GS Paper 3 10 marks · 150w 9 min Medium
Discuss different types of cyber crimes and measures required to be taken to fight the menace.
Subtopic: Internal Security · Cyber security
How to structure your answer
Introduction: rising cyber crime with digitalisation → types of cyber crimes (against individuals, property, state) → measures needed (legal, institutional, technical, awareness, international) → Conclusion: whole-of-society cyber resilience.
Written within the word limit
147 words · target 150 words · 9 min
As India digitalises rapidly, cyber crime has surged, with lakhs of complaints logged on the national portal each year. Cyber crimes exploit computers and networks as targets or tools, threatening individuals, businesses and the state.
Types of cyber crimes
- Against individuals: identity theft, phishing, cyberstalking, online financial and UPI fraud, and morphing.
- Against property and organisations: hacking, ransomware, data breaches and intellectual-property theft.
- Against the state and society: cyber terrorism, attacks on critical infrastructure, espionage, and spread of child sexual-abuse material and misinformation.
Measures required
- Legal: robust enforcement of the IT Act and the new data-protection law.
- Institutional: strengthen CERT-In, the Indian Cyber Crime Coordination Centre (I4C) and NCIIPC.
- Technical: security audits, encryption, incident response and protection of critical information infrastructure.
- Awareness and skills: citizen education, trained cyber police and forensic capacity.
- International: cooperation on cross-border cyber crime.
A coordinated, whole-of-society approach is essential to build cyber resilience.
What an examiner expects to see
- Cyber crimes classed as against individuals, property/organisations, and the state/society
- Individual crimes: phishing, identity theft, UPI/financial fraud, cyberstalking, morphing
- Organisational: hacking, ransomware, data breaches, IP theft
- State-level: cyber terrorism, CII attacks, espionage, CSAM and misinformation
- Legal backbone: IT Act 2000 and the Digital Personal Data Protection Act 2023
- Institutions: CERT-In, I4C, NCIIPC, cybercrime.gov.in reporting portal
- Awareness, trained cyber forensics and international cooperation are vital
Concrete cases, schemes and judgments
- Indian Cyber Crime Coordination Centre (I4C) and the National Cyber Crime Reporting Portal
- CERT-In as the national nodal agency for cyber incident response
- AIIMS Delhi ransomware attack (2022) crippling hospital systems
- Digital Personal Data Protection Act, 2023 for data security
Terminology to weave into the answer
ransomware and phishingIT Act 2000CERT-In and I4Ccritical information infrastructureDigital Personal Data Protection Actcyber terrorism