Global and Emerging Cyber Security Challenges
The International Dimension
International cyber governance is not one unified code. It is a layered arrangement of criminal-law treaties, general international law, voluntary norms, confidence-building measures, technical cooperation and capacity-building. Their subjects overlap, but their legal character and purpose differ.
| Problem | Primary international route | Nature of output | Central question |
| Cybercrime and electronic evidence | Budapest Convention; UN Convention against Cybercrime; MLATs; police and judicial cooperation | Treaty duties, domestic offences and procedures | How can evidence and offenders be reached across borders? |
| State conduct and international security | UN GGE, OEWG and the Global Mechanism | International law, voluntary norms, confidence-building and capacity-building | What behaviour reduces conflict and escalation? |
| Cyber operations and the law of conflict | UN Charter, customary international law and scholarly interpretation | Binding law plus contested interpretation | When do sovereignty, use of force, self-defence and humanitarian law apply? |
| National preparedness | Global Cybersecurity Index and peer cooperation | Benchmarking and capacity signals | Has a State built the legal, technical, organisational, skills and cooperation base? |
The international cyber-governance map — Do not use a cybercrime treaty to answer a cyber-warfare question, or a voluntary norm as if it were a binding criminal-law rule.
The core tension is easy to state. Networks require speed, interoperability and transnational cooperation; States require sovereignty, lawful process and control over coercive power. A durable system must therefore create trusted pathways across borders without allowing one State, platform or investigator to bypass another society’s law and rights.
Budapest Convention — and Why India Has Stayed Out
The Convention on Cybercrime, 2001, commonly called the Budapest Convention, is a Council of Europe treaty open beyond Europe. It entered into force in 2004. Its importance lies less in creating a global cyber police and more in aligning three things that investigations repeatedly need: substantive offences, procedural powers and international cooperation.
| Pillar | What the Convention seeks to harmonise | Why it matters |
| Substantive criminal law | Core offences such as illegal access, illegal interception, data and system interference, misuse of devices, computer-related forgery and fraud, and specified content or copyright offences. | Comparable offences reduce the chance that conduct is criminal in the victim State but legally unreachable in the State holding the offender or evidence. |
| Procedural law | Expedited preservation, production, search and seizure of stored computer data, real-time collection of traffic data and interception of content data subject to domestic law and safeguards. | Electronic evidence is fragile, replicable and easily moved; ordinary paper-era procedure may be too slow or technically mismatched. |
| International cooperation | Extradition, mutual assistance, spontaneous information, expedited preservation and a 24/7 contact network. | Investigators need a continuously available channel to preserve data before the slower formal request is completed. |
India is not a party. Its long-standing position has not been opposition to cooperation against cybercrime. India has supported the objectives in principle, but viewed the Convention as a regional instrument negotiated without its participation and preferred a universal framework under United Nations auspices. Concerns have also centred on sovereignty, the terms on which data may be accessed across borders, and the need for a more broadly representative rule-making process.
| Case for accession | Case for continued caution |
| Access to an established cooperation community, common procedures and the treaty’s 24/7 network. | India did not participate in drafting the original text; legitimacy and policy ownership matter in rules affecting sovereign investigative powers. |
| Faster preservation and assistance in cases where evidence is held in a party State. | Cross-border access must remain compatible with Indian law, privacy, due process and protection against foreign investigative overreach. |
| Greater procedural compatibility can reduce delay and improve admissibility. | The newer UN Convention offers a universal negotiating pedigree and may cover cooperation at a broader scale once it enters into force. |
| Accession need not mean abandoning bilateral or UN routes; instruments can be complementary. | Overlapping treaties can increase complexity, forum competition and inconsistent safeguards if domestic implementation is not carefully aligned. |
| ANALYTICAL CONCLUSION The choice is not sovereignty versus cooperation. The real question is which cooperative design gives India speed, reciprocity and influence while retaining lawful safeguards. The emergence of a UN treaty changes the context but does not automatically erase the practical value of the Budapest system. |
| CURRENT STATUS (AS OF AUGUST 2026) The Budapest Convention has 81 parties. India does not appear among its parties. It should no longer be described as the world’s only binding cybercrime treaty: a separate United Nations Convention against Cybercrime has been adopted and opened for signature, although that newer treaty is not yet in force. |
UN GGE and OEWG Processes; Norms of Responsible State Behaviour
Cybercrime cooperation deals principally with offenders and evidence. A different problem arises when information and communication technologies are used by or linked to States in ways that threaten international peace and security. The United Nations has developed a cumulative framework through Groups of Governmental Experts (GGE) and Open-ended Working Groups (OEWG).
| Process | Participation | Contribution | Limit |
| GGE | A limited group of experts appointed on the basis of equitable geographical distribution. | Built expert consensus, including recognition that international law and the UN Charter apply to State conduct involving ICTs; developed voluntary norms and explanations. | Small membership gives focus but raises representation concerns; consensus does not settle every legal interpretation. |
| OEWG | Open to all UN Member States, with structured stakeholder engagement. | Broadened ownership; discussed threats, law, norms, confidence-building, capacity-building and regular institutional dialogue. | Inclusiveness can make detailed consensus slow; geopolitical disputes often survive carefully negotiated language. |
The resulting framework has four mutually reinforcing parts: international law; voluntary non-binding norms; confidence-building measures; and capacity-building. Norms do not replace binding legal obligations. Their function is practical: they create shared expectations, reduce misperception and help States identify conduct that increases or lowers escalation risk.
The most exam-relevant expectations include:
States should not knowingly allow their territory to be used for internationally wrongful ICT acts and should respond to appropriate requests for assistance, consistent with international law and capacity.
A State should not conduct or knowingly support ICT activity contrary to its international obligations that intentionally damages critical infrastructure or impairs essential public services.
States should protect their own critical infrastructure and consider how best to exchange information and assistance regarding attacks on it.
States should not harm the information systems of another State’s authorised computer emergency response team, nor use such teams for malicious international activity.
States should encourage responsible reporting of vulnerabilities and share information on available remedies, while taking reasonable steps to ensure supply-chain integrity.
States should respect human rights and fundamental freedoms in their use and regulation of ICTs.
Implementation is harder than agreement. A norm against attacking critical infrastructure still leaves questions about what counts as critical, whether indirect effects qualify, how intent is proved, and how a victim should respond when attribution is uncertain. The framework therefore works best when States publish national positions, create points of contact, exercise crisis communication, exchange technical indicators and build capabilities in less-resourced countries.
| CURRENT STATUS (AS OF AUGUST 2026) The OEWG 2021–2025 completed its mandate and transmitted its final report in July 2025. The General Assembly endorsed the transition to a permanent, State-led Global Mechanism on ICTs in the Context of International Security. Its first substantive plenary met on 20–24 July 2026; dedicated thematic-group meetings are scheduled for December 2026. This replaces the outdated formulation that the OEWG ‘will meet through 2025’. |
UN Convention against Cybercrime 2024 — Content and India’s Position
The United Nations Convention against Cybercrime, formally adopted by the General Assembly through Resolution 79/243 on 24 December 2024, is the first cybercrime treaty negotiated under UN auspices. Its full title also emphasises international cooperation for specified ICT-enabled crimes and the sharing of electronic evidence for serious crimes.
| Component | Main content | Security value |
| Criminalisation | Cyber-dependent offences such as illegal access, interception and interference, along with specified ICT-related forgery, fraud, sexual offences against children, non-consensual dissemination of intimate images and laundering of proceeds. | Creates a wider common legal vocabulary for offences that can be initiated, routed or completed across several countries. |
| Electronic-evidence procedure | Preservation, production, search, seizure and collection measures for electronic data, with conditions and safeguards under domestic law. | Evidence rules are relevant even where the underlying serious offence is not itself a cyber-dependent crime. |
| International cooperation | Extradition, mutual legal assistance, direct and urgent channels, joint investigations where appropriate, and a 24/7 network. | Aims to reduce jurisdictional delay and loss of volatile evidence. |
| Technical assistance and capacity-building | Training, institutional development, technology support and attention to the needs of developing countries. | A treaty cannot work if only a few States can preserve, analyse and lawfully exchange digital evidence. |
| Safeguards | Human-rights and domestic-law safeguards, grounds for refusal, data-protection considerations and protection against discriminatory cooperation. | International speed must remain bounded by legality, necessity, proportionality and fair process. |
India participated actively in the negotiations and supported a universal convention capable of addressing crimes committed through ICTs and enabling cooperation on electronic evidence. This was consistent with India’s preference for a UN-based, broadly representative framework over reliance on a treaty of regional origin.
The Convention offers three gains for India: a broader cooperation network for transnational fraud and organised cybercrime; more standardised access to electronic evidence; and capacity-building for investigators, prosecutors and forensic institutions. It also raises three governance tests: broad cooperation powers must not be used to suppress legitimate expression; data sharing must protect privacy, purpose limitation and due process; and domestic law must define authorities, review and admissibility clearly.
| Stage | Legal meaning |
| Adoption | The negotiating text is accepted by the competent international body. Adoption alone does not bind a State as a party. |
| Signature | Indicates political endorsement and an intention to examine ratification; it is not the same as consent to be fully bound. |
| Ratification, acceptance, approval or accession | The State deposits the instrument through which it consents to be bound, subject to the treaty’s terms. |
| Entry into force | The treaty becomes legally operative after its specified threshold is met. This Convention requires the fortieth instrument and then a ninety-day period. |
| CURRENT STATUS (AS OF AUGUST 2026) The Convention opened for signature in Hanoi on 25–26 October 2025 and remains open for signature at UN Headquarters until 31 December 2026. The UN depositary records 81 signatories and 3 parties on 12 August 2026. It is not yet in force because forty instruments are required. India is not listed among the participants; therefore, write that India helped negotiate and supported the UN process, but has not signed or ratified the Convention as of this date. |
Tallinn Manual and the Application of International Law to Cyberspace
The Tallinn Manual asks how existing international law applies to cyber operations. The first edition, published in 2013, concentrated on severe operations involving the use of force, self-defence and armed conflict.
Tallinn Manual 2.0, published in 2017, expanded the analysis to routine peacetime operations involving sovereignty, jurisdiction, State responsibility, human rights and other legal regimes.
| ESSENTIAL CAUTION The Tallinn Manual is a non-legally-binding scholarly work by independent experts. It is not a treaty, not a judgment, not NATO doctrine and not the official legal position of any State or international organisation. Its value is analytical: it maps rules, competing interpretations and grey zones. |
| Legal issue | Basic proposition | Why cyberspace complicates it |
| Sovereignty and jurisdiction | A State exercises authority over persons, infrastructure and conduct connected to its territory or lawful jurisdiction. | Data and infrastructure are distributed; remote operations may produce effects without physical entry, and States differ on whether every sovereignty violation is a standalone rule. |
| Attribution and State responsibility | International responsibility requires conduct attributable to a State and breach of an international obligation. | Technical attribution, legal attribution and public political attribution have different evidence and confidence thresholds; proxies and compromised infrastructure obscure control. |
| Non-intervention | Coercive interference in matters reserved to another State may violate the principle of non-intervention. | Influence, espionage, manipulation and disruption form a spectrum; identifying coercion and the protected sovereign domain is contested. |
| Use of force and armed attack | The UN Charter regulates force; an armed attack may trigger the inherent right of self-defence under Article 51. | Most cyber incidents remain below these high thresholds. Scale and effects matter, but States do not agree on every criterion or response option. |
| International humanitarian law | Where an armed conflict exists, distinction, proportionality, precautions and protection of civilian objects remain relevant. | Civilian and military systems share infrastructure; malware may propagate unpredictably; the legal treatment of data as an object is debated. |
| Countermeasures | An injured State may take proportionate, temporary measures against a responsible State to induce compliance, subject to strict conditions. | Uncertain attribution, secrecy, reversibility and spillover create escalation and legality risks. |
For India, the strategic need is a publicly intelligible national position on international law in cyberspace. It need not disclose capabilities or red lines in operational detail. It should clarify how India understands sovereignty, prohibited intervention, thresholds, attribution, protection of civilian and critical infrastructure, lawful response and the role of evidence. Such clarity supports diplomacy, coalition-building and deterrence by reducing an adversary’s room to exploit ambiguity.
Cross-border Data Access and the MLAT Bottleneck; Data Localisation Debate
A cyber investigation often confronts a jurisdictional puzzle: the offence is experienced in India, the user appears through an address in another country, the account belongs to a global platform, and the relevant data sit in a distributed cloud. The investigator needs not only access, but access that is timely, lawful and admissible.
| Preserve | Identify | Authorise | Transmit | Authenticate | Use |
| Prevent volatile data from being deleted | Link account, device, address or transaction to the offence | Use the correct domestic, treaty or provider route | Transfer only what the lawful request covers | Maintain integrity, provenance and chain of custody | Present admissible evidence with rights safeguards |
Cross-border evidence is a chain, not a download — Speed without legality may make evidence unusable; legality without speed may leave nothing to obtain.
| Route | Use | Strength | Constraint |
| Domestic production or search power | Data or systems within lawful Indian jurisdiction. | Potentially fastest and directly supervised by domestic procedure. | Territorial reach, encryption, corporate structure and conflict of laws may limit effectiveness. |
| Provider preservation or emergency channel | Urgent request to prevent deletion or address an imminent risk, where provider policy and law permit. | Protects volatile data while a formal request is prepared. | Preservation is not disclosure; provider action cannot substitute for legal authority. |
| Letters Rogatory or MLAT request | Formal assistance through the requested State’s central authority and judicial or investigative process. | Respects sovereignty, dual legality and evidentiary safeguards. | Multiple checks, translation, incomplete requests and institutional queues can take longer than the useful life of data. |
| Treaty 24/7 network | Rapid contact, technical assistance and urgent preservation under an applicable convention. | Creates named, continuously available counterparts. | Its reach depends on participation, implementation and follow-through through formal legal channels. |
| Joint investigation and police cooperation | Coordinated action against transnational groups and infrastructure. | Combines intelligence, evidence and simultaneous enforcement. | Mandates, disclosure rules and evidentiary standards still differ. |
India’s mutual legal assistance framework makes the Ministry of Home Affairs the Central Authority for criminal matters. For electronic evidence, an investigator should show the account’s connection with the offence, specify the data and period sought, preserve data urgently where possible, and maintain the chain of custody. A vague request for ‘all data’ is likely to be delayed, refused or challenged.
Data localisation means requiring specified data to be stored or processed within the country, or requiring a local copy. It can improve jurisdictional availability, reduce dependence on a foreign request for some records, support regulatory inspection and encourage domestic infrastructure. It is nevertheless a location rule, not a complete security or evidence-access policy.
| Potential gain from localisation | Corresponding limitation or risk |
| Faster lawful access to data held by an entity subject to Indian process. | The provider, encryption key, controller or useful metadata may still be outside India; location does not guarantee intelligibility or cooperation. |
| Greater regulatory visibility and continuity for strategically important data. | Concentrated domestic stores can become high-value targets and require strong resilience, redundancy and access control. |
| Reduced exposure to foreign legal uncertainty for selected critical or sectoral datasets. | Blanket mandates raise cost, fragment global services and may invite reciprocal data barriers. |
| Support for domestic cloud and data-centre capability. | Industrial policy should not be confused with privacy; insecure local processing remains insecure. |
A better design is risk-calibrated data sovereignty: targeted sectoral storage rules where consequence justifies them; rapid preservation; standardised and audited request portals; bilateral and multilateral agreements; trained central and State investigators; clear conflict-of-laws procedure; and privacy safeguards based on legality, necessity, proportionality, purpose limitation and remedy. The data-protection framework developed earlier permits cross-border transfer subject to restrictions notified by the Central Government rather than imposing a general localisation rule on all digital personal data.
Global Cybersecurity Index — India’s Standing
The Global Cybersecurity Index (GCI) of the International Telecommunication Union measures national commitment across five pillars: legal, technical, organisational, capacity development and cooperation. The 2024 edition groups countries into tiers rather than presenting the result as a simple security league table.
| CURRENT STATUS (AS OF AUGUST 2026) In the Global Cybersecurity Index 2024, India received a score of 98.49 out of 100 and was placed in Tier 1 — Role-modelling. The Department of Telecommunications was the nodal agency representing India. Use ‘Tier 1’ and the score; do not invent a numerical rank. |
The result recognises institutional commitment: law, incident-response capacity, organisational arrangements, training and international cooperation. But an index score is not proof that networks are breach-proof, crime is falling or every institution is equally capable. It measures national structures and commitments; operational resilience must be tested through incident outcomes, recovery time, patching, audit quality, skilled personnel and citizen experience.
| What the GCI can support | What it cannot establish by itself |
| Comparison of the breadth of national cyber commitments across common pillars. | The absence of attacks, breaches, fraud, espionage or systemic outages. |
| Identification of weak pillars that require investment or cooperation. | Effective implementation in every State, district, sector, small enterprise or public body. |
| Recognition of legal, institutional, technical and capacity-building progress. | Attribution capability, classified preparedness or the quality of every regulatory intervention. |
| SECTION TAKEAWAY Cyber diplomacy must connect law, norms, operational cooperation and capacity. India should pursue universal rule-making without isolating itself from useful working networks; speed up evidence access without normalising unchecked surveillance; publish a principled international-law position; and turn a strong preparedness index into measurable resilience. |
Emerging Technologies and Security
An emerging technology is not a separate threat simply because it is new. Its security relevance depends on how it changes capability, scale, speed, dependency, attack surface and concentration of failure. Most technologies in this section are dual-use: they strengthen attackers, defenders, governance and development at the same time.
| Technology | Security opportunity | Security risk | Governing principle |
| Artificial intelligence | Faster detection, triage, anomaly analysis and defensive automation. | Scalable persuasion, impersonation, reconnaissance, vulnerability discovery and adaptive attacks. | Human accountability, risk-based testing and secure deployment. |
| Quantum technologies | New computation, sensing and secure-communication capabilities. | Future compromise of widely used public-key cryptography and present-day collection of long-lived secrets. | Crypto-agility and phased migration to post-quantum standards. |
| Blockchain | Tamper-evident shared records and programmable coordination in suitable trust models. | Smart-contract bugs, stolen keys, oracle failures, governance attacks and irreversible loss. | Use only where distributed consensus solves a real problem; secure the full system. |
| Internet of Things | Real-time monitoring, automation and better service delivery. | Vast numbers of weak, long-lived devices linked to physical processes. | Secure-by-design devices with supported lifecycles and network segmentation. |
| 5G and 6G | Low-latency, high-capacity and programmable connectivity for strategic applications. | Software, cloud, slicing, edge and supply-chain dependencies expand systemic risk. | Trusted procurement, assurance, zero-trust operations and security by design. |
Artificial Intelligence as Attacker and Defender; AI Governance
Artificial intelligence changes cyber security through automation and inference. It can lower the skill and time needed to produce convincing content, write or modify code, analyse targets and coordinate operations. It can also help defenders sift enormous log volumes, recognise behavioural anomalies and prioritise response. The decisive issue is not whether AI is ‘good’ or ‘bad’, but who controls the objective, data, tools and authority to act.
| Attacker use | Defender use | Residual caution |
| Generate persuasive multilingual phishing, pretexts and impersonation at scale. | Classify suspicious messages, detect look-alike domains and identify anomalous communication patterns. | Attackers adapt to detection; false positives can block legitimate users or speech. |
| Automate reconnaissance, summarise exposed systems and tailor attacks to a victim. | Correlate assets, vulnerabilities, threat intelligence and observed behaviour for risk-based prioritisation. | A confident model output may be wrong; sensitive prompts and logs may leak data. |
| Assist code mutation, evasion and exploitation of known weaknesses. | Analyse malware, identify patterns, recommend containment and accelerate secure-code review. | Defensive automation can propagate a bad decision at machine speed. |
| Create synthetic identities, voice or video for fraud and influence operations. | Use liveness checks, provenance signals, multimodal inconsistency detection and transaction-risk analytics. | No detector is permanently reliable; authenticity requires process, not one tool. |
| Poison training data, manipulate model inputs, steal models or abuse connected tools. | Red-team models, restrict tools, monitor drift and apply runtime guardrails. | The AI system itself becomes an asset with a software, data and supply-chain attack surface. |
| Prepare | Prevent | Detect | Respond | Learn |
| Threat-model the model, data, tools and deployment context | Control access, inputs, updates, plugins and high-risk actions | Use behavioural analytics, provenance and human review | Contain accounts, preserve evidence and communicate uncertainty | Red-team, audit failures, retrain controls and update policy |
AI-security cycle — The same technology may strengthen every stage, but it also creates new failure modes at every stage.
AI governance must cover two distinct questions. Governance of AI addresses bias, explainability, accountability, privacy, safety and social harm. AI for governance and security asks when public authorities may use AI for policing, welfare, border control, intelligence or cyber defence. The second requires stronger safeguards because an error can affect liberty, equality, public order or access to essential services.
A proportionate framework should require:
a named human or institution accountable for each consequential deployment, even where a model recommends the action;
risk classification based on context, affected rights and reversibility rather than the glamour or size of the model;
security testing of models, data pipelines, dependencies, tools, application interfaces and deployment infrastructure;
data governance, purpose limitation, access control, privacy protection and resistance to poisoning or unauthorised extraction;
meaningful logging, explainability appropriate to the decision, independent evaluation and a route to challenge harmful outcomes; and
incident disclosure and coordinated response when an AI system creates or amplifies a security event.
| CURRENT STATUS (AS OF AUGUST 2026) The IndiaAI Mission, approved in March 2024 with an outlay of ₹10,371.92 crore over five years, includes a Safe & Trusted AI pillar. The India AI Governance Guidelines, released in November 2025, adopt a principle-based, risk-based and techno-legal approach rather than a new horizontal AI statute at this stage. The IndiaAI Safety Institute has been established, and thirteen responsible-AI projects have been selected under the Safe & Trusted AI pillar. These policy instruments complement, but do not replace, applicable information-technology, data-protection, consumer, criminal and sectoral law. |
Deepfakes and Synthetic Media
A deepfake is synthetic or manipulated audio, image or video generated through computational techniques to imitate a person, event or authentic recording. The wider category of synthetic media includes content that may be wholly generated, partly altered or produced with benign creative intent. The security problem arises when realistic fabrication is combined with deception, speed and a high-trust context.
| Threat | Internal-security pathway | Most useful response |
| Impersonation and fraud | A cloned voice or video supplies the apparent authority needed to trigger payment, reveal credentials or bypass weak verification. | Out-of-band confirmation, transaction limits, liveness checks and separation of approval channels. |
| Operational deception | Fabricated instructions or statements create confusion during a crisis, military operation, disaster or communal tension. | Authenticated official channels, pre-established crisis protocols, rapid verification and restrained public communication. |
| Targeted abuse | Non-consensual intimate or defamatory synthetic content harms dignity, privacy, safety and participation, especially of women and vulnerable persons. | Fast victim-centric removal, evidence preservation, criminal investigation, platform cooperation and psychosocial support. |
| Evidence pollution | A false recording is treated as genuine, or genuine evidence is dismissed as fabricated — the liar’s dividend. | Provenance, chain of custody, forensic examination and corroboration rather than visual intuition. |
Detection is not a magic classifier. Compression, re-recording, model improvement and adversarial editing can defeat artefact-based tools. A stronger authenticity stack combines content provenance and durable labels; cryptographic signing at capture where feasible; platform metadata; source history; contextual verification; forensic analysis; and human judgement. Even then, a label proves something about the creation process, not whether the underlying claim is true.
| CURRENT STATUS (AS OF AUGUST 2026) The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 were amended in February 2026 to address synthetically generated information (SGI). The rules require covered generation-enabling intermediaries to apply a prominent label or permanent unique metadata or identifier and prohibit its suppression; significant social media intermediaries also have declaration and reasonable verification duties. For specified intimate, nudity, sexual or impersonation content under Rule 3(2)(b), the complaint-response period is two hours. These duties do not create a single offence called ‘deepfake’; liability still depends on the content, conduct and applicable law. |
| CRITICAL ASSESSMENT Mandatory provenance improves transparency, but malicious actors may remove labels, use foreign tools or launder content through re-recording. Overbroad automated removal can also suppress satire, art, journalism or political speech. Regulation must therefore combine traceability, rapid remedy, criminal accountability for harmful conduct, platform process and safeguards against censorship. |
Quantum Computing, the ‘Harvest Now, Decrypt Later’ Problem, Post-quantum Cryptography, National Quantum Mission
Quantum computers use properties of quantum systems to perform certain classes of computation differently from classical computers. A sufficiently capable fault-tolerant quantum computer could threaten widely used public-key schemes based on integer factorisation or discrete logarithms. It does not mean that every encrypted system suddenly becomes readable or that present quantum devices can already break all deployed cryptography.
The strategic danger is harvest now, decrypt later. An adversary can collect encrypted diplomatic, defence, identity, health, industrial or commercial data today and retain it until future capability makes decryption feasible. Data with a long secrecy life therefore requires action before a cryptographically relevant quantum computer exists.
| Concept | Meaning | Policy implication |
| Post-quantum cryptography (PQC) | Classical cryptographic algorithms designed to resist attacks by both classical and quantum computers. | Inventory vulnerable cryptography, test standardised algorithms, use hybrid transition where appropriate and build crypto-agility. |
| Quantum key distribution (QKD) | Uses quantum properties to establish keys and reveal eavesdropping on the quantum channel, subject to implementation and endpoint security. | Useful in selected high-value links, but not a universal replacement for authentication, endpoint security or scalable PQC. |
| Crypto-agility | The ability to discover, replace and update algorithms, keys, protocols and certificates without rebuilding the entire service. | Procurement, software architecture and inventories must anticipate multiple migrations and possible algorithm failure. |
| Cryptographic inventory | A map of where algorithms, keys, certificates, libraries and dependencies are used and how long protected data must remain secret. | Migration priority should follow secrecy life, system life, exposure and consequence — not organisational visibility alone. |
A practical migration sequence is:
discover cryptographic use in applications, devices, firmware, identity systems, third-party libraries and supply chains;
classify data by secrecy life and systems by replacement difficulty and national consequence;
prioritise high-consequence, long-life data and long-lived infrastructure;
test interoperable PQC and hybrid configurations against performance, implementation and side-channel risk;
migrate keys, certificates, protocols and applications in controlled phases with rollback and continuity plans; and
monitor standards, vulnerabilities, vendor support and cryptographic dependencies throughout the lifecycle.
| CURRENT STATUS (AS OF AUGUST 2026) The National Quantum Mission was approved on 19 April 2023 at a total cost of ₹6,003.65 crore for 2023–24 to 2030–31. Four Thematic Hubs cover quantum computing, quantum communication, quantum sensing and metrology, and quantum materials and devices. Internationally, three initial post-quantum standards — FIPS 203, FIPS 204 and FIPS 205 — were finalised in August 2024. In July 2025, CERT-In released a white paper on Transitioning to Quantum Cyber Readiness, while Indian telecom research has advanced PQC and quantum-secure products. The policy priority is migration readiness, not prediction of an exact ‘Q-day’. |
Blockchain, IoT and the Expanding Attack Surface
Blockchain is a type of distributed ledger in which participants maintain a shared record using cryptographic links and a consensus mechanism. It can make an authorised history difficult to alter without detection, but it does not make every connected application truthful, private, lawful or secure. Immutability of a ledger is not immunity of a system.
| Blockchain layer | Typical security failure | Required control |
| Private keys and wallets | Key theft, insecure custody, social engineering or irreversible loss. | Hardware-backed custody where justified, multi-party approval, recovery design and transaction monitoring. |
| Smart contracts | Logic flaws, unsafe permissions, re-entrancy, arithmetic or upgrade failures. | Minimal code, independent audit, formal methods where consequence is high, staged deployment and controlled pause mechanisms. |
| Consensus and governance | Concentrated validators, collusion, majority attack, contentious upgrades or unclear accountability. | Threat-model the actual participant set, governance rights, dispute process and failure recovery. |
| Oracles and interfaces | False external input, compromised application, bridge or programming interface. | Multiple trusted sources, signed data, anomaly checks and isolation of high-value functions. |
| Privacy and law | Permanent replication of personal, secret or unlawful data and uncertain jurisdiction. | Keep sensitive data off-chain where possible; store proofs or references with clear controller and erasure design. |
The Internet of Things (IoT) links sensors, actuators, appliances, vehicles, cameras, industrial equipment and other devices to networks and services. Its distinctive security risk is the bridge between cyber and physical effects. A compromised camera may expose privacy; a compromised medical, transport, energy or industrial device may affect safety and continuity.
| Why IoT expands risk | Security-by-design response |
| Large numbers of heterogeneous devices, often deployed outside controlled premises. | Unique device identity, asset inventory, authenticated onboarding and risk-based network segmentation. |
| Weak defaults, shared credentials and unnecessary exposed services. | No universal default password; least functionality, strong authentication and secure configuration. |
| Limited memory, power and processing capacity. | Controls proportionate to device capability, with compensating gateway and network protections. |
| Long operational life but short vendor support or unclear ownership. | Published support period, signed updates, vulnerability disclosure, software-component transparency and secure end-of-life process. |
| Cloud applications, mobile apps and programming interfaces extend the product beyond the device. | Treat the device, gateway, application, backend, data and update service as one security boundary. |
| Sensors and actuators interact with the physical world. | Fail-safe modes, manual override, safety separation, integrity monitoring and tested recovery. |
India needs baseline IoT assurance across procurement and lifecycle support: device identification, secure configuration, data protection, controlled interfaces, signed updates, security-state awareness, vulnerability reporting and an end-of-support plan. Critical-sector devices require stronger certification, segmentation, monitoring and safety engineering than ordinary consumer devices. This links directly to the earlier treatment of critical information infrastructure and supply-chain security.
5G/6G Security and Trusted Telecom Sources
5G is not merely a faster radio connection. It combines dense connectivity with software-defined and virtualised functions, cloud-native cores, edge computing, application interfaces and network slicing. These features enable low-latency and sector-specific services, but they also move trust from specialised hardware into software, orchestration, cloud infrastructure and a wider vendor ecosystem.
| Security concern | Why it grows in advanced networks | Required response |
| Supply-chain compromise | Hardware, firmware, chips, libraries, cloud components and managed services may contain hidden or inherited weaknesses. | Trusted-source policy, component transparency, secure development, testing, update assurance and vendor-risk governance. |
| Virtualisation and cloud risk | Shared infrastructure and automated orchestration can turn one control-plane error into wide impact. | Strong tenant isolation, hardened management plane, zero-trust access, continuous configuration assurance and resilient recovery. |
| Network-slice isolation | Slices share underlying resources while serving different risk domains. | End-to-end isolation validation, resource controls, slice-specific monitoring and safe failure containment. |
| Edge and API exposure | Processing moves nearer users and machines; third-party applications interact programmatically with network functions. | Authenticated and authorised APIs, rate limits, software-supply-chain controls, runtime monitoring and local physical security. |
| Massive machine connectivity | Compromised IoT devices can become entry points, botnets or channels into physical systems. | Device identity, admission control, segmentation, anomaly detection and manufacturer lifecycle obligations. |
| Availability and national dependence | Finance, logistics, governance, emergency response and defence rely on common connectivity. | Redundancy, geographic diversity, tested continuity, domestic capability and coordinated telecom incident response. |
India’s National Security Directive on Telecommunication Sector operationalised a framework under which designated categories of telecom equipment are procured from Trusted Sources with associated Trusted Products. The policy addresses national-security and supply-chain risk; it is not a declaration that an approved product is permanently vulnerability-free. Trust must be continuously earned through testing, patching, monitoring, audit and incident response.
6G is still a research, standards and ecosystem project. Likely features — deeper integration of AI, sensing, satellites and terrestrial networks, programmable surfaces, extreme densification and new spectrum — may create new capabilities and new dependencies. Security must enter standards, chip design, identity, cryptography, spectrum governance, testing and procurement before architecture hardens and switching costs become prohibitive.
| CURRENT STATUS (AS OF AUGUST 2026) The trusted-source framework has been implemented since 2021 and is reinforced by the newer telecommunications framework and security-assurance mechanisms. The Bharat 6G Vision was launched in March 2023, and the Bharat 6G Alliance links government, industry, academia and standards engagement. India’s stated ambition is a 10 per cent share of worldwide 6G patents by 2030. This is an innovation target, not a present deployment or security outcome. |
The combined way forward for emerging technologies is:
secure by design and by default: include abuse cases, rights impact, failure containment and safe update mechanisms before deployment;
assurance by consequence: subject systems affecting life, liberty, critical services or national security to stronger independent testing and monitoring;
strategic autonomy without isolation: build domestic capability while contributing to interoperable international standards and trusted research networks;
lifecycle responsibility: assign ownership for vulnerabilities, model or software updates, key migration, vendor exit and end-of-support;
institutional literacy: train police, regulators, judges, civil servants, engineers and commanders to distinguish technical possibility from verified evidence; and
constitutional technology policy: innovation should strengthen security and development without normalising opaque surveillance, automated discrimination or unreviewable coercive decisions.
| SECTION TAKEAWAY The goal is not technological self-denial. It is resilient adoption: capture the productivity and strategic benefits of AI, quantum systems, distributed ledgers, IoT and advanced telecom while controlling concentration, provenance, cryptography, supply chains, lifecycle support and rights impact. In security policy, the costliest vulnerability is often the one embedded during design and discovered only after national dependence has formed. |
Digital communication has altered internal security in two opposite ways. It gives citizens and the State extraordinary capacity to warn, organise, verify and assist; the same network can also recruit, deceive, intimidate and mobilise at a speed that traditional institutions struggle to match. The governing problem is therefore not whether social media is good or bad, but how power, trust and accountability operate within a networked public sphere.
| THE CORE DISTINCTION Cyber security mainly protects systems, data and services. Information security in the social sense protects the quality of perception and decision-making. An attacker may fail to breach a computer yet succeed in making citizens distrust an election, a military operation, a community or a public institution. |
