National Security and Technology: Cybersecurity, Encryption, and Surveillance
TOPIC CLASSIFICATION
Subject: Science & Technology — Security and Ethics
Sub-topic: Cybersecurity — Threats (Malware, Phishing, Ransomware, APTs, DoS/DDoS), Critical Infrastructure Protection, Cyber Attacks on India, Encryption (Symmetric, Asymmetric, End-to-End), Surveillance Laws (IT Act, 2000 — s.69, NPD, Pegasus, DPDP Act), National Cyber Security Strategy, CERT-In, NCIIPC, Botnet, Dark Web, Crypto and National Security
Mains GS Paper-III: Security — cybersecurity, encryption, surveillance, and their implications for national security and civil liberties; GS Paper-II: Governance — IT Act, data protection.
EXAMINER REASONING
Cybersecurity is one of the most dynamic areas of national security — as India digitises rapidly, the threat surface expands exponentially. Prelims tests: CERT-In, NCIIPC, IT Act 2000 (s.66, 67, 69, 69A, 70), encryption types (symmetric, asymmetric, E2EE), cryptography basics, data encryption standard, IPR issues, Aadhaar security, VVPAT, cyber crime statistics. Mains demands: (a) the nature of cybersecurity threats — state-sponsored APTs (China-linked — APT10, APT40 — targeting strategic sectors), ransomware (WannaCry, AIIMS 2022), (b) encryption and the 'governance gap' — E2EE (WhatsApp) vs law enforcement demands — the India-US tussle over E2EE vs traceability, (c) surveillance state concerns — Pegasus (2021), IT Rules 2021 (traceability), NPDS (National Portability Database for SIMs), CCTNS, (d) data localisation — RBI mandate (2018), DPDP Act 2023, (e) cybersecurity for critical infrastructure — power grid, banking, defence, space, railways, (f) India's cyber command — Defence Cyber Agency (2018), National Cyber Coordination Centre (NCCC), (g) the surveillance vs privacy debate — Puttaswamy judgment (2017) — right to privacy is fundamental but not absolute. The examiner's favourite framing is: "Can national security and the right to privacy coexist in the digital age?"
Core Concept
Cybersecurity Threat Landscape
| Threat Type | Description | Notable Examples in India |
|---|---|---|
| Ransomware | Malware encrypts data — demands ransom (crypto) | AIIMS Delhi (2022) — hospital ops shut; Serviceman (2022) — Power Grid cyberattack |