal exposure. If the payment involves foreign remittance or cryptocurrency, Section 3 of FEMA prohibits dealing in foreign exchange with unauthorised persons, and Section 10 requires accurate disclosure of the purpose of any remittance through authorised channels — a ransom payment rarely fits either requirement cleanly. The Indian government has also stated it does not support ransom payments, and separately, US OFAC sanctions can attach if the threat actor is a designated entity, which matters for any payment routed through US-linked financial infrastructure.
Why does the CERT-In 6-hour window matter so much?
CERT-In's Direction under the IT Act requires notification within 6 hours of becoming aware of a cybersecurity incident, and non-compliance carries real regulatory consequences. The clock starts at awareness, not at the moment legal counsel is engaged — which is exactly why the delay between detecting an incident and calling a lawyer is the most expensive delay in the entire response.
Why can't our IT team just handle the forensics?
Forensic findings produced without a legal engagement directing the work are generally not protected by attorney-client privilege, and can be compelled in a later regulatory investigation or civil claim. When forensics are conducted under attorney direction from the outset, the resulting findings are far more likely to be protected — a distinction that matters enormously if the investigation later reveals something the organisation would not want to become a matter of public record.
What does a ransomware retainer actually change during an incident?
A pre-incident retainer means the rules of engagement, response playbook, and legal points of contact are agreed before an attack happens, not negotiated during one. SIRI Shield retainer clients receive a 2-hour response SLA, meaning legal response begins essentially simultaneously with technical response rather than after a scoping call that eats into the CERT-In notification window.
What happens to our cyber insurance claim during an incident?
We review your policy alongside the incident as it unfolds — many policies impose their own notification deadlines and specific documentation requirements that run parallel to, and sometimes conflict with, regulatory obligations. Missing an insurer notification window can jeopardise coverage even when the underlying claim would otherwise be valid, which is why policy review happens inside the first response window, not after.
Do you negotiate directly with threat actors?
Where a client decides negotiation is the appropriate path after legal and sanctions assessment, we can conduct or oversee that negotiation under privilege, with the payment decision itself gated by the FEMA and sanctions screening described above. We do not initiate contact with a threat actor before that legal assessment is complete.
Ready when you are
Don't wait for a ransomware attack to discover you need us.
Get on SIRI's ransomware retainer before an incident occurs. We'll build your legal response playbook, test your incident procedures, and be ready to respond within 2 hours.
Related services
Other ways SIRI Law LLP supports your crisis readiness
Cybersecurity testing services
Penetration testing and red teaming to reduce your ransomware attack surface before an incident.
Data privacy & cybersecurity law
DPDPA compliance and breach response for the personal-data dimension of a ransomware incident.
Corporate & commercial law
Vendor contract review and liability allocation, before a breach makes a gap expensive.
Visit or contact us
SIRI Law LLP — Hyderabad, India
| Registered office | HITEC City, Madhapur, Hyderabad, Telangana 500081, India |
| Telephone | +91 79819 12046 |
| info@sirilawllp.com | |
| Other offices | New Delhi, India · Austin, Texas, USA · Online worldwide |
| Hours | Mon–Sat, 9:30 AM – 7:00 PM IST · Emergency line 24/7 |

