UPSC CSE 2026 Essay Paper Discussion
GS Paper 3 15 marks · 250w 14 min Medium

Cybersecurity is now a national-security priority as critical infrastructure goes digital. Examine the institutional architecture under CERT-In and the gaps in CII protection.

Subtopic: Security · Cybersecurity

Model answer outline

How to structure your answer

Introduction: CERT-In handled 16.05 lakh cybersecurity incidents in 2024 (CERT-In Annual Report); AIIMS Delhi ransomware attack (23 Nov 2022) compromised 5 servers; National Cyber Security Policy 2013 awaits update.

Body: 1) Institutional stack — CERT-In (CERT-In.org.in) under MeitY, NCIIPC under NTRO, I4C under MHA, Defence Cyber Agency under CDS. 2) CII framework — Section 70 IT Act, NCIIPC empanelled sectors (power, finance, transport, telecom, government). 3) Gaps — no Cybersecurity Act, fragmented breach notification, weak SME hygiene.

Way forward: Pass Cybersecurity Act/National Cybersecurity Strategy; mandatory breach disclosure under DPDP Rules; CERT-In 6-hour reporting reform; bug-bounty programmes for CII.

Full model answer

Written within the word limit

234 words · target 250 words · 14 min

Introduction:

CERT-In's Annual Report records 16.05 lakh cybersecurity incidents handled in 2024; the AIIMS Delhi ransomware attack of 23 November 2022 compromised five servers and paralysed critical hospital systems for two weeks; the National Cyber Security Policy 2013 still awaits an overdue update.

Institutional architecture:

The Indian Computer Emergency Response Team (CERT-In) under MeitY handles civilian incidents and issued the 6-hour reporting direction of 28 April 2022. The National Critical Information Infrastructure Protection Centre (NCIIPC) under NTRO operates under Section 70A of the IT Act 2000 to protect designated CII sectors — power, finance, transport, telecom, and government. The Indian Cyber Crime Coordination Centre (I4C) under MHA handles cyber-enabled crime; the Defence Cyber Agency under the Chief of Defence Staff (2019) handles military cyber-space.

CII protection framework and gaps:

Section 70 IT Act permits designation of CII, but the empanelment is patchy, and many state-level utilities and hospitals are not covered. The Mumbai grid outage of October 2020 — attributed to suspected cyber activity — exposed power-sector vulnerability. The AIIMS attack revealed that even apex national institutions run inadequate backup, segmentation, and incident-response drills.

Structural gaps:

India has no overarching Cybersecurity Act; breach notification is fragmented; SME hygiene remains weak; supply-chain attack risk (Solarwinds-style) is under-modelled. The draft National Cyber Security Strategy of 2020 remains pending finalisation.

Way forward / Conclusion:

Pass a Cybersecurity Act with a national strategy, mandate breach disclosure under DPDP Rules, harmonise CERT-In reporting timelines, and institutionalise bug-bounty programmes for CII operators under MeitY by 2027.

Key points

What an examiner expects to see

  • 16.05 lakh cyber incidents handled by CERT-In in 2024
  • AIIMS Delhi ransomware 23 November 2022
  • Section 70 IT Act 2000 — CII designation
  • NCIIPC under NTRO (Section 70A)
  • CERT-In 6-hour incident reporting direction (28 April 2022)
  • Indian Cyber Crime Coordination Centre (I4C) under MHA
  • Defence Cyber Agency under CDS (2019)
  • National Cyber Security Strategy draft 2020 pending
Examples to use

Concrete cases, schemes and judgments

  • AIIMS Delhi ransomware 2022
  • Mumbai grid outage Oct 2020 (suspected cyber)
  • ICICI and ICEGATE breaches
  • Solarwinds-style supply-chain risks
Keywords / terms

Terminology to weave into the answer

CERT-InNCIIPCCIII4CDefence Cyber AgencyIT Actransomware
Sources to read

Primary sources and verified references

CERT-In — Annual Reports https://www.cert-in.org.in/ Anantam IAS — Deepfakes https://anantamias.com/deepfakes/ Anantam IAS — Dark Web vs Deep Web https://anantamias.com/dark-web-vs-deep-web/

Share this answer