Section 2(1)(d) in The Information Technology (Intermediaries Guidelines) Rules, 2011
(d)"Cyber security incident" means any real or suspected adverse event in relation to cyber security that violates an explicitly or implicitly applicable security policy resulting in unauthorised access, denial of service or disruption, unauthorised use of a computer resource for processing or storage of information or changes to data, information without authorisation;