UPSC CSE 2026 Essay Paper Discussion
GS Paper 3 10 marks · 150w 9 min Medium

Discuss different types of cyber crimes and measures required to be taken to fight the menace.

Subtopic: Internal Security · Cyber security

Model answer outline

How to structure your answer

Introduction: rising cyber crime with digitalisation → types of cyber crimes (against individuals, property, state) → measures needed (legal, institutional, technical, awareness, international) → Conclusion: whole-of-society cyber resilience.
Full model answer

Written within the word limit

147 words · target 150 words · 9 min

As India digitalises rapidly, cyber crime has surged, with lakhs of complaints logged on the national portal each year. Cyber crimes exploit computers and networks as targets or tools, threatening individuals, businesses and the state.

Types of cyber crimes

  • Against individuals: identity theft, phishing, cyberstalking, online financial and UPI fraud, and morphing.
  • Against property and organisations: hacking, ransomware, data breaches and intellectual-property theft.
  • Against the state and society: cyber terrorism, attacks on critical infrastructure, espionage, and spread of child sexual-abuse material and misinformation.

Measures required

  • Legal: robust enforcement of the IT Act and the new data-protection law.
  • Institutional: strengthen CERT-In, the Indian Cyber Crime Coordination Centre (I4C) and NCIIPC.
  • Technical: security audits, encryption, incident response and protection of critical information infrastructure.
  • Awareness and skills: citizen education, trained cyber police and forensic capacity.
  • International: cooperation on cross-border cyber crime.

A coordinated, whole-of-society approach is essential to build cyber resilience.

Key points

What an examiner expects to see

  • Cyber crimes classed as against individuals, property/organisations, and the state/society
  • Individual crimes: phishing, identity theft, UPI/financial fraud, cyberstalking, morphing
  • Organisational: hacking, ransomware, data breaches, IP theft
  • State-level: cyber terrorism, CII attacks, espionage, CSAM and misinformation
  • Legal backbone: IT Act 2000 and the Digital Personal Data Protection Act 2023
  • Institutions: CERT-In, I4C, NCIIPC, cybercrime.gov.in reporting portal
  • Awareness, trained cyber forensics and international cooperation are vital
Examples to use

Concrete cases, schemes and judgments

  • Indian Cyber Crime Coordination Centre (I4C) and the National Cyber Crime Reporting Portal
  • CERT-In as the national nodal agency for cyber incident response
  • AIIMS Delhi ransomware attack (2022) crippling hospital systems
  • Digital Personal Data Protection Act, 2023 for data security
Keywords / terms

Terminology to weave into the answer

ransomware and phishingIT Act 2000CERT-In and I4Ccritical information infrastructureDigital Personal Data Protection Actcyber terrorism

Share this answer