Module 5 · Cyber Crime Investigation in India — Working with Cybercrime Cells

Manish Garg
Manish Garg Associate of (ISC)² · RingSafe
May 14, 2026
4 min read
Read as
100% Free

No signup. No paywall. No catch. One of our 10 most-requested practitioner modules — published in full so anyone can learn for free. We earn through consulting, not by gating knowledge.

See all 10 free modules →

Why this module exists. When a cyber incident becomes a criminal matter, organisations need to work with Indian law enforcement — the local police cybercrime cell, state cyber cell, CBI cyber wing for severe cases. The process is rarely intuitive, evidence requirements are specific, and the practitioner’s preparation determines whether the investigation produces a successful prosecution. This module is the practical guide.

Why this module exists. Most cyber incidents an enterprise reports do not result in successful prosecution. Sometimes that is because the attacker is offshore; often it is because evidence was not preserved correctly, or the FIR was filed under the wrong sections, or the cybercrime cell was not engaged early enough. This module is the playbook.

The Indian law-enforcement landscape for cyber

Authority When to engage
Local police station FIR filing for incidents below state-cyber-cell threshold
District / city cybercrime cell Most cyber-fraud cases; BEC fraud, account takeovers, ransomware
State CID cyber wing Larger frauds, multi-jurisdictional cases
National Cyber Crime Reporting Portal (cybercrime.gov.in) Online complaint filing; routes to relevant jurisdiction
CBI Cyber Crime Investigation Wing Inter-state major fraud, critical infrastructure attacks
CERT-In Technical incident response; not law enforcement but coordinates

The FIR — what to include

The First Information Report is the formal initiation of the criminal investigation. Quality of the FIR shapes the investigation. The fields that matter:

  • Specific sections cited. IT Act 43, 66, 66D as relevant + IPC 419, 420, 467, 468, 471 as relevant. Citing all applicable sections protects against later limitation.
  • Timeline of events. When the attack started, when it was discovered, what actions the organisation took, when the FIR is being filed.
  • Specific harm. Monetary loss, data exfiltrated, systems affected. Quantify where possible.
  • Evidence enumeration. Logs preserved, system images taken, hash values. Reference the chain of custody.
  • Suspect information. Even partial — IP addresses, email aliases, beneficiary bank accounts.
  • Cooperation declaration. Confirm that the organisation will provide further evidence as the investigation progresses.

Evidence preservation — the prerequisite

The cybercrime cell will want evidence. If you have not preserved it, the case dies before investigation begins. The minimum preservation list:

# Within hours of incident detection
- Forensic disk images of affected systems (Module 2 in this track)
- Memory captures where applicable (Module 3)
- SIEM export of relevant time window — with hash
- Email server export for incidents involving email — full headers + bodies
- Network traffic capture or NetFlow records
- Access logs from affected applications

# Documentation
- Incident chronology with timestamps in IST (and corresponding UTC)
- Personnel involved in detection and response
- Communications log — emails, Slack messages, phone calls related to the incident
- Hash values for every preserved artefact

# Storage
- Read-only media or write-protected storage
- Chain-of-custody form for every artefact transfer

Indian Evidence Act Section 65B (covered in next module) governs admissibility. The chain-of-custody and integrity-hash documentation is the difference between admissible and discarded evidence.

The Section 65B certificate

Any electronic record submitted as evidence must be accompanied by a Section 65B certificate. The certificate is a sworn statement (by someone responsible for the system that produced the record) that:

  • The record was produced by a computer in regular use.
  • The information was regularly fed into the system in the ordinary course of activity.
  • The computer was operating properly throughout the material period.
  • The information is derived from the regular operation of the computer.

Get the certificate format from your cybercrime cell or download from cybercrime.gov.in resources. Sign it correctly at the time of evidence handover; retroactive certification has been rejected in court.

Working with the cybercrime cell — pragmatics

  • Pre-incident relationship. Visit your local cybercrime cell once before you need them. Introduce the CISO and Legal counsel. Understand their preferred evidence formats and contact channels.
  • Designated liaison. Name one person — typically the CISO or Head of Information Security — as the cybercrime cell’s contact. Helps continuity.
  • Realistic expectations. Most cybercrime cells are under-resourced. Cases take months to investigate, longer to prosecute. Manage internal stakeholder expectations accordingly.
  • Provide technical translation. Investigators often need help understanding the technical chronology. Offer to walk them through the timeline with charts, not jargon.

International dimension

Most serious cyber attacks against Indian targets originate outside India. Cybercrime cells engage international cooperation through:

  • Mutual Legal Assistance Treaty (MLAT) requests — slow (12-24 months) but produces formally-admissible evidence.
  • INTERPOL Red Notices / Blue Notices — for known offenders with extradition routes.
  • CBI’s international cooperation cell — for major cases.
  • Direct foreign-LE cooperation — informal channels for time-critical IOC sharing.

For most enterprise cases, expect that international suspects are not extradited; the value of the criminal case is in domestic accomplices, money mules, and the deterrent message. Civil recovery via international counsel is often the financial-restitution path.

The civil-side parallel

Criminal cases focus on punishment; civil cases focus on recovery. Indian organisations typically pursue both:

  • IT Act Section 43 civil compensation claim.
  • Recovery of funds through bank cooperation (RBI 2022 fraud-management directives have improved this).
  • Insurance claim — cyber insurance, where applicable.

The civil case can move faster than the criminal. Pursue them in parallel; do not wait for criminal resolution.

Key takeaways

  • Local cybercrime cell for most cases; CBI cyber wing for major / inter-state.
  • FIR quality matters — cite all applicable IT Act + IPC sections.
  • Evidence preservation begins within hours of detection; Section 65B certification is non-optional.
  • Pre-incident relationship with the cybercrime cell pays off in actual incidents.
  • International dimension: MLAT slow, INTERPOL specific. Most foreign suspects not extradited.
  • Civil case in parallel with criminal; recovery is faster on civil side.
DPDP Act in your stack?

Get a DPDP gap assessment

Free 30-minute call. We map your data flows against DPDP §8 obligations and tell you exactly which gaps to fix first. Auditor-defensible output.

Book DPDP scoping call Replies in 4 working hrs · India-only · Senior consultants