UPSC CSE 2026 Essay Paper Discussion
GS Paper 3 10 marks · 150w 9 min Medium

Cybersecurity is now a national-security priority as critical infrastructure goes digital. Examine India’s institutional and legal framework and the gaps in protecting CIIs.

Subtopic: Security · Cybersecurity

Model answer outline

How to structure your answer

Introduction: CERT-In reported over 22 lakh cyber incidents in 2024 (Annual Report); India ranked 10th in ITU Global Cybersecurity Index 2024 (Tier 1).

Body: 1) Institutions — CERT-In (MeitY), NCIIPC under NTRO, I4C under MHA, NCSC, Defence Cyber Agency. 2) Laws — IT Act 2000, DPDP Act 2023, Section 70 CII regime, draft Digital India Act. 3) Gaps — sector-specific CSIRTs limited, attribution lag, OT and IoT exposure.

Way forward: Operationalise Digital India Act; expand NCIIPC sectoral coverage; mandate PQC migration timeline per CERT-In; ratify Budapest Convention dialogue.

Full model answer

Written within the word limit

128 words · target 150 words · 9 min

Introduction: CERT-In recorded 15.92 lakh cybersecurity incidents in 2024 (MeitY Lok Sabha reply, March 2025); AIIMS Delhi ransomware (November 2022) and SpiceJet (2022) exposed critical-infrastructure vulnerability.

Body: India's framework rests on the IT Act 2000 (Sections 66, 70 for CII), CERT-In Rules 2013, the National Cyber Security Policy 2013, and NCIIPC under NTRO. The DPDP Act 2023, BNS 2023 (Sections 111, 318 on cyber-fraud) and the proposed Digital India Act will replace IT Act 2000. CERT-In's six-hour reporting mandate (April 2022) and the National Cybersecurity Strategy (draft, PMO since 2020) await notification. Gaps: only seven sectoral CSIRTs operational, low cyber-insurance penetration, a 7.9 lakh-professional talent deficit (NASSCOM 2024), and no active-defence law for cross-border attacks.

Way forward: The National Cyber Security Coordinator should table the National Cybersecurity Strategy by Q2 FY27 and operationalise sectoral CSIRTs for banking, power, telecom and health with ₹1,500 crore under the proposed DIA.

Key points

What an examiner expects to see

  • 22 lakh+ cyber incidents 2024 (CERT-In)
  • ITU Global Cybersecurity Index 2024 — Tier 1
  • CERT-In under MeitY; NCIIPC under NTRO
  • I4C — Indian Cyber Crime Coordination Centre
  • Section 70 IT Act — CII protection
  • DPDP Act 2023 — data breach reporting
  • Defence Cyber Agency under HQ IDS
Examples to use

Concrete cases, schemes and judgments

  • AIIMS ransomware November 2022
  • Power grid Mumbai outage 2020
  • RailYatri data leak 2022
  • BSNL data leak 2024
Keywords / terms

Terminology to weave into the answer

CERT-InNCIIPCI4CCIIDPDPransomwarePQC
Sources to read

Primary sources and verified references

CERT-In — Annual Reports and Advisories https://www.cert-in.org.in/ Anantam IAS — Cyber Security in India https://anantamias.com/cyber-security/ Anantam IAS — Types of Attacks on Computer Networks https://anantamias.com/types-of-attacks-on-computer-network/

Share this answer