Skip to content

Cyber Security

UPSC Mains PYQs
  • National Cyber Security Strategy (2021): "What are the different elements of cyber security? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy." (15 Marks, 250 Words)
  • Cross-Border Cyber Attacks (2023): "Keeping in view India's internal security, analyze the impact of cross-border cyber-attacks. Also discuss defensive measures against these sophisticated attacks." (15 Marks, 250 Words)
  • Zero-Click & Sophisticated Threats (2022): Discuss how state-sponsored cyber warfare (e.g., ransomware attacks on public utilities, zero-click Pegasus spyware) poses a larger threat than conventional terrorism. Outline India's preparedness. (15 Marks, 250 Words)
📊 High-Yield Data & Statistical Fact Sheet
  • Cyber Threats & Prevention Metrics:
    • Annual CERT-In Incidents: Reached over 3.4+ Million reported threats annually.
    • Annual Cyber Crime Financial Loss: Estimated at ₹1.25 Lakh Crore in India during the last fiscal year.
    • Stolen Funds Saved: The I4C CITSS (helpline 1930) successfully blocked/saved over ₹8,600+ Crore from cyber fraud accounts.
    • Critical Sectors Protected: 7 critical sectors under NCIIPC (Energy, Transport, Banking & Financial, Telecom, Space, Strategic & Public Enterprises, Government).

Cybercrime Case Volume (MHA/I4C)

Loading chart...

Financial Loss Share by Fraud Type (%)

Loading chart...

Financial Loss Prevented by I4C (₹ Crores)

Loading chart...

1. SPECTRUM OF CYBER THREATS

Cyber warfare and transnational digital scams are asymmetric threats bypassing traditional kinetic borders:

  • Cyber Warfare & State-Sponsored Attacks: Geopolitically motivated cyber offensives targeting Critical Information Infrastructure (CII) e.g., malware attacks on the Kudankulam Nuclear Power Plant, power grid disruptions in Mumbai, and DDoS attacks on government ministries.
  • Ransomware & Denial of Service: Encrypting systems to demand cryptocurrency ransoms. A notable example is the cyber attack on AIIMS Delhi, which paralyzed digital hospital operations.
  • Advanced Persistent Threats (APTs) & Zero-Click Spyware: Stealthy, state-backed cyber- espionage networks. Zero-click exploits (e.g., Pegasus spyware) require no user interaction to compromise devices.
  • Transnational Financial Scams: Organized syndicates (often operating from Southeast Asian regions) running "digital arrest" scams and fake investment apps.

2. INDIA'S CYBER SECURITY ARCHITECTURE

  • CERT-In (Computer Emergency Response Team - India): Nodal agency under MEITY for responding to cyber incidents, tracking cyber threats, and running mock security drills.
  • NCIIPC (National Critical Information Infrastructure Protection Centre): Established under NTRO (Section 70A of the IT Act, 2000) to secure physical and digital assets whose disruption would severely impact national security or public health.
  • I4C (Indian Cyber Crime Coordination Centre): An MHA initiative focused on tracking cybercriminals and enabling immediate blocking of fraudulent financial transactions via the 1930 Helpline and National Cyber Crime Reporting Portal (NCRP).

3. STATUTORY & REGULATORY DEFENSE

  • Information Technology Act, 2000: The primary legal framework. Section 66F specifically outlines life imprisonment for acts of cyber terrorism.
  • Digital Personal Data Protection (DPDP) Act, 2023: Regulates the collection and processing of personal data. It enforces the concept of "Data Fiduciaries", mandates clear consent from individuals, and establishes the Data Protection Board of India (DPBI) to arbitrate disputes.
  • Digital India Act (Proposed): Aims to replace the outmoded IT Act 2000 to govern new-age digital challenges, including AI accountability, dark patterns, fake news, and social media safe harbor limitations.

QUICK REVISION BOX

  • Incident Response Nodal Agency: CERT-In (under MEITY).
  • Critical Infrastructure Nodal Agency: NCIIPC (under NTRO).
  • Cyber Crime Nodal Agency: I4C (under Ministry of Home Affairs).
  • Cyber Terrorism Section: Section 66F of IT Act, 2000 (carries life imprisonment).
  • Recent Data Protection Law: DPDP Act, 2023 (created DPBI).
  • Emergency Incident Reporting Limit: CERT-In mandates reporting within 6 hours of detection.
  • National Cybercrime Hotline: 1930 (administered by I4C).

Notes updated up to March 2026. Sources: CERT-In Annual Reports, Ministry of Home Affairs.