India Ramps Up Cyber Resilience Against Evolving Digital Threats
India is committed to ensuring a safe, reliable, and trustworthy online environment for its citizens. As the digital landscape expands and cyber threats become increasingly sophisticated, the government is taking proactive measures to strengthen the country’s cybersecurity posture.
Rising Threat Landscape
Addressing concerns about the rising number of cyber incidents, the government revealed data showing a steady increase in reported cyberattacks. According to CERT-In, India’s national cybersecurity agency, 140,2809 cybersecurity incidents were recorded in 2021, followed by 139,1457 in 2022 and a staggering 159,2917 in 2023.
Strengthening National Cybersecurity
“The government is fully cognizant and aware of enhancing cyber resilience at the national level, especially as digital threats continue to evolve globally,” explained Union Minister of State for Electronics and Information Technology, Jitin Prasada in response to queries on bolstering cybersecurity.
To combat these threats, the government has implemented a multi-pronged approach encompassing several key initiatives.
### Appointment of Chief Information Security Officers
Recognizing the critical need for dedicated cybersecurity expertise at all levels of government, the government has directed Central Ministries/Departments and state/UT governments to appoint Chief Information Security Officers (CISOs). These CISOs will be responsible for overseeing cybersecurity strategy, incident response, and overall cyber hygiene within their respective organizations.
### Protection of Critical Infrastructure
The government established the National Critical Information Infrastructure
Protection Centre (NCIIPC) under Section 70A of the Information Technology (IT) Act, 2000. The NCIIPC is tasked with protecting critical infrastructure from cyberattacks, focusing on sectors like power, transportation, finance, and healthcare which are crucial to national security.
### National Informatics Centre’s Role
The National Informatics Centre (NIC), a leading provider of IT support to government entities, plays a vital role in strengthening cyber defenses. NIC ensures comprehensive IT support for ministries, departments, agencies, and district administrators involved in various e-governance initiatives.
## Enhancing Preparedness and Response
In addition to these preventative measures, the government has emphasized proactive threat detection and response mechanisms:
### CERT-In’s Cyber Crisis Management
CERT-In, India’s nodal agency for cybersecurity incident response, was tasked with formulating a cyber crisis management plan. This plan is designed to guide ministries and departments at both the central and state levels in responding effectively to cyberattacks and acts of cyberterrorism.
### Baseline Security Guidelines
CERT-In has released guidelines covering information security practices for government entities. These guidelines, issued in June 2023, provide a framework for secure application design, development, implementation, and operations.
Furthermore, in September 2023, CERT-In released guidelines for secure application design, development, implementation, and operations. Recognizing the modern complexities of software development, CERT-In also released Software Bill of Materials (SBOM) guidelines in October 2024.
The SBOM guidelines are specifically aimed at entities in the public sector, government, essential services, and organizations involved in software exports. These guidelines encourage the documentation of software components to aid in identifying and mitigating vulnerabilities efficiently.
### Continuous Alert and Response
CERT-In continuously issues alerts and advisory notes regarding the latest cyber threats and vulnerabilities.
These advisories provide crucial information to individuals and organizations, helping them take proactive steps to protect their systems and data.
Qc
cert-In has also empanelled 155 security auditing organizations to support and audit the implementation of best practices. These organizations will play a critical role in assessing vulnerabilities and ensuring that government systems meet robust security standards.
By implementing these comprehensive cybersecurity measures, India aims to create a safer digital environment, protect critical infrastructure, and build national cyber resilience.