Understanding Cyber Security and Cyber Threats
Cyber security is the protection of information, devices, computer resources, communication systems and the digital processes built upon them against unauthorised access, use, disclosure, disruption, modification or destruction. The object is not merely to keep data secret; it is to preserve trusted digital functioning.
This distinction matters for internal security. A payment network may hold no military secret, yet its prolonged disruption can generate panic, interrupt livelihoods and erode confidence in the State. Conversely, a system may remain available while silently leaking strategic information. A sound answer must therefore examine confidentiality, integrity and availability together.
| CORE PROPOSITION Cyber security is best understood as risk governance for a digitally dependent society. Technology supplies the attack surface, but institutions, incentives, human behaviour, law, geopolitics and recovery capacity determine whether a technical flaw becomes an internal-security crisis. |
Cyberspace Fundamentals
Cyberspace is the interconnected environment created by people, software, services, data and information and communication technology. It includes the Internet, but is wider than it: a disconnected industrial control system, a device-to-device network or a military intranet may also form part of cyberspace.
Three distinctions prevent conceptual confusion. The Internet is the global network of networks; the World Wide Web is one service operating over it; cyberspace is the broader socio-technical environment in which digital identity, communication, computation and control interact. In Mains answers, these terms should not be used as synonyms.
Cyberspace evolved from relatively closed, organisation-specific systems into a dense fabric of cloud platforms, mobile devices, connected sensors and industrial controls. Connectivity increased efficiency and inclusion, but also converted local weaknesses into remotely exploitable pathways. The result is systemic interdependence: the security of one actor can depend on the practices of many others.
| Legal anchor | Meaning for this conceptual section |
| Information Technology Act, 2000 — Section 2(1)(nb) | Defines cyber security through protection against unauthorised access, use, disclosure, disruption, modification or destruction. The wording covers both information and the equipment or communication resources that hold and carry it. |
| Information Technology Act, 2000 — Section 75 | Gives the Act extraterritorial reach where conduct outside India involves a computer, computer system or computer network located in India. It is a jurisdictional bridge, not a guarantee that a foreign offender can be identified, arrested or extradited. |
Layers of Cyberspace and the Attribution Problem
A cyber incident appears virtual, but it moves through several layers. The layer model helps an aspirant locate both the point of failure and the appropriate response. An error at one layer can be exploited through another, while the resulting harm may emerge in the physical world.
| Layer | What it contains | Typical security question |
| Physical network layer | Devices, processors, routers, cables, spectrum links, satellites, data centres, power supply and industrial machinery. | Can infrastructure be damaged, tapped, disabled, substituted or physically seized? |
| Logical network layer | Code, protocols, addressing, routing, operating systems, applications and the logical connections among devices. | Which vulnerability, configuration or protocol allowed access, manipulation or disruption? |
| Cyber-persona layer | Digital representations of persons or organisations: accounts, credentials, certificates, aliases and device-linked identities. | Does the visible account represent the real operator, a stolen identity, an automated bot or a deliberate false flag? |
| Mission and impact plane (analytical) | The information, decision processes and essential services that the three technical layers enable. | What confidentiality, integrity, availability, safety or strategic function has actually been harmed? |
Attribution means connecting an operation to the responsible actor with a stated degree of confidence. It is not a single forensic finding. Investigators must move from technical indicators to the operator, from the operator to a possible sponsor, and from factual linkage to legal responsibility and a defensible policy judgement.
| Technical trail | Operator | Sponsor | Legal responsibility | Policy response |
| Logs, malware, infrastructure and timing | Who controlled the keyboard or automated system? | Who directed, financed or knowingly supported the operation? | Can the conduct be attributed under the applicable rules? | What level of confidence justifies diplomatic, legal or security action? |
Analytical flow — Attribution moves from artefacts to responsibility; each arrow adds uncertainty.
Four obstacles make attribution especially difficult:
Obfuscation: traffic can be routed through compromised systems, rented infrastructure, cloud services or botnets.
False flags: attackers can reuse another group’s tools, language, infrastructure patterns or deliberately planted indicators.
Evidence gaps: volatile logs, encryption, inconsistent retention and foreign service providers can interrupt the technical trail.
Control gaps: the person operating a keyboard may be different from the organiser, financier, sponsor or State legally responsible for the conduct.
Cloud services and botnets therefore separate the apparent origin of traffic from the person exercising control. An Internet Protocol address is a lead, not proof of identity.
The problem has three dimensions:
- technical attribution asks what infrastructure and code were used;
- legal attribution asks whether conduct can be assigned to a State or person under applicable rules;
- political attribution decides when and how responsibility should be stated publicly.
These dimensions may reach different confidence levels.
| MAINS INSIGHT Weak attribution complicates deterrence because punishment can be delayed, misdirected or escalatory. Yet perfect certainty is rarely possible. The practical standard is multi-source confidence built from forensics, intelligence, victim reporting, behaviour patterns and partner information, followed by a response proportionate to both the evidence and the harm. |
Why Cyber Is the Fifth Domain of Warfare
Cyberspace is often described as the fifth domain of operations, alongside land, sea, air and outer space. The phrase became influential because military and civilian power increasingly depends on networked information systems, and because cyber operations can support, precede or substitute for some kinetic actions.
| Characteristic | Why it changes security calculations |
| Cross-domain effects | Code can disrupt a physical process, distort command information or disable a service on which land, maritime, air or space operations depend. |
| Global reach and speed | An operator can act across borders without moving forces to the target’s territory, compressing warning and decision time. |
| Low replication cost | Once developed, many tools can be copied or adapted at far lower cost than conventional weapon systems, although sophisticated operations still demand intelligence, access and expertise. |
| Persistent contestation | Reconnaissance, espionage, pre-positioning and influence can continue below the threshold of armed conflict. |
| Deniability and ambiguity | Proxies, compromised infrastructure and dual-use tools create room for denial and make calibrated response harder. |
| Civil–military overlap | The same networks, cloud providers, cables and software supply chains serve citizens, firms and the State; national defence therefore depends heavily on private capability. |
The formulation needs a caveat. Cyberspace is not sovereign territory in the same way as land, and it is not independent of physical infrastructure. Every digital operation ultimately relies on hardware, energy, radio spectrum or human action. It is more accurate to call cyber a distinct operational domain with deep dependence on the other domains.
| CASE STUDY — ESTONIA In 2007, Estonia faced a sustained wave of disruptive cyber activity against public and private online services. The episode demonstrated how distributed attacks could pressure a highly digitised society while making rapid, conclusive attribution difficult. Its enduring lesson is the need for national resilience and international cooperation, not the assumption that every large attack automatically constitutes war. |
Basic Vocabulary for Precise Answers
Precision begins by separating what is valuable, what can go wrong and what produces harm.
| Term | Precise meaning | Exam use |
| Asset | Data, system, service, capability, reputation or physical process that has value. | Start with what must be protected. |
| Threat | A circumstance or actor capable of causing harm. | Threat is potential; it is not the same as an incident. |
| Threat actor | Person, group, organisation or State-linked entity that creates or exploits risk. | Classify by capability, intent and access—not by label alone. |
| Vulnerability | A weakness in technology, configuration, process or human behaviour. | A weakness can exist without being exploited. |
| Exploit | A method or code that takes advantage of a vulnerability. | Exploit is the means; impact is the consequence. |
| Attack vector | The path or method used to gain access or produce an effect. | Examples include a malicious link, exposed service or compromised update. |
| Attack surface | The total set of reachable points through which an adversary may try to enter or act. | Digitisation expands opportunity unless exposure is governed. |
| Event / incident / breach | An event is an observable occurrence; an incident harms or threatens operations; a breach is confirmed compromise of protected data or systems. | Avoid calling every alert a breach. |
| Risk | The combination of likelihood and consequence, shaped by threat, vulnerability, exposure and existing controls. | Risk enables prioritisation; zero risk is unrealistic. |
| Control | A technical, administrative, legal or physical measure that modifies risk. | Controls prevent, detect, respond or support recovery. |
| Resilience | The ability to withstand, adapt to and recover from disruption while preserving essential functions. | Security must include continuity and learning. |
| Zero-day vulnerability | A vulnerability for which an effective defence or vendor fix is not yet available to the defender at the time of exploitation. | The term describes defender disadvantage, not unlimited attacker power. |
| Indicator of compromise | An observable artefact suggesting that a system may have been compromised. | It supports investigation but is not, by itself, attribution. |
| Tactics, techniques and procedures | Patterns describing an actor’s objectives, methods and operational habits. | Useful for behavioural detection and actor assessment. |
Elements of Cyber Security
The elements of cyber security can be organised in three complementary ways: by security objective, by the environment being protected, and by the risk-management lifecycle.
Confidentiality, Integrity and Availability
The CIA triad is the basic test of whether information and systems remain trustworthy. Each objective protects a different public value, and a single incident may violate all three.
| Objective | Question to ask | Typical failure | Illustrative safeguards |
| Confidentiality | Can information be seen only by authorised persons and processes? | Espionage, credential theft, data leakage or unauthorised disclosure. | Access control, encryption, data classification, least privilege and secure disposal. |
| Integrity | Is information complete, accurate and changed only through authorised action? | Manipulated records, altered software, forged commands or corrupted sensor data. | Digital signatures, hashes, change control, validation, logging and separation of duties. |
| Availability | Are systems and data accessible to authorised users when required? | DDoS, ransomware, destructive malware, power failure or dependency outage. | Redundancy, capacity management, backups, failover, incident response and tested continuity plans. |
The triad is necessary but not sufficient.
- Authenticity establishes that an entity or message is genuine;
- accountability links actions to responsible identities;
- non-repudiation provides evidence against later denial;
- privacy governs lawful and proportionate use of personal data; and
- safety becomes central when digital commands control physical processes.
| ANALYTICAL EXAMPLE A hospital ransomware incident is not only an availability failure. Exfiltrated patient records violate confidentiality; altered prescriptions threaten integrity and safety; weak logs reduce accountability; and an improvised response may intrude upon privacy. The triad turns a generic incident into a multidimensional answer. |
Security Across Networks, Applications, Endpoints, Data, Identity, Cloud, Mobile and Industrial Systems
Cyber security is a system of interlocking domains. A mature organisation protects the full path from identity to device, application, data and underlying infrastructure. Strength in one area cannot permanently compensate for neglect in another.
| Element | Primary concern | Core practices | Internal-security significance |
| Network security | Traffic flowing among devices, segments and external networks. | Segmentation, secure configuration, filtering, encrypted communication, monitoring and DDoS resilience. | Limits unauthorised entry and lateral movement across essential services. |
| Application security | Flaws in software design, code, interfaces and dependencies. | Secure development, code review, testing, input validation, dependency management and timely remediation. | Public services increasingly depend on applications; a code flaw can become a population-scale gateway. |
| Endpoint security | Laptops, servers, workstations and connected devices where users and code act. | Hardening, patching, malware prevention, endpoint detection, device control and privileged-access management. | A single compromised endpoint can become the first foothold into a larger network. |
| Data security | Information throughout collection, storage, use, sharing, archival and deletion. | Classification, access control, encryption, data-loss prevention, integrity checks, backup and retention rules. | Protects privacy, state secrets, evidentiary value and confidence in public records. |
| Identity and access management | Who or what may access which resource, under what conditions. | Strong authentication, least privilege, role or attribute-based access, credential protection and access reviews. | Identity is the new control plane when users and services operate beyond a fixed perimeter. |
| Cloud security | Shared infrastructure, remote administration, exposed interfaces and divided responsibility. | Secure configuration, key management, workload isolation, logging, posture management and clarity on provider–customer duties. | Concentration can create common dependencies; misconfiguration can expose data at scale. |
| Mobile security | Portable, sensor-rich devices operating on varied networks and holding personal or official data. | Application control, secure updates, device encryption, remote management, permission hygiene and phishing resistance. | Mobile devices combine identity, communication, payments and location, making compromise socially consequential. |
| Operational technology and industrial control security | Systems that monitor or change physical processes, including industrial control systems. | Asset inventory, network separation, safe change control, specialised monitoring, controlled remote access and manual fallbacks. | Prioritises safety, reliability and continuity; careless security changes can themselves interrupt physical operations. |
Across these domains, people and governance remain cross-cutting elements. Boards and public authorities must assign risk ownership; procurement must account for supply-chain exposure; staff must recognise manipulation; and contracts must define reporting, logging, recovery and responsibility. Cyber security cannot be delegated entirely to an information-technology unit.
| Govern | Identify | Protect | Detect | Respond | Recover |
| Risk ownership, policy and oversight | Assets, dependencies and vulnerabilities | Controls that reduce likelihood and impact | Monitoring and anomaly recognition | Containment, communication and action | Restore, learn and strengthen |
The lifecycle prevents two common errors.
- First, buying preventive tools without governance and asset visibility leaves unknown exposures.
- Second, equating security with prevention ignores detection, containment and recovery.
Since some failures are inevitable, preparedness must minimise the time between intrusion, discovery, control and restoration.
Defence in Depth and Zero Trust Architecture
Defence in depth assumes that any single safeguard can fail. It places multiple, independent and mutually reinforcing controls across people, process and technology so that bypassing one layer does not yield unrestricted access or catastrophic impact.
Zero trust architecture removes implicit trust based merely on network location or prior connection. Access is granted to a specific resource after evaluating identity, device, context and policy; privileges are minimised; and trust is continuously reassessed. It is an architecture and operating principle—not a product and not a demand to distrust every person.
| Dimension | Defence in depth | Zero trust architecture | How they combine |
| Starting assumption | Any control may be defeated. | No user, device or workload receives implicit trust. | Layer controls and verify each access decision. |
| Design focus | Multiple barriers and recovery mechanisms. | Resource-centred, identity-aware, least-privilege access. | Prevent a foothold from becoming broad compromise. |
| Typical measures | Hardening, segmentation, filtering, monitoring, backups and response playbooks. | Strong identity, device posture, micro-segmentation, policy enforcement and continuous telemetry. | Use diverse controls with shared visibility. |
| Failure if misapplied | Many overlapping tools can create complexity without coverage. | A slogan-based rollout can disrupt work or centralise risk in identity systems. | Begin with assets and use cases; test and phase implementation. |
| MAINS LENS — ELEMENTS OF CYBER SECURITY A high-quality answer should move from objectives (confidentiality, integrity and availability) to domains (network, application, endpoint, data, identity, cloud, mobile and industrial systems), then to the lifecycle and the two design principles of defence in depth and zero trust. This directly demonstrates comprehensiveness without prematurely cataloguing institutions. |
Threat Taxonomy
A threat taxonomy is useful only if it guides response. The same incident can be classified by tool, access path, actor, motive and impact. Ransomware describes a method; phishing an access technique; an advanced persistent threat an operational pattern; and espionage a strategic objective. Mixing these levels produces weak analysis.
A typical intrusion may proceed through reconnaissance → initial access → execution and persistence → privilege escalation → lateral movement → command and control → data theft or disruption. Not every attack uses every stage, but the chain shows where layered controls can prevent, detect or contain harm.
Malware, Ransomware, Phishing and Common Attack Techniques
| Threat or technique | How it works | Likely impact | Priority defence |
| Malware | Software or firmware deliberately designed to perform unauthorised, harmful or disruptive action. It includes viruses, worms, Trojans, spyware and destructive payloads. | Data theft, surveillance, unauthorised control, disruption or propagation. | Secure configuration, patching, application control, endpoint monitoring and restricted privileges. |
| Ransomware | Malware or an intrusion campaign that denies access to systems or data and demands payment; modern campaigns may also steal data and threaten disclosure. | Operational stoppage, extortion, privacy harm, recovery cost and loss of trust. | Offline and tested backups, segmentation, strong identity, monitored administration, rapid containment and recovery planning. |
| Phishing | A deceptive message or interaction impersonates a trusted source to obtain information, induce payment, install malware or capture credentials. Voice and text-message variants are often called vishing and smishing. | Account takeover, fraud and initial access to organisational networks. | Phishing-resistant authentication, independent verification, filtering, user reporting and payment controls. |
| Distributed denial-of-service | Many sources flood or exhaust a target’s resources so legitimate users cannot obtain service. | Loss of availability, distraction from another intrusion or coercive pressure. | Distributed capacity, traffic scrubbing, rate controls, provider coordination and continuity alternatives. |
| Man-in-the-middle attack | The attacker positions itself between communicating parties to observe or alter exchanges while each party believes it is communicating directly with the other. | Credential theft, eavesdropping, transaction manipulation and loss of integrity. | Authenticated encryption, certificate validation, secure networks and transaction verification. |
| SQL injection | Untrusted input is interpreted as database commands because an application fails to separate data from executable queries. | Unauthorised reading, alteration or deletion of database contents and possible system compromise. | Parameterized queries, input handling, least-privilege database accounts, testing and monitoring. |
| Zero-day exploitation | An attacker exploits a vulnerability before the defender has an effective patch or mitigation in place. | Rapid compromise before signature-based defences or routine patching can respond. | Attack-surface reduction, behavioural detection, isolation, rapid intelligence sharing and compensating controls. |
The word Trojan describes disguise, not a guaranteed destructive effect: the program appears legitimate while carrying an unauthorised function.
A worm is distinguished by its ability to propagate across systems without attaching itself to a host file.
A virus usually replicates by infecting another file or program. These terms may overlap in real campaigns because attackers combine components.
Ransom payment is not a recovery strategy. It does not guarantee decryption, deletion of stolen data or non-recurrence; it may also finance further crime and create legal or sanctions risk. The durable response is prepared resilience: protected backups, rehearsed restoration, segmented administration, evidence preservation and stakeholder communication.
Supply-Chain Attacks, Insider Threats, Social Engineering, Cryptojacking and Botnets
| Category | Distinctive risk | Why ordinary perimeter security may fail | Response logic |
| Supply-chain attack | The adversary compromises a supplier, update, library, service provider or build process to reach downstream users. | The malicious component may arrive through a trusted relationship or digitally signed workflow. | Map dependencies, assess suppliers, secure development and build systems, verify updates, monitor behaviour and design containment. |
| Insider threat | A person with authorised access causes harm intentionally, negligently or after the account is compromised. | Activity may initially resemble legitimate work and use valid credentials. | Least privilege, separation of duties, behavioural monitoring, supportive reporting, access reviews and fair investigation. |
| Social engineering | Psychological manipulation exploits urgency, authority, fear, curiosity or helpfulness to induce unsafe action. | It bypasses technical controls by recruiting the user into the attack path. | Verification rituals, usable controls, reporting without blame, simulation, strong authentication and process-level checks. |
| Cryptojacking | Computing resources are used without authorisation to mine cryptocurrency. | The activity may hide inside browsers, cloud workloads or compromised servers and appear as a performance problem. | Monitor resource anomalies, secure cloud credentials, patch exposed services and control workloads. |
| Botnet | A network of compromised devices is remotely coordinated to send spam, spread malware, commit fraud or launch distributed attacks. | Traffic originates from many apparently unrelated devices, often without their owners’ knowledge. | Device security, command-and-control disruption, provider cooperation, sinkholing where lawful and victim remediation. |
These categories reveal a common theme: trust itself is an attack surface. The trusted supplier, authorised employee, familiar brand or ordinary home device becomes the channel of compromise. Therefore, security must verify behaviour and dependencies rather than relying only on a trusted/untrusted perimeter distinction.
Advanced Persistent Threats and State-Sponsored Actors
An advanced persistent threat is a well-resourced adversarial campaign that seeks sustained, covert access to achieve defined objectives. ‘Advanced’ refers to capability and adaptation; ‘persistent’ to patience and repeated effort; ‘threat’ to the organised actor. It is not the name of one malware family and is not automatically proof of State sponsorship.
| Feature | Operational meaning | Defender implication |
| Objective-led | The actor selects targets for strategic information, access or future disruptive option. | Protect mission-critical data and dependencies, not merely every device equally. |
| Long dwell and stealth | The actor may remain quiet, harvest credentials and blend with legitimate administration. | Hunt for behaviour and anomalies; preserve long-enough logs. |
| Adaptive tradecraft | Tools, infrastructure and techniques change when detected. | Share tactics and remediate root access paths, not only known file signatures. |
| Multiple access paths | Phishing, exposed services, suppliers, insiders or stolen credentials may be combined. | Use defence in depth and assume one barrier may fail. |
| Strategic sponsorship may exist | A State can direct, support, tolerate or benefit from an operation, sometimes through proxies. | Separate technical resemblance from evidence of direction and legal attribution. |
State-linked actors often seek intelligence or pre-positioning while remaining below the threshold that would provoke a military response. Their campaigns can be strategically serious without being ‘cyber war’. A careful answer uses calibrated terms such as suspected, assessed with confidence, State-linked or officially attributed, depending on the evidence.
Cybercrime Types and the Required Response
A legally useful first division is between cyber-dependent crime, which can exist only through information and communication technology, and cyber-enabled crime, where technology expands the scale, speed, reach or concealment of an offence that can also occur offline. Many investigations contain elements of both.
| Category | Illustrative offences | Distinct investigative need | Required response |
| Cyber-dependent crime | Unauthorised access, malware deployment, denial-of-service, interference with systems or data, and operation of botnets. | Volatile logs, malware analysis, infrastructure tracing and technical reconstruction. | Secure systems; preserve digital evidence; build specialised investigation and prosecution; disrupt criminal infrastructure; coordinate across borders. |
| Cyber-enabled financial and identity crime | Impersonation, payment fraud, account takeover, investment or marketplace fraud and identity theft. | Fast tracing of money, accounts, devices and communication before proceeds are layered or withdrawn. | Strong transaction safeguards, rapid reporting and freezing processes, platform–bank–police coordination, restitution and victim support. |
| Content- and person-related crime | Cyberstalking, threats, non-consensual intimate imagery, child sexual exploitation material and technology-facilitated abuse. | Victim-sensitive evidence collection, removal or preservation decisions, identity protection and risk assessment. | Accessible reporting, survivor support, lawful platform action, trained investigators and proportionate prosecution. |
| Market and intellectual-property crime | Illegal online markets, trafficking facilitation, counterfeit trade, theft of commercial secrets and large-scale infringement. | Linking online personas, payments, logistics and beneficiary networks. | Joint financial, cyber and organised-crime investigation; asset tracing; private-sector evidence; international cooperation. |
The response should follow a complete chain: prevent → report → preserve → investigate → prosecute or disrupt → recover → learn. Prevention reduces exposure; reporting creates early visibility; preservation protects admissible evidence; investigation joins technical and financial trails; disruption stops infrastructure even when arrest is delayed; and recovery reduces victim harm.
| Response pillar | What effective practice looks like | Frequent weakness |
| Prevention | Secure-by-design services, strong identity, defaults that protect users, staff awareness and transaction verification. | Placing the entire burden on individual awareness while retaining unsafe systems. |
| Detection and reporting | Simple reporting channels, automated telemetry, anomaly detection and rapid escalation. | Under-reporting caused by shame, fear of liability or unclear responsibility. |
| Evidence and investigation | Forensic readiness, lawful acquisition, chain of custody, trained personnel and links between cyber, financial and field investigation. | Delayed requests allow logs, cloud artefacts and money trails to disappear. |
| Disruption and prosecution | Coordinated action against domains, servers, mule accounts, proceeds and organisers, alongside fair trial safeguards. | Counting registered cases without dismantling the enabling ecosystem. |
| Victim recovery | Account restoration, financial assistance processes, safety planning, data remediation and clear communication. | Treating the complainant merely as an evidence source. |
| Cooperation | Standard request formats, trusted contact points and regular public–private and international collaboration. | Jurisdictional delay and incompatible retention or disclosure rules. |
| MAINS LENS — CYBERCRIME Do not answer ‘types of cybercrime’ with a list of malware alone. Classify offences into cyber-dependent and cyber-enabled forms, show major victim and sector dimensions, and then connect each class to prevention, evidence, investigation, disruption, prosecution and recovery. This converts taxonomy into administration. |
Current Status (as of August 2026)
| HOW TO READ THE CURRENT PICTURE Official operational reporting shows a threat environment centred on extortion, stolen trust and dependency risk. The signals below describe observed techniques and alerts; they should not be presented as a complete crime-prevalence series or as proof that every recipient was successfully compromised. |
| Current signal | Verified operational evidence | Analytical inference for Mains |
| Ransomware has become multi-stage extortion | The official national ransomware report on the 2024 landscape records data theft, multiple extortion methods, attacks on virtualised infrastructure and public-cloud storage, and greater use of legitimate system tools to evade detection. | Backups remain essential but are insufficient alone; identity, segmentation, data protection, monitoring and crisis communication must be integrated. |
| Trusted development ecosystems are targets | National incident-response advisories in March 2026 highlighted multiple software supply-chain compromises affecting developer ecosystems. | Procurement assurance must extend into build pipelines, packages, dependencies, update channels and downstream monitoring. |
| Compromised accounts deliver malware through familiar channels | A June 2026 advisory described a campaign using compromised messaging accounts and weaponised script files against desktop and web users. | The attacker can borrow social trust; verification, safer file handling, strong account security and endpoint controls must work together. |
| Mobile impersonation remains operationally important | A March 2026 advisory warned of Android malware distributed through fake road-transport and electronic-challan messages. | Citizen-facing security requires trusted communication, rapid takedown, mobile hygiene and fraud-response coordination—not only enterprise defences. |
Cyber Crime, Espionage, Terrorism and Warfare
The same technical act—unauthorised access, malware deployment or data theft—can carry different strategic meanings. Classification must therefore begin with actor, intent, target, scale, effect and context, not with the tool alone. These categories are analytical and can overlap; they are not four watertight legal boxes.
Four Categories, Four Response Frameworks
| Category | Primary purpose and usual actor | Typical target or effect | Lead response framework |
| Cybercrime | Financial gain, personal harm or illicit advantage; individuals, organised groups or crime-as-a-service networks. | Money, identity, data, devices, businesses and individuals. | Criminal justice, financial disruption, consumer protection, platform cooperation and victim recovery. |
| Cyber espionage | Covert acquisition of strategic, diplomatic, military, technological or commercial information; commonly intelligence-oriented and sometimes State-linked. | Confidential information and enduring access, usually with minimal visible disruption. | Counter-intelligence, cyber defence, diplomatic action, access removal and protection of sensitive knowledge. |
| Cyberterrorism | Ideological or political coercion through cyber-dependent conduct intended to create fear and serious harm; terrorist actors or affiliates. | Critical services, public safety or systems whose disruption can terrorise a population. | Counter-terrorism law, intelligence, specialised cyber response, infrastructure protection and prevention of violent-extremist mobilisation. |
| Cyber warfare | State-linked cyber operations used for military or strategic purposes in or around interstate conflict. | Command systems, military capability, critical functions or civilian objects affected as a means of coercion or conflict. | National defence, international law, diplomacy, alliance or partner coordination, resilience and calibrated deterrence. |
Cyber espionage is distinguished primarily by covert information acquisition. It may violate domestic law and sovereignty-related interests without, by itself, amounting to an armed attack. The response emphasises detection, counter-intelligence, protection of sources and technology, quiet remediation and, where justified, public attribution or diplomatic costs.
Cyberterrorism should be used narrowly. A cyber operation designed to cause or threaten serious harm for ideological coercion is different from terrorists using the Internet for propaganda, recruitment, fundraising or communication. The latter is the terrorist use of cyberspace and is treated further with media and information warfare; collapsing both concepts exaggerates the legal category.
| Legal signpost | Why it matters to classification |
| Information Technology Act, 2000 — Section 66F | Creates the offence of cyber terrorism around specified high-harm or national-security conduct and access to restricted security-related information. It therefore sets a much higher threshold than ordinary abusive online content. |
| International law | The United Nations Charter applies to State conduct involving information and communication technologies. Rules of international humanitarian law govern cyber operations carried out in the context of an armed conflict; not every hostile cyber incident activates that body of law. |
| CLASSIFICATION TEST Ask six questions in sequence: Who acted? Why? Against what? By what method? With what actual or intended effect? In what legal and conflict context? The answers may change during investigation. A financially motivated intrusion can become espionage if a sponsor purchases the stolen data; an espionage foothold can later be used for disruption. |
Cyber Warfare: Definition, Thresholds and India’s Vulnerability
Cyber warfare may be understood as State-linked cyber operations employed for military or strategic purposes whose context or effects connect them to interstate coercion or armed conflict. The term is descriptive, not a licence to call every hostile intrusion an act of war.
| Intensity level | Illustrative conduct | Analytical position |
| Intrusion and preparation | Scanning, credential theft, access creation or pre-positioning in networks. | Serious security concern, but usually below the use-of-force threshold. |
| Espionage | Covert extraction of diplomatic, military, technological or commercial information. | May be unlawful domestically and strategically damaging; generally not treated as armed attack merely because it is cyber-enabled. |
| Coercive interference | Disruption, manipulation or destructive action causing significant political, economic or societal effects. | Response depends on scale, effects, target, duration, attribution and surrounding context. |
| Use of force | Cyber effects comparable in scale and consequence to force, such as severe physical damage or injury. | May engage the prohibition on the use of force; assessment is effects- and context-based. |
| Armed attack | The gravest form of force, assessed through consequences and international law. | May engage the inherent right of self-defence; the threshold is deliberately high and fact-specific. |
The threshold problem has two sides. If every intrusion is called war, the concept loses precision and may encourage escalation. If only physical destruction counts, grave manipulation of essential digital services may be underestimated. A balanced answer evaluates scale, duration, reversibility, directness, target, physical consequences and military context.
Where cyber operations occur in an armed conflict, the established principles of distinction, proportionality and precautions remain relevant. Civilian objects and civilian infrastructure cannot be treated as free targets merely because operations are conducted through code. The dual-use character of networks makes careful target assessment especially important.
| CASE STUDY — STUXNET Disclosed in 2010, Stuxnet demonstrated how malicious code could manipulate industrial control processes and damage Iranian uranium-enrichment centrifuges while reporting apparently normal conditions to operators. The defensible lesson is the convergence of cyber and physical effects. Public evidence does not justify presenting disputed authorship as a settled fact. |
India’s vulnerability arises less from one dramatic weakness than from the interaction of digital dependence and uneven security maturity. Expanding digital public services, finance, communication, defence and industrial automation increase national capability, but also enlarge the number of identities, interfaces, suppliers and operational dependencies that must be secured.
| Vulnerability dimension | Why it matters | Strategic implication |
| Large and heterogeneous digital ecosystem | Citizens, small firms, major platforms, government bodies and critical operators possess widely different resources and practices. | A national baseline must raise the weakest links without freezing innovation. |
| Information technology–operational technology convergence | Business networks, remote access and industrial controls increasingly interact. | An ordinary credential compromise can become a safety or continuity incident. |
| Supply-chain and concentration risk | Common software, cloud, telecom and managed services create shared dependencies. | One compromise or outage may propagate across many organisations. |
| Human and identity exposure | High-volume digital transactions create opportunities for impersonation, coercion and credential theft. | Security must combine usable design, awareness, strong identity and rapid fraud response. |
| Attribution and cross-border constraints | Actors, infrastructure, victims, data and proceeds may sit in different jurisdictions. | Defence requires domestic capability plus sustained legal, diplomatic and provider cooperation. |
| Hybrid security environment | Cyber operations can accompany espionage, border tension, terrorism, disinformation or conventional conflict. | Assessment must join technical incident response with intelligence and strategic decision-making. |
This conceptual vulnerability analysis connects with the treatment of critical information infrastructure, national institutions and legal policy developed later. At this stage, the essential point is that preparedness must protect essential functions, not merely individual computers.
| MAINS LENS — CYBER WARFARE Define the term cautiously; explain the fifth-domain logic; distinguish intrusion, espionage, coercive interference, use of force and armed attack; then assess India through dependency, exposure, capability and cross-border constraints. Conclude with resilience and calibrated response rather than an exclusively offensive solution. |
Cross-Border Cyber Attacks and Defensive Measures
A cross-border cyber attack is an operation in which one or more material elements—actor, infrastructure, service provider, data, victim or effect—span jurisdictions. The path may cross several countries even when the operator and victim are geographically close. Digital routing therefore complicates jurisdiction without abolishing geography.
| Internal-security dimension | Potential impact of a cross-border attack |
| Political and administrative | Disruption of public services, manipulation of official information, erosion of institutional credibility and pressure on crisis decision-making. |
| Economic | Payment interruption, theft, business discontinuity, supply-chain effects, recovery cost and reduced confidence in the digital economy. |
| Social | Fear, fraud, interruption of health or welfare access, exploitation of social fault lines and disproportionate harm to users with limited digital literacy. |
| Strategic and military | Espionage, degradation of command or logistics, pre-positioning in essential networks and coercive signalling during tension or conflict. |
| Technological | Compromise of common software, telecom, cloud or industrial dependencies; theft of intellectual property and security knowledge. |
| Legal and diplomatic | Conflicting jurisdiction, delayed evidence access, sovereignty concerns, difficult attribution and risk of disproportionate or mistaken response. |
| Human rights | Privacy and expression may be harmed both by the attack and by indiscriminate surveillance, shutdowns or poorly bounded emergency measures. |
The cross-border challenge has four recurring bottlenecks:
Volatile evidence: logs, accounts and cloud artefacts may disappear before formal process reaches the holder.
Distributed custody: a provider, victim, server, domain registrar and payment intermediary may each sit in a different jurisdiction.
Rapid movement of proceeds: criminal funds can pass through mule accounts and virtual assets faster than ordinary freezing requests.
Innocent infrastructure: a visible server or device may itself be compromised, so hasty retaliation can target the wrong entity.
| Prevent | Detect | Contain | Attribute | Respond | Recover and learn |
| Reduce exposure | Find weak signals early | Stop lateral spread | Build confidence and evidence | Use legal, diplomatic and security instruments | Restore services and close the exploited path |
| Defensive layer | Priority measures | Why it answers the cross-border problem |
| Resilience by design | Asset and dependency mapping, secure configuration, timely remediation, segmentation, strong authentication, protected backups, redundancy and manual fallbacks. | Reduces the leverage of a remote attacker and contains failure before attribution is complete. |
| Continuous detection | Centralised and protected logging, endpoint and network visibility, anomaly detection, threat intelligence and user reporting. | Creates early warning and the technical record needed for investigation. |
| Prepared incident response | Clear authority, playbooks, decision thresholds, communications, sector exercises and pre-arranged vendor support. | Avoids delay and contradictory action during fast-moving incidents. |
| Forensic and evidentiary readiness | Time synchronisation, retention rules, chain of custody, malware analysis and trained cyber–financial investigation teams. | Converts technical traces into reliable legal and attribution evidence. |
| Public–private coordination | Trusted reporting channels, minimum security duties, provider cooperation, safe sharing and joint exercises. | Most infrastructure and evidence are distributed across government and private operators. |
| International legal cooperation | Fast preservation requests, mutual legal assistance, extradition where available, common evidence formats and operational contact networks. | Bridges jurisdictional gaps and increases the prospect of disruption or prosecution. |
| Diplomacy and strategic signalling | Norm-building, confidence-building measures, private demarches, coordinated attribution, sanctions or other lawful costs where evidence supports them. | Offers graduated options below military force and helps manage escalation. |
| Rights-respecting safeguards | Necessity, legality, proportionality, oversight, remedy and narrowly tailored collection or restriction. | Preserves public trust and prevents the defence itself from producing avoidable social harm. |
Section 75 of the Information Technology Act, 2000 can bring certain foreign conduct within Indian law when a computer resource in India is involved. Yet jurisdiction on paper does not automatically deliver evidence or custody. Successful enforcement still depends on attribution, preservation, foreign legal process, platform cooperation and the location of the accused and assets.
Defensive measures must be proportionate and graduated. Quiet remediation may be best when public attribution would expose intelligence; criminal investigation may suit profit-driven actors; diplomatic coordination may suit a State-linked campaign; and defence measures may be necessary in armed-conflict settings. The instrument should follow the evidence, objective and effect.
| Approach | What works | What does not work or creates risk |
| Deterrence | A credible combination of denial, attribution, prosecution, diplomatic cost and, where lawful, strategic response. | Threatening retaliation without reliable attribution, resilience or escalation control. |
| Compliance | Outcome-based baselines, risk ownership, testing and evidence of recovery capability. | Paper checklists that reward documentation while operational exposure persists. |
| Information sharing | Timely, actionable, protected exchange tied to remediation and feedback. | One-way reporting that produces no warning, assistance or learning for the reporting entity. |
| Central coordination | Clear roles, common situational awareness and interoperable procedures. | Overcentralisation that delays local containment or creates a single point of failure. |
| Surveillance and restriction | Targeted, lawful measures subject to necessity, proportionality, oversight and review. | Blanket monitoring or shutdowns that impose wide economic and rights costs without addressing the exploited vulnerability. |
| Offensive cyber capability | May support intelligence, disruption and deterrence within lawful political control. | Treating offence as a substitute for basic hygiene, recovery capacity or diplomatic strategy. |
The most credible way forward is resilience with accountability: know essential assets and dependencies; reduce preventable exposure; verify identity and access continuously; detect abnormal behaviour early; preserve evidence; protect victims; cooperate across sectors and borders; and subject exceptional powers to law and oversight.
Thus, cyber security is neither a purely technical subject nor a synonym for cyber warfare. It is the capacity of the State, economy and society to maintain trusted digital functions under conditions of uncertainty. The strongest Mains answer joins technology, institutions, law, strategy and rights in one coherent risk-and-resilience framework.
The conceptual foundations developed earlier explain what cyber threats are and why the cyber domain is strategically important. The present section asks a more concrete question: where is India exposed, and which digital dependencies require the highest level of protection?
India’s digital transformation has enlarged State capacity, financial inclusion and service delivery. The same transformation has also created concentrated dependencies: a hospital may depend on one patient-management platform, a power utility on remote control systems, and millions of citizens on a small set of identity, telecom and payment rails. Security must therefore be judged by the ability to prevent compromise and to continue essential functions when prevention fails.
| CORE PROPOSITION India’s cyber vulnerability is not evidence that digitalisation was mistaken. It is the predictable result of high digital dependence growing faster than uniform security maturity. The policy task is to convert connectivity into resilience through risk-based protection, institutional accountability and recoverable design. |
