Two findings show up in almost every Indian cloud estate we audit: 25–35% of spend is waste, and CERT-In's logging and reporting requirements are only partially met. They look like different problems — one for finance, one for legal — but they share a root cause: nobody owns cloud governance.
Part 1: Where the money leaks
- Zombie resources: unattached disks, idle public IPs, stopped-but-allocated VMs, and orphaned snapshots. Typically 5–8% of the bill.
- Over-provisioned compute: instances sized from guesswork running at 10–15% utilization. Right-sizing recovers 15–25% with zero performance impact.
- No commitment coverage: steady-state workloads on pay-as-you-go rates. Reserved instances / savings plans cut those costs 40–65%.
- Storage without lifecycle policies: years of logs and backups on premium tiers instead of cool/archive.
- Non-production running 24/7: dev, QA and UAT environments burning nights and weekends. Scheduling saves ~65% on those subscriptions.
The fix is not a one-time cleanup — it's an operating rhythm: enforced tagging (CostCenter, Environment, Owner), monthly reviews with showback per business unit, and policy that blocks untagged deployments.
Part 2: The CERT-In baseline
CERT-In's directions (in force since 2022) apply to companies operating in India regardless of where the cloud region sits. The practical requirements:
- 6-hour incident reporting for specified incident types — which means you need detection and an on-call runbook, because you can't report what you don't see.
- 180-day log retention across systems — in practice: centralized Log Analytics / storage-tier archival with retention locks.
- NTP synchronization to NIC/NPL Indian time sources or traceable equivalents.
- Accurate subscriber/customer records for service providers.
Add the DPDP Act's obligations on personal data and sector rules (RBI data-localization for payments), and "we'll sort compliance later" stops being a viable posture.
One governance layer solves both
The same instrumentation that finds waste satisfies auditors: complete tagging tells you both who owns the spend and who owns the incident; centralized logging feeds both cost dashboards and CERT-In retention; Azure Policy blocks both untagged resources and non-compliant regions. We package this as a quarterly governance cycle — cost review, security posture review, compliance evidence pack — so neither audit is ever a fire drill.
Want a snapshot of your own estate? CloudSwift's free cloud audit covers both sides: a costed savings plan and a CERT-In/DPDP gap list, delivered in two weeks.