Opens in a new tab
Join Anantam IAS Channel on Telegram

Cyber Security in India: Threats, Laws & Framework

Complete UPSC guide to cyber security in India. Covers IT Act 2000, CERT-In, NCIIPC, National Cyber Security Policy, cyber threats (ransomware, phishing), Digital Personal Data Protection Act 2023, and GS III notes.

Cyber Security in India: Defending a Digital Republic

For nearly two weeks in November 2022, the largest public hospital in the country ran on paper. A ransomware attack had locked roughly a hundred servers at AIIMS Delhi, knocked out the eHospital system, and pushed emergency, outpatient and laboratory work back to handwritten registers. Tens of millions of patient records sat encrypted behind a criminal demand. Delhi Police eventually invoked the cyber-terrorism section of the law and traced network addresses abroad. No bombs, no border crossing, no troops. Just a piece of malware, and a national institution brought to its knees.

That is what internal security looks like in a digital republic. India now runs the world’s largest stack of digital public infrastructure, more than a billion biometric identities, a real-time payments network that clears tens of billions of transactions a month, and government services delivered straight to phones. All of it depends on networks that an adversary can attack from anywhere, at almost no cost, with deniability built in. The stakes aren’t abstract. They are your savings, your hospital, your power supply, and the data the state holds on you.

The Challenge, Framed

Cyber security is the practice of protecting computers, networks and data from attack, damage or unauthorised access. In the security-studies sense it sits at the meeting point of crime, espionage, sabotage and warfare, which is exactly what makes it hard to govern. A bank fraud, a foreign intelligence operation, and an attempt to switch off a power grid can all arrive through the same email attachment. The defender has to be right every time. The attacker has to be lucky once.

What makes it an internal-security problem, and not just an IT problem, is scale and target. India’s push to digitise welfare, banking, health and identity has been spectacularly successful, and that success is also the attack surface. When a country moves its pensions, its medical records and its money online, every one of those systems becomes something worth attacking, and the people most exposed are often the least equipped to defend themselves. So the question for the state is no longer whether to be digital. It’s how to stay digital without being defenceless.

The threats break into a few rough buckets. There’s high-volume cyber crime, mostly financial fraud aimed at ordinary citizens. There’s ransomware and data theft aimed at hospitals, companies and government bodies. There’s the targeting of critical information infrastructure, the networks that run power, banking, telecom and transport. And there’s state-sponsored espionage and sabotage, where the line between a criminal gang and a hostile government is deliberately blurred. India faces all four at once.

The Threat Landscape

Start with the raw volume, because it tells the story. The Indian Computer Emergency Response Team, CERT-In, the national agency that tracks and coordinates responses to cyber incidents, handled about 13.9 lakh incidents in 2022, around 15.9 lakh in 2023, and more than 20.4 lakh in 2024. That’s a rise of close to half in two years, and crossing two million in a single year. And these are only the reported ones. Most security professionals will tell you the real number is far higher, because smaller firms and many organisations simply don’t disclose breaches.

The financial damage is where it stops being a chart and starts being personal. The government told Parliament in 2025 that Indians lost Rs 22,845 crore to cyber fraud in 2024, a jump of about 206% over the roughly Rs 7,465 crore lost in 2023. Behind that figure sit more than 36 lakh financial-fraud complaints filed in a single year on the national reporting system. A great deal of it flows through the payments rails: fake links, spoofed bank calls, and “verification” requests that drain a UPI account in seconds.

Two patterns inside that number are worth naming, because examiners and policymakers both keep returning to them. The first is the “digital arrest” scam, where fraudsters posing as police or central agencies hold a victim on a video call, accuse them of a crime, and frighten them into transferring money. Reported cases of this single con rose by more than 100% to over 1.2 lakh in 2024, with losses up several-fold. The second is the industrialised use of “mule accounts”, bank accounts rented or stolen to launder the proceeds. The Indian Cyber Crime Coordination Centre has flagged roughly 24 lakh such accounts through its suspect registry. And a striking share of the fraud is run from outside the country: nearly half the cyber frauds reported in early 2024 were traced to scam compounds in Cambodia, Laos and Myanmar, where trafficked workers, some of them Indians lured by fake jobs, are forced to defraud people back home.

Then there’s the heavier end. Ransomware, which locks an organisation’s data until it pays, has been climbing across sectors, and CERT-In’s own reporting flagged a sharp rise even before the AIIMS attack made headlines. Attacks on critical information infrastructure, the systems behind power, finance, telecom and health, are the ones that keep planners awake, because a successful one doesn’t just cost money, it can cost lives or cause a blackout. And layered over all of it is state-sponsored activity. Security researchers have repeatedly attributed intrusions against Indian power and government networks to actors linked to hostile states. The hard part, always, is attribution: proving who did it, to a standard you can act on, when the whole point of a cyber operation is to leave no fingerprints.

Bar chart of CERT-In tracked cyber incidents rising from 13.9 lakh in 2022 to 15.9 lakh in 2023 to 20.4 lakh in 2024
Reported incidents crossed two million in 2024, and the true figure is almost certainly higher.
Data card showing Rs 22,845 crore lost to cyber fraud in 2024, a 206 percent rise, with digital-arrest cases above 1.2 lakh and roughly 24 lakh mule accounts
The fraud economy in one frame: the loss is large, organised, and increasingly run from across the border.

India’s Institutional Response

India hasn’t been idle, and the architecture it has built is genuinely substantial, even if it’s scattered. The anchor is the Information Technology Act of 2000, amended in 2008, which remains the primary cyber law. It criminalises hacking and data theft under Section 66, defines cyber terrorism under Section 66F, the provision invoked in the AIIMS case, governs lawful interception under Section 69, and creates the framework for protecting critical systems and the agencies that run it.

CERT-In is the operational heart of incident response. Set up under Section 70B of the IT Act and housed in the Ministry of Electronics and Information Technology, it issues alerts, coordinates responses, and runs national drills. Its most consequential move came in April 2022, when it issued directions requiring any service provider, intermediary or data centre to report defined cyber incidents within six hours of becoming aware of them, to retain system logs for 180 days within India, and obliging VPN and cloud providers to keep customer records. The six-hour rule is one of the strictest reporting timelines in the world, and it remains contested by industry as onerous, which is part of the story.

For the systems that matter most, there’s the National Critical Information Infrastructure Protection Centre, NCIIPC, created under Section 70A and notified in 2014 as the national nodal agency for protecting critical information infrastructure, the networks whose failure would have, in the law’s own words, a debilitating impact on national security, the economy or public health. It sits under the National Technical Research Organisation, and through it the government can declare a system a “protected system” with hardened legal safeguards.

On the crime side, the Ministry of Home Affairs runs the Indian Cyber Crime Coordination Centre, I4C, a seven-part scheme that ties together a threat-analytics unit, forensic labs, a training centre and, crucially for citizens, the National Cyber Crime Reporting Portal and the helpline 1930. When you call 1930 after a fraud, you’re plugging into a system that links more than 260 banks and intermediaries and can, if you act fast, freeze the money before it’s withdrawn. That citizen-facing layer is arguably India’s most visible cyber-security success.

The newer pieces fill specific gaps. The Digital Personal Data Protection Act, passed in 2023, finally gives India a dedicated privacy law; its rules were notified in November 2025 and roll out in phases, establishing a Data Protection Board and, over the following 18 months, the substantive obligations on how organisations handle personal data. On capacity, Cyber Surakshit Bharat, launched by the ministry in 2018 as a public-private partnership, trains government chief information security officers. And in defence, the tri-service Defence Cyber Agency, stood up around 2019 under the Chief of Defence Staff, gives the armed forces a dedicated, if still modest, cyber arm. Strategic direction is meant to come from the National Cyber Security Coordinator in the National Security Council Secretariat.

Where the System Falls Short

For all of that, the honest assessment is that India’s cyber defence is better at responding than at preventing, and better on paper than in practice. The gaps are structural, and worth stating plainly.

Start with fragmentation. Count the agencies again: CERT-In under MeitY, NCIIPC under the NTRO and the PMO, I4C under Home Affairs, the Defence Cyber Agency under the military, the coordinator under the National Security Council. Five centres of gravity across four ministries, with overlapping mandates and no single accountable owner. When an attack crosses domains, as serious ones always do, it can fall between desks. A unified national authority with clear command has been recommended for years and still doesn’t exist.

Then there’s the strategy that never arrived. India’s working policy document is still the National Cyber Security Policy of 2013, written before UPI, before mass smartphone adoption, before generative AI. A National Cyber Security Strategy was drafted by a task force around 2020 and has been “awaiting approval” ever since. Running a two-million-incident-a-year threat environment on a 2013 framework is like defending a 2026 city with a 2013 map.

The law is dated too. The IT Act predates ransomware-as-a-service, deepfakes, crypto laundering and AI-driven fraud, and amending it case by case has produced a patchwork rather than a coherent code. The new data-protection law helps, but its long phase-in means full enforcement is still some way off, and critics worry its broad exemptions for the government tilt the balance toward the state.

Diagram mapping CERT-In, NCIIPC, I4C, the Defence Cyber Agency and the National Cyber Security Coordinator across four different ministries and the PMO
Five agencies, four ministries, one threat: the coordination problem is the core weakness.

The capacity gap is just as serious. By widely cited industry estimates India needs around a million cyber-security professionals and has roughly half that, a talent shortfall of close to 50% at a time when nearly every large firm reports being attacked. Incident reporting is still slow and patchy, especially among smaller organisations that fear reputational damage more than the breach itself. And underneath it all runs the hardest tension of all, the one between security and rights. The same powers that let the state intercept a terrorist’s communications can be turned on a journalist or an activist. Broad surveillance authority, weak independent oversight, and a data-protection regime with wide government carve-outs are a genuine concern in a constitutional democracy. The right answer is not to weaken security. It is to pair it with proportionality, judicial oversight and transparency, so that protecting the republic doesn’t quietly erode the freedoms the republic exists to protect.

The Way Forward

  1. Adopt and publish a National Cyber Security Strategy that replaces the 2013 policy, sets measurable targets, and clearly divides responsibilities among the existing agencies instead of adding another one.
  2. Move toward a single, empowered national cyber-security authority, or at minimum a statutory coordinator with real budget and command, so that cross-domain attacks have one accountable owner.
  3. Modernise the law. Update or replace the IT Act to cover ransomware, deepfakes, AI-enabled fraud and crypto, and operationalise the Digital Personal Data Protection Act quickly, with independent oversight of state access.
  4. Close the skills gap with scale, expanding cyber-security education, certification and the Cyber Surakshit Bharat model from government CISOs down to police and small businesses.
  5. Harden critical information infrastructure with mandatory baseline standards, regular audits and red-team drills for power, finance, health and telecom, treating a hospital’s servers as seriously as its oxygen supply.
  6. Strengthen the citizen front line. The 1930 helpline and reporting portal work, so resource them better, cut response times, and pair them with relentless public awareness on UPI fraud and digital-arrest scams.
  7. Build the rights safeguards in from the start, with proportional surveillance, judicial or independent authorisation, and breach transparency, so that capability and accountability grow together.
  8. Invest in deterrence and diplomacy, building credible defensive and offensive cyber capability while working through international forums on norms, attribution and cross-border action against scam compounds.

For Your Mains Answer

This topic sits squarely in GS Paper 3 under “challenges to internal security through communication networks, role of media and social networking sites in internal security challenges, basics of cyber security.” It also reaches into GS2 on government policies and the rights-versus-security debate, and it’s a ready-made example for the Essay paper on technology and society. Treat it as a place to show balance: name the security imperative and the civil-liberties concern in the same breath, and you signal maturity.

How to Build the Answer

Open with scale, not adjectives. Lead with one hard number, the two-million-plus incidents in 2024 or the Rs 22,845 crore lost to fraud, then frame why a digitising India is uniquely exposed. Move through the threat types, the institutional response naming the actual agencies and laws, the gaps, and a forward-looking close. Examiners reward a candidate who can name CERT-In, NCIIPC and I4C correctly and say what each one does, rather than writing “the government has taken several steps.”

Common Mistakes to Avoid

Don’t confuse the agencies, CERT-In does incident response, NCIIPC protects critical infrastructure, I4C handles cyber crime. Don’t treat cyber security as purely technical and forget the rights dimension. Don’t fear-monger or name specific countries as attackers without hedging, attribution is genuinely hard. And don’t claim the National Cyber Security Strategy exists, it’s still the 2013 policy in force, with the newer strategy awaiting approval.

A Compact Answer Spine

Digital India’s success is also its attack surface → scale of the threat (2 million-plus incidents in 2024; Rs 22,845 crore fraud loss) → four threat types: mass fraud, ransomware, critical-infrastructure attacks, state-sponsored espionage → institutional response (IT Act 2000, CERT-In and its 6-hour rule, NCIIPC, I4C and helpline 1930, DPDP Act 2023, Defence Cyber Agency) → gaps (fragmentation across five agencies, no adopted strategy, dated law, manpower shortfall, rights tension) → way forward (strategy, unified authority, modern law, skills, hardened CII, citizen front line, rights safeguards).

Diagram or Flowchart Idea

Draw a simple org map: a central “National Cyber Security” box branching to five nodes, CERT-In (MeitY), NCIIPC (NTRO/PMO), I4C (MHA), Defence Cyber Agency (military), and the National Cyber Security Coordinator (NSCS). Label the branches with their ministries to make the fragmentation visible at a glance, and your gaps paragraph writes itself.

The Rights-and-Security Balance Angle

The sophisticated line, worth a sentence in your conclusion, is that cyber security and civil liberties are not a trade-off to be won by one side. The same interception powers that stop a terrorist can chill a free press, so the test of a mature framework is proportionality and independent oversight, not maximum power. Cite the Puttaswamy privacy judgment and the wide government exemptions in the data law to ground the point.

How to Use Data Without Overclaiming

Anchor with two or three figures, not ten, and attribute them, “CERT-In tracked over 2 million incidents in 2024” and “the government told Parliament that cyber-fraud losses reached Rs 22,845 crore in 2024.” Round confidently, hedge honestly, and flag underreporting rather than pretending the official number is the whole truth. That reads as judgement, which is exactly what the examiner is grading.

FAQ

What is CERT-In and what does it do? CERT-In, the Indian Computer Emergency Response Team, is the national agency for responding to cyber-security incidents, set up under Section 70B of the IT Act and housed in the Ministry of Electronics and Information Technology. It issues alerts, coordinates incident response, runs security drills, and tracks national incident data, more than two million reported incidents in 2024. Its 2022 directions require organisations to report defined incidents within six hours and retain logs for 180 days.

How big is India’s cyber-fraud problem? Large and growing fast. The government told Parliament that Indians lost about Rs 22,845 crore to cyber fraud in 2024, a roughly 206% jump over 2023, across more than 36 lakh financial-fraud complaints. Digital-arrest scams and “mule” bank accounts drive much of it, and a significant share is run from scam compounds in Southeast Asia. The 1930 helpline and the national reporting portal are the main tools for victims to freeze stolen money quickly.

Which laws govern cyber security in India? The primary law is the Information Technology Act of 2000, amended in 2008, which covers hacking, cyber terrorism, interception and critical-infrastructure protection. The Digital Personal Data Protection Act of 2023, with rules notified in November 2025, adds a dedicated privacy and data-protection regime that rolls out in phases. The working strategy document is still the National Cyber Security Policy of 2013, since a newer National Cyber Security Strategy has been drafted but not yet adopted.

Why is India’s cyber-security framework considered fragmented? Because responsibility is split across at least five bodies in four ministries: CERT-In under MeitY for incident response, NCIIPC under the NTRO for critical infrastructure, I4C under the Home Ministry for cyber crime, the Defence Cyber Agency under the military, and the National Cyber Security Coordinator in the National Security Council. There is no single accountable authority, so serious attacks that cross domains can fall between agencies, which is why a unified national authority and an adopted national strategy are the most commonly recommended reforms.

Tell Google you want more of this.

Add Anantam IAS as a preferred source

One tap, and this site shows up more often in your own Top Stories, AI Overviews and AI Mode. Remove it any time.

Share this

PDF

Vaibhav Mishra Sir

Written by

Vaibhav Mishra Sir

Faculty — Polity & Governance · Anantam IAS

Vaibhav Mishra teaches Polity and Governance at Anantam IAS. He breaks the Indian Constitution down article-by-article, connects polity static matter to contemporary governance debates, and trains students to write Mains answers that cite the right articles, schedules and case law.

Specialises in · Indian polity, constitution and governance Experience · 10+ years Visit website ↗

Preparing for UPSC CSE 2026? Sit in a free demo class.

No sales call. No brochure. Watch a real Monday-morning GS session taught by ex-Rau's IAS faculty.