
Central Lawn of AIIMS
Credit: Dr.saptarshi · Public domain · sourceAlexander Nevsky Cathedral, Tallinn, Estonia
Credit: Diego Delso · CC BY-SA 3.0 · source1. Cybersecurity as a governance requirement
Digital governance increasingly connects welfare databases, government cloud platforms, hospitals, municipal services and payment systems. Cybersecurity therefore goes beyond protecting computers: it protects the State’s ability to deliver entitlements, maintain reliable records and exercise public authority. A compromised beneficiary database can redirect payments, while a ransomware attack on a hospital can interrupt essential care. Security failures can create exclusion even when the underlying scheme is well designed.
The foundational principles are confidentiality, integrity and availability, commonly called the CIA triad. Confidentiality prevents unauthorised disclosure; integrity protects information against improper alteration; availability ensures timely access to services. Authentication verifies identity, authorisation determines permitted actions, and auditability enables investigation and accountability. Privacy is related but distinct: even a technically secure system can violate privacy by collecting excessive personal data or using it for an unrelated purpose.
For GS-II, cybersecurity should be analysed through citizen-centric administration, institutional capacity and rights-based governance. Security measures must remain accessible to elderly persons, persons with disabilities and users with limited digital literacy. Offline alternatives and assisted channels are essential safeguards against exclusion. Public trust depends on competent prevention, honest communication and accessible remedies, not merely claims that a platform is completely secure.
2. Threats and vulnerabilities in public digital systems
Phishing and social engineering deceive users into revealing credentials, transferring money or installing malicious software. Ransomware can encrypt systems and may also involve stealing data for extortion. Distributed denial-of-service attacks overwhelm services, while compromised administrator accounts permit unauthorised access across connected systems. Attackers may manipulate records rather than steal them, making integrity checks especially important for land records, examination systems and welfare databases.
Government vulnerability often arises from legacy software, delayed updates, weak passwords, excessive access privileges and misconfigured cloud resources. Insecure application programming interfaces can expose information exchanged between platforms. Outsourced development and common software suppliers create supply-chain risks: a weakness in one vendor can affect several departments. Connected utilities and industrial control systems introduce potential consequences for physical infrastructure and public safety.
Human and organisational weaknesses amplify technical risks. Shared accounts obscure responsibility; procurement may prioritise initial cost over maintenance; contractual staff may retain access after leaving. Digitisation without accurate asset inventories or clear data ownership makes incident response difficult. Threat assessment should therefore identify the assets at risk, likely attackers, possible methods and the consequences for citizens, rather than treating every website as equally critical.
Public-service cyber incident response
- 1. Detect and verify the incident; activate the response team.
- 2. Contain affected systems while preserving essential services.
- 3. Preserve evidence and meet applicable reporting obligations.
- 4. Remove the cause and restore from verified clean backups.
- 5. Communicate appropriately with affected users and coordinate investigation.
- 6. Review failures, fix weaknesses and test revised arrangements.
3. India’s legal and institutional framework
The Information Technology Act, 2000 addresses unauthorised access and computer-related offences. Sections 43 and 66 cover specified acts involving computer resources, with Section 66 applying where relevant acts are committed dishonestly or fraudulently. Sections 66C and 66D concern identity theft and cheating by personation using computer resources. Section 70 provides for protected systems. Critical information infrastructure refers to computer resources whose incapacitation or destruction would have a debilitating impact on national security, the economy, public health or safety.
CERT-In, under the Ministry of Electronics and Information Technology, is the national agency for cyber incident response under Section 70B. Its functions include alerts, advisories, vulnerability information and response coordination. The National Critical Information Infrastructure Protection Centre, established under Section 70A and functioning under the National Technical Research Organisation, focuses on critical information infrastructure. The Indian Cyber Crime Coordination Centre under the Ministry of Home Affairs supports coordinated action against cybercrime; police remain central to criminal investigation.
CERT-In’s 2022 directions require covered entities to report specified incidents within six hours and retain ICT system logs securely for a rolling period of 180 days within Indian jurisdiction. The Digital Personal Data Protection Act, 2023 provides a complementary framework for personal-data protection, including security safeguards and breach-related obligations, subject to applicable commencement provisions and rules. Sectoral requirements, including RBI directions for regulated entities, add another layer. These instruments must not be confused with a single, comprehensive cybersecurity statute.
| Institution | Principal role | Important distinction |
|---|---|---|
| CERT-In | National cyber incident response and advisories | Not a substitute for police investigation |
| NCIIPC | Protection of critical information infrastructure | Focuses on infrastructure with potentially debilitating national consequences |
| I4C | Coordination and support for combating cybercrime | Supports law-enforcement capabilities and citizen reporting |
| State and Union Territory police | Registration and investigation of cybercrime cases | Criminal investigation differs from technical incident containment |
| Sectoral regulators | Cybersecurity requirements for regulated entities | Sectoral obligations complement broader legal requirements |
4. Accountability, rights and implementation challenges
Cybersecurity responsibility is distributed among Union agencies, states, sectoral regulators, police, public bodies and private providers. Specialisation is necessary, but overlapping mandates can produce reporting duplication and coordination gaps. Local bodies and smaller departments may lack dedicated security teams. Effective governance requires a clearly designated system owner, incident commander, escalation chain and mechanism for sharing actionable threat information without unnecessarily exposing personal data.
Security and privacy are mutually reinforcing when systems minimise data collection, limit retention and restrict access. However, surveillance or indiscriminate data retention justified in the name of security can create new risks. The Supreme Court’s 2017 Puttaswamy judgment recognised privacy as a fundamental right. State interference must meet constitutional requirements, including legality, legitimate purpose and proportionality, supported by safeguards against abuse.
Accountability also extends to procurement and citizen remedies. Contracts should specify security testing, vulnerability disclosure, vendor access controls, incident cooperation and secure exit arrangements. Outsourcing operations does not eliminate a public authority’s responsibility. Citizens need understandable breach communications, complaint channels and practical guidance against secondary fraud. Performance should be assessed through restoration time, patching delays and corrective action, not only expenditure or the number of audits conducted.
5. Building secure and resilient digital governance
A risk-based approach should prioritise essential services and sensitive datasets. Security by design integrates threat modelling and testing into system development. Zero-trust architecture avoids assuming that a user or device is trustworthy merely because it is inside a government network. Multi-factor authentication, least-privilege access, network segmentation and encryption reduce the likelihood and impact of compromise. Encryption must be supported by sound key management.
Resilience assumes that some attacks will succeed. Departments need isolated backups, tested restoration procedures, alternate service arrangements and clear recovery priorities. Regular exercises should include administrators, communications teams, vendors and law-enforcement contacts, not only technical specialists. Continuous monitoring and timely patching should follow deployment. Independent audits and responsible vulnerability disclosure help identify weaknesses, but a one-time compliance certificate cannot guarantee continuing security.
Capacity-building should combine specialist recruitment, shared security services for smaller agencies and practical training for frontline staff. Citizen awareness must explain safe payment practices and rapid fraud reporting without blaming victims. International cooperation is necessary because attackers, evidence and service providers may be located in different jurisdictions. Ultimately, successful cybersecurity preserves essential services while protecting liberty, accessibility and public accountability.
Real-world case studies
AIIMS New Delhi ransomware incident, 2022
The November 2022 cyberattack disrupted digital hospital services, requiring manual arrangements while systems were restored. It demonstrated that cybersecurity is a public-health governance issue. Key lessons include network segmentation, protected backups, recovery exercises and workable non-digital continuity plans.
Estonia’s cyberattacks, 2007
Large-scale denial-of-service attacks disrupted Estonian government, banking and media websites. The episode highlighted the vulnerability of a highly connected society and the importance of cross-sector coordination, international cooperation and continuity planning. Digital efficiency must be accompanied by resilience.
Previous year questions
No UPSC question has been asked directly on this micro-topic yet. Use the practice questions below.
Practice questions
Practice MCQ 1
Which institution is specifically associated with Section 70A of the Information Technology Act, 2000?
- A. National Critical Information Infrastructure Protection Centre
- B. Election Commission of India
- C. Central Information Commission
- D. National Informatics Centre
Practice MCQ 2
Consider the following statements: 1. Encryption alone guarantees service availability. 2. Least-privilege access limits users to permissions needed for their work. 3. Offline service alternatives can support continuity during a cyberattack. Which statements are correct?
- A. 1 and 2 only
- B. 2 and 3 only
- C. 1 and 3 only
- D. 1, 2 and 3
Practice MCQ 3
An attacker secretly changes bank-account details in a welfare database without interrupting the portal. Which security property is most directly compromised?
- A. Availability
- B. Integrity
- C. Portability
- D. Interoperability
Mains practice · Cybersecurity is a prerequisite for citizen-centric digital governance, not merely a technical responsibility. Discuss India’s institutional challenges and suggest measures that reconcile security, privacy and inclusion. Answer in 250 words.
- Link cybersecurity to welfare delivery, public trust and essential services.
- Distinguish CERT-In, NCIIPC, I4C and police responsibilities.
- Discuss legacy systems, vendor dependence and uneven administrative capacity.
- Apply privacy, proportionality, data minimisation and accountability principles.
- Recommend secure design, tested recovery, skilled personnel and citizen remedies.
- Retain accessible assisted and offline alternatives.
Further reading
- India Code: Information Technology Act, 2000, especially Sections 43, 66, 70, 70A and 70B.
- CERT-In: Directions dated 28 April 2022 and associated FAQs, cert-in.org.in.
- MeitY: National Cyber Security Policy, 2013.
- India Code and MeitY: Digital Personal Data Protection Act, 2023 and applicable commencement notifications and rules.
- Ministry of Home Affairs: Indian Cyber Crime Coordination Centre and National Cyber Crime Reporting Portal.
- Second Administrative Reforms Commission: Eleventh Report, Promoting e-Governance: The SMART Way Forward.