- Udyam registration
- The government portal that classifies a business as micro, small or medium under the MSME Act.
- CERT-In
- The Indian Computer Emergency Response Team — the national agency for cyber incidents, under the Ministry of Electronics and IT.
- Elemental Cyber Defense Controls
- CERT-In’s September 2025 baseline for MSMEs: 15 controls and 45 recommendations. Recommended, not mandatory.
- CERT-In-empanelled auditor
- A firm CERT-In has approved to carry out security audits. Required only where a regulator, government buyer or contract says so.
- The six-hour rule
- The duty under the April 2022 CERT-In Directions to report listed incidents within six hours of noticing them.
- Business email compromise (BEC)
- Fraud that uses a hijacked or lookalike email address to redirect a legitimate payment.
- SPF, DKIM and DMARC
- Email records that tell receiving servers which mail genuinely comes from your domain. DMARC is the one that lets you refuse the rest.
- QR swap
- Replacing or editing a merchant’s UPI QR code so that payments reach a fraudster’s account.
- 1930 and NCRP
- The national cyber-fraud helpline, and the National Cyber Crime Reporting Portal at cybercrime.gov.in.
- Cyber Swachhta Kendra
- CERT-In’s botnet cleaning and malware analysis centre, which issues free alerts and tools.
- Data Fiduciary
- Under the DPDP Act, whoever decides why and how personal data is processed — including a clinic, a CA firm or a trader.
- Multi-factor login
- Signing in with something you know plus something you have, such as an OTP or an app prompt, so a stolen password alone is not enough.