+91 98726 60544 hello@mitstech.co Mon–Sat · 09:00–18:30 IST

Telecom cyber security rules: who they catch

Security By Mits Engineering Team 2 min read
Telecom cyber security rules: who they catch

The Telecommunications (Telecom Cyber Security) Rules, 2024 were notified on 21 November 2024 and apply to telecommunication entities broadly — service providers, network operators, equipment manufacturers and importers. For a software firm the relevance is indirect but real: if your client is any of those, these rules shape what they can accept from a supplier and what they will require of you.

The reporting regime is two-stage and tight. A security incident must be notified to the government within six hours of being identified. Within twenty-four hours a detailed report follows, covering the users affected, the geographical scope, the duration of the incident and the mitigation steps taken. Six hours mirrors the CERT-In obligation, and the twenty-four hour detail requirement is the part that catches organisations out, because assembling an accurate account of affected users and scope inside a day requires instrumentation that already exists rather than an investigation started on the day.

For a supplier, that translates into a specific product requirement. Your system needs to be able to answer, quickly, which users were affected by a given failure, over what period, and in what locations. If those questions can only be answered by an engineer writing ad hoc queries against production, your client cannot meet a twenty-four hour deadline using your software. Building that reporting capability deliberately is a competitive advantage in this sector rather than an overhead.

The rules also mandate a Chief Telecommunication Security Officer who must be an Indian citizen and resident, responsible for implementing the cyber security framework and coordinating with government. That is a named accountable individual, which changes how decisions get made: security-relevant changes to a system your client operates will pass through that person, and their appetite for risk becomes a constraint on your delivery timeline.

Identifier obligations run alongside and matter for anyone in the device or IoT space. Equipment manufacturers must register identifiers before sale and importers must register them before importing into India. Tampering with, altering or fraudulently using identifiers is prohibited, and devices with tampered identifiers may be blocked from networks. If you build software that provisions, activates or manages connected devices, identifier registration is a step in your onboarding flow rather than a paperwork exercise somebody handles separately.

The rules do not impose direct obligations on ordinary non-telecom businesses, and it is worth being clear about that rather than assuming the widest reading. The government may collect telecom traffic data from designated points for security analysis, with confidentiality safeguards. Where these rules affect a general software company is through the customer relationship — a telecom client's obligations become contract terms in your agreement, and reading those terms against what your product can actually evidence is the practical exercise.

Need help with this? Explore our Cybersecurity & Compliance services. Learn more Back to all news

Keep reading

More on Security