Skip to content

Cyber Security

Basics of Cyber Security


Cyber Threat Landscape & Components

Cyber Threat Landscape & Components
What are the key classes of cyber threats? Provide examples.Key threat vectors: - Malware: Ransomware (WannaCry, Locky), Spyware (Pegasus), Worms, and Trojans. - Social Engineering: Phishing, Spear Phishing (highly targeted). - Infrastructure Attacks: DDoS (Traffic flooding), SQL Injection, Zero-Day exploits. - State-Sponsored Actors: Advanced Persistent Threats (APTs) like Lazarus Group (NK), APT10 (China).
What are the six core components of a robust cybersecurity system? - Cyber Security Components:
  1. Application Security: Secure coding, regular patches, vulnerability testing.
  2. Information Security: Data encryption (at rest/in transit), access controls (IAM), data loss prevention (DLP).
  3. Network Security: Firewalls, Intrusion Detection/Prevention Systems (IDS/IPS), VPNs.
  4. Operational Security: Strict security policies, employee access control, incident response.
  5. Disaster Recovery & Business Continuity: Backup systems, hot sites, recovery procedures.
  6. End-user Education: Security awareness, phishing simulations, password hygiene.
Why is cybersecurity critical for national security and strategic autonomy?Need and Importance: - National Security: Protects critical infrastructure (power, dams, defense communications) and prevents cyber-terrorism. - Economic Security: Secures payment gateways (UPI, SWIFT), stock exchanges, and guards against intellectual property theft. - Social Stability: Prevents cyber-bullying, identity theft, and secures personal data. - Governance: Secures Digital India databases (Aadhaar, DigiLocker, voter registries). - Strategic Autonomy: Promotes indigenous tech stacks, reducing reliance on vulnerable foreign software/hardware.

Cyber Crimes & Warfare: The Fifth Domain

Cyber Crimes & Warfare: The Fifth Domain
Classify the different types of cybercrimes with Indian contexts.Classification of Cybercrimes: - Financial Crimes: UPI/net banking fraud, card cloning/skimming, cryptocurrency theft. - Data Breaches: Aadhaar/PAN leaks, corporate espionage, medical records theft. - Social Crimes: Cyber bullying, stalking, revenge porn, and sextortion. - Against Individuals: Identity theft, online harassment, lottery/job scams. - Against Organizations: Ransomware (WannaCry), DDoS disruption, defacement. - Against Government: Critical infrastructure targets, cyber espionage, state-sponsored misinformation.
How does Cyber Warfare differ from Traditional Warfare across key operational parameters?Cyber Warfare (The Fifth Domain) vs Traditional Warfare: - Attribution: Traditional is clear and unambiguous. Cyber is extremely difficult to attribute due to proxy servers/spoofing. - Geography: Traditional is bound by physical frontiers. Cyber is completely borderless. - Cost: Traditional is highly capital-intensive. Cyber has a very low entry barrier. - Speed: Traditional requires mobilization time. Cyber is instantaneous. - Casualties: Traditional results in direct physical casualties. Cyber results in economic and system disruption. - Legal Framework: Traditional is governed by Geneva Conventions. Cyber is governed by emerging, non-binding global norms.
What are the key foreign cyber threat actors targeting India?Hostile State Actors: - China: APT groups (APT1, APT10) targeting power grids and space institutions. - Pakistan: Inter-Services Intelligence (ISI) cyber cells pushing malware and fake news. - North Korea: Lazarus Group conducting ransomware and crypto-heists for state revenue.

India's Cyber Vulnerabilities


Vulnerability Analysis & Historic Attacks

Vulnerability Analysis & Historic Attacks
What are the main technical, human, and regulatory vulnerabilities in India's cyber ecosystem?Key Vulnerabilities: - Infrastructure & Technical: Outdated legacy software in government offices, poor patch management, and high import dependence for hardware/chips (supply chain risk). - Human Factors: Low digital literacy, weak passwords, susceptibility to social engineering, and a severe shortage of skilled cyber professionals. - Organizational: Inadequate cybersecurity budgets, lack of periodic third-party audits, and poor incident response systems. - Legal & Regulatory: Slow judicial processes under the outdated IT Act (2000) leading to low conviction rates.
Detail major cyberattacks in India and the average cost of data breaches.Major Incidents & Statistics: - 2020 Mumbai Power Outage: Suspected Chinese malware targeted SCADA systems, causing grid failure. - 2021 AIIMS Ransomware: Encrypted critical patient databases, disrupting healthcare delivery for weeks. - Aadhaar & CoWIN leaks: Recurrent security alerts over the exposure of personal data of millions. - 2016 Debit Card Hack: Compromised 3.2 million debit cards across major Indian banks. - Statistics: India ranks as the 3rd most targeted country globally. The average cost of a data breach in India is estimated at ₹17.9 crore.

Critical Information Infrastructure (CII)

Critical Information Infrastructure (CII)
Define Critical Information Infrastructure (CII) and its legal protection in India. - CII Definition:
Under Section 70 of the IT Act 2000, CII is defined as any computer resource, the destruction or disruption of which would have a debilitating impact on national security, economy, public health, or safety.
Identify the seven key sectors designated as CII. - Designated CII Sectors:
  1. Power and Energy (Grid stations, nuclear plants)
  2. Banking and Finance (Payment networks, stock exchanges)
  3. Telecommunications (Fiber networks, data centers)
  4. Transport (Air traffic control, railways, metros)
  5. Government (Sovereign databases, e-gov systems)
  6. Strategic Enterprises (Space, defense)
  7. Healthcare (Vaccine management, hospitals)
What is the role of NCIIPC? Specify its parent agency and year of establishment. - NCIIPC:
Established in 2014 under Section 70A of the IT Act. It functions under the National Technical Research Organisation (NTRO) as the national nodal agency for protecting Critical Information Infrastructure.
What are the operational challenges and way forward for protecting India's CII?CII Protection Strategy: - Challenges: Securing legacy OT/SCADA systems, supply-chain vulnerabilities, and coordinate gaps between private and public operators. - Way Forward: Mandate **Air-Gapping** for nuclear/grid controls, establish redundancy (backups), conduct mandatory third-party audits, and create Public-Private Partnerships for threat sharing.

Government Initiatives


Institutional and Legal Framework
What is CERT-In? Detail its nodal role, parent ministry, and reporting guidelines.CERT-In (Indian Computer Emergency Response Team): - Established in 2004 under the Ministry of Electronics and Information Technology (MeitY). - It is the national nodal agency for responding to computer security incidents, running situational alerts, and issuing threat advisories. - UPSC Trap Under 2022 guidelines, CERT-In mandates all entities to report cyber incidents within 6 hours of detection.
What is the I4C? Specify its ministry, nodal portal, and core modules.I4C (Indian Cybercrime Coordination Centre): - Established in 2020 under the Ministry of Home Affairs (MHA). - Acts as a comprehensive portal to fight cybercrimes, hosting the National Cybercrime Reporting Portal (Helpline 1930). - Features the National Cybercrime Threat Analytics Unit (TAU), Joint Cybercrime Investigation Team, and the National Cybercrime Forensic Laboratory.
Explain the key sections of the IT Act 2000 and the controversy surrounding Section 66A.IT Act 2000 Key Sections: - Section 43: Penalty for damage to computer system/unauthorized access. - Section 66: Computer-related offenses (hacking, data theft). - Section 66A: Punishment for sending offensive messages (Struck down by SC in Shreya Singhal vs Union of India (2015) for violating Article 19(1)(a)). - Section 69: Government power to intercept, monitor, or decrypt information. - Section 70: Legal declaration of Protected Systems (CII).
Detail the compliance requirements introduced under the IT Rules 2021 and 2023 Amendments.IT Rules 2021 & 2023: - Traceability: Obligates messaging platforms to identify the first originator of a message. - SSMIs: Significant Social Media Intermediaries (5M+ users) must appoint a Chief Compliance Officer, Resident Grievance Officer, and Nodal Contact Person. - Grievance Appellate Committees (GACs): 2023 amendment set up government panels to hear user appeals against intermediary content moderation decisions.
Outline the core principles, duties, and penalties under the Digital Personal Data Protection (DPDP) Act, 2023.DPDP Act 2023: - Constitutional Basis: Rooted in Article 21 (Right to Privacy) following the K.S. Puttaswamy judgment. - Entities: Identifies the Data Principal (individual) and Data Fiduciary (data processor). - Core Principles: Informed consent, purpose limitation, storage limitation, and data minimization. - Data Protection Board of India (DPBI): Set up as the independent, digital-first adjudicatory body. - SDFs: Significant Data Fiduciaries face higher compliance (data impact assessments, independent audits). - Penalties: Graded financial penalties capped at ₹250 crore for failure to prevent data breaches. - Mains Critique: Broad exemptions granted to state agencies on sovereignty/security grounds, lack of data portability rights, and potential dilute of the RTI Act.

Schemes, R&D and Global Alliances

Schemes, R&D and Global Alliances
What is the Cyber Surakshit Bharat Initiative? - Cyber Surakshit Bharat (2018):
Launched by MeitY in partnership with industry leaders to spread awareness about cyber hygiene and train Chief Information Security Officers (CISOs) in government departments.
Detail the functions of Cyber Swachhta Kendra and NCCC.Defense Tools & Monitoring: - Cyber Swachhta Kendra: Botnet cleaning and malware analysis center, providing free malware detection tools to citizens. - NCCC (National Cyber Coordination Centre): Under MeitY; performs metadata-level scanning to provide real-time situational awareness of cyber threats.
Explain the role of DCyA and NATGRID.Special Agencies: - Defense Cyber Agency (DCyA): Tri-service command responsible for offensive and defensive military operations in cyberspace. - NATGRID: A centralized intelligence-sharing platform connecting 21 databases of security and intelligence agencies.
What is the Budapest Convention? Explain India's stance and the reasons behind it.Budapest Convention on Cybercrime (2001): - The first international treaty addressing computer crimes by harmonizing national laws. - UPSC Trap India is NOT a signatory. - Stance: India argues the convention was drafted without its participation, conflicts with national sovereignty (allows foreign agencies cross-border access to data without local warrants), and advocates instead for a UN-led multilateral framework.
Identify key bilateral and multilateral alliances India uses for cyber diplomacy.Cyber Diplomacy: - UN GGE: Participates in establishing voluntary norms for state behavior. - SCO & BRICS: Cooperative cyber-drills and joint ICT security working groups. - Bilateral Joint Working Groups: Active frameworks with the US (US-India Cyber Dialogue), Japan, Israel, and the UK for real-time intelligence sharing.

Emerging Technologies & Challenges


Facial Recognition & Surveillance Backing

Facial Recognition & Surveillance Backing
What is NAFRS? Detail its implementation and key concerns.NAFRS (National Automated Facial Recognition System): - Implemented by the NCRB (National Crime Records Bureau) to create a centralized database of photographs for matching against CCTV feeds. - Benefits: Speeds up criminal tracking, search for missing children, and border verification. - Concerns: High risk of mass surveillance, high false-positive rates (especially for women/minorities), lack of explicit user consent, and functioning in a legislative vacuum without dedicated FRT laws.
Detail the legal backing and oversight mechanism for state surveillance in India.Surveillance Framework: - Legal Backing: Section 69 of the IT Act (for digital intercepts) and the Indian Telegraph Act 1885 (for phone tapping). - Authorization: Interception orders must be signed by the Union Home Secretary (Centre) or State Home Secretary (States). - Oversight: Orders are subject to review by a cabinet-level Review Committee to prevent arbitrary misuse. - Pegasus Controversy (2021): Highlighted vulnerabilities regarding zero-click commercial spyware targeting civil society, reinforcing the need for independent judicial warrant systems.
What is the Puttaswamy proportionality test for state surveillance? - Proportionality Test (Puttaswamy 2017):
State surveillance must satisfy four criteria:
  1. Legality: Backed by a clear, accessible law.
  2. Necessity: Must serve a legitimate state aim (e.g., national security).
  3. Proportionality: The least intrusive method must be used.
  4. Procedural Safeguards: Must be subject to independent oversight (judicial/parliamentary).

Challenges & Way Forward

Challenges & Way Forward
Summarize the core structural challenges facing India's cybersecurity.Key Challenges: - Technical: Extreme hardware import dependency, lack of native OS/chip fabrication, and slow adoption of quantum-safe encryption. - Skill Deficit: Shortage of estimated 1 million cybersecurity professionals; brain drain of top talent. - Prosecution: Low conviction rate in cybercrimes (below 5%) due to poor forensic collection and police training. - International: Borderless nature of attacks and safe havens in hostile nations make prosecution almost impossible.
What are the key policy and institutional recommendations for a secure cyber future?Way Forward Actions: - Policy: Enact a unified National Cyber Security Strategy (updating the 2013 Policy), and include safe harbor protections for ethical security researchers. - Institutional: Create a single-command National Cyber Security Agency (NCSA) to streamline actions across CERT-In, MHA, and Defense. - Capacity: Fund cybersecurity academies in IITs/NITs, mandate cyber hygiene education in schools, and set up state-level cyber forensics laboratories. - Technology: Incentivize indigenous hardware and software fabrication (Security-by-Design), launch national bug bounty programs, and build quantum-key distribution networks.

Revision Strategy

Master Agencies: CERT-In (2004, MeitY), NCIIPC (2014, NTRO), I4C (2020, MHA). Remember Laws: IT Act 2000 (Sections 43, 66, 69, 70), IT Rules 2021 (originator traceability), DPDP Act 2023 (₹250 cr cap, DPBI). Concepts: Fifth Domain of Warfare, APT, Zero-Day Exploit, DDoS, Proportionality Test, NAFRS. Major Attacks: WannaCry 2017, Mumbai Power Outage 2020, AIIMS Ransomware 2021. Diplomacy: Budapest Convention (India is NOT a signatory), UN GGE, SCO.

💻 Cyber Security: The Fifth Domain


  • 🏙️ Focus: Threat vectors, incident response, and legal frameworks.
  • 🧱 Markers: CERT-In + NCIIPC + Zero-Day + DPDPA 2023 + IT Act. ✅

1. Cyber Threat Landscape

  • 🦠 Malware:
    • Ransomware: Encrypts data (e.g., WannaCry, Locky). ✅
    • Spyware: Steals info (Pegasus). ✅
    • Trojans: Disguised as legit software. ✅
  • 🎯 Advanced Persistent Threats (APT): State-sponsored, long-term targeted (e.g., APT10, Lazarus). ✅
  • 🚪 Zero-Day Exploit: Unknown vulnerability; no patch available. High danger. ✅
  • 🌊 DDoS: Overwhelming systems with traffic to crash them. ✅
  • 🎣 Phishing: Fraudulent messages for credentials. Spear Phishing is targeted. ✅

2. Institutional Framework (India)

  • 🛡️ CERT-In (2004):
    • Ministry: MeitY.
    • Role: Nodal agency for incident response. 6-hour mandatory reporting. ✅
  • 🧱 NCIIPC (2014):
    • Parent: NTRO.
    • Role: Protects Critical Information Infrastructure (CII) (Power, Banking, Telecom). ✅
  • 🏢 I4C (2020):
    • Ministry: MHA.
    • Role: Cybercrime coordination; National Cyber Crime Reporting Portal (1930). ✅
  • ⚔️ Defence Cyber Agency (DCyA): Tri-service command under Chief of Defense Staff (CDS) for offensive and defensive military cyber operations. ✅
  • 📱 Sanchar Saathi & Chakshu Portal: DoT portal for citizens to report fraud calls/messages (Chakshu) and block lost phones (CEIR). ✅
  • 🧱 NCRF (National Cybersecurity Reference Framework): Guidelines by NCIIPC defining governance for IT & Operational Technology (OT) networks. ✅
  • 🔗 NATGRID: Centralized intelligence platform connecting 21 sovereign databases. ✅
  • 🧹 Cyber Swachhta Kendra: Botnet cleaning and malware analysis portal. ✅
  • 📜 IT Act 2000:
    • Sec 66F: Cyber Terrorism (Life imprisonment). ✅
    • Sec 69: Govt power to intercept. ✅
    • Sec 70: Protected systems (CII). ✅
    • Sec 79: Safe harbor for intermediaries. ✅
  • 📱 IT Rules 2021: Traceability of 1st originator; SSMI (5M+ users) compliance. ✅
  • 🧬 DPDPA 2023:
    • Constitutional Basis: SC Puttaswamy judgment (Article 21 Right to Privacy).
    • Parties: Data Principal (individual) and Data Fiduciary (processor).
    • SDF (Significant Data Fiduciary): Large entities subject to strict third-party audits and data impact assessments.
    • DPBI: Data Protection Board of India (digital-first enforcement body).
    • Exemptions: Central government can exempt state agencies on sovereignty/security grounds.
    • Penalties: Graded monetary fines capped at ₹250 crore for failing to prevent data breaches. ✅

4. Top UPSC Traps

  1. CERT-In: It is NOT under MHA (under MeitY). ✅
  2. NCIIPC: It is NOT under MeitY (under NTRO). ✅
  3. Sec 66A: NOT valid (Struck down in 2015 by SC). ✅
  4. CII: Disruption results in "debilitating impact" on national security. ✅
  5. Budapest Convention: India is NOT a signatory. ✅

Ultra-Fast Revision Series for UPSC CSE.