AI-FIRST CYBERSECURITY · Always Wise. Always Ahead. +91-95851-60363 info@semperwise.com DOVER, DE, USA

Telecom cybersecurity · India

Six hours to report. And the rules now reach beyond telecom.

Since November 2024, a security incident on an Indian telecom network must be reported to the Department of Telecommunications within six hours, with the details in twenty-four. Since October 2025, the same rules reach the banks, fintechs and apps that treat a phone number as proof of identity. This page covers the clock, the five ways telecom networks and identities have actually failed, and what can be tested without touching a live core.

Reviewed 24 September 2026 · 16 sources cited

The short answer

Under the Telecommunications (Telecom Cyber Security) Rules, 2024, a telecom entity must report a security incident to the Central Government within six hours of becoming aware of it and supply the details — users affected, duration, area, impact and remedy — within 24 hours. It must also keep a security policy, run periodic security audits and have security-operations facilities. CERT-In’s six-hour report applies separately. Since October 2025 the rules also reach businesses that use mobile numbers to identify customers.

Why telecom

The network is the identity layer for everyone else.

Most sectors protect their own data. A telecom operator also protects everybody else’s: the one-time password a bank sends, the number a payments app treats as an account, the SIM that proves who someone is. When a SIM is swapped or an SMS is intercepted, the loss lands at a bank. That is why India’s telecom security rules have grown from a licence condition into a system of their own — and why, since October 2025, they reach businesses that are not telecom companies at all.

The Telecommunications (Telecom Cyber Security) Rules, 2024, in force since 21 November 2024 under the Telecommunications Act, 2023, require every telecom entity to adopt a telecom cyber security policy, identify and reduce the risk of security incidents, run periodic security audits, set up facilities such as a security operations centre, and report incidents to the Central Government within six hours. The Critical Telecommunication Infrastructure Rules, notified the next day, add stricter duties for networks the government designates as critical: two years of logs and architecture records, supply-chain records, vetted personnel, and remote maintenance from outside India only from pre-approved locations.

Then, on 22 October 2025, an amendment created the telecommunication identifier user entity — any business, other than a telecom licensee, that uses phone numbers to identify its customers or deliver its services. Such a business can validate numbers against operators’ records through a new mobile number validation platform, for a fee, and can be directed to; in an emergency, the government can order it to temporarily stop using a particular number. A bank, a lending app or a marketplace is now inside the telecom rulebook.

The threats are not theoretical. In 2025 South Korea’s regulator fined SK Telecom 134.8 billion won after the USIM data of more than 23 million users was taken, and found that its USIM authentication keys were not encrypted. In 2026 it fined KT after a rogue small cell, built with a certificate lifted from a lost femtocell, sat on its network for about eleven months. In India, CERT-In reported a possible intrusion at BSNL in May 2024, traced to a file-transfer server. The sections below take the clock first, then the failures.

Hour by hour

The first 72 hours of a telecom security incident

Two six-hour clocks run in parallel from the moment someone notices. This is the sequence worth rehearsing with the security team, the network operations centre and whoever reports on the DoT portal. The DPDP duties apply from about 13 May 2027; the rest apply now.

  1. 00:00

    Someone notices

    A monitoring alert, an outbound transfer nobody expected, a customer complaint about a SIM that stopped working. The clock starts when the entity becomes aware — not when the investigation confirms what happened.

    Telecom Cyber Security Rules and CERT-In Directions: both 6-hour windows open

  2. T+1h

    Contain, and keep the evidence

    Isolate what is affected without wiping it; the logs are the only record of how the attacker got in. For critical infrastructure, the rules already require architecture and supply-chain records to be kept.

    CERT-In: logs kept 180 days, in India · CTI Rules: logs and architecture records for at least 2 years

  3. T+6h

    Two reports filed

    The incident goes to the Central Government through the DoT portal and, separately, to CERT-In. Both go in with what is known so far. Neither waits for a root cause.

    Telecom Cyber Security Rules: report within 6 hours · CERT-In Directions: 6 hours

  4. T+12h

    Customers and the Data Protection Board

    Where subscribers’ personal data was affected, the DPDP Rules require notice to the Board and to each affected person without delay, in plain language. Banks and payment firms relying on the affected numbers will want to know too.

    DPDP Rules, 2025, Rule 7: without delay (from May 2027)

  5. T+24h

    The details DoT asks for

    Number of users affected, how long it lasted, the geographical area, how far the network or service was affected, and the remedial measures taken or planned. Numbers that are estimates should say so.

    Telecom Cyber Security Rules: details within 24 hours of becoming aware

  6. T+72h

    The detailed breach report

    The Board receives the full account: facts, likely cause, mitigation and what has been done for the people affected.

    DPDP Rule 7: detailed report within 72 hours (from May 2027)

  7. Weeks

    The follow-up

    The government can ask for further information, including the telecom cyber security policy, and can have a security audit carried out. The report, the evidence and the fixes need to agree with each other.

    Telecom Cyber Security Rules: information and security audit on request

Summarised from the instruments listed in the sources. Where a licence condition, a direction or a contract sets a shorter period, the shorter one applies. General information, not legal advice.

Evidence

What the numbers say about telecom

Indian figures from the Department of Telecommunications; incident figures from the Korean regulator’s decisions. Each is linked in the sources.

39.43 lakh Mobile connections disconnected after citizens’ fraud reports on Chakshu, as of February 2026 [7]
1.31 lakh SMS templates blacklisted through the same reports, alongside 2.27 lakh handsets [7]
₹5,043 cr Suspected fraud losses prevented by banks and payment platforms using DoT’s Fraud Risk Indicator, by August 2026 [8]
23M+ SK Telecom users whose numbers, IMSIs and other USIM data were compromised in 2025 [12]
11 months How long a rogue femtocell stayed connected to KT’s network before it was found [13]
2 years Minimum retention for logs and architecture records of critical telecom infrastructure [3]

The Fraud Risk Indicator figure is DoT’s own estimate of suspected losses prevented, based on declined transactions and alerts reported by the institutions using it.

Real patterns

Five ways telecom networks and identities have failed

Each from a reported case. The first starts outside the network entirely; the last two happened deep inside it.

01

The eSIM nobody asked for

  1. Way inA caller posing as customer care talks the subscriber into a step that converts the physical SIM to an eSIM the fraudster controls.
  2. ThenThe subscriber’s phone loses signal; calls, SMS and bank one-time passwords now arrive on the fraudster’s device.
  3. CostAccounts emptied and loans taken in the victim’s name — the pattern the Indian Cybercrime Coordination Centre warned about.

What we test: The SIM and eSIM change journeys in your apps, portals and retailer tools: who can start one, what is verified, what is rate-limited, and who is told.

02

The subscriber keys left readable

  1. Way inAn intruder inside the operator’s network, where access controls were neglected and access rights poorly managed.
  2. ThenA large volume of data sent out of the network — phone numbers, IMSIs and other USIM data; the USIM authentication keys had not been encrypted.
  3. CostMore than 23 million users affected, late notice to them, and a 134.8-billion-won fine for SK Telecom.

What we test: Architecture and privileged-access review of the systems holding subscriber keys, reviewed passively on a live core.

03

The lost femtocell

  1. Way inA certificate extracted from a lost small cell, installed on a home-built device that the network accepted as its own.
  2. ThenNearby phones connected to it; the attackers captured their traffic and used it to make fraudulent mobile payments.
  3. Cost16,647 subscribers’ data exposed, at least 368 defrauded, about eleven months undetected — and a fine for KT.

What we test: How small cells and customer equipment are provisioned: certificate lifetimes, source restrictions, and every route around the management server.

04

The forgotten file server

  1. Way inA file-transfer server holding data that matched the sample CERT-In had found.
  2. ThenCERT-In reported a possible intrusion and data breach to the operator.
  3. CostA written answer in Parliament, an inter-ministerial committee to audit telecom networks, and passwords changed on every similar server — BSNL, 2024.

What we test: Continuous discovery of everything you expose to the internet, what each system holds and how it is protected.

05

The backbone router

  1. Way inA known vulnerability in a provider-edge or customer-edge router — devices that are hard to monitor and rarely looked at.
  2. ThenFirmware and configuration changed to evade detection and keep long-term access.
  3. CostA global espionage campaign against telecom, government, transport and defence networks — the subject of a joint advisory by CISA and international partners in August 2025.

What we test: Configuration review of edge and management-plane devices and their patch state against known-exploited vulnerabilities.

Who the rules reach

Who the telecom security rules reach — and where we fit

The Telecommunications Act, 2023 and its rules spread duties well beyond the operators. What we do and do not do, row by row.

WhoWhat the rules askWhere we helpNot us
Telecom operators and ISPs Security policy, periodic security audits, security operations facilities, reporting in 6 and 24 hours Testing of portals, apps, APIs and exposed systems; passive architecture review; audit readiness and evidence Security audits by a government-specified “certified agency”
Networks notified as critical Two years of logs and architecture records, supply-chain records, vetted staff, approved remote-access locations, government inspection Evidence mapping and the records the rules ask for; boundary testing agreed in writing Active testing of a live core without your written instruction
Equipment makers and importers Security certification of telecom equipment against India’s security assurance requirements; IMEI duties Testing of device management interfaces and update mechanisms ahead of formal certification Security certification — that is done by NCCS-designated laboratories
Banks, fintechs and apps that identify users by number (TIUEs) Validation of numbers on the government platform when directed; suspension of a number when ordered Testing of login, one-time password and SIM-change journeys; fraud-control review —
SMS senders and aggregators Only whitelisted web links, app links and OTT links in SMS since October 2024 Testing of the portals and APIs that send messages on your behalf —

On live telecom cores and signalling, we work passive-first: architecture review, configuration review and boundary testing. Nothing is sent to a live core without written authorisation from the owner.

Next step

Before the next audit, or the next six-hour clock.

A 30-minute call with a practitioner who scopes around live networks. No charge, and no obligation.

  • Which portals, APIs and exposed systems to test first
  • What we review passively instead — and the written line between the two
  • How the findings map to the Telecom Cyber Security Rules and to ISO 27001
  • A fixed price, with a retest of every fix included
Book the call We reply within 24 business hours.

Where SemperWise fits

What we do for telecom — and for those who rely on it

Services are people doing the work; SemperWise One is the platform that keeps the evidence current between engagements. Each row says which.

“Our self-care, retailer and enterprise portals.”

Service

Authenticated testing as subscribers, retailers and enterprise administrators, with the SIM, eSIM and number-change journeys tested first.

Web application testing

“Our subscriber app and its APIs.”

Service

App and API testing for account takeover, one customer reading another’s data, and weak one-time-password handling.

Mobile app testing

“The network edge.”

Service

External and internal network testing up to the boundary of the core, with the line between active and passive agreed in writing.

Network penetration testing

“What do we actually expose?”

SemperWise One™

Continuous discovery of internet-facing systems — the forgotten file server, the management page nobody closed.

Attack surface management

“The six-hour report.”

Service

Incident-reporting runbooks mapped to the DoT and CERT-In clocks, rehearsed with the people who will file them.

CERT-In compliance

“Audit evidence that stays current.”

SemperWise One™

In SemperWise One, policies, audit findings and dated evidence mapped to ISO 27001 and your regulatory duties, with expiry dates so nothing goes stale.

Compliance automation

“We are a bank using SMS one-time passwords.”

Service

Testing of login, recovery and SIM-change handling in your apps, and review of what happens when a number changes hands.

API security testing

Terms

Telecom security terms, defined

Telecom Cyber Security Rules
The Telecommunications (Telecom Cyber Security) Rules, 2024, made under the Telecommunications Act, 2023 and in force since 21 November 2024.
CTSO
Chief Telecommunication Security Officer — the person a telecom entity appoints to coordinate with the government on these rules and report through the portal.
CTI
Critical Telecommunication Infrastructure — a telecom network the government notifies as critical, with stricter duties under separate rules.
TIUE
Telecommunication identifier user entity — a business, other than a telecom licensee, that uses phone numbers to identify its customers or deliver services.
MNV platform
The mobile number validation platform, through which a TIUE or government agency checks whether a number belongs to the person who gave it.
FRI
Financial Fraud Risk Indicator — DoT’s rating of a mobile number’s risk of involvement in financial fraud, shared with banks and payment platforms.
Chakshu
The facility on the Sanchar Saathi portal and app where citizens report suspected fraud calls and messages.
IMSI
International Mobile Subscriber Identity — the number that identifies a subscriber’s SIM to the network.
eSIM swap
Fraudulently moving a subscriber’s number to an embedded SIM controlled by someone else.
Femtocell
A small, low-power base station for a home or office that connects to the operator’s network over the internet.
ITSAR
Indian Telecom Security Assurance Requirements — the security standards telecom equipment is tested against by NCCS-designated laboratories.
Provider-edge router
A router at the boundary of an operator’s backbone where customer networks connect — a common target because it is rarely monitored closely.

Questions

Telecommunications security — answered.

What buyers in this sector ask us before they commit to anything.

What are the Telecom Cyber Security Rules, 2024?

The Telecommunications (Telecom Cyber Security) Rules, 2024 were made under the Telecommunications Act, 2023 and came into force on 21 November 2024. They require every telecom entity to adopt a telecom cyber security policy and inform the government, reduce the risk of security incidents, run periodic security audits, establish facilities such as a security operations centre, and report security incidents within six hours. The government can also seek traffic and other data through its portal for telecom cyber security.

How quickly must a telecom security incident be reported?

Within six hours of becoming aware of it, to the Central Government through the DoT portal, and within 24 hours with the number of users affected, the duration, the geographical area, the extent of the impact and the remedial measures. CERT-In’s own six-hour reporting duty under its April 2022 Directions applies separately. Where subscribers’ personal data is involved, the DPDP Rules add notice to the Data Protection Board and affected people without delay, and a detailed report within 72 hours, from about May 2027.

What is a telecommunication identifier user entity?

A TIUE is any business, other than a telecom licensee, that uses telecommunication identifiers — in practice, mobile numbers — to identify its customers or users, or to provision or deliver services. The category was added by the amendment of 22 October 2025. A TIUE can use the government’s mobile number validation platform, for a fee, to check that a number belongs to the customer who gave it, and can be directed to do so; the government can also order it to temporarily stop using a particular number.

Does the amendment mean every bank must validate every number?

Not automatically. As notified, a TIUE may request validation on the platform on its own initiative, or when directed by the Central or State Government or an authorised agency. What it does mean is that a business that relies on phone numbers is now inside the telecom rulebook, and should expect directions. Separately, DoT’s Fraud Risk Indicator already lets banks and payment platforms check a number’s risk; DoT reports more than ₹5,000 crore of suspected fraud prevented through it by August 2026. Take specific obligations to counsel.

What do the Critical Telecommunication Infrastructure Rules add?

For networks the government notifies as critical, the rules add duties to keep logs and network-architecture documentation for at least two years, keep supply-chain records for the equipment deployed, vet everyone with access, maintain incident-response and continuity procedures, and allow remote maintenance from outside India only from locations approved in advance. Government-authorised personnel can inspect hardware, software and data.

Can you penetration-test a live telecom network?

Not the live core, without written authorisation from the owner — and even then, we work passive-first. We test what faces subscribers, retailers and partners actively: portals, apps, APIs and internet-facing systems. Toward the core, we review architecture and configuration, and test the boundary, with the line between active and passive agreed in writing before anything runs. Where active testing deeper in is genuinely needed, it belongs on a lab or staging environment.

Are you a certified agency or an NCCS-designated laboratory?

No. Security audits under the Telecom Cyber Security Rules are carried out by agencies the government specifies, and security certification of telecom equipment is done by laboratories designated by the National Centre for Communication Security. SemperWise is neither. We prepare you for those audits and tests, test between them, verify fixes and keep the evidence — and we say so up front.

How do we reduce SIM and eSIM swap fraud?

Treat every change of SIM, eSIM or number as a high-risk transaction: verify the subscriber strongly, rate-limit and monitor the journey, notify the subscriber through a second channel, and give banks a signal that a number has recently changed hands. Test the self-care app, retailer tools and customer-care workflows that can start a swap — that is where the Indian Cybercrime Coordination Centre’s eSIM warnings point. Banks should not treat an SMS one-time password as enough on its own for high-value actions.

Sources

Checked by our research desk on 24 September 2026. Regulations and figures move; where a number here matters to a decision, follow it to the source.

  1. Telecommunications (Telecom Cyber Security) Rules, 2024 — SCC Online, 22 November 2024
  2. Telecom Cyber Security Rules 2024 finalised — Khaitan & Co
  3. Telecommunications (Critical Telecommunication Infrastructure) Rules, 2024 — SCC Online, 25 November 2024
  4. Telecommunications (Telecom Cyber Security) Amendment Rules, 2025 — SCC Online, 25 October 2025
  5. DoT notifies the Telecommunications (Telecom Cyber Security) Amendment Rules, 2025 — Internet Freedom Foundation
  6. Directions under sub-section (6) of section 70B of the IT Act, 2000 — CERT-In, 28 April 2022
  7. Chakshu facility of Sanchar Saathi enables citizens to report suspected fraud communications — PIB, 5 February 2026
  8. FRI prevents suspected cyber fraud losses of over ₹5,000 crore in 15 months — DD India, September 2026
  9. TRAI mandates whitelisted URLs, APKs or OTT links for SMS traffic — PIB, 2024
  10. eSIM fraud rising in India, I4C issues warning — Daily Jagran
  11. CERT-In reported possible intrusion, data breach at BSNL on May 20: Govt — Business Standard / PTI, 24 July 2024
  12. SK Telecom fined $97 mil. over April data breach — The Korea Times, 28 August 2025
  13. South Korea fines telco giant KT $39 million for customer data breach — BleepingComputer, 30 July 2026
  14. Countering Chinese state-sponsored actors’ compromise of networks worldwide — CISA, 27 August 2025
  15. About NCCS: ITSARs and Telecom Security Test Laboratories — National Centre for Communication Security
  16. Digital Personal Data Protection Rules, 2025 (Rule 7) — MeitY, 13 November 2025

All 17 industries we serve

Next step

Test the edges without touching the core.

A 30-minute call, no charge. You leave knowing which of your portals, APIs and exposed systems to test first, what we would review passively instead, and how the findings map to the Telecom Cyber Security Rules — with a written scope and fixed price if testing makes sense.