The Department of Information and Communications Technology (DICT) is investigating a possible exposure of about 410 files associated with 48 companies participating in its Trusted Assessment Provider accreditation program.
The agency has not confirmed that a breach occurred or that its own systems were compromised.
DICT said the reported files amount to about 600MB of data, or around 770MB when uncompressed, and may include corporate registration records, permits, certifications, cybersecurity credentials, employment documents, and DICT performance evaluations.
The National Computer Emergency Response Team (NCERT), under the DICT Cybersecurity Bureau, is handling the investigation. It is coordinating with the Trusted Assessment Provider involved and other parties while determining the authenticity, source, nature, and extent of the reported exposure.
That distinction remains important, as DICT’s statement refers to one provider and files associated with 48 companies participating in the accreditation program. It does not establish that 48 companies were separately breached, nor has the agency confirmed exactly what the reported “cybersecurity credentials” contain.
DICT said that if its investigation confirms personal or other protected data was compromised, it will take appropriate action, including notifying affected parties where applicable under the Data Privacy Act of 2012.
The program puts accredited cybersecurity providers in a sensitive part of the government’s security-assessment process.
DICT has described its Trusted Assessment Provider framework as an accreditation program that allows qualified cybersecurity firms to perform vulnerability assessments and security audits of government platforms and critical infrastructure.
The role is also formalized under the implementing rules of the E-Governance Act. For government Critical Information Infrastructure, vulnerability assessment and penetration testing engagements must be conducted by DICT-accredited providers that meet the Trusted Assessment Provider criteria.
The rules also call for VAPT reports to be submitted to NCERT and the program’s registry or equivalent.
The investigation comes as DICT expands cybersecurity testing across government. A department circular announced in September requires covered government entities to conduct VAPT at least annually, as well as after major system changes or cybersecurity incidents.
Agencies may perform the testing internally subject to DICT requirements or engage accredited Trusted Assessment Providers.