UPSC Margin
NotesTestsDaily CACSAT
UPSC Margin

Analytical concept notes, daily current affairs, and mock tests for serious UPSC aspirants.

Learn

  • Notes
  • Daily Current Affairs
  • Mock Tests
  • CSAT
  • Strategy Guide

Resources

  • About
  • Pricing
  • Blog
  • Contact
  • RSS Feed

Support

  • Help & FAQ
  • Privacy Policy
  • Terms of Use
  • Telegram Community

© 2026 UPSC Margin. All rights reserved.

Operated by Satyam Raj · hello@upscmargin.com

Back to Notes
Internal Security

India's Cyber Security Framework

July 23, 2026
6 min read

[TOPIC CLASSIFICATION]

  • Topic type: Legal-Technical Framework + Current Threats
  • PYQ frequency: High
  • Exam stage: Prelims + Mains
  • Primary GS paper: GS3 (Internal Security, Science & Tech) + GS2 (Governance)

[EXAMINER REASONING]

  1. Trap: Conflating IT Act (cyber crime, e-commerce) with critical infrastructure protection (NCIIPC) - different mandates
  2. Most confused: CERT-In 2022 directions (6-hour incident reporting, KYC for VPN/VPS, clock sync) - scope and compliance burden
  3. Key anchor: IT Act 2000 (amended 2008) + CERT-In directions 2022 + DPDP Act 2023 = current legal triad
  4. Current affairs hook: AIIMS ransomware (2022), Air India data breach (2023), state-sponsored APT attacks (APT41, Lazarus), DPDP Act 2023 operationalisation
  5. Mains hinge: Balancing security (CERT-In directions) vs privacy (DPDP Act) vs business ease; attribution difficulty in cyber attacks; India's strategic autonomy in cyberspace

Core Concept

India's cyber security architecture has evolved from the IT Act 2000 (e-commerce focus) to a multi-layered framework addressing critical infrastructure protection, data privacy, and strategic cyber operations - driven by escalating threats: ransomware (AIIMS, 2022), state-sponsored APTs (Chinese APT41, North Korean Lazarus), and data breaches (Air India, 2023; CoWIN leak allegations, 2023).

Legal-Policy Triad

IT Act, 2000 (amended 2008): Foundation - cyber crimes (hacking S.66, identity theft S.66C, cheating S.66D, cyber terrorism S.66F), intermediary liability (S.79), CERT-In as nodal agency (S.70B). 2008 amendment: Added cyber terrorism, child pornography, voyeurism; weakened intermediary safe harbour.

CERT-In Directions (April 28, 2022): Mandatory 6-hour incident reporting; KYC for VPN/VPS/cloud providers (5-year log retention); clock synchronisation with NTP (NPL/NIC); designated point of contact. Controversy: Overreach concerns, compliance burden on MSMEs, VPN providers exiting India (ExpressVPN, Surfshark). Revised FAQs (2023): Clarified "cyber incident" definition, exempted certain entities.

Digital Personal Data Protection Act, 2023 (DPDP): Consent-based processing; data fiduciary obligations; Data Protection Board; cross-border transfer rules; exemptions for state (security, sovereignty); penalties up to ₹250 cr. Not yet fully operational (rules pending).

Institutional Architecture

CERT-In (MeitY): National incident response - 24x7 helpdesk, vulnerability tracking, advisories, drills. NCIIPC (NTRO, 2014): Critical Information Infrastructure Protection - sectors: power, transport, banking, telecom, defence, space, e-gov. Cyber Swachhta Kendra (Botnet Cleaning): ISP-level malware detection/removal. Law enforcement coordination - cyber crime reporting portal (cybercrime.gov.in), forensic labs, capacity building. Tri-service offensive/defensive cyber ops. Technical intelligence, CII protection.

Read Next

More in Internal Security

Internal Security Challenges - Jammu and Kashmir

Comprehensive analytical note on Internal Security Challenges - Jammu and Kashmir for UPSC 2025-26. Covers security/legal framework, evolution, key developments, current…

Internal Security Challenges - Left Wing Extremism

Comprehensive analytical note on Internal Security Challenges - Left Wing Extremism for UPSC 2025-26. Covers security/legal framework, evolution, key developments, current…

Internal Security Challenges - North East Insurgency

Comprehensive analytical note on Internal Security Challenges - North East Insurgency for UPSC 2025-26. Covers security/legal framework, evolution, key developments, current…

Indian Cyber Crime Coordination Centre (I4C, MHA, 2020):
Defence Cyber Agency (DCA, 2019):
National Technical Research Organisation (NTRO):

Critical Information Infrastructure (CII)

Defined under IT Act S.70: "computer resource whose incapacitation would have debilitating impact on national security, economy, public health, safety." Sectors: Power (SCADA), Banking (CBS, SWIFT), Telecom (core network), Transport (rail signalling, ATC), Defence, Space, E-gov (Aadhaar, GSTN), Health (CoWIN, ABDM). NCIIPC mandate: Threat assessment, protection guidance, audit, incident response for CII.

Threat Landscape

Ransomware: AIIMS Delhi (Nov 2022, 1.3TB data, 2-week disruption), Oil India, SpiceJet, Solar Industries. State-sponsored APTs: APT41 (China) - power sector, telecom; Lazarus (North Korea) - crypto theft, banks; SideWinder (Pakistan) - government, defence. Data breaches: Air India (4.5M passengers, 2023), BigBasket (2020), Domino's (2021), CoWIN alleged leak (2023). Cyber crime: Phishing, KYC fraud, UPI fraud, sextortion - ₹11,000+ cr lost (2023, NCRB).

Capacity & International

Cyber Surakshit Bharat: MeitY training for CISOs. Information Security Education & Awareness (ISEA): Curriculum, certifications. Cyber Commandos: CAPF cyber units. International: Budapest Convention (India observer, not signatory - sovereignty concerns); UN GGE/OEWG (norms of responsible state behaviour); Quad Cyber Challenge; India-US Cyber Relationship Framework (2022); BIMSTEC cyber cooperation.


Key Facts

  • IT Act: 2000, amended 2008
  • CERT-In Directions: April 28, 2022 (6-hr reporting, VPN KYC, clock sync)
  • DPDP Act: August 2023 (not fully operational)
  • NCIIPC: 2014, under NTRO
  • I4C: 2020, under MHA
  • Defence Cyber Agency: 2019
  • Cyber Swachhta Kendra: 2017
  • AIIMS ransomware: Nov 2022
  • Air India breach: 2023 (4.5M records)
  • Cyber crime losses 2023: ₹11,000+ cr (NCRB)
  • Budapest Convention: India observer, not party
  • Quad Cyber Challenge: 2023
  • India-US Cyber Framework: 2022
  • CII sectors: 7 (power, banking, telecom, transport, defence, space, e-gov)

UPSC Question Themes (Illustrative)

Treat these as original practice prompts unless a linked official UPSC paper is provided; they are not represented as verbatim PYQs. | Type | Stage | What was tested | |---|---|---| | Practice | Mains | CERT-In directions 2022, privacy vs security, ransomware | | Practice | Prelims | IT Act sections, CERT-In role, CII definition | | Practice | Mains | Cyber security architecture, critical infrastructure, international cooperation | | Practice | Prelims | NCIIPC, Cyber Swachhta Kendra, Budapest Convention | | Practice | Mains | Data protection, cyber sovereignty, cyber crime trends |


Statement Elimination Guide

  • "CERT-In 2022 directions apply to all VPN providers globally." False. Applies to entities serving Indian users.
  • "India is a signatory to the Budapest Convention." False. Observer only - sovereignty/data localisation concerns.
  • "NCIIPC protects all government websites." False. Only notified Critical Information Infrastructure.
  • "DPDP Act 2023 is fully operational." False. Rules not yet notified; phased implementation expected.
  • "Cyber terrorism under IT Act requires foreign involvement." False. S.66F covers acts threatening India's unity, integrity, security - domestic or foreign.
  • "CERT-In and NCIIPC have identical mandates." False. CERT-In = national incident response; NCIIPC = CII protection.
  • "Intermediary safe harbour (S.79) is absolute." False. Conditional - due diligence, govt takedown orders.

Current Affairs Hook

  • CERT-In directions 2022: VPN exits, compliance debates, revised FAQs 2023
  • DPDP Act 2023: Rules drafting, Data Protection Board constitution, cross-border transfer norms
  • AIIMS ransomware (2022): 1.3TB data, 2-week outage, alleged Chinese APT
  • Air India data breach (2023): 4.5M passengers via SITA
  • CoWIN data leak allegations (2023): Telegram bot, CERT-In investigation
  • Chinese APT41 targeting Indian power/telecom (2022-24)
  • North Korean Lazarus crypto thefts (WazirX 2024 $230M)
  • Defence Cyber Agency operationalisation
  • Quad Cyber Challenge 2023
  • India-US Cyber Framework 2022

Interlinkages

  • Polity: DPDP Act, IT Act, fundamental rights (privacy Puttaswamy), federalism (cyber crime is state subject)
  • Economy: Digital economy ($1T target), fintech, UPI security, crypto regulation, startup compliance burden
  • International Relations: Budapest Convention, UN GGE/OEWG, Quad, India-US, China cyber espionage
  • Science & Tech: AI/ML in cyber defence, quantum cryptography, blockchain forensics, 5G security
  • Internal Security: Terror funding via cyber crime, radicalisation online, drone cyber takeover
  • Governance: E-gov security (Aadhaar, GSTN, CoWIN), digital public infrastructure protection

Common Mistakes

  1. Confusing CERT-In (incident response) with NCIIPC (CII protection) - distinct mandates
  2. Thinking DPDP Act is fully in force - rules pending
  3. Assuming Budapest Convention membership - India is observer only
  4. Missing CERT-In 2022 directions' 6-hour reporting + VPN KYC - high PYQ yield
  5. Overlooking state-sponsored APT attribution difficulty - "attribution problem" in mains
  6. Conflating cyber crime (IPC/IT Act) with cyber warfare (armed attack threshold)

Revision Snapshot

Cyber architecture: IT Act 2000/2008 (crimes, intermediaries, CERT-In) → CERT-In Directions 2022 (6-hr reporting, VPN KYC, clock sync) → DPDP Act 2023 (consent, fiduciary duties, penalties). Institutions: CERT-In (MeitY, national CERT), NCIIPC (NTRO, CII protection), I4C (MHA, law enforcement), DCA (Defence, military cyber), Cyber Swachhta Kendra (botnet cleaning). Threats: Ransomware (AIIMS 2022), APTs (China APT41, NK Lazarus, Pak SideWinder), data breaches (Air India 2023), cyber crime (₹11K+ cr 2023). International: Budapest observer, UN GGE norms, Quad cyber, India-US framework. PYQ anchor: CERT-In 2022 directions, CII definition, NCIIPC vs CERT-In, Budapest status, DPDP Act status.


Source Notes

  • Information Technology Act, 2000 (with 2008 amendment)
  • CERT-In Directions 28.04.2022 + FAQs 2023
  • Digital Personal Data Protection Act, 2023
  • NCIIPC Annual Reports
  • I4C/MHA Cyber Crime Reports
  • NCRB Crime in India (Cyber Crime chapter)
  • MeitY Annual Reports
  • Budapest Convention text
  • UN GGE/OEWG Reports
  • CERT-In Advisories & Vulnerability Notes

Authoritative References

  • Ministry of Home Affairs
  • Bureau of Police Research and Development
  • Press Information Bureau releases