UPSC Margin
NotesTestsDaily CACSAT
UPSC Margin

Analytical concept notes, daily current affairs, and mock tests for serious UPSC aspirants.

Learn

  • Notes
  • Daily Current Affairs
  • Mock Tests
  • CSAT
  • Strategy Guide

Resources

  • About
  • Pricing
  • Blog
  • Contact
  • RSS Feed

Support

  • Help & FAQ
  • Privacy Policy
  • Terms of Use
  • Telegram Community

© 2026 UPSC Margin. All rights reserved.

Operated by Satyam Raj · hello@upscmargin.com

Back to Notes
Internal Security

Cyber Security Framework in India

July 20, 2026
8 min read

[TOPIC CLASSIFICATION]

  • Topic type: Internal Security - Cyber Security
  • PYQ frequency: High - CERT-In, NCIIPC, IT Act, DPDP Act, critical infrastructure, ransomware
  • Exam stage: Prelims + Mains
  • Primary GS paper: GS 3 (Internal Security, Science & Tech)

[EXAMINER REASONING]

  1. Trap: Confusing CERT-In (operational incident response) with NCIIPC (critical infrastructure protection) and NSCS (strategic policy). CERT-In = national incident response; NCIIPC = designated CII protection; NSCS = apex policy coordination.
  2. Most confused: IT Act 2000 (amended 2008) vs DPDP Act 2023. IT Act = cybercrime, e-commerce, intermediary liability. DPDP Act = personal data protection, consent, data fiduciary duties. They overlap but serve different purposes.
  3. Key anchor: The 'Protected System' designation under Section 70 IT Act - only NCIIPC can notify Critical Information Infrastructure (CII). Any unauthorised access = 10 years imprisonment. This is the legal backbone of CII protection.
  4. Current affairs hook: 2024 - CERT-In's 6-hour incident reporting directive (April 2022) enforced with penalties; Digital Personal Data Protection Act (Aug 2023) rules notified 2024; National Cyber Security Strategy (2024) released; AIIMS ransomware (2022), SolarWinds/Sunburst impact on Indian entities; AI deepfakes in elections (2024).
  5. Mains hinge: Frame as 'capability vs threat asymmetry'. India is a top-3 digital economy (UPI, Aadhaar, DPI) but faces state-sponsored APTs (APT41, Lazarus, SideWinder), ransomware-as-a-service, and supply chain vulnerabilities. The response must integrate legal (DPDP), institutional (CERT-In/NCIIPC), technical (SOCs), and diplomatic (Budapest Convention, UN OEWG) layers.

Core Concept

Institutional Architecture

BodyMandateParent MinistryKey Power
National Security Council Secretariat (NSCS)Apex cyber policy coordinationPMONational Cyber Security Coordinator (NCSC)

Read Next

More in Internal Security

Internal Security Challenges - Jammu and Kashmir

Comprehensive analytical note on Internal Security Challenges - Jammu and Kashmir for UPSC 2025-26. Covers security/legal framework, evolution, key developments, current status, PYQ analysis, elimination traps, and 2023-24 current affairs. 6 min read.

Internal Security Challenges - Left Wing Extremism

Comprehensive analytical note on Internal Security Challenges - Left Wing Extremism for UPSC 2025-26. Covers security/legal framework, evolution, key developments, current status, PYQ analysis, elimination traps, and 2023-24 current affairs. 6 min read.

Internal Security Challenges - North East Insurgency

Comprehensive analytical note on Internal Security Challenges - North East Insurgency for UPSC 2025-26. Covers security/legal framework, evolution, key developments, current status, PYQ analysis, elimination traps, and 2023-24 current affairs. 6 min read.

CERT-In (Indian Computer Emergency Response Team)National incident response, 6-hr reporting, alerts, auditsMeitYSection 70B IT Act - mandatory incident reporting
NCIIPC (National Critical Information Infrastructure Protection Centre)Protect 'Critical Information Infrastructure' (CII)NTRO (PMO)Section 70 IT Act - 'Protected System' notification
Sectoral CERTsSector-specific response (Finance, Power, Defence, etc.)Respective MinistriesCoordinate with CERT-In
Defence Cyber Agency (DCyA)Military cyber operationsMinistry of DefenceTri-service command
National Technical Research Organisation (NTRO)Technical intelligence, cyber opsPMONCIIPC housed here

Legal Framework

Information Technology Act, 2000 (Amended 2008)

  • Section 43/66 - Unauthorised access, damage (3 yrs / 5 cr fine)
  • Section 66C/D - Identity theft, cheating by personation
  • Section 67/67A/67B - Obscene/sexually explicit content
  • Section 69 - Interception, monitoring, decryption (Central Govt)
  • Section 69A - Blocking public access (sovereignty, security, public order)
  • Section 70 - Protected Systems - NCIIPC notifies CII; unauthorised access = 10 yrs
  • Section 70B - CERT-In - Nodal agency; directions binding

Digital Personal Data Protection Act, 2023 (DPDP Act)

  • Consent-based processing; legitimate uses (State, employment, emergency)
  • Data Fiduciary duties: notice, consent, security, breach notification, DPO
  • Data Principal rights: access, correction, erasure, grievance
  • Cross-border transfer: Central Govt notifies permitted countries
  • Penalties: Up to Rs 250 cr per breach
  • Data Protection Board of India - adjudicatory body

Telecommunications Act, 2023

  • Replaces Telegraph Act 1885
  • Cyber security of telecom networks; authorised officers for interception
  • Critical telecom infrastructure protection

Sectoral Regulations

  • RBI - Cyber Security Framework for Banks (2016), UPI/CC security, tokenisation
  • SEBI - Cyber Security & Resilience Framework (2023) for MIIs, brokers
  • IRDAI - Cyber Security Guidelines for Insurers (2023)
  • TRAI - Telecom Cyber Security Regulations (2024)
  • MoP - CEA Cyber Security Guidelines for Power Sector (2021)

National Cyber Security Strategy 2024 (Key Pillars)

  1. Secure - Harden critical infrastructure; mandatory CII audits; zero-trust architecture
  2. Resilient - National Cyber Crisis Management Plan; sectoral SOCs; ransomware playbooks
  3. Trusted - Indigenous cyber products (MeitY's 'Cyber Surakshit Bharat'); supply chain security
  4. Capable - 1 lakh certified professionals by 2027; Cyber Commandos for states
  5. Collaborative - Public-private partnership; international cooperation (QUAD, BIMSTEC, Budapest)
  6. Governed - NSCS oversight; annual cyber security audit of ministries

Critical Information Infrastructure (CII) Sectors (Notified by NCIIPC)

  1. Power & Energy
  2. Banking, Financial Services & Insurance (BFSI)
  3. Telecom
  4. Transport (Rail, Air, Port)
  5. Health
  6. Strategic & Public Enterprises (Defence, Space, Atomic Energy)
  7. Government (e-Gov, Digital Public Infrastructure - Aadhaar, UPI, DigiLocker)

Key Facts

  • CERT-In established: 2004 (operational 2005); under MeitY
  • NCIIPC established: 2014; under NTRO (PMO)
  • National Cyber Security Coordinator (NCSC): Lt Gen (Dr) Rajesh Pant (2020-2024), new appt 2024
  • 6-hour incident reporting: CERT-In Direction (Apr 2022) - mandatory for all entities
  • Protected Systems notified: 100+ (as of 2024) across 7 sectors
  • Cyber crimes reported (NCRB): 65,000+ (2022); 1.1M+ (I4C portal, 2023)
  • Ransomware attacks: 53% increase (2023 vs 2022); major hits - AIIMS (2022), Sun Pharma (2023), BSNL (2024)
  • APT groups targeting India: APT41 (China), Lazarus (NK), SideWinder (Pak), Transparent Tribe (Pak), Donot Team
  • Digital Public Infrastructure (DPI): Aadhaar, UPI, DigiLocker, ONDC, Account Aggregator - all designated CII
  • Budapest Convention: India not a signatory (sovereignty concerns); participates in UN OEWG
  • Cyber Surakshit Bharat: MeitY programme - CISO training, awareness

Previous Year Questions

YearStageWhat was tested
2024PrelimsCERT-In's 6-hour incident reporting mandate comes under which Section? (70B IT Act)
2023Mains"India's cyber security architecture is fragmented across multiple agencies." Critically examine.
2022PrelimsNCIIPC is designated to protect which infrastructure? (Critical Information Infrastructure)
2021MainsWhat are the key features of the Information Technology (Intermediary Guidelines) Rules, 2021?
2020PrelimsThe Budapest Convention relates to: Cybercrime
2019MainsDiscuss the potential of cyber attacks on critical infrastructure. Suggest measures.

Statement Elimination Guide

  • Correct: "CERT-In is the national nodal agency for cyber incident response under Section 70B of the IT Act."
  • False: "NCIIPC operates under the Ministry of Electronics and IT." (It operates under NTRO, which reports to PMO)
  • Trap: "The DPDP Act 2023 applies to all personal data processing in India, including offline data." (False - only digital personal data; offline digitised later is covered)
  • Correct: "Section 70 of the IT Act empowers NCIIPC to declare 'Protected Systems' - unauthorised access attracts 10 years imprisonment."
  • False: "India is a signatory to the Budapest Convention on Cybercrime." (India has not signed - sovereignty, data localisation concerns)
  • Correct: "The Digital Personal Data Protection Act 2023 provides for a Data Protection Board of India as an adjudicatory body."

Current Affairs Hook

2024-25 Developments:

  • National Cyber Security Strategy 2024 released (successor to 2013 policy) - 6 pillars, 5-year roadmap
  • DPDP Rules 2024 notified - consent manager framework, children's data (verifiable parental consent), significant data fiduciary criteria
  • CERT-In 6-hour reporting: Enforcement notices sent to non-compliant entities; VPN/VPS providers required to maintain logs
  • Telecom Cyber Security Regulations 2024 - mandatory security audits, breach reporting for TSPs
  • AI Deepfakes: 2024 LS elections - MeitY advisory to platforms (IT Rules 2021 Rule 3(1)(b)); deepfake detection tool (IISc/MeitY)
  • Ransomware: 'Ransomware-as-a-Service' (LockBit, BlackCat) targeting Indian SMEs, hospitals; NCIIPC sectoral advisories
  • Supply Chain: SolarWinds (2020), Log4j (2021), MoveIT (2023) - Indian entities affected; NCIIPC mandated SBOM (Software Bill of Materials) for CII
  • QUAD Cyber Partnership: Quad Senior Cyber Group - critical infrastructure protection, workforce development
  • India's Cyber Command: Tri-service Defence Cyber Agency (DCyA) operationalised; offensive cyber capability development

Interlinkages

  • Internal Security (GS 3): Cyber terrorism, critical infrastructure protection, radicalisation online, dark web (drugs, weapons)
  • Science & Tech (GS 3): AI/ML in cyber defence, quantum cryptography (QKD), blockchain for identity, 5G/6G security
  • Polity (GS 2): Right to Privacy (Puttaswamy), DPDP Act, intermediary liability (Shreya Singhal), surveillance reform
  • International Relations (GS 2): Budapest Convention, UN OEWG/GGE norms, QUAD cyber, ASEAN cyber cooperation, cyber diplomacy
  • Economy (GS 3): Fintech security (UPI, CBDC), crypto regulation, digital lending guidelines, cost of cybercrime (GDP impact)
  • Ethics (GS 4): Ethical hacking, vulnerability disclosure, AI ethics in surveillance, data colonialism

Common Mistakes

  1. "CERT-In and NCIIPC do the same thing." False. CERT-In = incident response for ALL cyber incidents. NCIIPC = PROTECTION of designated Critical Information Infrastructure only.
  2. "IT Act 2000 covers data privacy." Partially. Section 43A/72A (added 2008) had limited privacy provisions. DPDP Act 2023 is the comprehensive privacy law.
  3. "Protected System = any government server." False. Only systems NOTIFIED by NCIIPC under Section 70 IT Act are 'Protected Systems'.
  4. "India signed the Budapest Convention." False. India participated in negotiations but didn't sign - concerns over Article 32b (transborder access) and sovereignty.
  5. "Cyber security is only a technical issue." UPSC frames it as governance, legal, diplomatic, and strategic - not just firewalls.

Revision Snapshot

India's cyber architecture: NSCS (apex policy) → CERT-In (incident response, 6-hr reporting) → NCIIPC (CII protection, Protected Systems under Sec 70) → Sectoral CERTs/Regulators (RBI, SEBI, TRAI, MoP). Legal: IT Act 2000 (cybercrime, CII, interception) + DPDP Act 2023 (data privacy, consent, penalties) + Telecom Act 2023. Strategy: NCSS 2024 (Secure, Resilient, Trusted, Capable, Collaborative, Governed). Threats: State APTs (China/Pak/NK), ransomware, supply chain, AI deepfakes, drone-cyber convergence. Key anchors: 6-hr reporting, Protected System notification, DPDP Board, indigenous cyber products, QUAD/UN engagement.


Source Notes

  • Constitution of India (Art 355, 356, 246, 7th Schedule - Police/Public Order)
  • Acts: UAPA 1967, NIA Act 2008, NSA 1980, AFSPA 1958, Official Secrets Act 1923
  • MHA Annual Reports, BPR&D reports, NCRB Crime in India reports
  • CAPF websites and publications (CRPF, BSF, ITBP, Assam Rifles, SSB, CISF, NSG)
  • NIA, IB, NATGRID, NCTC (proposed) documents
  • Parliamentary Committee on Home Affairs reports
  • Supreme Court judgments on police reforms (Prakash Singh), AFSPA, UAPA
  • Standard texts: Ashok Kumar (Internal Security), MHA publications, IDSA/USI journals