Revision summary
Cyber attacks can halt power and payments, steal identity and defence data, and spread ransomware or disinformation. The IT Act 2000 as amended in 2008 is the legal base for offences and CERT-In. National Cyber Security Policy 2013 and NCIIPC address resilience and critical information infrastructure. Sectoral CERTs, RBI rules, Cyber Swachhta Kendra and cyber police cells complete the map. Skills, private compliance and a full data-protection law were still thin in 2017.
Model answer
Introduction
India's banks, power grids, railways, Aadhaar-linked welfare and defence networks now run on code. A cyber attack can steal data, freeze payments, or damage industrial controls without a soldier crossing the border. Threats have grown with Digital India. The preventive framework is a mix of the Information Technology Act, CERT-In, sectoral teams, and the protection of critical information infrastructure. Capacity and private-sector hygiene still lag the threat.
Body
Potential threats of cyber attack
- Critical infrastructure: malware in power, telecom, ports, oil and nuclear plants can cause physical outage, as global incidents on industrial control systems have shown.
- Financial crime: phishing, ransomware, ATM and SWIFT-style fraud, and attacks on payment systems hit households and correspondent banking.
- Data theft and espionage: state and criminal actors target ministries, defence labs, and Aadhaar-seeded databases for identity and strategic intelligence.
- Military and space networks: degraded command, navigation or satellite links in a crisis would be a force multiplier for an adversary.
- Disinformation and election systems: compromise of parties, media or voter databases can undermine trust even without changing a result.
- Supply-chain and insider threats: tainted hardware, unpatched software, and contractors with excess privilege.
- Distributed denial of service on government portals during unrest or disaster blocks public communication.
- Attribution is hard, so proxy and non-state groups can strike with deniability.
Security framework to prevent it
- Information Technology Act, 2000 (amended 2008): defines offences (including critical-infrastructure damage), electronic evidence, and intermediary duties; it is the basic criminal and compliance law.
- Indian Computer Emergency Response Team (CERT-In) under the IT Act: national incident response, advisories, vulnerability notes, and mandatory reporting directions for intermediaries and firms.
- National Cyber Security Policy, 2013: the Union's policy umbrella for a secure and resilient cyberspace, public-private partnership, and capacity building (a successor architecture has been debated, but 2013 remained the named policy).
- National Critical Information Infrastructure Protection Centre (NCIIPC) under the National Technical Research Organisation: identifies and advises protection of CII in power, banking, telecom, transport and government.
- Sectoral CERTs (finance, power, telecom) and Reserve Bank cyber guidelines for banks sit beside CERT-In.
- National Cyber Coordination Centre and related monitoring aim to share threat intelligence across agencies.
- Cyber Swachhta Kendra (botnet cleaning) and public digital-literacy drives try to cut the large pool of infected home machines.
- Defence and intelligence cyber units, and police cyber cells in States, handle military and criminal tracks; coordination among them is still a weak joint.
- Prevention also needs procurement standards, encryption, backup drills, and Make in India trusted electronics so the stack is not only a foreign black box.
- Gaps: shortage of skilled analysts, uneven private compliance, slow forensics, and the tension between surveillance powers and a still-thin data-protection statute in 2017.
Flow diagram
flowchart TD T[Threats CII finance espionage] --> I[Incidents] F[IT Act 2000-2008] --> C[CERT-In response] N[NCIIPC] --> K[Protect critical infrastructure] P[Policy 2013 sectoral CERTs] --> H[Hygiene and drills] C --> H K --> H
Conclusion
Cyber attacks threaten grids, banks, identity systems and military networks, often below the threshold of open war. India's framework is the IT Act, CERT-In, the 2013 policy, NCIIPC and sectoral rules. It will prevent damage only if reporting is honest, CII is actually hardened, and skills reach banks and State police, not only a few national teams.
Quick related
Students also ask
-
Religious indoctrination via social media has resulted in Indian youth joining the ISIS. What is ISIS and its mission? How can ISIS be dangerous to the internal security of our country.
Next question on this syllabus topic (2015 · Q18). View answer →
-
Is the IT Act enough to prevent attacks?
It criminalises many acts and empowers CERT-In. Prevention also needs patching, CII standards, skills and honest incident reporting by firms.
-
Are only foreign states the threat?
No. Criminal ransomware, insiders and hacktivists matter. State actors add espionage and possible infrastructure sabotage.
PYQ trend
When UPSC asked this
Related PYQs from other years, newest first. Open a question to read it.
-
2021 · Q9 · GS III · 10 marks
Discuss how emerging technologies and globalisation contribute to money laundering. Elaborate measures to tackle the problem of money laundering both at national and international levels. -
2021 · Q10 · GS III · 10 marks
Keeping in view India's internal security, analyse the impact of cross-border cyber attacks. Also discuss defensive measures against these sophisticated attacks. -
2020 · Q9 · GS III · 10 marks
Discuss different types of cybercrimes and measures required to be taken to fight the menace. -
2019 · Q10 · GS III · 10 marks
What is CyberDome Project? Explain how it can be useful in controlling internet crimes in India. -
2018 · Q19 · GS III · 15 marks
Data security has assumed significant importance in the digitized world due to rising cyber-crimes. The Justice B. N. Srikrishna Committee Report addresses issues related to data security. What, in your view, are the strengths and weaknesses of the Report relating to protection of personal data in cyber space? (250 Words, 15 Marks). -
2018 · Q20 · GS III · 15 marks
India's proximity to two of the world's biggest illicit opium-growing states has enhanced her internal security concerns. Explain the linkages between drug trafficking and other illicit activities such as gunrunning, money laundering and human trafficking. What countermeasures should be taken to prevent the same? (250 Words, 15 Marks). -
2015 · Q18 · GS III · 12 marks
Religious indoctrination via social media has resulted in Indian youth joining the ISIS. What is ISIS and its mission? How can ISIS be dangerous to the internal security of our country. -
2015 · Q20 · GS III · 12 marks
Considering the threats cyberspace poses for the country, India needs a "Digital Armed Forces" to prevent crimes. Critically evaluate the National Cyber Security Policy, 2013 outlining the challenges perceived in its effective implementation.
More from this topic
Q19 · UPSC Mains 2022 · GS III · 15 marks
What are the different elements of cyber security ? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy.
Cyber Security and Money Laundering
Cyber security elements are confidentiality, integrity, availability, authentication, human process, supply chain, and legal institutions. India’s notified document is the National Cyber Security Policy 2013. A National Cyber Security Strategy was discussed around 2020; a complete public successor was not firmly in force as a single comprehensive charter by 2022. Operational bodies include CERT-In, NCIIPC and I4C, plus sector regulators. Gaps remain in MSME/hospital security, skills, supply chain and fragmented law.
Q10 · UPSC Mains 2021 · GS III · 10 marks
Keeping in view India's internal security, analyse the impact of cross-border cyber attacks. Also discuss defensive measures against these sophisticated attacks.
Cyber Security and Money Laundering
Cross-border cyber operations can stall critical infrastructure, rob finance, and steal state data without a kinetic raid. Attribution problems let states and proxies hide behind criminal malware. CERT-In, NCIIPC, Defence Cyber Agency, sector CERTs, and the IT Act are the Indian defensive core. Segmentation, backups, vendor control, and phishing defence are the practical layer. Resilience and international CERT cooperation matter more than a claim of perfect security.
Q9 · UPSC Mains 2021 · GS III · 10 marks
Discuss how emerging technologies and globalisation contribute to money laundering. Elaborate measures to tackle the problem of money laundering both at national and international levels.
Cyber Security and Money Laundering
Global trade, hawala, shells, and now crypto and mule rails turn criminal cash into apparently clean assets. PMLA, FIU-IND, and regulator KYC are the core national tools. FATF, Egmont, and UN conventions organise the international chase and asset return. Technology also helps investigators if travel rules and chain analysis are funded. Beneficial ownership and virtual assets remain the soft spots.
Toppers' copies
Toppers' copies for this question will be uploaded soon.