Revision summary
Cyber attacks can halt power and payments, steal identity and defence data, and spread ransomware or disinformation. The IT Act 2000 as amended in 2008 is the legal base for offences and CERT-In. National Cyber Security Policy 2013 and NCIIPC address resilience and critical information infrastructure. Sectoral CERTs, RBI rules, Cyber Swachhta Kendra and cyber police cells complete the map. Skills, private compliance and a full data-protection law were still thin in 2017.
Model answer
Copper italics in this answer — like this — are the key facts. Each one is unpacked in the Facts & figures rail.
Introduction
India's banks, power grids, railways, Aadhaar-linked welfare and defence networks now run on code. A cyber attack can steal data, freeze payments, or damage industrial controls without a soldier crossing the border. Threats have grown with Digital India. The preventive framework is a mix of the Information Technology Act, CERT-In, sectoral teams, and the protection of critical information infrastructure. Capacity and private-sector hygiene still lag the threat.
Body
Potential threats of cyber attack
- Critical infrastructure: malware in power, telecom, ports, oil and nuclear plants can cause physical outage, as global incidents on industrial control systems have shown.
- Financial crime: phishing, ransomware, ATM and SWIFT-style fraud, and attacks on payment systems hit households and correspondent banking.
- Data theft and espionage: state and criminal actors target ministries, defence labs, and Aadhaar-seeded databases for identity and strategic intelligence.
- Military and space networks: degraded command, navigation or satellite links in a crisis would be a force multiplier for an adversary.
- Disinformation and election systems: compromise of parties, media or voter databases can undermine trust even without changing a result.
- Supply-chain and insider threats: tainted hardware, unpatched software, and contractors with excess privilege.
- Distributed denial of service on government portals during unrest or disaster blocks public communication.
- Attribution is hard, so proxy and non-state groups can strike with deniability.
Security framework to prevent it
- Information Technology Act, 2000 (amended 2008): defines offences (including critical-infrastructure damage), electronic evidence, and intermediary duties; it is the basic criminal and compliance law.
- Indian Computer Emergency Response Team (CERT-In) under the IT Act: national incident response, advisories, vulnerability notes, and mandatory reporting directions for intermediaries and firms.
- National Cyber Security Policy, 2013: the Union's policy umbrella for a secure and resilient cyberspace, public-private partnership, and capacity building (a successor architecture has been debated, but 2013 remained the named policy).
- National Critical Information Infrastructure Protection Centre (NCIIPC) under the National Technical Research Organisation: identifies and advises protection of CII in power, banking, telecom, transport and government.
- Sectoral CERTs (finance, power, telecom) and Reserve Bank cyber guidelines for banks sit beside CERT-In.
- National Cyber Coordination Centre and related monitoring aim to share threat intelligence across agencies.
- Cyber Swachhta Kendra (botnet cleaning) and public digital-literacy drives try to cut the large pool of infected home machines.
- Defence and intelligence cyber units, and police cyber cells in States, handle military and criminal tracks; coordination among them is still a weak joint.
- Prevention also needs procurement standards, encryption, backup drills, and Make in India trusted electronics so the stack is not only a foreign black box.
- Gaps: shortage of skilled analysts, uneven private compliance, slow forensics, and the tension between surveillance powers and a still-thin data-protection statute in 2017.
Flow diagram
flowchart TD T[Threats CII finance espionage] --> I[Incidents] F[IT Act 2000-2008] --> C[CERT-In response] N[NCIIPC] --> K[Protect critical infrastructure] P[Policy 2013 sectoral CERTs] --> H[Hygiene and drills] C[C] --> H[H] K[K] --> H[H]
Conclusion
Cyber attacks threaten grids, banks, identity systems and military networks, often below the threshold of open war. India's framework is the IT Act, CERT-In, the 2013 policy, NCIIPC and sectoral rules. It will prevent damage only if reporting is honest, CII is actually hardened, and skills reach banks and State police, not only a few national teams.
Quick related
Students also ask
-
Religious indoctrination via social media has resulted in Indian youth joining the ISIS. What is ISIS and its mission? How can ISIS be dangerous to the internal security of our country.
Next question on this syllabus topic (2015 · Q18). View answer →
-
Is the IT Act enough to prevent attacks?
It criminalises many acts and empowers CERT-In. Prevention also needs patching, CII standards, skills and honest incident reporting by firms.
-
Are only foreign states the threat?
No. Criminal ransomware, insiders and hacktivists matter. State actors add espionage and possible infrastructure sabotage.
Same topic · past papers
UPSC has asked this before
These previous-year questions sit on the same topic. Open one to practise the earlier ask.
-
2015 · Q20 · GS III · 12 marks
Considering the threats cyberspace poses for the country, India needs a "Digital Armed Forces" to prevent crimes. Critically evaluate the National Cyber Security Policy, 2013 outlining the challenges perceived in its effective implementation. -
2021 · Q10 · GS III · 10 marks
Keeping in view India's internal security, analyse the impact of cross-border cyber attacks. Also discuss defensive measures against these sophisticated attacks. -
2018 · Q20 · GS III · 15 marks
India's proximity to two of the world's biggest illicit opium-growing states has enhanced her internal security concerns. Explain the linkages between drug trafficking and other illicit activities such as gunrunning, money laundering and human trafficking. What countermeasures should be taken to prevent the same? (250 Words, 15 Marks). -
2024 · Q16 · GS III · 15 marks
what are asteroids? How real is the threat of them causing extinction of life? What strategies have been developed to prevent such a catastrophe?
More from this topic
Q20 · UPSC Mains 2026 · GS III · 15 marks · Solution
Discuss counterfeit currency and money laundering as major sources of terror funding in India. State the actions being taken at International level to check these menaces. Highlight the role of Financial Action Task Force (FATF) and methods of compliance by its member states in preventing terror funding.
Cyber Security and Money Laundering
Counterfeit currency and money laundering are primary conduits for financing terrorism in India, exploiting porous borders and digital vulnerabilities. Internationally, multilateral conventions, UN resolutions, and intelligence-sharing networks operate to disrupt illicit financial flows. The Financial Action Task Force (FATF) sets global standards through its recommendations, compelling member states to implement strict legal, regulatory, and institutional frameworks. Compliance requires robust domestic anti-money laundering laws, designated non-financial businesses regulation, and suspicious transaction reporting. Strengthening public-private partnerships and cross-border cooperation remains vital for choking terror supply lines.
Q9 · UPSC Mains 2026 · GS III · 10 marks · Solution
Explain how fake news and disinformation pose threat to Internal Security and Public Order in Indian context? In this regard, discuss salient features of amendments in respect of Information Technology (Intermediatory Guidelines and Digital Media Ethics Code) Rules 2021.
Cyber Security and Money Laundering
• Fake news fuels communal riots, radicalizes youth through encrypted apps, and destabilizes democratic trust. • Cross-border adversaries weaponize disinformation as an asymmetric threat against India's internal security. • The 2021 IT Rules amendments mandate India-based key officers: Chief Compliance, Grievance, and Nodal Contact. • Intermediaries must use automated tools for due diligence and remove unlawful content within strict timelines. • Designated government bodies are empowered to flag and remove fake news related to central government business. • Effective mitigation requires balancing strict regulatory oversight and traceability with the protection of fundamental rights.
Q19 · UPSC Mains 2022 · GS III · 15 marks · Solution
What are the different elements of cyber security ? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy.
Cyber Security and Money Laundering
Cyber security elements are confidentiality, integrity, availability, authentication, human process, supply chain, and legal institutions. India’s notified document is the National Cyber Security Policy 2013. A National Cyber Security Strategy was discussed around 2020; a complete public successor was not firmly in force as a single comprehensive charter by 2022. Operational bodies include CERT-In, NCIIPC and I4C, plus sector regulators. Gaps remain in MSME/hospital security, skills, supply chain and fragmented law.