Internal Security· Prelims · GS-III
The Invisible Battlefield: Cyber Security
From CERT-In and NCIIPC to the DPDP Act, 2023 and the Hanoi cybercrime convention: the complete GS-3 guide to India's cyber security architecture, laws, threats and gaps.
Cyber security is the discipline of keeping the digital world safe: it protects information, computers, computer resources, communication devices and the data stored in them from unauthorised access, use, disclosure, disruption, modification or destruction. It is at once a technology problem (firewalls, encryption), a process problem (how incidents are reported and contained) and a people problem (whether citizens practise basic cyber hygiene).
The stakes for India are now existential. NCRP registrations rose from 10.29 lakh in 2022 to 15.96 lakh in 2023 to 22.68 lakh in 2024, with reported citizen losses of Rs 2,290 crore, Rs 7,465 crore and Rs 22,845 crore respectively (MHA, Lok Sabha answers, December 2024).
What cyber security means: the definition and its scope
At its simplest, cyber security is protection against the unauthorised use of digital systems and data. The scope of the field is usually mapped into nine domains. Network security keeps internal networks free of intrusions, the domain in which CERT-In issued advisories against Chinese advanced persistent threats in 2023. Information security guards data itself, the discipline tested by the Aadhaar and CoWIN leaks. Application security and endpoint security protect the software we run and the devices we run it on, illustrated by vulnerabilities found in BHIM and Aarogya Setu and by the Pegasus spyware affair. The remaining domains are cloud security (the MeghRaj framework), operational security (the RBI's cybersecurity framework for banks), critical-infrastructure security (the AIIMS Delhi ransomware attack of 2022), cyber forensics (the NIA's probes into terror funding), disaster recovery (AIIMS restoring its services) and the cyber laws and regulations that bind all of it, from the IT Act to the DPDP Act.
Domain | What it protects | Illustration from India |
|---|---|---|
Network security | Internal networks from intrusions | CERT-In advisories against Chinese APTs (2023) |
Information security | Data from unauthorised access | Aadhaar and CoWIN data leaks |
Application security | Software from exploitable flaws | Vulnerabilities in BHIM, Aarogya Setu |
Endpoint security | Devices like laptops and phones | Pegasus spyware targeting journalists, officials |
Cloud security | Data stored on cloud platforms | Government's MeghRaj cloud framework |
Operational security | Data-handling policies and processes | RBI cybersecurity framework for banks |
Critical infrastructure | Power, health, transport systems | AIIMS Delhi ransomware attack (2022) |
Cyber forensics | Investigation of cyber crimes | NIA probes into terror funding links |
Disaster recovery | Service continuity after attacks | AIIMS restored digital services post-attack |
Cyber laws and regulations | Legal safeguards | IT Act 2000; DPDP Act 2023; IT Rules 2021 |
Why it matters: India's digital stakes
India's exposure is a function of its digitisation. With over 1.09 billion internet subscribers, a UPI system that handles nearly half of the world's digital payments, and flagship platforms like Aadhaar, DigiLocker and CoWIN holding the life data of hundreds of millions of citizens, a cyber incident is no longer an IT event: it is a governance event. Six dimensions of the stakes are visible.
- Critical infrastructure: attacks on power grids, hospitals and transport paralyse daily life; the Mumbai power outage of 2020 and the AIIMS Delhi ransomware attack of 2022 are the reference cases.
- Data security and privacy: Aadhaar, health records and financial data are national assets; the CoWIN leak of 2023 and the Mobikwik breach exposing 9.9 crore users show the cost of failure.
- Economic and financial security: digital payments fraud erodes trust in the formal economy; over 17,000 fraud cases involving Rs 36,000 crore were reported in April-December of FY 2025-26 alone.
- National security: cyber espionage and sabotage target defence and strategic systems; the DRDO espionage case of 2021 and ShadowPad malware attacks of 2023 belong here.
- Securing digital governance: e-governance platforms and flagship schemes must stay resilient; even a DigiLocker breach attempt in 2022 drew national attention.
- Democratic safeguards: manipulated media can distort elections and public order; deepfakes surfaced during the Madhya Pradesh and Telangana elections.
The scale, in hard numbers: NCRP registrations rose from 10.29 lakh in 2022 to 15.96 lakh in 2023 to 22.68 lakh in 2024, with reported citizen losses of Rs 2,290 crore, Rs 7,465 crore and Rs 22,845 crore respectively (MHA, Lok Sabha answers, December 2024).
The threat map: crimes and the actors behind them
Cyber crimes are conventional crimes committed through new means, plus a few crimes that only cyberspace makes possible. The standard taxonomy runs as follows.
Cyber crime | Description | Example |
|---|---|---|
Malware | Malicious software that damages systems or steals data | Malware-laced SMS alerts targeting banking customers (2023) |
Phishing | Fraudulent messages or websites that steal credentials | Fake UPI and SBI login pages; 10,000+ URLs flagged by CERT-In (2023) |
Ransomware | Encryption of data with ransom demanded for release | AIIMS Delhi attack (2022) halted hospital operations |
Spyware | Software that secretly harvests user data | Pegasus spyware allegedly used against journalists and officials |
DoS / DDoS attacks | Flooding systems to deny service to genuine users | Attacks on banks and government portals during geopolitical tensions |
Data breaches and identity theft | Unauthorised access to and misuse of personal or financial data | CoWIN, Air India and BigBasket leaks |
Cyber espionage | State-backed theft of strategic data | Chinese hackers targeting infrastructure and defence |
Cyber terrorism | Use of cyberspace to strike terror or disrupt national security | ISIS propaganda and recruitment via encrypted apps and the dark web |
Social engineering | Manipulating people into revealing confidential information | Sextortion, fake Army jobs, romance frauds |
Deepfakes and AI-based threats | AI-generated fake video or voice used for fraud and misinformation | Celebrity and politician deepfakes; election misinformation |
Four kinds of actors sit behind these crimes. State-sponsored attackers conduct espionage, sabotage and election interference: China's APT41 has targeted Indian telecom and power grids, North Korea's Lazarus Group steals cryptocurrency globally, and the Stuxnet worm (a US-Israel operation) disabled Iranian nuclear centrifuges. Non-state actors range from hacktivists like Anonymous, who deface websites as protest, to profit-driven cyber criminals running phishing and loan-app scams. Organised crime syndicates run cybercrime as a business: Ransomware-as-a-Service groups such as REvil and Conti, and the Noida-based betting and loan-fraud rackets busted in 2023-24. Finally, insider threats misuse legitimate access: malicious insiders like disgruntled employees, and negligent insiders who fall for phishing, with Aadhaar data leaked by operators as the Indian cautionary tale.
Cyber warfare is the state-level extreme of this spectrum: the use of digital attacks by a nation-state or its proxies to disrupt, damage or destroy another country's information systems, critical infrastructure or networks for strategic, military or political advantage. Its marks are espionage and intelligence gathering (the SolarWinds supply-chain breach of 2020), sabotage of critical infrastructure (Stuxnet at Natanz in 2010), denial of service, economic damage (the NotPetya attack of 2017 cost roughly ten billion dollars globally), pre-positioning of hidden access for later activation, degradation of military command systems, psychological operations such as website defacements, and information warfare through disinformation. India saw the full playbook during Operation Sindoor: about 200,000 probing and attack attempts against the power grid, roughly 19 hours of DDoS against the President's website, defacement of defence-linked portals, and a parallel disinformation wave of fake grid-collapse claims, ATM-shutdown rumours and an AI-generated deepfake of the External Affairs Minister.
Who guards the grid: India's institutional architecture
India's cyber institutions are clustered by ministry, with apex coordination sitting near the Prime Minister's Office. The National Cyber Security Coordinator (NCSC) coordinates all cyber agencies, advises the PMO on cyber strategy and oversees frameworks like the National Cyber Security Reference Framework. The National Cyber Coordination Centre (NCCC) performs near-real-time threat scanning and shares metadata across agencies to build situational awareness, while the Cyber Multi-Agency Centre (CyMAC), housed under the Multi-Agency Centre, fuses intelligence on cyber espionage, terrorism and emerging-technology misuse from the IB, the Defence Cyber Agency, the DoT, CERT-In, I4C, NCIIPC and the NIC.
Under MeitY, CERT-In (the Indian Computer Emergency Response Team) is the national nodal agency for incident response under Section 70B of the IT Act: it issues alerts and advisories, investigates breaches and enforces the 2022 Directions that mandate six-hour breach reporting, with penalties of up to one year's imprisonment and/or fine up to Rs 1 crore per violation (Section 70B(7)). The Cyber Swachhta Kendra is its botnet-cleaning arm, offering free malware-removal tools through ISPs (89.55 lakh downloads so far), and CSIRT-Fin coordinates incident response for the banking and financial sector with the RBI, SEBI and IRDAI.
The MHA cluster fights cybercrime as crime. The Indian Cyber Crime Coordination Centre (I4C) is the nodal point against cybercrime: it runs the national cybercrime reporting portal, coordinates mutual legal assistance requests and takedowns, and operates the 1930 helpline and the Citizen Financial Cyber Fraud Reporting and Management System, which has helped save over Rs 3,431 crore across more than 9.94 lakh complaints. The defence cluster fields the Defence Cyber Agency (DCyA), a tri-service body that defends armed-forces networks and builds offensive cyber capability. The Department of Telecommunications runs the Telecom Security Operations Centre and the citizen-facing Sanchar Saathi platform: its Chakshu module reports fraudulent calls, its IMEI tracking has blocked over 42 lakh stolen devices, 1.43 crore fraudulent mobile connections have been disconnected, 16.97 lakh WhatsApp accounts disabled, and its Financial Fraud Risk Indicator has helped prevent Rs 475 crore in fraud.
Two sectoral guardians complete the picture. The National Critical Information Infrastructure Protection Centre (NCIIPC), designated under Section 70A of the IT Act, protects critical information infrastructure across power, banking, telecom, transport, government and strategic enterprises, issuing alerts and running audits. The Data Protection Board of India, created under the DPDP Act, adjudicates data breaches and imposes penalties. Alongside them runs a quiet indigenisation push: the Defence Ministry's adoption of the indigenous Maya OS, the Chakravyuh endpoint-detection system against advanced persistent threats, and the Bharat 6G Vision, which targets 10% of global 6G patents by 2030 with secure-by-design telecom infrastructure.
Reporting cybercrime: the portal and the 1930 helpline
The National Cyber Crime Reporting Portal (cybercrime.gov.in) is the citizen-facing front door of India's cybercrime response. Citizens can report financial frauds, social-media crimes, hacking, ransomware and impersonation, and crimes against women and children through a dedicated track that allows anonymous reporting. Other complaints require registration and login, after which the complaint is routed to the police of the concerned state or union territory for action.
For financial fraud, speed matters more than paperwork, which is why the 1930 helpline exists as a national number for immediate reporting. Its logic is the golden hour: siphoned money moves through mule accounts within minutes, so the helpline triggers the Citizen Financial Cyber Fraud Reporting and Management System, which instantly alerts the concerned banks, wallets and payment gateways to lien-mark the suspect accounts and freeze the trail. Callers should keep transaction IDs, UPI references and the fraudster's contact details ready before dialling.
Both instruments run under the Indian Cyber Crime Coordination Centre (I4C) of the Home Ministry, which coordinates with state police, banks and intermediaries on investigation, takedowns and mutual legal assistance. The portal and the helpline are therefore not standalone conveniences but the reporting end of the enforcement architecture described above: report fast, report with transaction details, and the system is designed to act within the golden hour.
The legal architecture
India's cyber law is layered: a 2000-vintage statute at the core, sectoral rules around it, and a new data-protection regime coming into force in phases. The table below maps the architecture.
Law or provision | What it does | Why it matters for the exam |
|---|---|---|
IT Act, 2000 | India's core cyber statute: the legal spine for computer-related offences and digital governance. | The foundation of every cyber-law question; know it as the 2000-vintage core of the architecture. |
Section 66, IT Act | Punishes computer-related offences such as hacking and data theft. | The most-cited penal provision in cybercrime questions. |
Section 66F, IT Act | Defines and punishes cyber terrorism. | Brings the national-security angle into cyber-law answers. |
Section 69A, IT Act | Empowers the government to order the blocking of online content. | Central to free-speech versus security debates. |
Section 79, IT Act | Grants intermediaries conditional safe harbour from liability for third-party content. | Key for platform-liability and intermediary-rule questions. |
Section 66A, IT Act | Criminalised sending offensive messages online; struck down in Shreya Singhal v. Union of India (2015) for vagueness and chilling free speech. | The classic example of the Article 19(2) reasonable-restrictions test in cyberspace. |
CERT-In (Section 70B) | National nodal agency for cyber incidents; enforces the 6-hour breach-reporting rule (Section 70B(7): up to one year's imprisonment and/or fine up to Rs 1 crore). | The institutional core of incident response; the numbers make strong mains fodder. |
NCIIPC (Section 70A) | Protects critical information infrastructure. | The critical-infrastructure security pillar of the architecture. |
I4C | Coordinates the national fight against cybercrime through the 1930 helpline and the National Cyber Crime Reporting Portal. | The citizen-facing end of cybercrime response. |
DPDP Act, 2023 | India's first consent-based data-protection law; penalties go up to Rs 250 crore; the DPDP Rules, 2025 were notified on 13 November 2025 with a phased rollout running to May 2027. | The new data-governance regime; the privacy answer after Puttaswamy. |
National Cyber Security Policy, 2013 | India's first dedicated cyber policy; targeted 5 lakh cybersecurity professionals; non-binding and now dated, predating ransomware-as-a-service and AI-driven fraud. | Know both the Tier-1 GCI 2024 outcome and the gaps: no binding standards, strategy still awaited. |
UN Convention against Cybercrime | India signed in September 2026, a year after it opened for signature at Hanoi; enters into force only after 40 ratifications. India never joined the 2001 Budapest Convention. | India's cyber-diplomacy stand; the Budapest contrast is a favourite prelims trap. |
Two cautionary notes sharpen the picture. Section 66A, which criminalised the sending of offensive messages online, was struck down by the Supreme Court in Shreya Singhal v. Union of India (2015) for vagueness and chilling free speech: a reminder that cyber law must satisfy Article 19(2)'s reasonable-restrictions test. And critics argue the framework retains excessive executive control: CERT-In's directions and the DPDP Act's state exemptions concentrate power in the executive with thin independent oversight, creating privacy risks even as they strengthen security.
The 2013 policy and the missing strategy
The National Cyber Security Policy (NCSP), 2013, framed by the Department of Electronics and Information Technology, is India's first dedicated cyber policy. Its objectives are to create a secure cyber ecosystem and trust in IT, protect critical information infrastructure through the NCIIPC, empower CERT-In as the 24x7 nodal agency for emergencies and early warnings, strengthen the legal structure within the IT Act and encourage organisations to appoint Chief Information Security Officers. Its headline capacity target was the creation of 5 lakh cybersecurity professionals, and its strategies leaned on public-private partnership (Information Sharing and Analysis Centres, testing labs), workforce development and indigenous R and D to cut foreign supply-chain dependence. India reached Tier-1 status in the Global Cybersecurity Index 2024 with a 98.49/100 score, a genuine marker of progress.
The critique, however, is structural. The 2013 policy is non-binding and dated: it predates ransomware-as-a-service, AI-driven social engineering and the current scale of state-sponsored intrusion, and it imposes no mandatory security standards on critical infrastructure. The draft National Cyber Security Strategy (NCSS), 2021 that was meant to replace it is still awaiting Cabinet approval, leaving a policy vacuum at the centre of the architecture. The 2022 mains question asking how far India has developed a comprehensive strategy was probing exactly this gap.
What a successor policy is expected to address is now clear even in outline. It would need to interface with the Digital Personal Data Protection Act, 2023, set mandatory baseline security standards for critical infrastructure rather than voluntary guidance, account for AI-enabled phishing and deepfakes, harden software and hardware supply chains, and clarify the National Cyber Security Coordinator's coordinating role across the Home Ministry, MeitY and defence clusters. The draft National Cyber Security Strategy of 2021 was meant to do this work and is reported to still await Cabinet approval, which is why the 2013 policy, non-binding and predating the current threat landscape, continues as the formal framework. Until a new strategy is notified, India's cyber posture rests on institutional improvisation rather than a codified doctrine.
India and the world: from Budapest to Hanoi
Cyberspace has no borders, so India has built a diplomacy of cyber norms. It participates in the UN Open-Ended Working Group, backing its eleven voluntary norms of responsible state behaviour (including not attacking critical infrastructure) and confidence-building measures like the Global Points-of-Contact directory. Its 2023 G-20 presidency carried a responsible-cyber-conduct agenda into the Delhi Declaration; the QUAD runs regional cyber-resilience, threat-intelligence sharing, joint exercises and capacity building; and bilateral dialogues with the United States, the 2020 India-Japan cybersecurity agreement, and cooperation with the EU and Australia round out the network. Academically, the Tallinn Manual 2.0 offers a non-binding framework explaining how existing international law, including the laws of war, applies to cyber operations, such as when a cyberattack qualifies as an armed attack warranting self-defence.
On treaties, India's position has been consistent: it never signed the Budapest Convention on Cybercrime (2001), the Council of Europe's instrument, because provisions like Article 32(b) would have allowed foreign authorities to access data on Indian servers without domestic authorisation, raising sovereignty and privacy objections. The same objections shape its approach to the new United Nations Convention against Cybercrime, the Hanoi Convention.
The Hanoi Convention is the first comprehensive global cybercrime treaty: adopted by the UN General Assembly on 24 December 2024 (Resolution 79/243) after nearly five years of UNODC-secretariat negotiations, it criminalises offences such as ransomware, fraud and online child sexual abuse material, enables cross-border sharing of electronic evidence in serious crimes, creates a 24/7 cooperation network, and provides capacity building and technical assistance for developing nations, with a Conference of States Parties to review implementation. It opened for signature in Hanoi on 25-26 October 2025. India, which had helped draft the treaty but stayed away from the Hanoi ceremony over sovereignty, data-governance and privacy concerns, signed the convention on 25 September 2026, with External Affairs Minister S. Jaishankar signing on the sidelines of the 81st UN General Assembly. As of 25 September 2026 there are 91 signatories but only three parties (Qatar, Azerbaijan and Vietnam): the treaty enters into force 90 days after the 40th ratification, so it is not yet in force, and India's signature will need domestic ratification procedures before it becomes a full party.
The cracks in the architecture and the way forward
Ten weaknesses recur in assessments of India's cyber posture. The institutional framework is fragmented: CERT-In, NCIIPC, I4C and the Defence Cyber Agency operate with overlapping mandates and no unified response mechanism. The IT Act, 2000 is outdated, lacking provisions calibrated to AI threats, ransomware and cyber warfare. The National Cyber Security Strategy remains delayed. Legacy operational-technology systems in power, railways and other sectors suffer an air-gap fallacy, exposed through digital integration. The workforce gap is stark: about 380,000 professionals against demand exceeding 1.2 million, and fewer than 15 states have advanced digital crime labs. There is no formal public-private threat-intelligence sharing mechanism, corporations under-report breaches to protect brands, and citizens lack basic cyber hygiene: over Rs 1,750 crore was lost to cyber fraud in January-April 2024 alone.
The way forward, as mapped across the sources, has eight elements.
- A unified cyber command: one coordinated authority for cyber intelligence and response, on the model of Israel's National Cyber Directorate.
- A binding, time-bound strategy: replace the 2013 policy with a strategy that clarifies roles and goals, as Estonia's Cyber-Conscious Estonia 2024-2030 does.
- A critical-infrastructure protection law: move from advisories to mandatory security standards for power, banking, telecom and healthcare.
- Institutionalised threat sharing: formal public-private intelligence exchange, with protections for reporters.
- Silicon sovereignty: indigenous hardware, software and certification to cut supply-chain risk.
- Citizen cyber hygiene: sustained mass-awareness campaigns against digital-arrest and deepfake scams, and State CERTs, forensic labs and cyber-police academies.
- Assume-breach culture: continuous resilience testing and Zero-Trust Access, starting with fintech and banking.
- A national cyber-conflict SOP: tiered alert systems and a clear escalation matrix distinguishing routine intrusion from an act of war.
UPSC and this topic: PYQ weightage
How the Commission has asked this topic: cyber security is one of the most frequently examined internal-security themes, with questions almost every year. The weight falls on four clusters: law and data protection, strategy and institutions, threat types, and cross-border warfare.
- 2024: context and salient features of the Digital Personal Data Protection Act, 2023, the data-protection cluster.
- 2022: the different elements of cyber security, and how far India has developed a comprehensive National Cyber Security Strategy, the strategy cluster.
- 2021: impact of cross-border cyber-attacks on internal security, and defensive measures against sophisticated attacks.
- 2020: different types of cybercrimes and the measures required to fight the menace.
- 2019: the Cyber Dome Project and its utility in controlling internet crimes in India.
- 2018: strengths and weaknesses of the Justice B. N. Srikrishna Committee report on protection of personal data.
- 2017: potential threats of cyber attacks and the security framework to prevent them.
- 2016: use of the internet and social media by non-state actors for subversive activities, and guidelines to curb it.
- 2015: the case for a Digital Armed Forces, and a critical evaluation of the National Cyber Security Policy, 2013.
- 2013: what cyber warfare means, India's cyber vulnerabilities, and the state of preparedness.
The statutory definition: the IT (Amendment) Act, 2008
The IT (Amendment) Act, 2008 defines cyber security as "protecting information, equipment, devices computer, computer resource, communication device and information stored therein from unauthorised access, use, disclosure, disruption, modification or destruction." The breadth is deliberate: it covers the device, the data and the channel together, so answers should treat cyber security as the protection of information and its communicating channels, not just of computers.
The four baskets of cyber threats
Analysts sort cyber threats into four baskets: espionage, crime, terrorism and warfare, with cyber extremism, the use of technology and the internet to promote and spread radical ideologies, sitting across all four. The definitions below are the standard taxonomy's own words.
Cyber espionage is "the use of computer networks to gain illicit access to confidential information, typically that held by a government or other organisation." Cyber crime is "any unlawful act where a computer or communication device or computer network is used to commit or facilitate the commission of a crime." Cyber terrorism is "the use of the Internet to attack critical infrastructure, financial systems, or data that cause fear, disruption, or coercion, in order to achieve political or ideological gains through threat or intimidation." Cyber warfare is "the use of computer technology to disrupt the activities of a state or organisation, especially the deliberate attacking of information systems for strategic or military purposes."
Cyber warfare: the fifth domain
Cyber warfare is treated as the fifth domain of warfare, after land, sea, air and space: organised units, delineated by national borders, conducting offensive and defensive manoeuvres through electronic means. The textbook illustration is the Stuxnet attack on Iran's nuclear programme, a sophisticated operation against industrial control systems. The comparison below is what examiners expect when they ask how cyber war differs from traditional war.
Feature | Traditional war | Cyber war |
|---|---|---|
Theatre | Bounded by geography. | Borderless; an independent theatre of its own. |
Attacker | Visible and attributable. | Disguised; attribution is the hard problem. |
Contact | Kinetic contact between forces. | Contactless. |
Deployment | Slow mobilisation of forces. | Rapid. |
Cost | Expensive platforms and logistics. | Low entry cost. |
Targets | Military first, then civilian. | Wide: power grids, banks, hospitals, data. |
Critical Information Infrastructure, defined
Critical Information Infrastructure is, in the standard definition, "the physical and cyber systems and assets that are so vital to a country that their incapacity or destruction would have a debilitating impact on national security and the economic and social welfare of a state." The policy insight is interdependence: power, telecom, banking, transport and health systems lean on each other, so a breach in one cascades into the others. Protecting this layer is NCIIPC's job as the national nodal agency under Section 70A of the IT Act.
Institutions at a glance
The institutional cluster is the table examiners reach for when they ask "who guards the grid". The legal homes matter: Section 70B creates CERT-In, Section 70A creates NCIIPC, and the MHA cluster fights cybercrime as crime.
Institution | Legal or administrative home | Core job |
|---|---|---|
CERT-In | Section 70B, IT Act 2000; MeitY. | National agency for cyber-incident response; the 2022 Directions require reporting of specified incidents within six hours. |
NCIIPC | Section 70A, IT Act 2000; under NTRO. | National nodal agency for protecting Critical Information Infrastructure. |
I4C | MHA; attached office since 2024. | Nodal body for cybercrime coordination; anchors the 1930 helpline and reporting ecosystem. |
NCCC | Intelligence establishment. | Operational hub screening metadata of cyber traffic for threat analysis. |
NCSC | PMO. | Apex coordination of national cyber-security policy. |
DCyA | Tri-service; raised 2019. | Cyber operations for defence networks. |
CyberDome | Kerala Police. | Technology centre for policing cybercrime. |
NATGRID | MHA. | Post-26/11 intelligence grid fusing data from 21 sources for counter-terror analysis. |
The 2013 policy's objectives
The National Cyber Security Policy, 2013 set seven objectives that remain the reference frame for every successor draft: a secure computing environment; a skilled cyber-security workforce; protection of critical information infrastructure; international cooperation on norms and incident response; cyber-security awareness among citizens and businesses; a designated national nodal agency; and stronger law-enforcement capacity. Its non-binding character is also its standard critique, the reason a National Cyber Security Strategy has been awaited.
DPDP stakeholders: who is who
The DPDP Act, 2023 is built on five roles. Knowing who owes what to whom is the difference between a generic privacy answer and a precise one.
Stakeholder | Role | Key duty or right |
|---|---|---|
Data Principal | The individual to whom the personal data relates. | Rights to information, correction and erasure, grievance redressal and nomination. |
Data Fiduciary | The person or entity that determines the purpose and means of processing. | Duties of notice and consent, reasonable security safeguards, breach intimation and retention discipline. |
Data Processor | Processes data on behalf of the fiduciary. | Acts within the fiduciary's instructions. |
Significant Data Fiduciary | Fiduciaries the government designates by volume, sensitivity and risk. | Extra duties: data protection officer, audits and data-protection impact assessments. |
Data Protection Board of India | The adjudicatory body under the Act. | Inquires into breaches; penalties up to Rs 250 crore. |
The UN Convention: cooperation machinery and the critique
The UN Convention against Cybercrime, adopted on 24 December 2024 by UNGA Resolution 79/243 and opened for signature at Hanoi on 25-26 October 2025, is the first comprehensive global cybercrime treaty. Its cooperation machinery is the mains point: a 24/7 contact network, mutual legal assistance and extradition for covered offences, joint investigations, sharing of electronic evidence, and recovery of the proceeds of cybercrime, alongside victim-support and capacity-building provisions.
The critique travels with the treaty. Analysts warn its definitions are broad enough for misuse by authoritarian regimes, with privacy and human-rights safeguards contested through the negotiations. India engaged actively in the talks and signed the Convention on 25 September 2026 on the UNGA sidelines. As of late September 2026, the UN treaty database showed over 90 signatories but only three ratifications, so the Convention had not yet entered into force: that takes the 40th ratification plus 90 days.
Key Terms
- Cyber security: Cyber security is the practice of protecting computers, networks, data and critical systems from theft, damage and disruption. For India it spans personal fraud, enterprise breaches and state-sponsored attacks on critical infrastructure. It matters because the economy and governance now run on digital rails. Example: Protecting the power grid from RedEcho-style intrusions.
- DPDP Act, 2023: The Digital Personal Data Protection Act, 2023 is India's first comprehensive data-privacy law, regulating how personal data is collected and processed, with a Data Protection Board and penalties up to Rs 250 crore. It exempts the state on sovereignty grounds. It matters as the legal spine of India's data economy. Example: Consent-based data processing mandated for tech platforms.
- Non-state actors: Non-state actors are individuals or groups that act across borders without being organs of a state, such as terrorist outfits, insurgent groups, organised crime syndicates, hacker collectives and diaspora extremist networks. They matter for internal security because they can strike inside a country while their sponsors keep deniability. The Resistance Front's claimed role in the Pahalgam attack shows how a front outfit masks state sponsorship. Example: The Resistance Front (TRF), D-Company.
- Operation Sindoor: Operation Sindoor is the codename for India's precision strikes on the night of 6-7 May 2025 against nine terror targets in Pakistan and Pakistan-occupied Kashmir, launched in response to the 22 April 2025 Pahalgam attack that killed 26 people. The strikes on LeT and JeM infrastructure at Muridke and Bahawalpur escalated into a four-day confrontation until a cessation understanding on 10 May. It marks a doctrinal shift in India's counter-terrorism response. Example: Strikes on Muridke and Bahawalpur, 7 May 2025.
- National Cyber Security Coordinator (NCSC): The National Cyber Security Coordinator, created in 2014 under the National Security Council Secretariat, coordinates cyber-security efforts across government and advises on policy. The NCSC oversees the national cyber-security strategy process. It matters as the apex coordination point for cyber policy. Example: NCSC's role in drafting the national cyber security strategy.
- National Cyber Coordination Centre (NCCC): The National Cyber Coordination Centre is the operational hub that scans the country's internet traffic for cyber threats and shares alerts with agencies and critical-sector operators. It matters as India's cyber-threat radar, generating the situational picture others act on. Example: NCCC's real-time scanning of malicious internet traffic.
- Cyber Multi-Agency Centre (CyMAC): The Cyber Multi-Agency Centre, established by the MHA on 22 January 2025 under the MAC platform, coordinates cyber agencies including IB, CERT-In, I4C, NCIIPC and the Defence Cyber Agency. It handles cyber espionage, cyber terrorism and misuse of emerging tech. It matters as the fusion hub for national cyber defence. Example: Joint IB-CERT-In-I4C coordination through CyMAC.
- CERT-In (the Indian Computer Emergency Response Team): CERT-In is India's national nodal agency for responding to cybersecurity incidents, functioning under MeitY since 2004. It issues alerts and advisories, coordinates incident response, and since 2022 mandates that service providers report breaches within six hours. It matters as the first responder and rule-setter of India's cyber incident architecture. Example: CERT-In's six-hour breach-reporting mandate for service providers.
- Cyber Swachhta Kendra: Cyber Swachhta Kendra, the Botnet Cleaning and Malware Analysis Centre, is MeitY's facility that detects botnet infections and notifies users to clean their devices with free tools. It matters as the citizen-facing arm of cyber hygiene, reducing the pool of compromised Indian devices. Example: Free botnet-removal tools offered to infected users.
- CSIRT-Fin: CSIRT-Fin is the Computer Security Incident Response Team for the financial sector, set up under CERT-In to handle cyber incidents affecting banks and financial institutions. It matters because financial-sector breaches have systemic consequences. Example: Coordinated response to a bank's malware incident.
- Indian Cyber Crime Coordination Centre (I4C): The Indian Cyber Crime Coordination Centre is the MHA's nodal body for cybercrime, set up in 2018 and made an attached office of the Ministry in 2024. It runs the 1930 helpline, the National Cybercrime Reporting Portal and the Pratibimb module that maps criminals' locations. It matters as the operational hub of India's fight against cyber fraud and online radicalisation. Example: The 1930 helpline and cybercrime.gov.in portal run by I4C.
- 1930 helpline: The 1930 helpline is the national toll-free number for reporting cyber financial fraud, run by I4C. Quick reporting lets police freeze fraudulent transactions before money is withdrawn. It matters as the single national number every fraud victim should know. Example: Victims dialling 1930 to freeze siphoned funds.
- Defence Cyber Agency (DCyA): The Defence Cyber Agency is the tri-service agency raised in 2019 to conduct cyber operations for the armed forces, headquartered in Delhi. It matters as the military's dedicated cyber arm, distinct from civilian agencies. Example: The tri-service cyber command supporting military operations.
- Telecom Security Operations Centre: The Telecom Security Operations Centre is the Department of Telecommunications' facility for monitoring telecom network security and responding to threats against communication infrastructure. It matters because telecom networks are both critical infrastructure and a vector for fraud. Example: DoT's monitoring of telecom network intrusions.
- Sanchar Saathi: Sanchar Saathi is the Department of Telecommunications' citizen portal for reporting lost or stolen phones, blocking IMEIs, and checking fraudulent mobile connections issued in one's name. It matters as the front line against SIM-based cyber fraud. Example: Blocking a stolen phone's IMEI through Sanchar Saathi.
- National Critical Information Infrastructure Protection Centre (NCIIPC): The National Critical Information Infrastructure Protection Centre is the national nodal agency for protecting Critical Information Infrastructure, created under Section 70A of the IT Act and functioning under the National Technical Research Organisation. It identifies critical sectors like power, banking and telecom and coordinates their cyber defence. It matters because attacks on these sectors can paralyse the economy. Example: NCIIPC's protection mandate over power-grid and banking networks.
- Data Protection Board of India: The Data Protection Board of India is the statutory adjudicatory body created under the Digital Personal Data Protection Act, 2023. It inquires into data breaches and non-compliance, directs remedial action, hears grievances of data principals, and can impose significant financial penalties. It matters for UPSC as the enforcement arm of India's first comprehensive data privacy law, linking the right to privacy to digital governance.
- Maya OS: Maya OS is the Defence Ministry's indigenous Ubuntu-based operating system, developed by DRDO, C-DAC and NIC to replace Windows on internet-facing defence computers. Bundled with the Chakravyuh endpoint security suite, it counters malware targeting foreign software. It matters as India's software-sovereignty push in defence. Example: Defence Ministry terminals migrating from Windows to Maya OS.
- Chakravyuh: Chakravyuh is the endpoint anti-malware and security suite bundled with Maya OS, creating a protective layer that traps lateral movement by advanced attackers. Named after the Mahabharata's impregnable battle formation, it is part of the Defence Ministry's indigenisation drive. It matters as the defensive shield of India's military computing. Example: Chakravyuh blocking APT lateral movement on defence systems.
- Bharat 6G Vision: Bharat 6G Vision is the Department of Telecommunications' 2023 roadmap for India's leadership in sixth-generation telecom, targeting 6G rollout by 2030 with indigenous technology. It matters because telecom standards shape both economic competitiveness and national security. Example: The 2023 vision document targeting indigenous 6G by 2030.
- Section 66A: Section 66A of the IT Act, 2000 criminalised sending offensive online messages, but the Supreme Court struck it down in Shreya Singhal (2015) for violating free speech. It matters as the landmark case that defined the limits of online-speech regulation in India. Example: The provision voided for chilling free expression online.
- Shreya Singhal v. Union of India (2015): Shreya Singhal v. Union of India is the 2015 Supreme Court judgment that struck down Section 66A of the IT Act as unconstitutional for vagueness and overbreadth. It upheld Section 69A blocking with safeguards. It matters as the foundational precedent balancing free speech and online regulation. Example: The ruling that voided Section 66A.
- National Cyber Security Policy (NCSP), 2013: The National Cyber Security Policy, 2013 was India's first cyber-security policy, aiming to build a secure cyber ecosystem, create 5 lakh professionals and protect critical infrastructure. Non-binding and now dated, it was never replaced by a notified successor strategy. It matters as the starting point of India's cyber-policy architecture. Example: The 2013 policy's target of five lakh cyber professionals.
- National Cyber Security Strategy (NCSS), 2021: The National Cyber Security Strategy, 2021 is the draft strategy prepared by the National Security Council Secretariat to update the 2013 policy for the age of 5G, cloud and state-sponsored attacks. It was never formally notified, leaving a strategy gap critics flag. It matters as the missing link in India's cyber architecture. Example: The unreleased successor to the 2013 cyber policy.
- Open-Ended Working Group: The Open-Ended Working Group is the UN forum, established in 2018, where all states negotiate norms for responsible state behaviour in cyberspace. India participates actively. It matters because cyber norms, unlike treaties, are being written in such consensus forums. Example: UN negotiations on state behaviour in cyberspace.
- QUAD: Quad is the strategic dialogue of India, the United States, Japan and Australia, aimed at a free and open Indo-Pacific. It is not a formal military alliance but a flexible platform for cooperation on maritime security, critical technologies, supply chains and humanitarian assistance. For UPSC, it exemplifies India's multi-alignment: deepening US partnership while preserving strategic autonomy and engaging China-adjacent security concerns without a treaty commitment. Example: The first Quad Leaders' Summit, held virtually in March 2021, which launched working groups on vaccines, climate and critical tech..
- Tallinn Manual 2.0: Tallinn Manual 2.0 is the 2017 academic restatement of how international law applies to cyber operations, prepared by experts at NATO's cyber defence centre. Though not binding, it is the most cited reference on cyber warfare law. It matters for debates on when a cyberattack amounts to use of force. Example: The expert manual on international law and cyber operations.
- Budapest Convention on Cybercrime (2001): The Budapest Convention on Cybercrime, 2001 is the Council of Europe treaty harmonising cybercrime laws and enabling cross-border evidence sharing. India has not signed it, objecting that it was drafted without developing-country participation and allows cross-border data access infringing sovereignty. It matters as the treaty India deliberately stays out of. Example: The cybercrime treaty India declined over sovereignty concerns.
- United Nations Convention against Cybercrime: The United Nations Convention against Cybercrime is the first comprehensive global cybercrime treaty, adopted by the UN General Assembly in December 2024 after five years of negotiation. It provides for cross-border electronic-evidence sharing and cooperation. India signed it on 25 September 2026. It matters as the new global rulebook India has now joined. Example: The 2024 UN treaty on cross-border cybercrime cooperation.
- Hanoi Convention: The Hanoi Convention is the popular name for the UN Convention against Cybercrime, opened for signature in Hanoi in October 2025. As of September 2026 it had not yet entered into force, which requires 40 ratifications. It matters as the treaty set to govern global cybercrime cooperation. Example: The cybercrime treaty opened for signature at Hanoi in 2025.
- Section 43: Section 43 of the IT Act, 2000 provides civil penalties for unauthorised access, data theft and damage to computer systems. It matters as the workhorse provision for everyday hacking and data-theft cases. Example: Penalties for unauthorised access to a company's servers.
- Section 66: Section 66 of the IT Act, 2000 punishes computer-related offences committed dishonestly or fraudulently, such as hacking to commit fraud, with imprisonment. It matters as the criminal counterpart to Section 43's civil penalties. Example: Criminal prosecution for hacking into bank accounts.
- National Cyber Crime Reporting Portal: The citizen portal (cybercrime.gov.in) run under I4C for reporting financial fraud, social-media crimes, hacking, ransomware and crimes against women and children, the last through an anonymous track. Complaints route to the concerned state or UT police. Example: the portal is the reporting front end of the I4C enforcement architecture.
- Citizen Financial Cyber Fraud Reporting and Management System: The I4C system triggered by the 1930 helpline that instantly alerts banks, wallets and payment gateways to lien-mark suspect accounts and freeze siphoned money within the golden hour. Example: the system is credited with saving thousands of crores across nearly ten lakh complaints.
- Critical Information Infrastructure: Critical Information Infrastructure is the physical and cyber systems and assets so vital to a country that their incapacity or destruction would have a debilitating impact on national security and economic and social welfare. Example: power grids, banking networks and telecom systems protected by NCIIPC.
- Cyber warfare: Cyber warfare is the use of computer technology to disrupt the activities of a state or organisation, especially the deliberate attacking of information systems for strategic or military purposes, treated as the fifth domain of warfare. Example: the Stuxnet operation against Iran's nuclear programme.
- Cyber espionage: Cyber espionage is the use of computer networks to gain illicit access to confidential information, typically that held by a government or other organisation. Example: state-backed intrusions into defence or research networks.
- Cyber terrorism: Cyber terrorism is the use of the Internet to attack critical infrastructure, financial systems or data to cause fear, disruption or coercion for political or ideological gains. Example: ideological attacks on power grids or banking systems.
- Data Fiduciary: A Data Fiduciary is the person or entity that determines the purpose and means of processing personal data under the DPDP Act, 2023. Example: a bank or e-commerce platform deciding why and how customer data is used.
- Data Principal: A Data Principal is the individual to whom personal data relates under the DPDP Act, 2023, holding rights to information, correction, erasure, grievance redressal and nomination. Example: a user demanding deletion of their account data.
- Data Processor: A Data Processor is the entity that processes personal data on behalf of a Data Fiduciary under the DPDP Act, 2023. Example: a cloud vendor storing customer data for a bank.
- Significant Data Fiduciary: A Significant Data Fiduciary is a fiduciary designated by the government based on the volume, sensitivity and risk of the data it processes, carrying extra duties under the DPDP Act, 2023. Example: large social-media platforms required to appoint a data protection officer and conduct audits.
Practice questions
With reference to the Indian Computer Emergency Response Team (CERT-In), consider the following statements:
1. It is the national nodal agency for cyber incident response under Section 70B of the Information Technology Act, 2000.
2. Its Directions of 2022 mandate reporting of cyber incidents within six hours.
3. It functions under the Ministry of Home Affairs.
Which of the statements given above is/are correct?
Show answer
Answer: (A) CERT-In is under MeitY, not the MHA; its 70B mandate and six-hour rule are correct.
With reference to the Digital Personal Data Protection Act, 2023, consider the following statements:
1. A Data Fiduciary is the person or entity that determines the purpose and means of processing personal data.
2. The Act provides for penalties extending up to Rs 250 crore for failure to take reasonable security safeguards.
3. The Data Protection Board of India is the adjudicating authority under the Act.
Which of the statements given above is/are correct?
Show answer
Answer: (C) All three statements correctly describe the DPDP Act's fiduciary model, penalty ceiling and Board.
Which of the following pairs of provisions of the Information Technology Act, 2000 is/are correctly matched?
1. Section 43 : Civil liability for unauthorised access to computer systems
2. Section 66F : Punishment for cyber terrorism
3. Section 79 : Safe harbour for intermediaries
Select the correct answer using the code given below:
Show answer
Answer: (D) Section 43 is civil, 66F is cyber terrorism, and 79 is intermediary safe harbour.
With reference to the United Nations Convention against Cybercrime (Hanoi Convention), consider the following statements:
1. It was opened for signature at Hanoi in October 2025.
2. It is the first comprehensive global treaty on cybercrime.
3. India was among the first-day signatories at the Hanoi ceremony.
Which of the statements given above is/are correct?
Show answer
Answer: (A) India skipped the Hanoi opening ceremony and signed a year later, in September 2026.
With reference to the National Critical Information Infrastructure Protection Centre (NCIIPC), consider the following statements:
1. It protects Critical Information Infrastructure across sectors such as power, banking, telecom and transport.
2. It was designated as the national nodal agency under Section 70A of the Information Technology Act, 2000.
3. It functions under the Ministry of Home Affairs.
Which of the statements given above is/are correct?
Show answer
Answer: (A) NCIIPC functions under the National Technical Research Organisation, not the MHA.
Answer key
- Q1: (a). CERT-In is under MeitY, not the MHA; its 70B mandate and six-hour rule are correct.
- Q2: (c). All three statements correctly describe the DPDP Act's fiduciary model, penalty ceiling and Board.
- Q3: (d). Section 43 is civil, 66F is cyber terrorism, and 79 is intermediary safe harbour.
- Q4: (a). India skipped the Hanoi opening ceremony and signed a year later, in September 2026.
- Q5: (a). NCIIPC functions under the National Technical Research Organisation, not the MHA.
Mains Practice question
Q. Describe the context and salient features of the Digital Personal Data Protection Act, 2023. (150 words, 10 marks)
Framing hintLocate the Act in the Puttaswamy (2017) right-to-privacy lineage and the Srikrishna Committee report; then list features in tight clusters rather than as a flat dump.
- Context: Puttaswamy recognised privacy under Article 21; Justice B. N. Srikrishna Committee (2018) recommended a data-protection law; assent on 11 August 2023.
- Core model: consent-based processing; Data Principals (individuals) with rights of access, correction, erasure, grievance redressal and nomination; Data Fiduciaries with purpose-limitation and security duties; Significant Data Fiduciaries with extra obligations.
- Enforcement: Data Protection Board of India; breach notification; penalties up to Rs 250 crore; cross-border transfers allowed except to notified countries.
- Rules, 2025: notified 13 November 2025; phased rollout, substantive duties enforceable from around May 2027.
- Critique: broad state exemptions on sovereignty and security grounds; executive-heavy design; conclude with the privacy-security balance.
Q. Keeping in view India's internal security, analyse the impact of cross-border cyber-attacks and discuss defensive measures against these sophisticated attacks. (250 words, 15 marks)
Framing hintDefine cross-border cyber-attacks first, split the body into impact and defence, and close with one institutional reform.
- Definition: state-sponsored or proxy attacks from foreign jurisdictions; nearly 60% of 2025 attacks traced to the China-Pakistan axis.
- Impacts: critical-infrastructure sabotage (Mumbai grid 2020, AIIMS 2022); espionage (APT41, ShadowPad); data weaponisation; economic fraud; disinformation during operations like Sindoor.
- Defensive layers: institutions (CERT-In, NCIIPC, DCyA, NCCC, CyMAC); legal (IT Act, 66F, 69A blocking); indigenous stack (Maya OS, Chakravyuh); hygiene (Sanchar Saathi, Cyber Swachhta Kendra).
- Global layer: OEWG norms, QUAD, Hanoi Convention signature (Sept 2026).
- Close: the missing pieces are a unified cyber command and a binding strategy.
Q. What are the different elements of cyber security? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy. (250 words, 15 marks)
Framing hintAnswer in two halves: first enumerate the elements, then audit the strategy against its own objectives.
- Elements: network, information, application, endpoint, cloud, operational and critical-infrastructure security; forensics, disaster recovery, cyber law.
- What exists: NCSP 2013; CERT-In, NCIIPC, I4C, DCyA; IT Act plus DPDP Act; GCI 2024 Tier-1 (98.49/100).
- Extent of success: Tier-1 status, falling attack costs for defenders, mass-reporting tools; but NCSS 2021 still pending; fragmented mandates; 380,000 professionals against 1.2 million demand.
- Challenges: outdated IT Act, no mandatory CII standards, weak state readiness, thin public-private sharing, under-reporting, poor hygiene.
- Verdict: an institution-rich but strategy-poor architecture; conclude with the unified-command and binding-strategy asks.
Frequently asked questions
What is the difference between Section 43 and Section 66 of the IT Act, 2000?
Section 43 creates civil liability: anyone who accesses a computer system without permission, steals data, introduces a virus or damages the system must compensate the victim, and no dishonest intent has to be proved. Section 66 is the criminal mirror: the same acts become punishable with up to three years' imprisonment or a Rs 5 lakh fine when done dishonestly or fraudulently. The same act can attract both, compensation for the victim and punishment for the offender.
What is the Budapest Convention, and why has India not signed it?
The Budapest Convention on Cybercrime (2001) is the Council of Europe's treaty on harmonising cybercrime law and cross-border evidence sharing. India has refused to accede for over two decades because provisions such as Article 32(b) would let foreign authorities access data stored on Indian servers without domestic authorisation, which New Delhi treats as a sovereignty and privacy red line. The Hanoi Convention was partly India's preferred alternative, and its non-membership in Budapest is why cross-border evidence gathering remains slow.
What is the current status of the Hanoi Convention?
The United Nations Convention against Cybercrime was adopted in December 2024 and opened for signature in Hanoi on 25-26 October 2025. India signed on 25 September 2026. As of 25 September 2026 it has 91 signatories but only three parties (Qatar, Azerbaijan and Vietnam), so it has not yet entered into force: entry requires 40 ratifications, after which it takes effect 90 days later. India's signature signals intent; domestic ratification procedures must follow before it is fully bound.
Does the DPDP Act, 2023 bind the government as well?
Formally yes, but with wide carve-outs. The Act exempts the State from several provisions where processing is necessary for sovereignty, integrity and security of India, friendly relations with foreign states, maintenance of public order, or preventing incitement to cognisable offences. Critics argue these exemptions are drafted broadly and lack independent oversight, which is the central privacy-versus-security tension in the law, and a ready-made critical point for mains answers.
Asked in the mains
Previous-year questions from this topic
How UPSC has actually asked this topic — with the year and marks for each question.
- 202410 marks
Describe the context and salient features of the Digital Personal Data Protection Act, 2023.
- 202210 marks
What are the different elements of cyber security? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy.
- 202110 marks
Keeping in view India’s internal security, analyze the impact of cross-border cyber-attacks. Also discuss defensive measures against these sophisticated attacks.
- 202010 marks
Discuss different types of cybercrimes and measures required to be taken to fight the menace.
- 201910 marks
What is the Cyber Dome Project? Explain how it can be useful in controlling internet crimes in India.