Revision summary
Cyber attacks can halt power and payments, steal identity and defence data, and spread ransomware or disinformation. The IT Act 2000 as amended in 2008 is the legal base for offences and CERT-In. National Cyber Security Policy 2013 and NCIIPC address resilience and critical information infrastructure. Sectoral CERTs, RBI rules, Cyber Swachhta Kendra and cyber police cells complete the map. Skills, private compliance and a full data-protection law were still thin in 2017.
Model answer
Introduction
India's banks, power grids, railways, Aadhaar-linked welfare and defence networks now run on code. A cyber attack can steal data, freeze payments, or damage industrial controls without a soldier crossing the border. Threats have grown with Digital India. The preventive framework is a mix of the Information Technology Act, CERT-In, sectoral teams, and the protection of critical information infrastructure. Capacity and private-sector hygiene still lag the threat.
Body
Potential threats of cyber attack
- Critical infrastructure: malware in power, telecom, ports, oil and nuclear plants can cause physical outage, as global incidents on industrial control systems have shown.
- Financial crime: phishing, ransomware, ATM and SWIFT-style fraud, and attacks on payment systems hit households and correspondent banking.
- Data theft and espionage: state and criminal actors target ministries, defence labs, and Aadhaar-seeded databases for identity and strategic intelligence.
- Military and space networks: degraded command, navigation or satellite links in a crisis would be a force multiplier for an adversary.
- Disinformation and election systems: compromise of parties, media or voter databases can undermine trust even without changing a result.
- Supply-chain and insider threats: tainted hardware, unpatched software, and contractors with excess privilege.
- Distributed denial of service on government portals during unrest or disaster blocks public communication.
- Attribution is hard, so proxy and non-state groups can strike with deniability.
Security framework to prevent it
- Information Technology Act, 2000 (amended 2008): defines offences (including critical-infrastructure damage), electronic evidence, and intermediary duties; it is the basic criminal and compliance law.
- Indian Computer Emergency Response Team (CERT-In) under the IT Act: national incident response, advisories, vulnerability notes, and mandatory reporting directions for intermediaries and firms.
- National Cyber Security Policy, 2013: the Union's policy umbrella for a secure and resilient cyberspace, public-private partnership, and capacity building (a successor architecture has been debated, but 2013 remained the named policy).
- National Critical Information Infrastructure Protection Centre (NCIIPC) under the National Technical Research Organisation: identifies and advises protection of CII in power, banking, telecom, transport and government.
- Sectoral CERTs (finance, power, telecom) and Reserve Bank cyber guidelines for banks sit beside CERT-In.
- National Cyber Coordination Centre and related monitoring aim to share threat intelligence across agencies.
- Cyber Swachhta Kendra (botnet cleaning) and public digital-literacy drives try to cut the large pool of infected home machines.
- Defence and intelligence cyber units, and police cyber cells in States, handle military and criminal tracks; coordination among them is still a weak joint.
- Prevention also needs procurement standards, encryption, backup drills, and Make in India trusted electronics so the stack is not only a foreign black box.
- Gaps: shortage of skilled analysts, uneven private compliance, slow forensics, and the tension between surveillance powers and a still-thin data-protection statute in 2017.
Flow diagram
flowchart TD T[Threats CII finance espionage] --> I[Incidents] F[IT Act 2000-2008] --> C[CERT-In response] N[NCIIPC] --> K[Protect critical infrastructure] P[Policy 2013 sectoral CERTs] --> H[Hygiene and drills] C --> H K --> H
Conclusion
Cyber attacks threaten grids, banks, identity systems and military networks, often below the threshold of open war. India's framework is the IT Act, CERT-In, the 2013 policy, NCIIPC and sectoral rules. It will prevent damage only if reporting is honest, CII is actually hardened, and skills reach banks and State police, not only a few national teams.
Quick related
Students also ask
-
The north-eastern region of India has been infested with insurgency for a very long time. Analyze the major reasons for the survival of armed insurgency in this region.
Next question in the 2017 paper (Q10). View answer →
-
Is the IT Act enough to prevent attacks?
It criminalises many acts and empowers CERT-In. Prevention also needs patching, CII standards, skills and honest incident reporting by firms.
-
Are only foreign states the threat?
No. Criminal ransomware, insiders and hacktivists matter. State actors add espionage and possible infrastructure sabotage.
PYQ trend
When UPSC asked this
Related PYQs from other years, newest first. Open a question to read it.
-
2021 · Q9 · GS III · 10 marks
Discuss how emerging technologies and globalisation contribute to money laundering. Elaborate measures to tackle the problem of money laundering both at national and international levels. -
2021 · Q10 · GS III · 10 marks
Keeping in view India's internal security, analyse the impact of cross-border cyber attacks. Also discuss defensive measures against these sophisticated attacks. -
2020 · Q9 · GS III · 10 marks
Discuss different types of cybercrimes and measures required to be taken to fight the menace. -
2019 · Q10 · GS III · 10 marks
What is CyberDome Project? Explain how it can be useful in controlling internet crimes in India. -
2018 · Q19 · GS III · 15 marks
Data security has assumed significant importance in the digitized world due to rising cyber-crimes. The Justice B. N. Srikrishna Committee Report addresses issues related to data security. What, in your view, are the strengths and weaknesses of the Report relating to protection of personal data in cyber space? (250 Words, 15 Marks). -
2018 · Q20 · GS III · 15 marks
India's proximity to two of the world's biggest illicit opium-growing states has enhanced her internal security concerns. Explain the linkages between drug trafficking and other illicit activities such as gunrunning, money laundering and human trafficking. What countermeasures should be taken to prevent the same? (250 Words, 15 Marks). -
2015 · Q18 · GS III · 12 marks
Religious indoctrination via social media has resulted in Indian youth joining the ISIS. What is ISIS and its mission? How can ISIS be dangerous to the internal security of our country. -
2015 · Q20 · GS III · 12 marks
Considering the threats cyberspace poses for the country, India needs a "Digital Armed Forces" to prevent crimes. Critically evaluate the National Cyber Security Policy, 2013 outlining the challenges perceived in its effective implementation.
More from this paper
Q1 · UPSC Mains 2017 · GS III · 10 marks
Among several factors for India's potential growth, savings rate is the most effective one. Do you agree? What are the other factors available for growth potential?
Indian Economy
Savings finance investment and matter for potential growth, as in the Harrod-Domar link between the savings rate and output. India already saves a large share of GDP, mainly in households, so a higher rate is not the only or always the strongest lever. Idle gold and land savings, or a high incremental capital-output ratio, waste the savings effort. Other factors are investment quality, skills, infrastructure, institutions, technology and financial intermediation. Jan Dhan, pensions, GST, Make in India and transport programmes try to put savings to work.
Q2 · UPSC Mains 2017 · GS III · 10 marks
Account for the failure of manufacturing sector in achieving the goal of labour-intensive exports rather than capital-intensive exports. Suggest measures for more labour-intensive rather than capital-intensive exports.
Indian Economy
India's export growth after reforms was real, but the mix was more petroleum, engineering and chemicals than garments and leather. Rigid factory labour rules, costly land and power, and capital subsidies encouraged automation and small size. Bangladesh and Vietnam took buyer-driven apparel chains that hire many workers. Correctives are labour flexibility, the apparel and leather packages, MUDRA and clusters, GST refunds, Sagarmala, and skills tied to orders. The aim is jobs per unit of export, not only a larger export bill.
Q3 · UPSC Mains 2017 · GS III · 10 marks
Examine the developments of Airports in India through Joint Ventures under Public-Private Partnership(PPP) model. What are the challenges faced by the authorities in this regard.
Infrastructure
AAI could not fund metro airport expansion alone, so PPP joint ventures were used for greenfield and brownfield hubs. Bengaluru, Hyderabad and Cochin show greenfield JVs; Delhi and Mumbai show brownfield OMDA with AAI equity. AERA regulates major-airport tariffs; later AAI rounds tried to PPP more State capitals. UDAN supports regional routes that do not attract the same private capital. Challenges are land, tariff disputes, high revenue-share bids, exclusive contract clauses, and weak PPP appetite for small airports.
Toppers' copies
Toppers' copies for this question will be uploaded soon.