India and Global Cybersecurity: Policies, Institutions and International Engagements
Cybersecurity forms a core pillar of national security and economic stability as India expands its digital infrastructure. With over 100 crore internet connections, protecting critical digital assets, preventing financial fraud, and securing sovereign data require structured policy mechanisms, dedicated agencies, and active diplomatic participation. India approaches cyberspace through a framework that links domestic legal statutes with multilateral engagements to create an open, safe, and accountable digital ecosystem.
Domestic Policy Frameworks
India’s legal and policy framework for cybersecurity relies on statutory enactments, executive policies, and sectoral guidelines designed to secure critical infrastructure and protect personal data.
Information Technology Act, 2000 and National Cyber Security Policy
- Information Technology Act, 2000: The primary legislation governing cybercrime and electronic commerce in India. Key provisions include Section 43A for data protection liabilities, Section 66F for cyber terrorism penalties, and Section 69A for government power to block public access to cyber threats.
- National Cyber Security Policy, 2013: Formulated to build a secure and resilient cyberspace for citizens, businesses, and government. It set targets to build operational capabilities, create a 24/7 national nodal agency, and protect Critical Information Infrastructure (CII).
- CERT-In Directions, 2022: Issued under Section 70B of the IT Act, 2000, mandating that all cybersecurity incidents be reported to CERT-In within six hours of detection. It requires service providers, data centers, and intermediaries to maintain system logs for 180 days.
Digital Personal Data Protection Act, 2023
- Statutory Data Protection: Replaced the legacy Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
- Data Fiduciary Mandate: Requires organizations processing personal data to implement technical and organizational measures to prevent data breaches.
- Data Protection Board of India: Established as an adjudicatory body to inquire into data breaches and impose financial penalties up to ₹250 crore for failures in observing reasonable security safeguards.
Key Institutional Architecture
The operational responsibility for securing India’s national cyberspace is distributed among specialized nodal agencies, law enforcement coordination centers, and defense commands.
Indian Computer Emergency Response Team (CERT-In)
- Status and Mandate: Statutory body created under Section 70B of the IT Act, 2000, functioning under the Ministry of Electronics and Information Technology (MeitY).
- Functions: Collects, analyzes, and disseminates information on cyber incidents; issues vulnerability notes, advisories, and security guidelines; coordinates emergency incident response across public and private systems.
- Capacity Measures: Empanels certified security auditing organizations and operates the Cyber Swachhta Kendra (Botnet Cleaning and Malware Analysis Centre).
National Critical Information Infrastructure Protection Centre (NCIIPC)
- Status and Mandate: Created under Section 70A of the IT Act, 2000, functioning as part of the National Technical Research Organisation (NTRO).
- Focus Area: Designated as the national nodal agency for all measures aimed at protecting Critical Information Infrastructure (CII) whose destruction impacts national security, economy, or public health.
- Core Sectors: Identifies protected systems across five critical verticals: Power and Energy, Banking, Financial Services and Insurance (BFSI), Telecom, Transport, and Strategic Enterprises.
Indian Cyber Crime Coordination Centre (I4C) and Military Units
- I4C Framework: Established under the Ministry of Home Affairs (MHA) in New Delhi to act as a central point for law enforcement agencies fighting cybercrime. Operates the National Cyber Crime Reporting Portal (cybercrime.gov.in) and the 1930 helpline for financial fraud.
- Defence Cyber Agency (DC&A): Tri-service command of the Indian Armed Forces tasked with handling cyber warfare threats, defensive network security, and joint military cyber operations.
- National Cyber Security Coordinator (NCSC): Functions under the National Security Council Secretariat (NSCS) to advise the Prime Minister’s Office and coordinate national-level strategy across ministries.
International Engagements and Global Norms
India actively participates in international norm-building, legal treaties, and regional partnerships to address cross-border cyber threats and data governance challenges.
Multilateral Negotiations and UN Forums
- UN GGE and OEWG: Engages in the United Nations Group of Governmental Experts (UN GGE) and Open-Ended Working Group (OEWG) on security of and in the use of information and communications technologies.
- Position on International Law: Maintains that existing international law, including the UN Charter and principles of state sovereignty, applies to cyberspace.
- UN Cybercrime Convention: Participated in the drafting of the UN Convention against Cybercrime adopted by the UN General Assembly in December 2024, providing a global framework for cross-border electronic evidence collection.
- Budapest Convention Stand: India is not a signatory to the Council of Europe’s 2001 Budapest Convention on Cybercrime, citing concerns over non-participation during initial drafting and international data-sharing rules that impact national sovereignty.
Regional and Bilateral Security Alliances
- Quad Cyber Group: Collaborates with the United States, Japan, and Australia to strengthen software supply chain security, protect critical infrastructure, and build regional workforce capabilities across the Indo-Pacific.
- Bilateral Cyber Dialogues: Maintains formal cyber security dialogues with partners including the United States, European Union, United Kingdom, Japan, France, and Australia to share threat intelligence and coordinate incident response.
- SCO and BRICS Frameworks: Participates in the Shanghai Cooperation Organisation (SCO) Expert Working Group on International Information Security and BRICS Working Group on Security in the Use of ICTs.
Institutional Roles and Responsibilities
| Agency / Entity | Administrative Ministry / Parent Body | Primary Operational Role |
| CERT-In | Ministry of Electronics and Information Technology (MeitY) | National incident response, vulnerability issuance, cyber advisories. |
| NCIIPC | National Technical Research Organisation (NTRO) | Securing designated Critical Information Infrastructure (CII). |
| I4C | Ministry of Home Affairs (MHA) | Law enforcement coordination, citizen cybercrime reporting portal, 1930 financial helpline. |
| Defence Cyber Agency | Ministry of Defence (MoD) | Tri-service military cyber defense and strategic network operations. |
| Cyber Diplomacy Division | Ministry of External Affairs (MEA) | International cyber policy negotiations, bilateral dialogues, treaty engagements. |
Quick Cybersecurity Facts
- CERT-In was established in 2004 under the provisions of the Information Technology Act, 2000.
- Section 66F of the IT Act prescribes punishment up to life imprisonment for acts of cyber terrorism.
- The Cyber Swachhta Kendra is operated by CERT-In to analyze malware and assist users in detecting botnet infections.
- India’s 1930 national helpline connects victims of financial cyber fraud directly to banks for immediate fund freezing.
- Critical Information Infrastructure (CII) protection in India is governed under Section 70A of the Information Technology Act.
- The National Cyber Crime Reporting Portal (cybercrime.gov.in) allows citizens to report cybercrimes online, with special focus on crimes against women and children.
- The Budapest Convention on Cybercrime entered into force in 2004 as the first international treaty on computer crime, but India remains a non-signatory.
- The UN General Assembly adopted the UN Convention against Cybercrime in December 2024, creating a universal mechanism for cross-border cybercrime cooperation.