Cyber security has added a new dimension to India’s internal and external security because critical services now depend on digital networks. Banking, defence, power grids, health systems, governance, transport and communication are vulnerable to cyberattacks. With the growth of Digital India, UPI, Aadhaar-based services and e-governance, cyber threats have become both a national security issue and a citizen safety issue. In 2025, CERT-In handled over 29.44 lakh cyber incidents, showing the scale of the challenge.
Cyber threats are rising in multiple forms. India faces phishing, ransomware, cyber fraud, deepfakes, data breaches, attacks on critical infrastructure, financial fraud and cyber espionage. For example, cyber fraud complaints between 2021 and 2026 reportedly caused losses of around ₹55,659 crore, according to MHA-linked data reported from national cybercrime platforms. Recently, reports of a data breach linked to files concerning the Kudankulam nuclear project also highlighted the security risks around critical infrastructure and contractors.
India is enhancing its cyber security capabilities through the following measures:
- Institutional framework: India has strengthened agencies like CERT-In, National Critical Information Infrastructure Protection Centre (NCIIPC), Indian Cyber Crime Coordination Centre (I4C) and the office of the National Cyber Security Coordinator. CERT-In acts as the national agency for cyber incident response under the IT Act.
- Incident response and threat intelligence: CERT-In issues alerts, advisories and vulnerability notes. In 2025, it issued 1,530 alerts, 390 vulnerability notes and 65 advisories, which shows improved monitoring and response capacity.
- Cybercrime reporting: The National Cyber Crime Reporting Portal and the 1930 helpline help citizens report online fraud. Moreover, I4C coordinates cybercrime prevention among states, police agencies and financial institutions.
- Legal and regulatory measures: The Information Technology Act, 2000, CERT-In Rules and CERT-In Directions 2022 require cyber incident reporting and better log maintenance. The Digital Personal Data Protection Act, 2023, along with later rules, strengthens data privacy and breach-related accountability.
- Critical infrastructure protection: NCIIPC works to protect sectors such as power, banking, telecom, transport, government and strategic infrastructure.
- Capacity building: Programmes like Cyber Surakshit Bharat train CISOs and IT officials of central/state governments, PSUs and banks.
- Cyber hygiene and awareness: Cyber Swachhta Kendra, operated by CERT-In, provides botnet cleaning and malware analysis tools. It also promotes awareness through campaigns like Cyber Swachhta Pakhwada and National Cyber Security Awareness Month.
- Defence and strategic capability: India is also strengthening cyber defence through defence cyber agencies, secure communication systems, cyber exercises and cooperation with like-minded countries.
However, several challenges remain:
- Shortage of skilled cyber professionals.
- Weak cyber hygiene among citizens and small businesses.
- Rising AI-enabled attacks, deepfakes and automated phishing.
- Coordination gaps between central and state agencies.
- Dependence on foreign hardware, software and cloud systems.
- Delayed reporting of breaches by private entities.
Conclusion
Thus, India is moving from a reactive cyber security model to a proactive, institutional and technology-driven cyber security architecture. However, cyber security cannot depend only on government agencies. India must strengthen public awareness, indigenous technology, cyber forensics, state police capacity and international cooperation. In the digital age, cyber resilience is as important as border security.





