HACKED24, Autonomous Enterprise IT

APAC incident reporting runs on local clocks, not group time

Hong Kong, Singapore and India now give APAC subsidiaries their own reporting clocks of 2 to 72 hours. A global incident process must map them or the local entity misses them.

David Lorenz
Oct 8, 20266 min read
A white ceramic hexagonal clock face without hands or numerals, with 4 small brushed aluminium hexagons around it, lit by indigo to cyan accent light on a pale grey background.

Key points

  • Since 1 January 2026, designated critical infrastructure operators in Hong Kong must report serious computer-system incidents within 12 hours of becoming aware of them.
  • Singapore requires owners of critical information infrastructure to report certain incidents within 2 hours, and India's CERT-In expects reports within 6 hours.
  • India's DPDP Rules 2025 add a 72-hour detailed breach report to the Data Protection Board from 13 May 2027, on top of the CERT-In clock.
  • A global incident process that waits for headquarters to finish its assessment will miss these local deadlines by design.

On 1 January 2026, Hong Kong's Protection of Critical Infrastructures (Computer Systems) Ordinance took effect. A designated operator now has 12 hours to notify the regulator of a serious incident. Many groups headquartered in the US or Europe still run APAC incident reporting through a central process that was built around 72 hours, a GDPR habit.

That gap matters. In Hong Kong, Singapore and India, the clock starts when the local entity becomes aware of the incident, and in several cases a named person on the ground is the regulator's contact. The obligation sits with the subsidiary, so the subsidiary carries the risk if headquarters is still in its first bridge call.

Hong Kong now gives critical operators 12 hours

Cap. 653 was passed by the Legislative Council in March 2025 and the Security Bureau set the commencement date to 1 January 2026. The Commissioner of Critical Infrastructure (Computer-system Security) designates operators in sectors such as energy, banking and financial services, transport, healthcare and telecommunications, together with the computer systems that count as critical.

The reporting windows are tight. A serious incident, meaning one that has disrupted, is disrupting or is likely to disrupt the core function of the infrastructure, must be notified within 12 hours of becoming aware. Other incidents go in within 48 hours, followed by a written report within 14 days. The Code of Practice issued on 1 January 2026 says the clock starts once there is a reasonable degree of certainty that an incident happened.

Designated operators must also keep an office in Hong Kong and maintain a computer-system security management unit with a supervising employee. That unit does not have to sit in Hong Kong, which is helpful for a group SOC. Failure to meet statutory obligations is an offence, with fines of up to HK$5 million according to law firm summaries of the Ordinance.

Singapore and India already run on hours

Singapore moved first. The Cybersecurity (Amendment) Act 2024 provisions that came into force on 31 October 2025 widen the incidents that owners of critical information infrastructure (CII) must report, including incidents suspected to be caused by advanced persistent threats. The window, per the Cyber Security Agency of Singapore, is 2 hours from becoming aware.

India has had a hard clock since 2022. The CERT-In Directions of 28 April 2022 apply to service providers, intermediaries, data centres, body corporates and government bodies. Listed incident types must be reported to CERT-In within 6 hours of noticing them, and every covered entity must register a named point of contact. ICT logs must be kept for a rolling 180 days within Indian jurisdiction.

India's DPDP Rules add a second clock for personal data

The Digital Personal Data Protection Act 2023 became operational with the DPDP Rules 2025, which the Ministry of Electronics and Information Technology (MeitY) notified in November 2025. The Rules phase in over 18 months. The Data Protection Board provisions apply immediately, consent manager registration from 13 November 2026, and the core obligations, including breach intimation, from 13 May 2027.

Under Rule 7, a data fiduciary must inform the Board without delay and submit a detailed report within 72 hours of becoming aware of a breach. Affected individuals must also be told without delay, in plain language. The penalty schedule of the Act allows up to INR 250 crore for failing to maintain reasonable security safeguards and up to INR 200 crore for failing to notify the Board or affected individuals.

This is where groups underestimate the work. A ransomware case in an Indian subsidiary can trigger CERT-In at 6 hours and the Board at 72 hours, with different recipients, different content and different people signing. A significant data fiduciary must in addition appoint a Data Protection Officer based in India.

APAC incident reporting windows at a glance

Jurisdiction and regime Who is covered Window Clock starts
Hong Kong, Cap. 653 Designated critical infrastructure operators Serious incident: 12 hours. Other incident: 48 hours. Written report: 14 days Becoming aware
Singapore, Cybersecurity Act as amended CII owners 2 hours Becoming aware
India, CERT-In Directions 2022 Service providers, intermediaries, data centres, body corporates 6 hours Noticing the incident
India, DPDP Rules 2025, Rule 7 (from 13 May 2027) Data fiduciaries Board: without delay, detailed report within 72 hours. Individuals: without delay Becoming aware of the breach

The table shows the core problem. The shortest APAC clocks expire before a typical headquarters process has decided whether an event is an incident at all. If the local entity needs approval from a regional or global legal team before it may notify, the deadline is gone. We described the board side of the first 24 hours in incident response for boards. The APAC regimes move parts of that timeline into the first 2 to 12 hours, and into the subsidiary.

What to do now

  1. CIO: Build a register of every APAC entity with its regulator, window, trigger wording and named local contact. Check with local counsel whether each entity is designated or in scope. Do it once and review it every quarter.
  2. CISO: Change the incident runbook so that the clock for each jurisdiction starts at local awareness. The global SOC records the time of awareness per entity, and the first regulatory triage happens within 1 hour.
  3. Board: Delegate the authority to file an initial notification to the accountable local officer in advance. Headquarters may refine the follow-up report, but it should not hold the first notice.
  4. IT Operations: Confirm that logging in India covers the 180 days CERT-In requires and that evidence for Hong Kong and India can be produced locally without waiting for a central export.
  5. CFO: Check that cyber insurance notification terms do not conflict with these windows. Our note on cyber insurance requirements covers what insurers now ask for.

Note

As of October 8, 2026. Designation status, thresholds and forms change, and the DPDP breach rules apply from 13 May 2027. This is not legal advice. Check the primary sources and local counsel for each entity.

At HACKED24 we approach this as an operations question first. We set up monitoring to record awareness time per legal entity, and a senior partner owns the mapping between global severity and local obligation, so the clock in Kowloon or Bengaluru is visible from the first alert. If you want a review of your current incident process against these windows, our Executive IT & AI Review is the starting point.

David Lorenz

Founder and Managing Partner of HACKED24. More than 20 years in enterprise IT architecture, security and operations.

Want to see what this means for your IT?

Every enquiry is answered personally, usually on the same business day.