UPSC Margin
NotesTestsDaily CACSAT
UPSC Margin

Analytical concept notes, daily current affairs, and mock tests for serious UPSC aspirants.

Learn

  • Notes
  • Daily Current Affairs
  • Mock Tests
  • CSAT
  • Strategy Guide

Resources

  • About
  • Pricing
  • Blog
  • Contact
  • RSS Feed

Support

  • Help & FAQ
  • Privacy Policy
  • Terms of Use
  • Telegram Community

© 2026 UPSC Margin. All rights reserved.

Operated by Satyam Raj · hello@upscmargin.com

Back to Notes
Science & TechFree till Sep 9

National Security and Technology: Cybersecurity, Encryption, and Surveillance

July 19, 2026

TOPIC CLASSIFICATION

Subject: Science & Technology — Security and Ethics
Sub-topic: Cybersecurity — Threats (Malware, Phishing, Ransomware, APTs, DoS/DDoS), Critical Infrastructure Protection, Cyber Attacks on India, Encryption (Symmetric, Asymmetric, End-to-End), Surveillance Laws (IT Act, 2000 — s.69, NPD, Pegasus, DPDP Act), National Cyber Security Strategy, CERT-In, NCIIPC, Botnet, Dark Web, Crypto and National Security
Mains GS Paper-III: Security — cybersecurity, encryption, surveillance, and their implications for national security and civil liberties; GS Paper-II: Governance — IT Act, data protection.


EXAMINER REASONING

Cybersecurity is one of the most dynamic areas of national security — as India digitises rapidly, the threat surface expands exponentially. Prelims tests: CERT-In, NCIIPC, IT Act 2000 (s.66, 67, 69, 69A, 70), encryption types (symmetric, asymmetric, E2EE), cryptography basics, data encryption standard, IPR issues, Aadhaar security, VVPAT, cyber crime statistics. Mains demands: (a) the nature of cybersecurity threats — state-sponsored APTs (China-linked — APT10, APT40 — targeting strategic sectors), ransomware (WannaCry, AIIMS 2022), (b) encryption and the 'governance gap' — E2EE (WhatsApp) vs law enforcement demands — the India-US tussle over E2EE vs traceability, (c) surveillance state concerns — Pegasus (2021), IT Rules 2021 (traceability), NPDS (National Portability Database for SIMs), CCTNS, (d) data localisation — RBI mandate (2018), DPDP Act 2023, (e) cybersecurity for critical infrastructure — power grid, banking, defence, space, railways, (f) India's cyber command — Defence Cyber Agency (2018), National Cyber Coordination Centre (NCCC), (g) the surveillance vs privacy debate — Puttaswamy judgment (2017) — right to privacy is fundamental but not absolute. The examiner's favourite framing is: "Can national security and the right to privacy coexist in the digital age?"


Core Concept

Cybersecurity Threat Landscape

Threat TypeDescriptionNotable Examples in India
RansomwareMalware encrypts data — demands ransom (crypto)AIIMS Delhi (2022) — hospital ops shut; Serviceman (2022) — Power Grid cyberattack

Read Next

More in Science & Tech

5G and 6G Technology: Features and India's Rollout

Artificial Intelligence: Applications, Ethics, and India's AI Strategy

Artificial Intelligence is reshaping global economies, and India is positioning itself as a significant AI player. This note covers AI applications in healthcare, agriculture, governance, and defence, ethical concerns including algorithmic bias, privacy, and job displacement, and India's AI strategy — INDIAai platform, NITI Aayog's national AI strategy (#AIforAll), the Bhashini language AI initiative, and the Global Partnership on AI (GPAI).

AstroSat and India's Space Observatories

Phishing / Spear-PhishingFraudulent communications to steal credentialsTargeted attacks on defence personnel, government officials
DDoS (Distributed Denial of Service)Overwhelm servers with trafficMultiple attacks on Indian banks (2023, 2024)
APTs (Advanced Persistent Threats)State-sponsored — long-term espionageChina-linked APT10 (CloudHopper) — IT sector; APT40 — maritime, defence
Malware / TrojansSteal data, credentials, install backdoorsPegasus (NSO Group) — zero-click spyware; Dridex banking trojan
Zero-Day ExploitsUnknown vulnerabilities — no patch availablePegasus exploited iOS zero-days
Supply Chain AttacksCompromise software/hardware at sourceSolarWinds (2020); update server breaches
CryptojackingSteal computing resources for crypto miningWebsites running hidden miners

Encryption: Types and National Security Implications

Encryption TypeHow It WorksExampleNational Security Implications
SymmetricSame key for encryption and decryptionAES, DES, 3DESFast — but key distribution is a vulnerability
Asymmetric (Public Key)Public key encrypts, private key decryptsRSA, ECC, DHMore secure — used for digital signatures, SSL/TLS
End-to-End Encryption (E2EE)Only sender and receiver can decrypt — provider cannotWhatsApp, Signal, Telegram (secret chat)Law enforcement cannot access content — creates conflict with surveillance laws
Homomorphic EncryptionComputation on encrypted data (without decrypting)Research stagePrivacy-preserving analytics — but computationally expensive
Quantum Encryption (QKD)Quantum key distribution — theoretically unbreakableISRO/Raman Research Institute QKD (2023)Future-proof against quantum computers

Surveillance Laws and Frameworks in India

Law / FrameworkYearKey ProvisionSignificance
IT Act, 2000 (s.69)2000 (amended 2008)Government can decrypt any information in the interest of sovereignty/securityThe core surveillance power — subject to procedural safeguards
IT Act, 2000 (s.69A)2008 AmendmentGovernment can block public access to any informationWebsite blocking — blocking orders by MeitY
IT Act, 2000 (s.69B)2008 AmendmentGovernment can monitor and collect traffic dataFor cybersecurity — monitoring without consent
IT Rules, 2021 (Intermediary Guidelines)2021Traceability — social media platforms must trace the first originator of a messageDirect challenge to E2EE — WhatsApp sued in Supreme Court — pending
Indian Telegraph Act, 1885 (s.5(2))1885Government can intercept communications in public emergencyOld law — still used for phone tapping
Prevention of Terrorism (Repealed)2002 (repealed 2004)Enhanced surveillance powers for POTAAbused — repealed — but surveillance architectures remain
UAPA (Unlawful Activities Prevention Act)1967 (amended 2019, 2020)Electronic records admissible; seizure/blocking powersUsed for cyber-related terrorism cases
NPD (National Portability Database)ProposedCentralised database of all SIM-based communicationPrivacy concerns — database of call records, location data

Key Cybersecurity Institutions in India

InstitutionEstablishedRole
CERT-In (Indian Computer Emergency Response Team)2004 (statutory under IT Act, s.70B)Cybersecurity incident response; vulnerability handling; coordination
NCIIPC (National Critical Information Infrastructure Protection Centre)2014Protection of critical information infrastructure (power, banking, telecom, transport, defence, space)
National Cyber Coordination Centre (NCCC)2018Situational awareness — threat intelligence sharing
Defence Cyber Agency (DCA)2018 (under CDS)Cyber warfare for military (Army, Navy, IAF)
National Intelligence Grid (NATGRID)2011 (conceptual) — operational 2024Real-time data integration from 21 source databases for counter-terrorism
National Technical Research Organisation (NTRO)2004Technical intelligence — signals intelligence (SIGINT)

Key Facts

FactDetail
IT Act, 2000India's primary law for cyber crimes and e-commerce — based on UNCITRAL Model Law
CERT-In establishedSection 70B of IT Act (2000) — operational since 2004
Indian Cyber Crime Coordination Centre (I4C)2018 — MHA — coordinates state police cyber cells
National Cyber Security StrategyDrafted (2020) — pending Cabinet approval
Data Protection ActDigital Personal Data Protection Act, 2023
Pegasus spywareExploited iOS zero-click vulnerability; targeted Indian journalists, activists, politicians (2021)
AIIMS Ransomware (2022)Hospital ops shut for 2 weeks — ~$1M ransom demanded
India's ranking in Global Cybersecurity Index (GCI)Ranked 'Tier 1' (role modelling) — 2024
Cyber crime cases in India (2023)~90,000+ cases — up 15% YoY
Digital ArrestsNew cyber fraud modus operandi — fake law enforcement calls

PYQ Table

YearQuestionType
2023"The end-to-end encryption (E2EE) debate represents a fundamental conflict between privacy and security. Discuss."Mains
2022"Cyber threats to India's critical infrastructure are growing. Analyse the institutional mechanisms in place."Mains
2021What is Pegasus spyware and how does it compromise mobile devices?Mains/Prelims
2020"The IT Act, 2000 has been amended multiple times to address emerging cyber threats. Critically evaluate."Mains
2019CERT-In comes under which Ministry?Prelims
2018"Surveillance technologies are necessary for national security but must be balanced with civil liberties. Discuss."Mains

Statement Elimination Guide

StatementTruth ValueWhy?
"End-to-end encryption means that the service provider can access user messages"FalseE2EE ensures that only the sender and recipient can read the messages — the provider (WhatsApp, Signal) cannot access the content
"The IT Act, 2000 was India's first cyber law"TrueThe Information Technology Act, 2000 is India's first and primary cyber law
"CERT-In is responsible for protecting critical information infrastructure in India"FalseNCIIPC is responsible for CII protection — CERT-In handles general cybersecurity incidents
"The Pegasus spyware was developed by an Indian company"FalsePegasus was developed by NSO Group (an Israeli cyber intelligence firm)
"The National Cyber Security Strategy has been formally adopted by the Government of India"FalseThe National Cyber Security Strategy was drafted in 2020 but is still pending Cabinet approval

Current Affairs Hook

2023-26: DPDP Act 2023 — the Digital Personal Data Protection Act was passed in August 2023 — rules still being drafted (2024-25) — impact on data localisation, surveillance, cross-border data flow. IT Rules 2021 vs WhatsApp — the traceability requirement is pending in the Supreme Court — the E2EE vs surveillance debate. Pegasus controversy (2021) — the Supreme Court-appointed Technical Committee (2021-23) found no conclusive evidence of state-sponsored Pegasus use — but the issue remains politically live. PIB Fact Check — expanding govt fact-checking to include digital content (amendments to IT Rules). AIIMS ransomware — led to a dramatic upgrade in healthcare cybersecurity — NCIIPC guidelines for hospitals. Digital Arrests (2024) — a new wave of cyber fraud where scammers impersonate police/govt officials via video calls. Quantum Key Distribution — ISRO successfully demonstrated QKD over 300 km (2023). India's internet shutdowns — India records the highest number of internet shutdowns globally (7th consecutive year) — raises tensions between security and civil liberties.


Interlinkages

  • → Right to Privacy (GS-II): Puttaswamy (2017) — surveillance must be necessary, proportionate, and procedurally fair — test for all surveillance laws
  • → E-Governance (GS-II): Digital India's Aadhaar, DigiLocker, UMANG — all depend on cybersecurity
  • → Critical Infrastructure (GS-III): Power grid, banking, telecom — all targets — Power Grid cyber attack (2022)
  • → Data Localisation (GS-III): RBI (2018), DPDP Act — data within India — security vs. economic efficiency
  • → Defence (GS-III): DCA, CDS — cyber as the fifth domain of warfare (land, sea, air, space, cyber)
  • → Social Media (GS-II): IT Rules 2021 — intermediary liability — traceability — fake news
  • → International Relations (GS-II): India-US cyber dialogue; India-Russia in cybersecurity; cooperation on crypto and ransomware (FATF)

Common Mistakes

MistakeCorrection
"CERT-In and NCIIPC are the same institution"CERT-In handles general cybersecurity — NCIIPC is specifically for Critical Information Infrastructure (power, banking, defence)
"End-to-end encryption is the same as HTTPS"HTTPS encrypts data in transit between client and server — E2EE ensures the server cannot decrypt (HTTPS lets servers see the data)
"The IT Act 2000 deals only with cyber crimes"It also covers e-commerce, digital signatures, data protection (before DPDP Act), and intermediary liability
"India has a formal National Cyber Security Policy"The National Cyber Security Policy 2013 is outdated — a new draft National Cyber Security Strategy (2020) is pending Cabinet approval
"All encryption is illegal in India"Encryption is legal — only s.69 of IT Act allows the government to decrypt data on national security grounds — not a blanket ban

Revision Snapshot

Cybersecurity, Encryption & Surveillance
├── Threats:
│   ├── Ransomware (AIIMS 2022), APTs (China-linked), Phishing, DDoS
│   ├── State-sponsored (APT10, APT40) — strategic sectors
│   └── Pegasus — zero-click spyware — NSO Group
├── Encryption:
│   ├── E2EE (WhatsApp/Signal) vs Traceability (IT Rules 2021)
│   ├── AES (symmetric), RSA/ECC (asymmetric)
│   └── Quantum Key Distribution (ISRO 2023)
├── Surveillance Laws:
│   ├── IT Act s.69, 69A, 69B — interception, blocking, monitoring
│   ├── IT Rules 2021 — traceability — challenged in SC
│   ├── Indian Telegraph Act (1885) — phone tapping
│   └── UAPA — electronic records
├── Institutions:
│   ├── CERT-In — general cybersecurity
│   ├── NCIIPC — critical infrastructure
│   ├── DCA (2018) — military cyber warfare
│   └── NCCC — threat intelligence
└── Tension: Puttaswamy (privacy) vs National Security — E2EE debate

Source Notes

  • Information Technology Act, 2000 (as amended 2008) — s.66, 67, 69, 69A, 69B, 70B
  • IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021
  • Digital Personal Data Protection Act, 2023
  • Justice K.S. Puttaswamy v. Union of India (2017) — Right to Privacy
  • CERT-In — Annual Cybersecurity Reports (2024, 2025)
  • NCIIPC — Guidelines for CII Protection (2023, 2024)
  • NITI Aayog — Cybersecurity in India (2023)
  • Ministry of Home Affairs — I4C (Indian Cyber Crime Coordination Centre) Reports
  • Cybersecurity and Cyberlaws in India — Vakul Sharma
  • Report of the Committee on Data Protection (Justice B.N. Srikrishna, 2018)
  • The Pegasus Project — Consortium of Investigative Journalists (2021, 2022)