Adaptive Logo
Product
View Product
Use Cases
View Product
Resources
View Product
Pricing
Partners
Careers
General 15 min read

Cybersecurity Process Checklist for Companies Preparing for an IPO in India

Debarshi BasakAug 5, 2026
Cybersecurity Process Checklist for Companies Preparing for an IPO in India
Assets

This checklist is designed for an operating company preparing for a Main Board or SME IPO. It does not replace additional requirements applicable to banks, NBFCs, insurers, payment companies, telecom operators, health companies, critical infrastructure operators or entities that are themselves SEBI-registered intermediaries.

As of August 2026, the main regulatory anchors are the SEBI ICDR Regulations, last amended March 21, 2026; the SEBI LODR Regulations, last amended July 14, 2026; CERT-In directions; the Companies Act; and India's evolving data-protection framework. (Securities and Exchange Board of India)


1. Cybersecurity governance

  • Appoint a named CISO or senior information-security owner with sufficient independence, budget and access to senior management.
  • Establish an IPO cybersecurity steering group comprising the CISO, CIO/CTO, CFO, company secretary, legal counsel, internal audit, risk, privacy and business owners.
  • Obtain board approval for:
    • Cybersecurity policy
    • Cyber-risk appetite
    • Incident-response policy
    • Data-protection policy
    • Business-continuity and disaster-recovery policy
    • Third-party security policy
  • Provide the board or relevant committee with quarterly cyber-risk reporting.
  • Define measurable risk indicators, including critical vulnerabilities, phishing rates, privileged accounts, vendor risks, recovery-test results and security incidents.
  • Document which committee oversees cybersecurity: board, audit committee or risk-management committee.
  • Record board decisions, risk acceptances, remediation commitments and funding approvals.

For listed entities to which the SEBI Risk Management Committee provisions apply—currently the top 1,000 listed entities and high-value debt listed entities—the committee's functions must specifically cover cybersecurity. Its risk framework is expected to address information and cyber risks, mitigation controls and business continuity. (Securities and Exchange Board of India)

Evidence: board minutes, committee charter, CISO appointment letter, approved policies, cyber budget, quarterly dashboards.


2. Regulatory applicability assessment

  • Prepare a cybersecurity legal and regulatory obligations register.
  • Map requirements under:
    • Information Technology Act, 2000
    • CERT-In directions
    • IT SPDI Rules, where applicable
    • Digital Personal Data Protection Act and Rules
    • Companies Act, 2013
    • SEBI ICDR and LODR Regulations
    • Sector-specific regulations
    • Contractual and overseas privacy requirements
  • Identify all legal entities, subsidiaries, branches and overseas operations covered.
  • Assign an accountable owner and evidence location for every obligation.
  • Review compliance status at least quarterly during the IPO process.
  • Maintain a regulatory-change monitoring process.

The Companies Act requires the audit committee to evaluate internal financial controls and risk-management systems. The board-report framework also covers internal financial controls, making technology controls relevant where systems support financial reporting. (India Code)

DPDP transition planning

  • Build a DPDP implementation plan now rather than waiting for full commencement.
  • Complete data mapping, notice, consent, security, retention, deletion, grievance and breach-response processes.
  • Identify whether the company could be designated a Significant Data Fiduciary.
  • Ensure contracts allow processors to support breach notification and data-principal requests.

The DPDP Act and Rules have staggered commencement. Most substantive processing, security and breach-related provisions are scheduled to take effect 18 months after the November 13, 2025 Gazette publication—May 13, 2027—while certain provisions commence earlier.


3. Asset, system and data inventory

  • Maintain a centralized inventory of:
    • Servers and endpoints
    • Network and security devices
    • Cloud accounts and workloads
    • SaaS applications
    • Databases
    • APIs
    • Web and mobile applications
    • Source-code repositories
    • OT/ICS systems
    • Artificial-intelligence systems
    • Third-party hosted systems
  • Record asset owner, location, environment, business service, data classification, vendor and end-of-life date.
  • Identify "crown-jewel" applications and databases.
  • Map each critical asset to its business process, revenue dependency and financial-reporting impact.
  • Identify unsupported software and hardware and approve replacement plans.
  • Reconcile the asset inventory against network, cloud, endpoint and finance/procurement records.
  • Maintain a data inventory showing:
    • Personal and sensitive information
    • Employees, customers and vendors affected
    • Collection purpose
    • Storage location
    • Access rights
    • Data transfers
    • Retention period
    • Deletion method

CERT-In's audit guidance expects audit scope to be derived from an updated asset inventory and to cover infrastructure, applications, APIs, cloud, databases, OT, data security and incident-response capability.


4. Identity and access management

  • Implement multi-factor authentication for:
    • Privileged accounts
    • Remote access
    • Cloud administration
    • Email
    • Source-code systems
    • Finance and ERP systems
  • Maintain a formal joiner-mover-leaver process.
  • Disable departed-user accounts promptly.
  • Review all user access at least quarterly for critical systems.
  • Implement privileged-access management or equivalent controls.
  • Eliminate shared administrator accounts wherever technically possible.
  • Maintain emergency or break-glass access procedures.
  • Rotate service-account credentials and remove embedded passwords.
  • Restrict developers' access to production.
  • Review dormant, generic and excessive-access accounts.
  • Apply least privilege to users, systems, applications and automated processes.

CERT-In's guidance specifically recommends least-privilege controls and secure management of authorized assets.

Evidence: access matrices, quarterly review sign-offs, termination samples, privileged-account inventory, MFA reports.


5. Security operations and technical controls

  • Establish secure configuration standards for endpoints, servers, network devices, databases and cloud services.
  • Implement endpoint detection and response and anti-malware coverage.
  • Deploy email security, phishing protection and domain-protection controls.
  • Segment production, development, corporate, guest and OT networks.
  • Encrypt sensitive data in transit and at rest.
  • Maintain key-management and certificate-management processes.
  • Operate a documented patch-management process with severity-based timelines.
  • Monitor internet-facing assets and attack-surface changes.
  • Remove unused ports, default credentials and unnecessary services.
  • Implement data-loss prevention based on actual data risks.
  • Monitor cloud-security posture and privileged cloud activity.
  • Maintain secure configuration and hardening evidence.
  • Establish a security-operations capability, internally or through a managed provider.
  • Tune security alerts and document alert investigation and closure.

CERT-In recommends an authorized hardware and software inventory, patch management, secure configurations, removal of default settings and least-privilege access.


6. CERT-In compliance

  • Designate and register a point of contact for CERT-In.
  • Maintain a 24×7 escalation mechanism capable of meeting the six-hour reporting deadline.
  • Create a CERT-In incident-classification matrix.
  • Pre-prepare incident-reporting templates.
  • Ensure the response team can submit an initial report even where complete information is unavailable.
  • Synchronize ICT system clocks with NIC/NPL-traceable time sources.
  • Enable logging across all relevant ICT systems.
  • Retain logs securely for a rolling period of at least 180 days.
  • Ensure required logs are maintained within Indian jurisdiction.
  • Make logs readily retrievable for an incident investigation.
  • Test CERT-In reporting through a tabletop exercise.
  • Ensure vendors notify the company quickly enough for the company to meet its six-hour deadline.

CERT-In requires body corporates to report specified incidents within six hours of noticing them, designate a point of contact, synchronize system clocks and retain ICT logs for 180 days within India. Reportable categories include unauthorized access, ransomware, phishing, data breaches, data leaks, cloud attacks, digital-payment incidents and attacks on AI systems.


7. Incident response and crisis management

  • Maintain an incident-response plan covering cyber, privacy, fraud, ransomware, insider threats and third-party incidents.
  • Define severity levels and objective escalation criteria.
  • Include the following teams in the escalation matrix:
    • Security and IT
    • CEO and CFO
    • Company secretary
    • Legal and privacy
    • Communications and investor relations
    • Internal audit
    • HR
    • Business owners
    • Insurer and forensic advisers
  • Establish processes for containment, eradication, recovery and evidence preservation.
  • Maintain legal privilege and chain-of-custody procedures where appropriate.
  • Define decision-making authority for shutting systems down or activating disaster recovery.
  • Prepare communications for customers, employees, exchanges, regulators, lenders and media.
  • Conduct ransomware and data-breach tabletop exercises.
  • Track corrective actions from each incident.
  • Maintain an incident register covering at least the period used for IPO due diligence.
  • Document regulatory reports, notifications, losses, downtime and affected records.

8. SEBI materiality and disclosure process

  • Integrate cyber incidents into the company's Regulation 30 materiality policy.
  • Define when an incident must be escalated to the company secretary and authorized disclosure committee.
  • Assess:
    • Financial loss
    • Revenue or operational disruption
    • Customer and employee impact
    • Data loss
    • Regulatory action
    • Litigation
    • Reputational effect
    • Likely market-price impact
  • Establish a process to disclose material incidents to stock exchanges within the applicable timeline.
  • Prepare initial, interim and closure disclosure templates.
  • Ensure stock-exchange disclosure occurs before broader public communication where required.
  • Maintain evidence supporting every materiality decision.
  • Include cyber incidents, breaches and loss of data/documents in the quarterly corporate-governance reporting process after listing.
  • Reconcile quarterly disclosures against the security incident register.

Under Regulation 30, material events emanating from within the listed entity generally have a 12-hour disclosure timeline; externally emanating events generally have a 24-hour timeline. Listed entities must also disclose details of cyber incidents, breaches or loss of data/documents through the prescribed corporate-governance report. A material cyber incident should therefore be assessed under both the immediate material-event process and the periodic cyber-disclosure requirement.


9. Application and product security

  • Adopt a secure software-development lifecycle.
  • Include security requirements at design stage.
  • Conduct threat modelling for critical applications.
  • Perform peer review and secure code review.
  • Implement SAST, DAST and software-composition analysis.
  • Test APIs, mobile applications and authentication flows.
  • Protect CI/CD pipelines and source-code repositories.
  • Scan secrets and credentials in code.
  • Maintain a software bill of materials for critical software.
  • Establish vulnerability-disclosure and responsible-disclosure procedures.
  • Require security testing before major releases and infrastructure changes.
  • Segregate development, testing and production.
  • Require formal approval for emergency changes.
  • Retest vulnerabilities after remediation.

CERT-In's audit guidance identifies web, mobile, API, code, cloud and supply-chain testing as relevant scope areas and recommends audits after major technology or infrastructure changes.


10. Third-party, cloud and supply-chain security

  • Maintain an inventory of all technology and data-processing vendors.
  • Classify vendors by data access, connectivity, criticality and substitutability.
  • Conduct security due diligence before onboarding critical vendors.
  • Include in contracts:
    • Security standards
    • Confidentiality
    • Data-use limitations
    • Data-location requirements
    • Subcontractor restrictions
    • Encryption requirements
    • Access controls
    • Audit rights
    • Vulnerability remediation
    • Business-continuity obligations
    • Data return and deletion
    • Rapid incident notification
    • Cooperation with regulators and forensic investigations
  • Ensure vendor notification periods support CERT-In's six-hour reporting requirement.
  • Conduct periodic assessments of critical vendors.
  • Obtain and review independent audit reports rather than merely collecting certificates.
  • Identify concentration risk involving major cloud or SaaS providers.
  • Maintain cloud exit, portability and data-recovery plans.
  • Include third-party assets in penetration tests and incident exercises where contractually possible.

CERT-In's audit guidelines call for vendor and supply-chain risk assessment to form part of audit scope, including hosted and third-party infrastructure.


11. Business continuity, disaster recovery and ransomware resilience

  • Complete a business-impact analysis.
  • Define approved recovery-time and recovery-point objectives.
  • Map critical business services to applications, infrastructure, people and vendors.
  • Maintain offline or immutable backups.
  • Segregate backup administration from production administration.
  • Test restoration of critical systems and data.
  • Perform disaster-recovery failover exercises.
  • Test recovery from ransomware and cloud-account compromise.
  • Address dependency on identity, DNS, email, telecom and cloud services.
  • Record actual recovery times and gaps.
  • Obtain management approval for unresolved recovery risks.
  • Include cyber scenarios in enterprise crisis-management exercises.

SEBI's prescribed Risk Management Committee role expressly includes mitigation processes and a business-continuity plan.


12. Independent audit and vulnerability management

  • Commission an independent cyber-risk assessment early in the IPO programme.
  • Use a CERT-In-empanelled auditor where required or appropriate.
  • Ensure audit scope includes:
    • Governance and process controls
    • External and internal infrastructure
    • Cloud and SaaS
    • Web, mobile and APIs
    • Source code
    • Databases
    • Active Directory and identity
    • ERP and financial-reporting systems
    • OT/ICS
    • Third-party risks
    • Incident-response capability
    • Backup and recovery
  • Agree written rules of engagement for penetration testing.
  • Track findings using severity, owner, target date and evidence.
  • Revalidate closed findings.
  • Escalate overdue high and critical findings to senior management.
  • Formally approve risk acceptance and compensating controls.
  • Do not rely on a "clean certificate" without retaining the detailed findings and closure evidence.
  • Schedule at least annual audits and additional assessments after major changes.
  • Maintain audit-report confidentiality and controlled access.

CERT-In's 2025 audit guidelines recommend at least annual cyber audits, broader audits after major changes, complete infrastructure coverage, independent evidence-based assessments and management oversight of remediation. They also state that responsibility for the organization's security remains with management, not the auditor.


13. IPO due-diligence and disclosure pack

Prepare a central data room containing:

  • Cybersecurity policies and standards.
  • Board and committee minutes covering cybersecurity.
  • Organization chart and CISO reporting line.
  • Asset, application and vendor inventories.
  • Data-flow and privacy maps.
  • Cyber-risk register.
  • Incident register and root-cause reports.
  • Copies of CERT-In and other regulatory notifications.
  • Cyber insurance policies and claims.
  • Independent audit, VAPT and remediation reports.
  • Business-continuity and disaster-recovery test results.
  • Security awareness and phishing-test results.
  • Material vendor contracts and security clauses.
  • Pending cyber complaints, litigation and investigations.
  • Cybersecurity budgets and planned investments.
  • Management representations concerning undisclosed incidents.
  • A cross-reference showing where each DRHP cybersecurity statement is evidenced.

DRHP review points

  • Include company-specific cybersecurity risks rather than generic boilerplate.
  • Disclose past incidents that are material in context.
  • Describe dependence on technology, cloud providers, digital platforms and critical vendors.
  • Address operational disruption, privacy, ransomware, intellectual-property theft and fraud risks.
  • Avoid absolute statements such as "our systems are fully secure."
  • Ensure the DRHP is consistent with board records, customer communications, regulatory reports and audit findings.
  • Update material developments between the DRHP, RHP and Prospectus.
  • Review all disclosures jointly with legal counsel, BRLMs, the company secretary and CISO.

Recent Indian IPO filings commonly include tailored risk factors concerning cyberattacks, breaches, data loss and technology dependence, reflecting the need to consider these risks in the offer-document materiality exercise. (Securities and Exchange Board of India)


14. Post-listing operating calendar

  • Monthly security operations and vulnerability review.
  • Quarterly board or risk-committee cyber update.
  • Quarterly reconciliation of the incident register with LODR reporting.
  • Quarterly access review for critical systems.
  • Periodic materiality assessment training for security and compliance teams.
  • Annual independent cyber audit.
  • Annual incident-response tabletop.
  • Annual disaster-recovery and restoration testing.
  • Annual review of policies, risk appetite and materiality thresholds.
  • Periodic review of critical vendors.
  • Continuous regulatory-change monitoring.
  • Update prospectus or exchange disclosures when material developments occur.

How Adaptive Can Help

Adaptive is a Just-in-Time infrastructure access platform that closes the checklist items IPO-bound companies most often fail — the ones that demand system-enforced behavior rather than documentation:

Checklist areaWhat diligence teams and auditors ask forHow Adaptive helps
Identity & access management (Section 4)MFA on privileged, remote, and database access; least privilege; no shared credentialsSSO and MFA in front of every resource — including databases and legacy systems with no native SAML/OIDC support; users receive ephemeral credentials, so shared admin passwords disappear
Access reviews and joiner-mover-leaverQuarterly reviews of critical systems; prompt deprovisioningJust-in-Time access with approvals: privileges are granted per-request, scoped to the resource, and expire automatically — departed users hold nothing, and reviews shrink to exceptions
Audit & accountability (Section 6, CERT-In)Logs retained 180 days within India; every action attributable to an individualSession Recording and Activity Monitoring capture every query and command, attributed to the SSO identity and stored centrally — evidence that is ready for the six-hour reporting drill, auditors, and the IPO data room
Developer access to production (Sections 4 and 9)Segregation of duties; controlled emergency accessScoped, time-boxed grants with approval workflows and full recording — production access without standing privileges, including break-glass paths that leave an audit trail
Data protection (DPDP readiness, Section 2)Limiting exposure of personal and sensitive dataData Masking keeps sensitive fields hidden from users and tools that don't need them

Because Adaptive deploys as an agentless, container-based gateway inside your own network, it strengthens the evidence trail without expanding the assessment boundary — and it typically stands up in days, comfortably inside an IPO preparation timeline.


Minimum "go/no-go" conditions before filing the DRHP

The company should ordinarily avoid entering the filing stage with:

  • Unidentified internet-facing or critical assets.
  • Unsupported critical systems without an approved mitigation plan.
  • Unresolved critical vulnerabilities on public-facing systems.
  • No tested six-hour CERT-In reporting procedure.
  • No reliable 180-day logging capability.
  • Material incidents absent from the incident register.
  • Contradictions between audit findings and draft disclosures.
  • Untested backups or disaster recovery.
  • Critical vendors without incident-notification obligations.
  • Undocumented management acceptance of major cyber risks.
  • Material cyber litigation, regulatory action or losses not assessed for disclosure.

Applicability caution: SEBI's CSCRF is framed for SEBI Regulated Entities. An ordinary operating company does not become subject to the entire CSCRF merely because it undertakes an IPO; it may apply where the issuer is itself a SEBI-regulated intermediary or other covered entity. (Securities and Exchange Board of India)

This should be validated by Indian securities counsel and sector-specific regulatory advisers before implementation.

References
  1. SEBI | Securities and Exchange Board of India (Issue of Capital and Disclosure Requirements) Regulations, 2018 [Last amended on March 21, 2026]https://www.sebi.gov.in/legal/regulations/mar-2026/securities-and-exchange-board-of-india-issue-of-capital-and-disclosure-requirements-regulations-2018-last-amended-on-march-21-2026-_100581.html
  2. SEBI (LODR) Regulations, 2015https://www.sebi.gov.in/sebi_data/attachdocs/jun-2026/1780915347745.pdf
  3. Companies Act, 2013 — Section 177https://www.indiacode.nic.in/show-data?actid=AC_CEN_22_29_00008_201318_1517807327856&orderno=181
  4. Rentomojo Limited - Draft Abridged Prospectushttps://www.sebi.gov.in/sebi_data/commondocs/apr-2026/Rentomojo%20Limited-Draft%20Abridged%20Prospectus_p.pdf
  5. Frequently Asked Questions (FAQs) on Cybersecurity and Cyber Resilience Framework (CSCRF)https://www.sebi.gov.in/sebi_data/faqfiles/jun-2025/1749647139924.pdf
  6. Adaptivehttps://adaptive.live
Agents are the new perimeter. Contain the chaos.
No Network Changes Required
Cloud or On-Premises Deployment
Enterprise-Grade Security