Cybersecurity is now a national-security priority as critical infrastructure goes digital. Examine India’s institutional and legal framework and the gaps in protecting CIIs.
Subtopic: Security · Cybersecurity
How to structure your answer
Introduction: CERT-In reported over 22 lakh cyber incidents in 2024 (Annual Report); India ranked 10th in ITU Global Cybersecurity Index 2024 (Tier 1).
Body: 1) Institutions — CERT-In (MeitY), NCIIPC under NTRO, I4C under MHA, NCSC, Defence Cyber Agency. 2) Laws — IT Act 2000, DPDP Act 2023, Section 70 CII regime, draft Digital India Act. 3) Gaps — sector-specific CSIRTs limited, attribution lag, OT and IoT exposure.
Way forward: Operationalise Digital India Act; expand NCIIPC sectoral coverage; mandate PQC migration timeline per CERT-In; ratify Budapest Convention dialogue.
Written within the word limit
128 words · target 150 words · 9 min
Introduction: CERT-In recorded 15.92 lakh cybersecurity incidents in 2024 (MeitY Lok Sabha reply, March 2025); AIIMS Delhi ransomware (November 2022) and SpiceJet (2022) exposed critical-infrastructure vulnerability.
Body: India's framework rests on the IT Act 2000 (Sections 66, 70 for CII), CERT-In Rules 2013, the National Cyber Security Policy 2013, and NCIIPC under NTRO. The DPDP Act 2023, BNS 2023 (Sections 111, 318 on cyber-fraud) and the proposed Digital India Act will replace IT Act 2000. CERT-In's six-hour reporting mandate (April 2022) and the National Cybersecurity Strategy (draft, PMO since 2020) await notification. Gaps: only seven sectoral CSIRTs operational, low cyber-insurance penetration, a 7.9 lakh-professional talent deficit (NASSCOM 2024), and no active-defence law for cross-border attacks.
Way forward: The National Cyber Security Coordinator should table the National Cybersecurity Strategy by Q2 FY27 and operationalise sectoral CSIRTs for banking, power, telecom and health with ₹1,500 crore under the proposed DIA.
What an examiner expects to see
- 22 lakh+ cyber incidents 2024 (CERT-In)
- ITU Global Cybersecurity Index 2024 — Tier 1
- CERT-In under MeitY; NCIIPC under NTRO
- I4C — Indian Cyber Crime Coordination Centre
- Section 70 IT Act — CII protection
- DPDP Act 2023 — data breach reporting
- Defence Cyber Agency under HQ IDS
Concrete cases, schemes and judgments
- AIIMS ransomware November 2022
- Power grid Mumbai outage 2020
- RailYatri data leak 2022
- BSNL data leak 2024