RISKFORTIS
Enforcement092d 01h 44m

Fortis Drill #01

The 72-hour DPDP breach response drill.

Ninety minutes. Five seats. One incident, two regulatory clocks running in parallel from the moment your team says it became aware. Scored against the rule text, not against opinion.

90
min
5–12
seats
72
sim hours
03
graded filings
14
decisions

The setup

06:40 on a Tuesday.
Nobody has said the word breach yet.

Arclight Finserv is a mid-size Indian consumer lending platform with 3.2 million customers. A KYC document store operated by one of its processors has been indexed by a search engine. A journalist has the link. Support has three tickets open that nobody has connected yet.

Your team walks in at 06:40 with what Arclight actually knows — which is very little, unevenly distributed, and some of it wrong.

Fictional company, real statutes. Deliberate — no trademark exposure, full regulatory fidelity.

Incident file · ARC-2026-0417

EntityArclight Finserv Pvt Ltd
Data principals3,200,000
Exposed storeKYC documents (processor)
Awareness06:40 IST, disputed
Regulators in scopeCERT-In · DPB · RBI

The five seats

Each seat gets a different version of the truth.

01

DPO / Privacy Lead

Receives the data principal complaint log and the consent records for the affected cohort.

02

CISO / Security Head

Receives the processor's access logs — including the timestamp that moves awareness eleven days.

03

In-house Counsel

Receives the processor agreement, and the clause that does not say what everyone assumes it says.

04

IT & Infrastructure

Receives the containment options, each with a cost in downtime and in destroyed evidence.

05

Corporate Communications

Receives the journalist's email, with a deadline earlier than any of the statutory ones.

Information is role-gated. No one seat sees everything — which is the point.

The dual clock

Two windows, one axis, drawn to scale.

Both clocks start at awareness. The CERT-In window closes before most incident bridges have finished their first handover call.

CERT-IN INITIAL REPORT6h
DPDP RULE 7 DETAILED REPORT72h

CERT-In occupies 8.3% of the DPDP window. Teams routinely plan for the 72 and miss the 6.

The awareness trap

Every clock starts at a date someone else picks.

Set the moment your organisation became aware. The four statutory deadlines compute from it. Then find out what happens when the logs disagree with you.

Awareness parameters

RBI outsourcing directions stack on top: your processor is your obligation.

CERT-In initial report00d 09h 35m 13s overdue

Direction 20(3)/2022 · 6h window

DPB initial intimation02d 08h 24m 46s

DPDP Rules 2025, Rule 7(1) · without delay

Data principal notification02d 08h 24m 46s

Rule 7(1)(b) · without delay

DPB detailed report02d 08h 24m 46s

Rule 7(2) · 72h window

The three filings

Three documents leave the building. All three are graded.

Filing 01 · 6h

CERT-In incident report

Submitted on the prescribed format, with the facts you can actually stand behind at hour six.

Filing 02 · Rule 7(1)

Initial intimation to the Board

Nature, extent, timing and likely impact — written before the forensics are finished.

Filing 03 · Rule 7(1)(b)

Notice to data principals

Plain language, no hedging, and a stated action the customer can take today.

Scoring

Six dimensions, weighted and published.

Immune Response Score · 100 points
DimensionWeight
Clock compliance30
Notification accuracy20
Containment and forensics15
Documentation and evidence15
Stakeholder communication10
Legal exposure10

Read the full rubric — we publish it

We score the team, never individuals. No participant is named or ranked in anything that reaches your board.

Immune Response Report · 18 pages

This is why it comes out of the compliance budget, not L&D.

The report

What you hand the auditor afterwards.

  • Timestamped decision log for all 14 decision points
  • Clock performance against each statutory window
  • The three filings as drafted, with counsel's redline
  • Gaps found in the existing response plan, ranked
  • Attestation of exercise, signed and dated
  • Remediation actions with named owners and dates

Objections

Facilitated, once a year, unscored. This is timed, graded against the rule text, and produces an attestation you can hand an auditor. And you can re-run it next quarter to show improvement.

Pricing

Single drill

₹2,40,000

One session, five seats, full report.

Quarterly programme

₹7,80,000

Four drills a year, escalating scenarios, trend reporting.

Group & multi-entity

On request

Multiple subsidiaries, shared processor estate, one incident.

Full pricing and inclusions

Ninety minutes will tell you more than any gap assessment.

Book a drill

Next available slots: August 2026 · Hyderabad, Mumbai, Bengaluru, or remote.