📞 Call Now 💬 WhatsApp 📋 Report
⚖️
SIRI Law LLP
● Typically replies within 30 min
👋 Hi! How can SIRI Law LLP help you today?

We offer expert legal and cybersecurity advisory. Tap below for a confidential chat.
SIRI Law · Now
💬  Start Chat on WhatsApp
SIRI Response | Emergency Cyber Incident Response & Digital Forensics — SIRI Law LLP
Cyber Resilience › SIRI Response

SIRI Response — containment that holds up in court, not just on the network.

A cyber incident is happening now. SIRI Response activates containment, forensic acquisition, and attack reconstruction under legal privilege — evidence built to Section 63 Bharatiya Sakshya Adhiniyam standards from the first hour, not reconstructed for admissibility afterward.

6 hrsCERT-In notification window from awareness
2Signatures now required under Section 63 BSA
24/7SIRI Response activation availability
The evidence-admissibility clock
Live tracking · scroll to see every relevant change
In force since
1 JUL 2024
Bharatiya Sakshya Adhiniyam 2023 replaces the Indian Evidence Act 1872 — Section 65B becomes Section 63, governing all electronic evidence.
Stricter now
S.63(4) BSA
Certification now generally requires two signatures — the person in charge of the device and a technical expert — plus hash-value disclosure.
Baseline since 2022
6 HR WINDOW
CERT-In's 2022 Directions require notification within 6 hours of becoming aware of a qualifying incident — unchanged, but only achievable with a response team already in place.
Still binding
OLD MATTERS
The BSA's savings clause preserves the old Section 65B framework for matters already pending before 1 July 2024 — evidence timing matters for which regime applies.
Notified
14 NOV 2025
DPDP Rules 2025 notified — breach-related evidence obligations under DPDPA sit alongside, not instead of, BSA evidentiary requirements.

What most incident response gets wrong

Stopping the attack and preserving usable evidence are two different disciplines — most vendors are good at only one.

A typical incident response engagement optimises for one thing: getting systems back online. Logs get pulled, machines get wiped and rebuilt, and the organisation moves on — until a regulator, an insurer, or opposing counsel in a later dispute asks for the evidence that shows what actually happened. At that point, most technical-only responders discover their evidence was never collected to a standard that survives scrutiny.

Since 1 July 2024, electronic evidence in India is governed by Section 63 of the Bharatiya Sakshya Adhiniyam 2023, which replaced the old Section 65B of the Evidence Act. The certification requirement got stricter, not looser — Section 63(4) now generally requires two separate signatures, one from the person in charge of the device or system, and one from a technical expert, along with hash-value disclosure establishing the evidence hasn't been altered since collection.

Two signatures, not one — the certification bar moved up
Under the old Section 65B regime, a single certificate from the person managing the system was often sufficient. Section 63 BSA's expert co-signature requirement means forensic evidence collected without a qualified expert involved from the outset may not meet the current admissibility standard, regardless of how the underlying investigation was conducted.

SIRI Response is built around this reality: forensic acquisition, chain-of-custody documentation, and evidence certification happen as part of the technical response itself, under an engagement that's legally privileged from the moment it begins — not bolted on after the fact by a lawyer reviewing what a security vendor already collected.

What organisations get wrong

Four assumptions that undermine an incident response before it starts

Most evidentiary gaps trace back to decisions made in the first hours, not the investigation itself.

01 — SPEED

“Wipe and rebuild, we'll worry about evidence later”

Once a compromised system is wiped, volatile evidence — memory contents, active connections, in-progress processes — is gone permanently. Forensic acquisition has to happen before remediation, not after.

02 — CERTIFICATION

“Our IT team can just write up what they found”

Under Section 63 BSA, a description from IT staff without a co-signing technical expert and proper hash documentation is unlikely to meet the current admissibility bar if the matter ever reaches a regulator or a court.

03 — SCOPE

“We only need to secure the systems we know were hit”

Attack reconstruction routinely finds lateral movement and persistence mechanisms the initial detection missed — a response scoped only to the obviously affected systems frequently leaves the actual entry point unaddressed.

04 — SEQUENCING

“Legal can review this after we're back online”

Decisions made during containment — what gets isolated, what communications go out, whether law enforcement is engaged — carry legal consequences that are far easier to get right during the response than to unwind afterward.

What SIRI Response covers

From first containment to a court-admissible record of what happened

A single engagement, not a technical phase followed by a separate legal review.

INTAKE

Incident Intake & Classification

Rapid assessment of scope, likely attack vector, and immediate containment priorities.

  • 24/7 activation line
  • Initial severity classification
  • Immediate containment guidance
See the intake process →
CONTAINMENT

Containment & Eradication

Stopping lateral movement and removing attacker access without destroying evidence in the process.

  • Network segmentation guidance
  • Credential rotation strategy
  • Persistence-mechanism removal
See Cyber Legal Response →
FORENSICS

Forensic Acquisition

Evidence collection to Section 63 BSA certification standards — imaging, hash documentation, and chain of custody.

  • Memory & disk imaging
  • Hash-value documentation
  • Two-signature certification support
See SOC & SIEM →
ANALYSIS

Attack Reconstruction

Establishing initial access, persistence, and the actual scope of what was accessed or exfiltrated.

  • Timeline reconstruction
  • Data-impact assessment
  • Indicators of compromise
See the Resilience Audit →
RECOVERY

Recovery Support

Validated restoration coordinated with SIRI's recovery and assurance capability, not a separate handoff.

  • Recovery sequencing
  • Post-recovery validation
  • Hardening recommendations
See Recovery & Assurance →
LEGAL

Legal Handoff

Notification analysis and regulatory coordination begin in parallel, not after containment closes.

  • CERT-In notification support
  • Sector-specific reporting
  • Litigation-readiness assessment
See Cyber Legal Response →

Evidence, not guesswork

Generic incident response vs. SIRI Response — what actually differs

The technical steps often look similar on a slide. The evidentiary outcome usually isn't.

CapabilityGeneric IR vendorIn-house onlySIRI Response
Technical containmentYesDepends on teamYes
Forensic acquisition to Section 63 BSA standardRarely by defaultNoYes
Expert co-signature on evidence certificationAdditional cost, often missedNoIncluded
Attorney-client privilege over findingsNoNoYes
Legal notification analysis in parallel with technical workNo — sequentialNoYes — parallel
Continuity into recovery and post-incident hardeningSometimesDepends on capacityYes

Sources: Bharatiya Sakshya Adhiniyam 2023, Section 63 (in force 1 July 2024, replacing Section 65B of the Indian Evidence Act 1872); CERT-In Directions 2022, s.70B(6) IT Act 2000. Summarised for comparison; confirm current requirements before relying on any specific certification standard.

Numbers every board should know

What the numbers actually say about response speed and evidence

6 hrs

CERT-In notification window

From awareness of a qualifying incident — unchanged since the 2022 Directions.

2

Signatures required

Under Section 63(4) BSA — device custodian and technical expert, since 1 July 2024.

24%

Rise in ransomware

Reported by CERT-In in its latest reporting period — the volume this responds to is growing, not stable.

70%

Of malware detections

Are trojans and file infectors (Seqrite 2026) — usually the entry point behind a ransomware incident.

Why SIRI for incident response specifically

Technical containment and legal-grade evidence, from the same team, at the same time

Not a security vendor who happens to work with a law firm — one engagement, one chain of privilege, from first call to closed matter.

01

One engagement, from containment to court

Technical response and legally certified evidence collection happen together, not as a technical phase followed by a legal review of what's left.

02

Privilege from the first call

Findings, forensic reports, and investigation notes are protected by attorney-client privilege because the engagement is legal from activation.

03

Built for the current evidentiary standard

Section 63 BSA's two-signature requirement is built into the acquisition process, not treated as an afterthought during certification.

04

Continuity into recovery

The team that runs containment and forensics is the same team available for recovery validation and post-incident hardening.

Who this is built for

Organisations SIRI Response is built for

Ransomware Business email compromise Unauthorised access Data exfiltration Insider incidents Suspected intrusion Third-party/vendor compromise

How we work

From activation to closed matter

01

Activation

24/7 intake, initial severity classification, immediate containment guidance issued.

Immediate
02

Containment & Forensics

Attacker access removed; evidence acquired and certified to current admissibility standards.

Hours 1–24
03

Investigation

Attack reconstruction, data-impact assessment, and legal exposure analysis run in parallel.

Days 1–5
04

Recovery & Closure

Validated restoration, post-incident report, and hardening recommendations delivered.

Days 5–14

Frequently asked

SIRI Response, answered directly

What's the very first thing I should do if I suspect an active incident?

Contact SIRI's 24/7 response line before taking remediation steps yourself where possible — wiping or rebuilding a compromised system destroys volatile evidence that can't be recovered afterward. If immediate isolation is necessary to stop active damage, do that, but avoid full system rebuilds until forensic imaging has occurred.

Why does the two-signature requirement under Section 63 BSA matter for my incident?

If your incident could result in a later regulatory action, insurance claim, or dispute, the evidence collected during response needs to meet current admissibility standards to be usable. Evidence certified by only one signatory, without a technical expert's co-signature, risks challenge on exactly the point where it matters most — whether it can actually be relied on.

How is SIRI Response different from calling our existing IT security vendor?

Most IT security vendors are optimised for restoring operations, not for producing evidence that survives later scrutiny. SIRI Response runs forensic acquisition to current legal certification standards from the outset, under a privileged legal engagement, so the technical and evidentiary work happen together rather than the evidentiary gap being discovered later.

Does activating SIRI Response mean we're committing to litigation?

No. Most engagements never proceed to litigation. The value of proper evidence collection is that the option remains available if it's later needed — for a regulatory response, an insurance claim, or a dispute — rather than discovering after the fact that the evidence wasn't collected to a standard that holds up.

Can SIRI Response help if the incident happened days ago and we've already taken some remediation steps?

Yes, though the evidentiary picture is stronger the earlier forensic acquisition begins. Even after some remediation, meaningful evidence often remains in logs, backups, and secondary systems — an assessment of what's still recoverable is part of the initial engagement.

If this is happening now

Activate SIRI Response.

Call the 24/7 line directly, or start with the Cyber Resilience Audit if you're preparing rather than responding.

24/7 for active incidents: +91 79819 12046

Visit or contact us

SIRI Law LLP — Hyderabad, India

Registered officeHITEC City, Madhapur, Hyderabad, Telangana 500081, India
Telephone+91 79819 12046
Emailinfo@sirilawllp.com
Other officesNew Delhi, India · Austin, Texas, USA · Online worldwide
HoursMon–Sat, 9:30 AM – 7:00 PM IST · Emergency line 24/7
© SIRI Law LLP · Hyderabad, Telangana

This page is provided for general informational purposes and does not constitute legal advice. References to RBI's 2026 Resilience & Assurance Framework, SEBI CSCRF deadlines, CERT-In obligations, the Bharatiya Sakshya Adhiniyam 2023, and cited statistics reflect publicly available information as of publication and remain subject to regulatory change; verify current applicability to your specific entity category before relying on any specific requirement. No lawyer-client relationship is formed by viewing this page. Engagement requires a formal retainer. SIRI Law LLP is a registered law firm under the Limited Liability Partnership Act 2008, practising under the Advocates Act 1961; complaints regarding professional conduct may be directed to the Bar Council of Telangana.

Scroll to Top