UPSC Margin
NotesTestsDaily CACSAT
UPSC Margin

Analytical concept notes, daily current affairs, and mock tests for serious UPSC aspirants.

Learn

  • Notes
  • Daily Current Affairs
  • Mock Tests
  • CSAT
  • Strategy Guide

Resources

  • About
  • Pricing
  • Blog
  • Contact
  • RSS Feed

Support

  • Help & FAQ
  • Privacy Policy
  • Terms of Use
  • Telegram Community

© 2026 UPSC Margin. All rights reserved.

Operated by Satyam Raj · hello@upscmargin.com

Back to Notes
Internal SecurityFree till Sep 9

India's Cyber Command: Structure and Capabilities

July 19, 2026

India's Cyber Command: Structure and Capabilities

Introduction

India's growing digital footprint — 80+ crore internet users, UPI transactions exceeding ₹200 lakh crore annually, and increasing military digitization — creates unprecedented cyber vulnerabilities. In response, India has established multiple cyber commands and agencies across the armed forces, intelligence community, and civil administration. This note examines the evolution, structure, capabilities, and challenges of India's cyber security and cyber warfare apparatus.

Cyber Threat Landscape

Threats Facing India

Threat TypeSourceTarget
State-sponsored APTsChina (APT10, APT31, Red Apollo), Pakistan (Transparent Tribe, SideWinder)Defence, strategic sector, govt networks
Cyber espionageVarious state actorsDiplomatic missions, policy think-tanks, PSUs
RansomwareCriminal groups (REvil, LockBit)Hospitals, banks, corporations
Cyber terrorismISIS-inspired, Lashkar-e-TaibaCritical infrastructure, propaganda
DDoS attacksState-sponsored and hacktivistGovernment websites, financial systems

Read Next

More in Internal Security

Border Security: Challenges and India's Approach

India shares 15,200 km of land border with seven countries — a unique geopolitical challenge with diverse threats from terrorism (Pakistan), infiltration (Bangladesh), and China's assertive posture. This note covers the Border Security Force (BSF), India-China border disputes (LAC), the India-Pakistan border (LC/IB), the India-Bangladesh border fencing, integrated border management, and the debate on 'One Border One Force'.

Coastal Security: Threats and Strengthening Measures

India has a 7,516 km coastline touching nine states and two UTs — a vast maritime frontier susceptible to terrorism, smuggling, and illegal fishing. This note covers the 26/11 attack lesson, the coastal security framework (ICG, Navy, Coastal Police), the Coastal Security Scheme, and the Coastal Surveillance Network.

Coastal Surveillance: Sagar Prahari and Coastal Radar Network

Disinformation
State-backed information warfare
Social media, elections, communal harmony
Supply chain attacksInjection of malware in software/hardwareAll sectors — via third-party vendors

Notable Attacks on India

  • 2020: Power grid in Mumbai shut down (suspected Chinese actors)
  • 2022: AIIMS Delhi ransomware attack (data encrypted for weeks)
  • 2023: CERT-In reported 1.3+ million cyber incidents
  • 2024: Phishing attacks targeting SBI customers, defence personnel

Evolution of India's Cyber Command Structure

Timeline

YearDevelopment
2004National Technical Research Organisation (NTRO) established (cyber capabilities)
2009Cyber Security Policy Task Force
2010Defence Information Assurance and Research Agency (DIARA)
2013National Cyber Security Policy (NCSP)
2014National Critical Information Infrastructure Protection Centre (NCIIPC)
2015Defence Cyber Agency (DCA) approved (formally operationalized 2019)
2018National Cyber Security Strategy released
2019Joint Services Cyber Command — DCA operational
2021Defence Cyber Agency becomes fully functional
2022National Cyber Security Strategy 2.0 (draft)
2023CERT-In directions on cyber incident reporting
2024Expansion of DCA to all tri-service commands

Organisational Structure

Defence Cyber Agency (DCA)

  • Established: 2019 (under HQ Integrated Defence Staff)
  • Nodal agency: For all armed forces cyber operations
  • Headquarters: New Delhi
  • Manpower: ~1,000 personnel (growing)
  • Composition: Personnel from Army, Navy, Air Force

Functions of DCA

  1. Offensive cyber operations: Computer Network Attack (CNA) against adversary systems
  2. Defensive cyber operations: Protect military networks (Computer Network Defence — CND)
  3. Cyber intelligence: Gather and analyze threat intelligence
  4. Training: Cyber security training for all military personnel
  5. Infrastructure protection: Secure weapons platforms, communication networks, and C4I systems
  6. Cyber forensics: Post-attack analysis and attribution
  7. Cyber simulation: War-gaming and red teaming exercises

Other Key Cyber Organisations

AgencyParent MinistryPrimary Role
CERT-InMeitYCivil cyber incident response, coordination
NCIIPCNTRO (PMO)Protection of critical information infrastructure
National Cyber Co-ordination Centre (NCCC)PMO/NSACyber threat monitoring, real-time situational awareness
Indian Computer Emergency Response Team (CERT-In)MeitYCyber incident reporting and response
Cyber LabsHome MinistryCyber crime investigation, training for state police
National Cyber Forensics LaboratoryHome MinistryDigital forensics for law enforcement
Joint Cyber Cell (JCC)Multi-agencyInter-agency coordination for cyber threats

National Security Council Secretariat (NSCS) Role

  • National Cyber Security Coordinator: Senior officer in NSCS
  • Coordinates across defence, intelligence, and civil agencies
  • Reports to National Security Advisor (NSA)
  • Leads National Cyber Security Strategy formulation

Capabilities

Offensive Cyber Capabilities

  • Cyber Command (DCA): Developing capability for targeted cyber operations
  • NTRO: Signals intelligence (SIGINT) and cyber collection
  • RAW: Cyber intelligence and potentially covert cyber operations
  • Capabilities reported: Network penetration, malware development, zero-day exploitation, social engineering

Defensive Cyber Capabilities

  • Network monitoring: 24×7 Security Operations Centres (SOCs) across all three services
  • Encryption: Indigenous SAGAR cryptographic suite for secure communication
  • Secure networks: AFNET (Air Force), WAN (Army), NFSWAN (Navy) — all encrypted
  • VPN infrastructure: For deployed forces in peace and conflict
  • Cyber hygiene: Regular vulnerability assessments, patch management

Joint Cyber Exercises

  • Exercise Cyber Suraksha: Tri-service cyber defence exercise
  • Exercise Cyber Shakti: NSA-led national-level cyber exercise
  • International participation: Participates in multinational exercises (Cobra Warrior, Red Flag)
  • Cyber war-gaming: Regular simulations with friendly foreign countries (US, Israel, France)

Cyber Strategy for National Security

National Cyber Security Strategy (2018)

  • Vision: Build a secure and resilient cyberspace for India's growth
  • Pillars:
    1. Securing national cyberspace (critical infrastructure, government networks)
    2. Strengthening legal framework (IT Act amendments)
    3. Building workforce capacity (5 lakh trained cyber professionals by 2025)
    4. International cooperation (cyber norms, bilateral agreements)
    5. Indigenous technology (crypto, hardware, software)

Cyber Doctrine for the Armed Forces (Draft)

  • Principles: Defend, deter, and dominate in cyberspace
  • Self-defence right: Arguing for right to respond to cyber attacks (including kinetic response)
  • Attribution: Strengthening forensic capability for unambiguous attribution
  • Resilience: Building redundancy in military networks

Challenges

ChallengeDetails
Personnel shortageIndia needs 5+ lakh cyber security professionals; current availability ~2 lakh
Integrated command gapsDCA is joint but still lacks unified budget, equipment, and career progression
Legal frameworkIT Act 2000 outdated; no clear rules of engagement for cyber operations
Civil-military coordinationNCCC, CERT-In, DCA operate in silos — limited information sharing
Indigenous technologyHeavy dependence on foreign hardware/software (backdoor risks)
Cyber in the nuclear domainNo clarity on cyber-nuclear nexus — risk of accidental escalation
Private sector linkageLimited cyber threat intelligence sharing with private sector
International normsNo consensus on responsible state behaviour in cyberspace
Quantum threatFuture quantum computing could break current encryption

International Comparison

CountryCyber CommandBudgetStatus
USAUSCYBERCOM$10B+Full-spectrum offensive/defensive
ChinaPLA SSF (Strategic Support Force)ClassifiedMassive — bundled with space/electronic warfare
RussiaTroops of Information OperationsClassifiedDisinformation + offensive cyber
IsraelUnit 8200 + INCD$500M+Tech-focused, offensive-oriented
IndiaDCA + NCIIPC + CERT-In~₹500 croreNascent, defensive-heavy

Recent Initiatives

  1. Cyber Surakshit Bharat: Public-private partnership for cybersecurity (2020)
  2. National Cyber Crime Portal: For citizen reporting (2021)
  3. CERT-In directions (2022): Mandatory incident reporting within 6 hours
  4. Cyber Security Labs in all states: Under CCTNS (Crime and Criminal Tracking Network)
  5. SAMBHAV initiative: Safe and Appropriate Mobile Bharat — mobile security testing
  6. Quantum computing labs: DRDO and ISRO working on quantum-safe cryptography

Conclusion

India's cyber command architecture is evolving from a defensive, civilian-focused posture to an integrated, offensive-capable tri-service structure. The Defence Cyber Agency is a crucial step, but it remains under-resourced compared to peer commands globally. For a country with India's digital ambitions and geopolitical challenges, building credible cyber deterrence — both defensive resilience and offensive capability — is an urgent national security priority.

Practice Questions

  1. Discuss the structure and functions of India's Defence Cyber Agency. How does it contribute to national security?
  2. "India's cyber security posture needs strengthening across legal, organizational, and technological dimensions." Critically examine.
  3. What are the major cyber threats facing India? How can the proposed National Cyber Security Strategy 2.0 address them?