Why this matters now
Cybersecurity is a high-frequency GS-3 (and internal-security) theme — the threat types, critical infrastructure, India’s agencies and the policy gaps are repeatedly tested.
Types of cyber threats
- Malware & ransomware — encrypting/stealing data for ransom;
- Phishing & social engineering;
- DDoS attacks — overwhelming services;
- Data breaches and identity theft;
- State-sponsored attacks, cyber espionage and cyber warfare on critical infrastructure.
Critical Information Infrastructure
Critical Information Infrastructure (CII) — power grids, banking, telecom, transport, defence — is a prime target; its disruption can cripple a nation. Protecting CII is a core national-security priority, overseen by the NCIIPC.
India’s framework and the way forward
Key institutions: CERT-In (the national incident-response team), the NCIIPC (critical infrastructure), the National Cyber Security Coordinator and Cyber Swachhta Kendra. The IT Act, 2000 and the DPDP Act, 2023 provide the legal base. The way forward: a new national cybersecurity strategy, capacity-building, indigenous tech, international cooperation and public awareness.
UPSC angle
Know the threat types (ransomware, phishing, DDoS, state-sponsored), CII and NCIIPC, CERT-In, the IT Act 2000/DPDP 2023, and the need for a national cybersecurity strategy.
Frequently asked questions
What is cybersecurity?
The practice of protecting computer systems, networks and data from digital attacks, damage or unauthorised access.
What is Critical Information Infrastructure?
Computer resources whose disruption would have a debilitating impact on national security, the economy or public health — like power, banking and telecom.
What is CERT-In?
The Indian Computer Emergency Response Team — the national agency for responding to cybersecurity incidents.
Which laws govern cybersecurity in India?
Primarily the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023.