[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract
[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract

CYBER WATCH / EDITORIAL POLICY

Evidence first.
Context, not speculation.

How we select, review, and maintain Cyber Watch updates.

Back to Cyber Watch

What we cover

Cyber Watch follows material cyberattacks, data breaches, ransomware, software supply-chain compromise, and consequential exploited vulnerabilities. We prioritize enterprise relevance and include India-specific reporting when reliable evidence is available. This is a selective briefing, not a complete incident register or real-time monitoring service.

AI assistance, human approval

AI assists with discovery, source reading, deduplication, and drafting. New stories enter a private editorial queue. Only records explicitly marked Published by an authorized workspace editor appear publicly. The agent does not approve its own work or overwrite published articles; material developments enter a separate proposed-update queue.

Sources and uncertainty

We link to the underlying reporting or official notice. Officially confirmed identifies a primary disclosure; Reported identifies attributed journalism or research; Developing flags unsettled details or conflicting accounts. Attacker claims, estimates, and allegations are not treated as confirmed facts.

Dates and updates

The feed is organized by the date of the selected source report. An incident may have happened earlier. Article pages distinguish incident timing, publication, and material updates. Corrections retain a dated explanation rather than silently presenting an old story as new.

Responsible reporting

Summaries are original and concise. We do not publish stolen personal records, credentials, malicious downloads, or criminal leak-site links. Illustrative material must not be presented as evidence of an actual incident. Coverage does not imply that software escrow prevents cyberattacks or reverses data theft.

Corrections and withdrawal

If a report is inaccurate or requires clarification, contact Castler with the article URL, the disputed statement, and a reliable supporting source. Our editors can correct the record or withdraw it from the public feed.

Contact Castler about a correction