India’s Cyber Security Challenges
India’s Threat Exposure
Threat exposure is the possibility that an adversary can exploit a weakness in a digitally dependent system and produce harmful consequences. It is wider than a list of hacking incidents. Exposure arises from the interaction of dependency, attack surface, adversary capability and consequence.
| Digital dependence | Attack surface | Threat actor | Compromise | Cascading consequence |
| Essential service relies on connected systems | People, code, devices, vendors and remote links | Criminal, insider, proxy or State-linked operator | Confidentiality, integrity, availability or safety fails | Service disruption, financial loss, panic or strategic harm |
This framework avoids two mistakes.
- First, it prevents the number of reported incidents from being treated as the sole measure of national risk: one compromise of a high-consequence system may matter more than thousands of low-impact scans.
- Second, it shifts attention from the attacker alone to the way systems are designed, procured, operated and recovered.
India’s exposure is amplified by five structural features:
Scale and speed: rapid adoption creates millions of users, endpoints and transactions, making weak practices attractive to automated and organised attackers.
Uneven maturity: advanced national platforms coexist with legacy software, unsupported devices, poorly segmented networks and small organisations with limited security staff.
Interdependence: power, telecom, cloud, identity and finance support one another; disruption can travel across sectors even when the initial intrusion is narrow.
Supply-chain depth: public systems depend on original equipment manufacturers, managed-service providers, software libraries, data centres and field contractors whose access may be difficult to supervise continuously.
Human and institutional asymmetry: attackers can repeatedly test the weakest user or vendor, whereas defenders must maintain secure behaviour across the entire ecosystem.
Attacks on Critical Sectors: Power, Healthcare and Finance
A sector becomes an attractive target when it combines high dependence, low tolerance for downtime and large public consequences. Power, healthcare and finance illustrate three different forms of cyber harm: physical disruption, interruption of life-supporting services, and damage to monetary integrity and confidence.
| Sector | What attackers may target | Distinctive consequence | Security priority |
| Power and energy | Control centres, substation automation, smart meters, engineering workstations, communication links and utility business networks. | A local failure can cascade through generation, transmission, distribution, transport, telecom and emergency services. | Safety-aware IT–OT segmentation, authenticated remote access, tested restoration and supply-chain assurance. |
| Healthcare | Patient-registration systems, clinical records, laboratories, imaging, pharmacy, billing, connected devices and third-party applications. | Downtime delays care; altered or unavailable records can affect clinical decisions; health data is intensely personal. | Continuity of care, offline procedures, resilient backups, data minimisation and rapid restoration. |
| Financial system | Banks, payment interfaces, switching and settlement systems, credentials, application programming interfaces, market infrastructure and service providers. | Integrity failure can misdirect money; availability failure can freeze economic activity; even rumours can erode confidence. | Strong authentication, transaction analytics, segregation of duties, reconciliation and systemic-continuity planning. |
In the power sector, the decisive distinction is between ordinary information technology and the operational technology that monitors or controls physical processes. Corporate email may be the first foothold; engineering access, shared credentials or removable media may then create a path towards more sensitive networks. Because electricity cannot be secured one substation at a time, grid resilience requires coordinated standards across generators, load-dispatch centres, transmission companies, distribution utilities and vendors.
| CASE STUDY — KUDANKULAM ADMINISTRATIVE NETWORK In 2019, malware was identified on an Internet-connected computer in the administrative network of Kudankulam Nuclear Power Plant. The official investigation stated that the administrative network was isolated from the critical internal network and that plant control systems were not affected. The lesson is precise: segmentation limited consequence, but an infection in the surrounding enterprise environment still demanded hardening, removable-media controls and continuous monitoring. |
The 2022 attack on AIIMS, New Delhi shows why healthcare security is a public-service issue rather than merely a data-protection issue. Five servers supporting the e-Hospital application were affected and about 1.3 terabytes of data was encrypted. Registration, appointments, admission, discharge and record-keeping had to be handled manually while systems were restored from an unaffected backup; most functions returned after about two weeks.
| CASE STUDY — AIIMS AND CONTINUITY OF CARE The verified public record supports three lessons: network segmentation must prevent one compromise from spreading; offline clinical procedures must be practised rather than improvised; and backups matter only when they are isolated, usable and restoration-tested. It does not, on the public evidence cited here, justify a categorical claim that patient data was exfiltrated or sold. |
The financial system faces a dual threat. An adversary may attack the institution—by compromising a bank, payment processor, vendor or application—or attack the customer through impersonation and social engineering. The latter may leave the underlying payment rail technically secure while inducing a validly authenticated but fraudulently obtained transfer. Policy must therefore protect both system integrity and human decision-making.
A Mains answer should also separate a cyber incident from a cyber-caused systemic failure. Outages may result from equipment, operational or environmental causes and may merely be accompanied by cyber allegations. Attribution should be stated at the confidence level supported by the evidence; suspicion is not proof.
Data Breaches and Identity Infrastructure
A data breach is a security incident in which information is accessed, disclosed, altered, lost or destroyed without authorisation. A data leak is often used for exposure without a confirmed hostile intrusion, while identity theft is the subsequent misuse of identifying information to impersonate a person. These events overlap, but they are not identical.
| Term | Core question | Illustrative failure |
| Breach | Was information or a system compromised without authority? | An attacker extracts a customer database or an insider copies records. |
| Leak or exposure | Did information become accessible because of error, misconfiguration or unsafe sharing? | A cloud storage bucket or public link reveals records. |
| Identity theft | Was identifying information used to act as another person? | Stolen KYC details are used to open or take over an account. |
| Account takeover | Were credentials, authentication or recovery channels captured? | A criminal resets a password after controlling the victim’s SIM or email. |
Identity infrastructure is not one database. It is the chain through which identity is established, authenticated, reused and recovered: foundational records; government identifiers; telecom and bank KYC; passwords, biometrics and one-time passwords; digital certificates; mobile devices; recovery email; service-provider copies; and the human officials or agents who handle them. The chain is only as strong as its weakest reusable component.
This distinction is essential in discussions of Aadhaar. A forged document, compromised enrolment device, leaked photocopy, fraudulent mobile connection or insecure downstream KYC repository should not automatically be described as a breach of the Central Identities Data Repository.
Analysts must identify where compromise occurred. The repository itself has been notified as a protected system, but the wider identity ecosystem includes many endpoints outside that core.
Identity-related breaches generate layered internal-security harms:
Persistent vulnerability: passwords can be changed; a date of birth, facial image or biometric trait cannot be replaced easily.
Fraud amplification: leaked profiles make phishing and impersonation more convincing and help criminals answer account-recovery questions.
Profiling and coercion: combined datasets can reveal health, location, financial or social relationships that enable discrimination, blackmail or targeting.
Exclusion risk: an identity-protection control can itself deny genuine users access if recovery and grievance systems are weak.
Strategic intelligence: large, linked datasets can help a hostile actor map officials, scientists, defence personnel or critical-sector employees.
Protection must therefore follow the data and identity life cycle. Collect only what is needed; separate identifiers from transaction data where feasible; replace reusable numbers with purpose-specific tokens; encrypt data in transit and at rest; protect encryption keys separately; use phishing-resistant multifactor authentication for privileged access; log queries and exports; restrict bulk downloads; test vendors; and revoke credentials quickly after compromise.
The hardest issue is institutional. Organisations often treat information as an asset to accumulate, while the citizen bears the consequences of exposure. Good governance reverses that incentive through named ownership, purpose limitation, retention schedules, breach response, independent audit and usable redress. The detailed data-protection law is developed later; for threat analysis, the central insight is that identity security is an ecosystem problem.
| MAINS INSIGHT Do not equate every identity-related fraud with a breach of a central identity database. Write the chain: source record → credential or authenticator → KYC copy → service account → recovery channel. Locating the compromised link produces a more accurate diagnosis and a more proportionate remedy. |
Spyware and the Lawful-Interception Controversy
Spyware is software designed to obtain information from a device, monitor activity or exercise control without the informed authorisation of the device user. Advanced variants may exploit an unknown vulnerability, require little or no user interaction, collect messages and files, activate sensors, or capture information before it is protected by application-level encryption.
Spyware creates an unusual security paradox. The State may need narrowly tailored surveillance to investigate terrorism, espionage, organised crime or grave threats. Yet the same capability, if used without lawful authority and safeguards, can invade privacy, expose journalistic sources, chill speech, compromise legal privilege and weaken the security of devices on which public institutions themselves depend.
| Dimension | Lawful interception | Unlawful or unaccountable spyware use |
| Authority | Traceable to a valid law, competent order and specified lawful ground. | No lawful basis, authority is concealed, or power is used for an extraneous purpose. |
| Targeting | Specific, necessary and linked to a legitimate investigation or security objective. | Indiscriminate, politically motivated or untethered from demonstrated necessity. |
| Technique | Collection is limited to what the order authorises, with control over access and retention. | Device-wide access captures unrelated personal, professional and privileged material. |
| Safeguards | Time limit, record, minimisation, review, audit and controlled dissemination. | Secrecy becomes a substitute for accountability; no effective review or remedy exists. |
| Democratic effect | Can protect life, public order and national security when used proportionately. | Can chill dissent, journalism and association and erode trust in legitimate intelligence work. |
In Justice K.S. Puttaswamy (Retd.) and Anr. v. Union of India and Ors. (2017), a nine-judge Bench recognised privacy as a constitutionally protected right emerging primarily from Article 21 and also from other freedoms and dignity under Part III. Privacy is not absolute, but an intrusion must be supported by law and satisfy a legitimate aim, necessity and proportionality, with safeguards against abuse.
In Manohar Lal Sharma v. Union of India and Ors. (2021), the Supreme Court considered allegations concerning Pegasus spyware. It constituted an independent technical committee under the supervision of a retired Supreme Court judge. The Court accepted that national security may limit the information that can be publicly disclosed, but rejected the idea that merely invoking national security makes the State immune from judicial scrutiny.
| CONSTITUTIONAL TEST A credible surveillance framework must answer seven questions: Is there law? Is the purpose legitimate? Is the measure necessary? Is it the least rights-restrictive effective option? Is collection proportionate? Are access, retention and sharing controlled? Is there independent review and a meaningful remedy? |
The controversy is not resolved by saying either ‘security requires secrecy’ or ‘privacy prohibits surveillance’. Operational secrecy may protect methods and ongoing investigations; democratic legitimacy requires that the existence, scope and legality of power remain reviewable. Independent oversight can inspect sensitive material without making it public, while audit trails and minimisation can reduce abuse without revealing operational targets.
A further technical issue is the market for exploitable vulnerabilities. If a public agency secretly preserves a serious software flaw for surveillance, citizens, companies and government systems may remain exposed to other actors who discover the same flaw. Decisions on retaining or disclosing vulnerabilities therefore require a formal process that balances intelligence value against the wider duty to secure the digital ecosystem.
Financial Cyber Fraud: UPI, Mule Accounts and ‘Digital Arrest’
Financial cyber fraud is best understood as a process, not a payment type. The criminal must attract a victim, create a false belief, obtain control over a transaction, receive the proceeds and move them beyond easy recall. UPI, bank transfer, card, wallet or virtual asset may be the channel; manipulation and laundering are the organising logic.
| Lure | Manipulation | Payment control | Mule layer | Cash-out |
| Call, message, advertisement or fake platform | Fear, urgency, greed, authority or trust | Victim authorises payment or credentials are captured | Proceeds move through rented or controlled accounts | Withdrawal, onward transfer or virtual-asset conversion |
Many so-called UPI frauds do not involve a breach of the UPI platform. A victim may approve a collect request believing it will credit money, enter a UPI PIN on a fraudulent screen, install a remote-access application, reveal an OTP, scan a maliciously presented QR code, call a fake customer-care number, or lose control of the registered device or SIM. The interface records an authorised instruction even though consent was obtained by deception.
| Fraud pattern | Manipulation used | Defensive response |
| Collect-request or refund trick | Victim is told that entering the PIN will receive or reverse money. | Prominent transaction-direction warnings; confirmation screens that show payee and debit amount plainly. |
| Remote-access or screen-sharing scam | Fraudster observes credentials or guides the victim through a transfer. | Device-risk signals, application warnings, cooling-off for anomalous beneficiaries and user education. |
| Account takeover | SIM, email, credentials or recovery process is compromised. | Device binding, strong recovery checks, rapid credential revocation and behavioural detection. |
| Impersonation | Fake bank, police, regulator, relative or customer-care official creates urgency. | Verified contact channels, caller and message authentication, anti-spoofing and public awareness. |
| Investment or task scam | Small initial gains manufacture trust before larger deposits are demanded. | Advertising and platform controls, beneficiary-risk intelligence and rapid freezing of receiving accounts. |
A money mule is a person or entity whose account is used to receive, transfer or withdraw criminal proceeds. Some mules knowingly rent accounts; others are recruited through fake jobs, romance, commissions or requests to ‘help’ receive money. Criminal groups may combine personal accounts, shell entities, merchant facilities and bulk payouts, moving funds through several layers within minutes.
Mule accounts are a strategic chokepoint because they connect the digital deception to usable proceeds. Effective controls include risk-based onboarding, verification of beneficial control, detection of sudden changes in account behaviour, limits and holds for anomalous transfers, beneficiary-name confirmation, sharing of suspect identifiers, and fast coordination among banks and police. Controls must nevertheless avoid indiscriminate freezing that traps innocent customers without timely review.
In a ‘digital arrest’ scam, criminals impersonate police, CBI, narcotics, RBI, customs or another authority. They claim that a parcel, SIM or bank account is linked to crime, display fabricated documents or a staged police-office background, isolate the victim on a video call and demand transfer to a supposed ‘safe’ or ‘verification’ account. The psychological mechanism is authority plus fear plus secrecy.
| CITIZEN RULE — THERE IS NO DIGITAL ARREST No police officer, court, CBI, RBI or regulator places a person under ‘digital arrest’ through a video call or asks that money be moved to a ‘safe account’. Stop the interaction, independently verify through an official channel, contact the bank immediately, report financial cyber fraud on 1930 or the National Cyber Crime Reporting Portal, and preserve call, message and transaction evidence. Speed matters because proceeds are rapidly layered. |
| CURRENT STATUS (AS OF AUGUST 2026) Official action increasingly targets the laundering layer, not only the fraudulent message. In March 2026, the Government reported that MuleHunter.AI was live in 26 banks and being scaled further. In May 2026, the Indian Cyber Crime Coordination Centre and Reserve Bank Innovation Hub agreed to share suspect identifiers and mule-account intelligence for AI-assisted detection. Official alerts and enforcement actions through June–July 2026 confirm that ‘digital arrest’ remains an active, often cross-border, organised economic-crime pattern. These developments are time-sensitive and should be refreshed before the examination. |
A sound policy response combines prevention, friction and restitution. Prevention reduces spoofing and false advertisements; friction questions high-risk transfers; real-time reporting seeks to hold funds before layering; investigation maps mule and telecom infrastructure; and restitution returns recovered money through lawful process. Blaming the victim alone ignores the industrial design of modern fraud.
Dark Web Markets and Cybercrime-as-a-Service
The Internet is commonly described in three layers. The distinction concerns discoverability and access, not moral status. Content outside ordinary search indexing is not automatically illegal, and privacy technology can protect journalists, researchers, officials and persons living under repression as well as offenders.
| Layer | Meaning | Examples and caution |
| Surface web | Public content ordinarily reachable and indexed by search engines. | News sites, public portals and open webpages; criminal content can also exist here. |
| Deep web | Content not indexed or requiring authentication, permission or a specific query. | Email, bank accounts, cloud drives, intranets and databases; overwhelmingly legitimate. |
| Dark web | A deliberately concealed part of the deep web accessed through specialised software or configurations, such as onion services on Tor. | Supports anonymity and censorship resistance, but also hosts illicit markets, forums and criminal services. |
Dark-web markets adapt ordinary e-commerce features—catalogues, search, vendor ratings, escrow and dispute systems—to illicit goods and services. They can trade stolen credentials, payment-card data, malware, forged documents, drugs and unauthorised access. Trust is fragile: markets may be infiltrated, hacked, seized or abandoned through an exit scam in which operators disappear with user funds.
Cybercrime-as-a-Service converts specialised capability into a purchasable input. One actor may steal credentials; an initial-access broker may sell entry into a network; another may rent a botnet or phishing kit; an affiliate may deploy ransomware; a negotiator may extort the victim; and a laundering network may move proceeds. The ecosystem lowers the technical threshold for offending and allows rapid replacement of disrupted components.
| Service layer | What is sold or rented | Security implication |
| Access | Compromised credentials, remote sessions or footholds in organisations. | Defenders must monitor identity misuse and unusual access, not only malware. |
| Tooling | Phishing kits, infostealers, loaders, exploit packages and malicious infrastructure. | Reusable kits scale attacks across languages and jurisdictions. |
| Delivery and disruption | Botnets, spam, proxy networks, DDoS capacity and bulletproof hosting. | Takedown requires infrastructure and provider coordination, not only arrest of one user. |
| Extortion operations | Ransomware affiliate programmes, data-leak sites and negotiation support. | Division of labour complicates attribution and expands the pool of offenders. |
| Monetisation | Mule recruitment, illegal payment gateways, virtual-asset conversion and cash-out. | Financial intelligence and beneficial-ownership analysis become part of cyber defence. |
Cryptocurrency should not be described as inherently criminal or perfectly anonymous. Many public blockchains expose transaction histories, but addresses are pseudonymous: the ledger does not by itself identify the person controlling an address. Mixers, cross-chain transfers, rapid creation of new addresses, privacy-enhancing assets and unregulated intermediaries can complicate attribution, while regulated gateways and blockchain analytics can also create investigative opportunities.
| CURRENT STATUS (AS OF AUGUST 2026) International evidence in 2026 describes darknet markets as fragmented, volatile and short-lived, repeatedly disrupted by law-enforcement action, hacks, voluntary closures and exit scams. FATF also emphasises that transfers on public blockchains remain visible and traceable but pseudonymous, especially challenging when peer-to-peer transactions bypass regulated intermediaries. These are current typologies, not permanent market shares or fixed platform rankings. |
The response must target the ecosystem: infiltrate and seize market infrastructure; preserve digital evidence; identify administrators and high-value vendors; disrupt hosting and domains; analyse financial flows; regulate virtual-asset service providers on a risk basis; protect witnesses and victims; and cooperate across borders. Takedowns matter, but resilience requires reducing the demand for stolen access and closing the vulnerabilities that supply it.
Critical Information Infrastructure
Critical infrastructure protection begins with a simple observation: not every computer failure is equally consequential. A country must identify the digital resources whose loss would impair security, the economy, public health or safety, then apply stronger legal, technical and organisational safeguards to them.
The unit of analysis is not only a large institution. A modest server, control link, identity service, certificate authority or vendor update mechanism may be critical because many essential systems depend upon it. CII analysis must therefore map functions and dependencies, not merely compile a list of prestigious organisations.
| Essential function | Digital dependency | Debilitating-impact test | CII identification | Protected-system notification |
| Service vital to security, economy, health or safety | Computer resource enables or controls the service | Would incapacitation or destruction have debilitating impact? | Resource is treated as critical information infrastructure | Appropriate Government may confer formal legal status under Section 70 |
Definition Under the Information Technology Act and Protected Systems
The Information Technology Act, 2000 provides the legal anchor. The Explanation to Section 70(1) defines Critical Information Infrastructure as ‘the computer resource, the incapacitation or destruction of which, shall have debilitating impact on national security, economy, public health or safety.’ The test is therefore consequence-based.
Section 70 also creates the category of a protected system. The appropriate Government may, by notification in the Official Gazette, declare any computer resource that directly or indirectly affects the facility of CII to be a protected system and may authorise who can access it. Unauthorised access or an attempt to obtain such access is punishable with imprisonment that may extend to ten years and fine.
| Concept | Nature | Legal or policy consequence |
| Critical infrastructure | A broader policy concept covering assets and services essential to society, including physical facilities, people and supply chains. | May be protected through sectoral, physical, safety, disaster-management and cyber measures. |
| Critical Information Infrastructure | A computer resource whose incapacitation or destruction would have the debilitating impact specified in Section 70. | Triggers the national CII-protection framework and NCIIPC’s nodal role. |
| Protected system | A computer resource formally notified by the appropriate Government under Section 70 because it directly or indirectly affects CII. | Access is restricted to authorised persons; special security practices apply; unauthorised access attracts enhanced punishment. |
| DO NOT COLLAPSE THE CATEGORIES A resource may be functionally critical before it is formally notified. Conversely, notification as a protected system is a specific legal act. Therefore, ‘CII’ and ‘protected system’ are related but not interchangeable, and ordinary critical infrastructure may include important non-digital components outside the statutory definition. |
| Legal instrument | Core provision for revision |
| Information Technology Act, 2000 — Section 70 | Defines CII; enables protected-system notification and authorised-access orders; penalises unauthorised access or attempts; empowers the Central Government to prescribe security practices. |
| Information Technology Act, 2000 — Section 70A | Enables designation of a national nodal agency for CII protection and makes it responsible for all protective measures, including research and development. |
| Information Technology (National Critical Information Infrastructure Protection Centre and Manner of Performing Functions and Duties) Rules, 2013 | Designates NCIIPC as the nodal agency, places it under NTRO, provides for continuous functioning and specifies its protective, coordinating, advisory and research functions. |
| Information Technology (Information Security Practices and Procedures for Protected System) Rules, 2018 | Requires a governance and security framework for protected systems, including senior-level oversight, a designated CISO, documented practices, risk management, audit, incident response and coordination with NCIIPC. |
The 2018 Rules are important because they convert security from an informal technical activity into an organisational duty. A protected-system owner must know which assets and service providers support the system, assign senior responsibility, manage change and access, assess risk, maintain logs and incident readiness, and permit assurance rather than relying on a one-time certificate.
Protected-system notification should not encourage publication of an attacker’s roadmap. Transparency is needed about legal authority, accountability and broad categories, while architecture details, vulnerabilities and authorised-access lists may require controlled handling. This is the recurring balance between public law and operational secrecy.
NCIIPC: Mandate and Sectoral Coverage
The National Critical Information Infrastructure Protection Centre is the national nodal agency for CII protection under Section 70A. It is part of and under the administrative control of the National Technical Research Organisation and is required by the governing rules to function continuously.
Its mandate is preventive and strategic, not merely reactive. NCIIPC protects and advises CII entities, identifies critical elements for possible notification, analyses national-level threats, supports early warning, develops protection strategies and audit methodologies, encourages research and training, issues guidance, coordinates with CERT-In and sectoral bodies, and may seek information or give directions when CII is threatened.
| Mandate cluster | What it means in practice |
| Identify and prioritise | Map essential functions, interdependencies and high-consequence computer resources; recommend suitable elements for notification. |
| Anticipate and advise | Collect and analyse threat and vulnerability information; issue warnings, advisories, guidelines and vulnerability or audit notes. |
| Assure and improve | Develop protection strategies, standards, risk-assessment and audit approaches; promote procurement and supply-chain practices suited to CII. |
| Coordinate | Work with critical-sector nodal officers, CERT-In, regulators, ministries, operators and other relevant organisations. |
| Build capacity | Support exercises, awareness, training, research and development and a wider ecosystem of competent protection and audit personnel. |
| Act during threat | Call for information and give directions to critical sectors or persons serving or significantly affecting CII, consistent with the governing rules. |
NCIIPC’s sectoral coverage is organised around six broad critical sectors. The list is a coordination framework, not proof that every organisation within the sector is CII or that no resource outside the list can meet the statutory impact test.
| Critical sector | Illustrative dependencies requiring protection |
| Power and Energy | Generation, transmission, grid operation, distribution, oil and gas information systems, communication and safety-supporting resources. |
| Banking, Financial Services and Insurance | Payment, clearing, settlement, banking, securities and insurance systems whose disruption may impair confidence or economic continuity. |
| Telecom | Core networks, switching, signalling, spectrum and network-management systems, data centres and links on which other sectors depend. |
| Transport | Digital systems supporting aviation, rail, road, ports, shipping, traffic management, signalling and logistics. |
| Government | Central and State systems enabling governance, identity, revenue, security and essential public services. |
| Strategic and Public Enterprises | Systems in strategically significant establishments and public enterprises whose failure may have national consequences. |
| Actor | Primary responsibility in the CII ecosystem |
| NCIIPC | National CII identification, strategic guidance, coordination, assurance, early warning and protection support. |
| Sector ministry or regulator | Translate national expectations into sector-specific obligations, supervision, exercises and enforcement. |
| Owner or operator | Own the risk; maintain asset and dependency knowledge; implement controls; report incidents; restore the essential function. |
| CISO and senior management | Make risk decisions, allocate resources, supervise access and vendors, approve exceptions and ensure preparedness. |
| Vendor or service provider | Secure products and services, disclose vulnerabilities, control privileged access, preserve evidence and support recovery under enforceable contracts. |
| CURRENT STATUS (AS OF AUGUST 2026) The six-sector coverage remains Power and Energy; Banking, Financial Services and Insurance; Telecom; Transport; Government; and Strategic and Public Enterprises. Government reporting for FY 2024–25 recorded 90 NCIIPC audits across the reported categories of power and energy, transport and BFSI, showing that the institution is operational rather than merely proposed. The figure is an activity count for specified sectors and must not be misread as the number of CII entities or protected systems. |
The central challenge is federated accountability. Much CII is operated by ministries, States, public enterprises or private companies, while dependencies cross regulatory boundaries. NCIIPC can provide strategic coherence, but day-to-day security must live inside the operator’s engineering, procurement and executive decisions. Public–private information sharing is therefore indispensable, provided confidentiality, liability and action protocols are clear.
OT and SCADA Vulnerability in Power, Transport, Water and Telecom
Operational Technology comprises programmable systems and devices that monitor or cause changes in the physical environment. Industrial Control Systems is a broad family within OT. A Supervisory Control and Data Acquisition system collects field data and enables supervisory control across dispersed assets; a Programmable Logic Controller executes local control logic; and a Human–Machine Interface presents process state to operators.
OT security differs from office IT because failure can cause unsafe pressure, speed, voltage, chemical dose, signalling or service states. Confidentiality matters, but safety, availability, process integrity and deterministic performance often dominate. A technically elegant security control can be unacceptable if it introduces latency, unexpected reboot or unsafe plant behaviour.
| Dimension | Enterprise IT | OT and industrial-control environment |
| Primary objective | Protect information and business services. | Keep the physical process safe, stable, available and within engineered limits. |
| Change cycle | Frequent updates and relatively short technology life cycles. | Long-lived equipment; changes require engineering validation, outage windows and safety approval. |
| Failure tolerance | Reboot or temporary isolation may be acceptable. | Unplanned shutdown or delayed control may create physical, environmental or public-safety harm. |
| Monitoring | Active scanning and endpoint agents are common. | Passive or carefully tested techniques may be necessary to avoid destabilising fragile devices. |
| Access | Users and applications dominate. | Operators, engineers, vendors, field devices and remote maintenance paths all matter. |
| Recovery | Restore data and applications. | Restore a known-safe physical process in the correct engineering sequence, sometimes through manual operation. |
Recurring OT and SCADA weaknesses include:
Legacy and unsupported components that cannot be patched promptly or lack modern authentication, encryption and logging.
Flat networks and unsafe convergence that allow compromise of email, enterprise identity or vendor systems to move towards engineering assets.
Remote access left continuously enabled, protected by shared credentials or exposed through poorly governed third parties.
Insecure protocols and engineering trust designed for closed environments, where commands may be accepted without strong authentication or integrity checks.
Incomplete asset visibility: operators may not know every controller, firmware version, communication path, wireless link or embedded dependency.
Supply-chain and maintenance risk: compromised updates, counterfeit equipment, vendor laptops and removable media can bypass perimeter assumptions.
Weak recovery preparation: configuration backups may be absent, untested or stored where the same attack can reach them.
| Sector | Illustrative OT function | Potential cyber-physical consequence |
| Power | Grid balancing, protection relays, substations, generation and distribution control. | Outage, equipment damage, unstable operation and cascading disruption to dependent sectors. |
| Transport | Rail signalling, traffic management, port and airport operations, fleet and tunnel systems. | Unsafe movement, collision risk, congestion, stranded passengers and supply-chain interruption. |
| Water | Pumping, treatment, reservoir level, valve and chemical-dosing control. | Loss of supply, contamination risk, flooding, equipment damage or false process readings. |
| Telecom | Power, environmental control and network-management systems in exchanges, towers and data facilities. | Loss or manipulation of connectivity on which emergency, financial and government services depend. |
| Know | Separate | Control | Observe | Sustain | Recover safely |
| Asset and dependency register | Zones, conduits and IT–OT segmentation | Least privilege and secured remote access | Passive monitoring, logs and baselines | Safe patching, backups and vendor governance | Tested manual operations and engineering restoration |
OT resilience sequence — Protection must preserve safety and continuity while reducing opportunities for unauthorised control.
The phrase air gap must be used carefully. Physical separation can reduce remote exposure, but data still moves through maintenance laptops, removable media, update processes, contractors and adjacent administrative networks. Segmentation is valuable only when conduits are identified, access is enforced, exceptions are controlled and attempts to cross boundaries are monitored.
A practical defence uses asset inventory; consequence-based zoning; allow-listed communication; multifactor-authenticated, time-bound and recorded vendor access; secure engineering workstations; application allow-listing; passive anomaly monitoring; configuration integrity; removable-media stations; tested backups; incident exercises; and a manual or degraded mode that maintains safety while automation is restored.
| CURRENT STATUS (AS OF AUGUST 2026) India’s power-sector framework includes the CEA (Cyber Security in Power Sector) Guidelines, 2021, CSIRT-Power and six sectoral CERTs. The Central Electricity Authority’s site continued to list the Draft Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2025 among draft regulations in July 2026; it should therefore not be described as a final regulation. CERT-In’s 2026 OT guidance continues to emphasise segmentation, controlled remote access, logging and robust protection of ICS, SCADA and PLC environments. |
The difficult trade-off is not security versus operations; it is poorly designed security versus safe, resilient operations. Controls must be tested with process engineers, vendors and operators. The correct objective is a system that remains within safe limits during attack, reveals abnormal behaviour early and can be restored without trusting compromised configurations.
Cloud Hosting Versus In-House Hosting for Government Systems
In-house hosting places servers, storage and much of the supporting infrastructure under the department or its dedicated facility. Cloud hosting obtains configurable computing resources as a service from a provider, with capacity provisioned and scaled through standardised interfaces. Neither model is automatically secure; each changes the location and concentration of risk.
Cloud must also be separated by service and deployment model. Infrastructure, platform and software services divide responsibility differently. Public cloud uses shared provider infrastructure; a virtual private cloud creates logical isolation; a government community or private cloud offers stronger separation for a defined community; and a hybrid arrangement connects distinct environments. Labels do not replace verification of actual controls.
| Dimension | Cloud hosting | In-house hosting |
| Cost and capacity | Elastic, metered resources reduce large upfront procurement and can absorb demand peaks. | Capital expenditure and spare capacity are borne by the department, but predictable workloads may be economical over time. |
| Deployment speed | Standard services and automation can shorten provisioning and recovery. | Procurement, installation and scaling are slower and depend on internal teams. |
| Expertise | Provider can supply mature infrastructure security, availability and specialised tools at scale. | Department retains direct control but must recruit and retain the full range of security, network, facility and platform expertise. |
| Control and visibility | Physical infrastructure and some logs or actions remain with the provider; access depends on contract and service model. | Greater direct control and physical access, but visibility is useful only if the department actually monitors and maintains the system. |
| Concentration risk | A provider, region, identity plane or configuration error can affect many services at once. | Failure may be confined to the department, but local redundancy and disaster recovery may be weaker. |
| Data and jurisdiction | Location, replication, subcontractors, keys and foreign legal exposure require contractual and technical control. | Location is easier to determine, though vendors, remote support and supply chains still create external dependencies. |
| Exit and portability | Proprietary services and data-transfer costs can create vendor lock-in. | Technology debt and bespoke applications can create a different form of lock-in to ageing hardware and skills. |
The central cloud principle is shared responsibility. A provider may secure the physical facility, hypervisor and managed service, while the department remains responsible for data classification, identity and access, application code, configuration, user behaviour, key management choices, retention, backups and lawful processing. Outsourcing infrastructure does not outsource constitutional or administrative accountability.
| Government question | Required examination before placement |
| What is the mission? | Citizen information portal, routine administration, sensitive personal data, law-enforcement operation, protected system or real-time industrial control require different assurance. |
| What failure is intolerable? | Identify maximum acceptable downtime, data loss, integrity error and safety consequence; design redundancy and recovery accordingly. |
| Where will data and backups reside? | Specify primary, replicated and disaster-recovery locations, subcontractors, support access and rules for lawful disclosure. |
| Who controls identity and keys? | Use least privilege, privileged-access management, strong authentication, department-controlled or appropriately segregated keys and emergency-access procedures. |
| Can the department see and investigate? | Ensure usable logs, time synchronisation, alerts, evidence preservation, audit rights and prompt incident notification. |
| Can the service be exited? | Require portable formats, transition assistance, tested restoration elsewhere, secure deletion and continuity during contractual dispute or provider failure. |
| CURRENT STATUS (AS OF AUGUST 2026) Under the Government of India’s GI Cloud (MeghRaj) approach, departments are expected to assess cloud for current and new applications, and MeitY empanels cloud service offerings for government use. Current guidance does not make security automatic: departments must classify information, select a suitable deployment model, use empanelled and audited offerings where applicable, specify Indian data-residency and audit requirements, and retain responsibility for application, access, configuration, incident and exit controls. |
For ordinary citizen-facing applications with variable load, a properly governed cloud can improve elasticity, patching, distributed availability and recovery. For highly sensitive workloads, protected systems or tightly coupled OT, a government community cloud, dedicated environment, in-house system or hybrid design may offer more suitable control. The choice should follow data classification and consequence analysis, not institutional habit or a blanket preference.
A secure cloud or hybrid arrangement requires at least the following:
Architecture: tenant isolation, segmented networks, resilient regions or facilities, secure interfaces and denial-of-service protection.
Identity: least privilege, multifactor authentication, separate administrative roles, privileged-session recording and rapid revocation.
Data: encryption in transit and at rest, controlled keys, tokenisation where suitable, retention limits, backup isolation and verified deletion at exit.
Assurance: independent testing, continuous configuration assessment, software and supply-chain visibility, auditable logs and tested incident playbooks.
Contract: measurable availability, incident-notification time, audit and evidence access, subcontractor control, vulnerability disclosure, liability, continuity and portability.
Sovereignty and legality: known data location, enforceable jurisdiction, controlled foreign or vendor access and the ability to meet lawful investigation and public-record obligations.
Critical assessment: cloud can reduce the risk of neglected hardware and under-provisioned disaster recovery, but it can magnify identity misconfiguration, concentration and dependency on one provider. In-house systems give direct control, but often conceal weak patching, staffing and backup discipline. The better conclusion is a workload-based hybrid strategy with common security baselines, portable design and tested exit, not the claim that one model is universally safer.
| MAINS ANSWER FRAME For a question comparing cloud and in-house hosting, write four moves: define both models → compare cost, elasticity, control, sovereignty and concentration risk → explain shared responsibility and security controls → recommend classified, workload-based hybrid adoption with audit, portability and recovery. |
| SECTION TAKEAWAY India’s exposure is created by the meeting of scale, uneven maturity and essential digital dependence. The answer is neither indiscriminate securitisation nor faith in technology. It is to identify high-consequence functions, protect identity and financial pathways, subject surveillance to constitutional safeguards, disrupt criminal service ecosystems, harden OT without compromising safety, and make every critical service recoverable. |
The threat exposure and protection of critical information infrastructure developed earlier answer what must be secured. The next question is institutional: who must act, under which legal authority, and how should overlapping responsibilities be coordinated?
India has not created one all-purpose cyber super-agency. Its architecture is deliberately distributed across strategic coordination, technical warning, incident response, critical-infrastructure protection, criminal investigation, military operations, sector regulators and State police. This allows specialisation, but also creates hand-off, duplication and accountability problems.
| CORE PROPOSITION Cyber governance succeeds when authority, information and operational responsibility meet at the same time. A large number of institutions is not a weakness by itself; the weakness arises when nobody can identify the lead agency, share usable information or enforce remediation during a fast-moving incident. |
