My business's systems were hit by ransomware, what are my legal obligations and options?

Our company's servers were encrypted by ransomware and attackers are demanding payment in crypto. I have been reading conflicting things online and I would like to understand what Indian law actually says about this, which Act and Section applies, what the realistic timelines and costs are, and what I should be doing right now to protect my position. If the matter can be resolved without litigation I would prefer that route, but I want to know what my rights are before I agree to anything or sign any document.

My business's systems were hit by ransomware, what are my legal obligations and options? is governed in India primarily by Information Technology Act, 2000 – Section 66, Information Technology Act, 2000 – Section 43, Digital Personal Data Protection Act, 2023 – Section 8(6) and CERT-In Directions, 2022. The short answer is set out below, followed by the practical steps most people in this situation need to take. Read it alongside the specific provisions named, because the exact relief available to you turns on the facts you can prove on paper.

Under the CERT-In Directions of April 2022, ransomware attacks must be reported to CERT-In within 6 hours of noticing the incident, regardless of severity — this is mandatory, not optional, for all body corporates.

Section 66 of the IT Act covers the attacker's conduct (unauthorised access, data destruction/encryption) with imprisonment up to 3 years or fine up to Rs 5 lakh, and Section 43 provides for civil compensation for the damage caused.

If personal data of customers/employees was compromised, Section 8(6) of the DPDP Act, 2023 requires you to notify the Data Protection Board and the affected individuals of the breach without undue delay.

Paying the ransom is not illegal per se but is strongly discouraged by CERT-In and law enforcement since it funds further crime and does not guarantee decryption; document any payment for insurance/investigation purposes if made under advice.

Maintain logs and a forensic image of affected systems before remediation, as this evidence is essential both for the CERT-In report and for any cyber-insurance claim.

What to do next: 1) Isolate affected systems immediately to stop the spread; 2) Report to CERT-In within 6 hours as mandated; 3) File a police complaint at the cyber cell and cybercrime.gov.in; 4) Notify affected data subjects and the Data Protection Board if personal data is involved.

If the other side has already issued a notice, filed a case or set a deadline, treat the matter as time-sensitive — most remedies under Information Technology Act, 2000 – Section 66 carry limitation periods, and a delay you cannot explain weakens an otherwise strong case. You can post the details on the MyVakeel forum for a practising advocate to review, or book a paid consultation with a Bar Council verified lawyer in this practice area.

Disclaimer: This information is for general awareness and does not constitute legal advice. Statutes and their interpretation change, and outcomes depend on the facts of your case. Please consult a qualified advocate before acting on it.