Q9 · UPSC Civil Services Mains 2017 · GS III · 10 marks · 3 min read

← Q20 Q18 →

Discuss the potential threats of Cyber attack and the security framework to prevent it.

Topic: Cyber Security and Money Laundering. Syllabus: Challenges to internal security through communication networks, role of media and social networking sites in internal security challenges, basics of cyber security; money-laundering and its prevention. Same official PYQ from year-wise 2017 and Cyber Security and Money Laundering.

Revision summary

Cyber attacks can halt power and payments, steal identity and defence data, and spread ransomware or disinformation. The IT Act 2000 as amended in 2008 is the legal base for offences and CERT-In. National Cyber Security Policy 2013 and NCIIPC address resilience and critical information infrastructure. Sectoral CERTs, RBI rules, Cyber Swachhta Kendra and cyber police cells complete the map. Skills, private compliance and a full data-protection law were still thin in 2017.

Model answer

Introduction

India's banks, power grids, railways, Aadhaar-linked welfare and defence networks now run on code. A cyber attack can steal data, freeze payments, or damage industrial controls without a soldier crossing the border. Threats have grown with Digital India. The preventive framework is a mix of the Information Technology Act, CERT-In, sectoral teams, and the protection of critical information infrastructure. Capacity and private-sector hygiene still lag the threat.

Body

Potential threats of cyber attack

  • Critical infrastructure: malware in power, telecom, ports, oil and nuclear plants can cause physical outage, as global incidents on industrial control systems have shown.
  • Financial crime: phishing, ransomware, ATM and SWIFT-style fraud, and attacks on payment systems hit households and correspondent banking.
  • Data theft and espionage: state and criminal actors target ministries, defence labs, and Aadhaar-seeded databases for identity and strategic intelligence.
  • Military and space networks: degraded command, navigation or satellite links in a crisis would be a force multiplier for an adversary.
  • Disinformation and election systems: compromise of parties, media or voter databases can undermine trust even without changing a result.
  • Supply-chain and insider threats: tainted hardware, unpatched software, and contractors with excess privilege.
  • Distributed denial of service on government portals during unrest or disaster blocks public communication.
  • Attribution is hard, so proxy and non-state groups can strike with deniability.

Security framework to prevent it

  • Information Technology Act, 2000 (amended 2008): defines offences (including critical-infrastructure damage), electronic evidence, and intermediary duties; it is the basic criminal and compliance law.
  • Indian Computer Emergency Response Team (CERT-In) under the IT Act: national incident response, advisories, vulnerability notes, and mandatory reporting directions for intermediaries and firms.
  • National Cyber Security Policy, 2013: the Union's policy umbrella for a secure and resilient cyberspace, public-private partnership, and capacity building (a successor architecture has been debated, but 2013 remained the named policy).
  • National Critical Information Infrastructure Protection Centre (NCIIPC) under the National Technical Research Organisation: identifies and advises protection of CII in power, banking, telecom, transport and government.
  • Sectoral CERTs (finance, power, telecom) and Reserve Bank cyber guidelines for banks sit beside CERT-In.
  • National Cyber Coordination Centre and related monitoring aim to share threat intelligence across agencies.
  • Cyber Swachhta Kendra (botnet cleaning) and public digital-literacy drives try to cut the large pool of infected home machines.
  • Defence and intelligence cyber units, and police cyber cells in States, handle military and criminal tracks; coordination among them is still a weak joint.
  • Prevention also needs procurement standards, encryption, backup drills, and Make in India trusted electronics so the stack is not only a foreign black box.
  • Gaps: shortage of skilled analysts, uneven private compliance, slow forensics, and the tension between surveillance powers and a still-thin data-protection statute in 2017.

Flow diagram

flowchart TD
  T[Threats CII finance espionage] --> I[Incidents]
  F[IT Act 2000-2008] --> C[CERT-In response]
  N[NCIIPC] --> K[Protect critical infrastructure]
  P[Policy 2013 sectoral CERTs] --> H[Hygiene and drills]
  C --> H
  K --> H

Conclusion

Cyber attacks threaten grids, banks, identity systems and military networks, often below the threshold of open war. India's framework is the IT Act, CERT-In, the 2013 policy, NCIIPC and sectoral rules. It will prevent damage only if reporting is honest, CII is actually hardened, and skills reach banks and State police, not only a few national teams.

Quick related

Students also ask

PYQ trend

When UPSC asked this

Related PYQs from other years, newest first. Open a question to read it.

  1. 2021 · Q9 · GS III · 10 marks

    Discuss how emerging technologies and globalisation contribute to money laundering. Elaborate measures to tackle the problem of money laundering both at national and international levels.

    View answer →

  2. 2021 · Q10 · GS III · 10 marks

    Keeping in view India's internal security, analyse the impact of cross-border cyber attacks. Also discuss defensive measures against these sophisticated attacks.

    View answer →

  3. 2020 · Q9 · GS III · 10 marks

    Discuss different types of cybercrimes and measures required to be taken to fight the menace.

    View answer →

  4. 2019 · Q10 · GS III · 10 marks

    What is CyberDome Project? Explain how it can be useful in controlling internet crimes in India.

    View answer →

  5. 2018 · Q19 · GS III · 15 marks

    Data security has assumed significant importance in the digitized world due to rising cyber-crimes. The Justice B. N. Srikrishna Committee Report addresses issues related to data security. What, in your view, are the strengths and weaknesses of the Report relating to protection of personal data in cyber space? (250 Words, 15 Marks).

    View answer →

  6. 2018 · Q20 · GS III · 15 marks

    India's proximity to two of the world's biggest illicit opium-growing states has enhanced her internal security concerns. Explain the linkages between drug trafficking and other illicit activities such as gunrunning, money laundering and human trafficking. What countermeasures should be taken to prevent the same? (250 Words, 15 Marks).

    View answer →

  7. 2015 · Q18 · GS III · 12 marks

    Religious indoctrination via social media has resulted in Indian youth joining the ISIS. What is ISIS and its mission? How can ISIS be dangerous to the internal security of our country.

    View answer →

  8. 2015 · Q20 · GS III · 12 marks

    Considering the threats cyberspace poses for the country, India needs a "Digital Armed Forces" to prevent crimes. Critically evaluate the National Cyber Security Policy, 2013 outlining the challenges perceived in its effective implementation.

    View answer →

More from this topic

Q19 · UPSC Mains 2022 · GS III · 15 marks

What are the different elements of cyber security ? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy.

Cyber Security and Money Laundering

Cyber security elements are confidentiality, integrity, availability, authentication, human process, supply chain, and legal institutions. India’s notified document is the National Cyber Security Policy 2013. A National Cyber Security Strategy was discussed around 2020; a complete public successor was not firmly in force as a single comprehensive charter by 2022. Operational bodies include CERT-In, NCIIPC and I4C, plus sector regulators. Gaps remain in MSME/hospital security, skills, supply chain and fragmented law.

Q10 · UPSC Mains 2021 · GS III · 10 marks

Keeping in view India's internal security, analyse the impact of cross-border cyber attacks. Also discuss defensive measures against these sophisticated attacks.

Cyber Security and Money Laundering

Cross-border cyber operations can stall critical infrastructure, rob finance, and steal state data without a kinetic raid. Attribution problems let states and proxies hide behind criminal malware. CERT-In, NCIIPC, Defence Cyber Agency, sector CERTs, and the IT Act are the Indian defensive core. Segmentation, backups, vendor control, and phishing defence are the practical layer. Resilience and international CERT cooperation matter more than a claim of perfect security.

Q9 · UPSC Mains 2021 · GS III · 10 marks

Discuss how emerging technologies and globalisation contribute to money laundering. Elaborate measures to tackle the problem of money laundering both at national and international levels.

Cyber Security and Money Laundering

Global trade, hawala, shells, and now crypto and mule rails turn criminal cash into apparently clean assets. PMLA, FIU-IND, and regulator KYC are the core national tools. FATF, Egmont, and UN conventions organise the international chase and asset return. Technology also helps investigators if travel rules and chain analysis are funded. Beneficial ownership and virtual assets remain the soft spots.

Toppers' copies

Toppers' copies for this question will be uploaded soon.