UPSC Margin
NotesTestsDaily CACSAT
UPSC Margin

Analytical concept notes, daily current affairs, and mock tests for serious UPSC aspirants.

Learn

  • Notes
  • Daily Current Affairs
  • Mock Tests
  • CSAT
  • Strategy Guide

Resources

  • About
  • Pricing
  • Blog
  • Contact
  • RSS Feed

Support

  • Help & FAQ
  • Privacy Policy
  • Terms of Use
  • Telegram Community

© 2026 UPSC Margin. All rights reserved.

Operated by Satyam Raj · hello@upscmargin.com

Back to Notes
Science & TechFree till Sep 9

Cyber Threats: Types, Vulnerabilities, and India's Preparedness

July 19, 2026

TOPIC CLASSIFICATION

Subject: Science & Technology / Internal Security Sub-area: Cybersecurity Prelim PYQ Trend: High (regular questions on malware, CERT-In, cyber laws) Mains Relevance: GS-3 (Internal Security, Science & Technology)

EXAMINER REASONING

Cyber threats are a high-yield UPSC topic straddling Science & Tech and Internal Security. The examiner focuses on: (a) types of threats — malware, phishing, ransomware, APTs; (b) India's institutional mechanism — CERT-In, NCIIPC, sectoral CERTs; (c) vulnerabilities — supply chain, IoT, AI-based attacks; (d) legal framework — IT Act 2000, amendments, data protection. Expect questions that ask you to link cyber threats with critical infrastructure (power grid, financial system, defence) and India's preparedness gap.

Core Concept

Types of Cyber Threats:

ThreatDescriptionRecent Example
MalwareMalicious software (virus, worm, trojan)Pegasus spyware (NSO Group)
RansomwareEncrypts data, demands ransomAIIMS attack (2022), CDAC (2024)
Phishing/Social EngineeringDeceptive emails/websites to steal credentialsSpear-phishing targeting govt officials
DDoSOverwhelms servers with trafficHDFC Bank (2021), SWIFT-related
APT (Advanced Persistent Threat)State-sponsored, long-term infiltration

Read Next

More in Science & Tech

5G and 6G Technology: Features and India's Rollout

Artificial Intelligence: Applications, Ethics, and India's AI Strategy

Artificial Intelligence is reshaping global economies, and India is positioning itself as a significant AI player. This note covers AI applications in healthcare, agriculture, governance, and defence, ethical concerns including algorithmic bias, privacy, and job displacement, and India's AI strategy — INDIAai platform, NITI Aayog's national AI strategy (#AIforAll), the Bhashini language AI initiative, and the Global Partnership on AI (GPAI).

AstroSat and India's Space Observatories

Operation Patchwork (Chinese-linked)
Zero-Day ExploitUnknown vulnerability exploitedVarious — patched post-discovery
Supply Chain AttackCompromise via trusted vendorSolarWinds (global), Bharat Biotech (2025)
AI-Enabled AttacksDeepfakes, AI-generated phishingDeepfake CEO fraud (multiple instances)

Vulnerabilities:

  • Human Factor: Weak passwords, lack of awareness, insider threats — accounts for ~85% of breaches
  • Technical: Legacy systems (govt still uses XP-based systems in some depts), unpatched software
  • Infrastructure: Undersea cables (vulnerable to interception), DNS infrastructure, SSL/TLS misconfigurations
  • Legal: IT Act changes pending, weak enforcement, limited forensic capacity
  • Supply Chain: Dependence on foreign hardware (chipsets from China, US servers)

India's Preparedness:

  • National Cyber Security Policy 2013 — being revised as National Cyber Security Strategy 2025
  • CERT-In (Indian Computer Emergency Response Team): National nodal agency for cyber incident response
  • NCIIPC: Under NTRO — protects critical information infrastructure
  • Cyber Swachhta Kendra: Free botnet cleaning tools
  • National Critical Information Infrastructure Protection Centre (NCIIPC): Identifies and protects CII
  • Cyber Crime Coordination Centre (I4C): Under MHA — coordinates state police cyber cells
  • National Cyber Security Strategy 2020 — sectoral CERTs, cyber insurance, research
  • Defence Cyber Agency (DCA): Tri-service organisation for military cyber operations

Key Facts

  1. India ranks #1 in cyber attacks originating (some reports) due to large population and low awareness
  2. CERT-In handled ~2.5 million cyber security incidents in 2024 (vs 1.4 million in 2022)
  3. IT Act 2000 — primary legislation; Section 66 (hacking), Section 67 (obscene content), Section 69 (interception)
  4. Personal Data Protection Bill 2023 — passed as PDPB Act, 2023
  5. India has 7 sectoral CERTs so far (power, finance, telecom, transport, etc.)
  6. National Cyber Security Coordinator (NCSC): Under PMO — coordinates all cyber efforts
  7. Cyber insurance market in India estimated at ₹4,000 crore (2025)
  8. India is also a signatory to Budapest Convention on Cybercrime (accessed 2023)

PYQ Trend

YearQuestionTopic
2024"Discuss the role of CERT-In in India's cyber security framework"Institutions
2023"What are Advanced Persistent Threats? How do they affect national security?"APT
2022"Examine the challenges in securing India's cyberspace"Vulnerabilities
2021"How does cyber warfare threaten national security?"Cyber warfare
2020"Analyse the importance of data protection laws in India"Legal framework

Statement Elimination Guide

  • "Cyber threats only affect financial institutions" — affects all sectors: defence, health, power, transport
  • "The IT Act 2000 is the only cyber law in India" — PDPB Act 2023, IPC sections also apply
  • "CERT-In is the national nodal agency for cyber incident response" — correct
  • "India has no dedicated national cyber security strategy" — NCSP 2013 exists; new strategy being drafted
  • "Supply chain vulnerabilities are a growing concern for India's cybersecurity" — correct, given import dependence

Current Affairs Hook

  • 2025: Ransomware attack on CDAC (under MeitY) — sensitive research data compromised
  • 2026: India launches National Cyber Security Strategy 2025 — ₹10,000 Cr outlay
  • Global: WEF Global Risks Report ranks cyber-attacks as 4th most severe risk
  • AI Threats: Deepfake-enabled fraud rising (₹30 Cr+ reported cases in 2025)
  • New Vistas: Quantum computing threat to encryption — India's Quantum Mission includes post-quantum crypto research

Interlinkages

  • Internal Security (GS-3): Cyber terrorism, radicalisation via encrypted apps, dark web
  • Defence (GS-3): Military cyber commands, warfare doctrine, critical infrastructure protection
  • Economy (GS-3): Fintech growth, digital payments (UPI) — security concerns
  • Governance (GS-2): E-governance security, Aadhaar breach concerns
  • International Relations (GS-2): Budapest Convention, UN GGE on cyber, Digital Public Goods (DPG)
  • Ethics (GS-4): Privacy vs security, data localisation ethics, surveillance

Common Mistakes

  1. Treating cyber threats as purely technical — UPSC expects socio-economic, legal, and governance dimensions
  2. Mixing up CERT-In and NCIIPC — CERT-In (general incidents) vs NCIIPC (critical infrastructure protection)
  3. Ignoring the human element — 85% breaches involve human error; it's not just about technology
  4. Not mentioning the supply chain vulnerability — a key dimension in a hardware-importing nation
  5. Confusing Data Protection Bill with cybersecurity — data protection is about privacy; cybersecurity is about system protection

Revision Snapshot

CYBER THREATS — Quick Recap
├── Types: Malware | Phishing | Ransomware | APT | DDoS | Zero-Day | Supply Chain
├── Vulnerabilities: Human | Technical | Legal | Infrastructure | Supply Chain
├── Institutions: CERT-In | NCIIPC | I4C | NCSC | DCA | Sectoral CERTs
├── Laws: IT Act 2000 | PDPB 2023 | National Cyber Security Policy
└── Challenges: Awareness | Forensics | Borderless Crime | Rapid Tech Change

Source Notes

  • CERT-In — Annual Reports (2022-24)
  • MHA — Annual Report on Internal Security
  • WEF — Global Risks Report 2025
  • DSCI (Data Security Council of India) — Cyber Threat Reports
  • Ministry of Electronics & IT — Cyber Security Framework
  • National Cyber Security Strategy 2020 — Draft Document