The Clock Is Ticking: India’s IT Rules 2026 Make Cybersecurity a Boardroom Priority

The Clock Is Ticking: India’s IT Rules 2026 Make Cybersecurity a Boardroom Priority

Ravindra Baviskar, Director – Sales Engineering, India & SAAR, Sophos

A seasoned cybersecurity professional, Ravindra has over 12 years of solid experience in network security and information security under his belt. In his current role as Director – Sales Engineering for India and SAARC at Sophos, he plays a strategic role in driving technical engagement, customer success and channel-led growth across the region.

His responsibilities encompass the entire spectrum of presales and technical advisory functions, including security solution consulting, architecture, design and implementation of information security services. He works closely with enterprise customers and channel partners to understand evolving security requirements and translate them into effective, scalable and business-aligned cybersecurity solutions.

With a combination of deep technical expertise, customer-centric consulting and channel leadership, Baviskar contributes to strengthening cybersecurity adoption and building resilient security ecosystems across India and the SAARC region.

Despite the introduction of one of the most aggressive compliance timelines globally by India’s new IT Amendment Rules 2026, and much noise over legal and regulatory implications, for CIOs and CISOs this remains fundamentally an operational security challenge.

India’s new IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2026 have introduced one of the most aggressive compliance timelines globally: unlawful or harmful content may now need to be acted upon within just three hours. While much of the discussion has focused on legal and regulatory implications, for CIOs and CISOs this is fundamentally an operational security challenge.

The reality is simple: organisations cannot meet a three-hour clock with manual workflows and siloed teams.

Compliance Is No Longer a Legal Function Alone

Traditionally, regulatory obligations followed a familiar path – legal teams interpreted requirements, operations implemented controls, and security supported where needed. That model breaks under a three-hour response expectation.

To comply, organisations need continuous visibility, automated detection, integrated workflows, and response capabilities that are already active before an incident occurs.

As AI-generated and synthetically generated information (SGI) becomes a regulatory focus, content moderation and cybersecurity are beginning to converge. The amended rules introduce obligations around AI content labelling, provenance controls, and faster removal timelines, creating entirely new operational responsibilities for digital platforms. 

AI Content Governance Is Now a Security Issue

Deepfakes and synthetic media are no longer just trust or policy concerns. They are becoming attack vectors.

AI-generated content is increasingly being used to support phishing campaigns, impersonation, fraud, and social engineering. At the same time, the requirement to preserve labels and provenance metadata creates additional infrastructure that organisations must protect.

If adversaries manipulate moderation systems or tamper with provenance mechanisms, the result is not only a security event, it may become a compliance failure.

Identity Security Will Decide Compliance Outcomes

One of the most overlooked risks is identity compromise.

Imagine a moderation account being compromised, alerts suppressed, or queues deliberately overloaded. Harmful content remains online beyond regulatory timelines and suddenly a cybersecurity incident becomes a regulatory breach.

This shift’s identity controls from “good security practice” to business necessity.

Organisations should prioritise:

· Multi-factor authentication for moderation and administrative users

· Continuous monitoring for anomalous access

· Privileged access controls for moderation environments

· Rapid account isolation and recovery procedures

Meeting a three-hour obligation becomes impossible if the systems responsible for action aren’t trusted.

Product-Level, Real-Time Compliance Is the New Operating Model

The most important implication of the IT Rules is that compliance cannot sit outside the product experience.

Detection, escalation, response workflows, and audit trails must become native capabilities.

For security teams, this means expanding SOC visibility beyond infrastructure and endpoints into content operations and trust systems. Content moderation signals should feed SIEM and MDR workflows in the same way intrusion alerts already do.

Automation is no longer optimisation; it becomes the only scalable way to operate.

Security Leaders Need a Unified Response Model

The challenge becomes even more complex when multiple obligations overlap.

A single incident involving harmful content, account compromise, and user data exposure could trigger:

· A three-hour takedown obligation under the IT Rules

· Cyber incident reporting requirements

· Personal data breach notification obligations 

Separate teams and disconnected workflows will not keep pace.

The organisations that adapt fastest will be those that treat compliance and cybersecurity as one operating discipline.

Five Priorities for CIOs and CISOs

1. Integrate content moderation signals into SOC workflows

2. Audit identity controls for moderation and administrative environments

3. Protect AI labelling and provenance infrastructure as critical assets

4. Run incident simulations involving simultaneous security and compliance events

5. Position cybersecurity investment as regulatory readiness at board level 

India’s regulatory environment is moving faster than many enterprise security programs.

The question is no longer whether organisations will face these obligations, it is whether their security architecture is prepared to respond when the clock starts.