India’s Cybersecurity Policies and International Engagements
India’s cybersecurity framework combines laws, specialised institutions, and international cooperation to protect digital infrastructure, sensitive data, and critical systems. As the country’s digital footprint expands, these mechanisms help address cybercrime, data breaches, and threats to national security.
Domestic Policy Framework
India’s cyber policy architecture rests on statutory provisions, executive directions, and data protection rules. The focus is on incident reporting, protection of critical infrastructure, and stronger safeguards for personal data.
- Information Technology Act, 2000: The principal law governing cybercrime and electronic commerce in India.
- Section 43A: Provides for liability in case of failure to protect sensitive personal data through reasonable security practices.
- Section 66F: Deals with cyber terrorism and prescribes punishment for such offences.
- Section 69A: Empowers the government to block access to public information in specified cyber threat situations.
- National Cyber Security Policy, 2013: Aimed to create a secure and resilient cyberspace for citizens, businesses, and government.
- Policy targets: Included building operational capabilities, establishing a 24/7 national nodal agency, and protecting Critical Information Infrastructure (CII).
- CERT-In Directions, 2022: Issued under Section 70B of the IT Act, 2000. These require cyber incidents to be reported to CERT-In within six hours of detection.
- Log retention: Service providers, data centres, and intermediaries must maintain system logs for 180 days.
- Digital Personal Data Protection Act, 2023: Replaced the earlier Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
- Data fiduciary obligation: Organisations processing personal data must adopt technical and organisational safeguards to prevent breaches.
- Data Protection Board of India: Set up to inquire into data breaches and impose penalties for failure to observe reasonable security safeguards.
Key Institutional Architecture
Operational responsibility for cybersecurity is shared among response agencies, infrastructure protection bodies, and law enforcement coordination centres. Each institution has a defined role in incident response, threat assessment, or strategic defence.
- CERT-In: A statutory body under Section 70B of the IT Act, 2000, functioning under the Ministry of Electronics and Information Technology (MeitY).
- CERT-In functions: Collects, analyses, and disseminates information on cyber incidents; issues advisories, vulnerability notes, and security guidelines; and coordinates emergency response.
- Cyber Swachhta Kendra: Operated by CERT-In as the Botnet Cleaning and Malware Analysis Centre.
- Security auditing: CERT-In empanels certified security auditing organisations to strengthen cyber resilience.
- NCIIPC: Created under Section 70A of the IT Act, 2000 and functions as part of the National Technical Research Organisation (NTRO).
- NCIIPC role: The national nodal agency for protecting Critical Information Infrastructure whose destruction can affect national security, economy, or public health.
- Protected sectors: Power and Energy, Banking, Financial Services and Insurance (BFSI), Telecom, Transport, and Strategic Enterprises.
- I4C: Established under the Ministry of Home Affairs (MHA) as a central point for law enforcement agencies dealing with cybercrime.
- I4C platforms: Operates the National Cyber Crime Reporting Portal (cybercrime.gov.in) and the 1930 helpline for financial fraud.
- Defence Cyber Agency: A tri-service command of the Indian Armed Forces for cyber warfare threats, defensive network security, and joint military cyber operations.
- National Cyber Security Coordinator: Functions under the National Security Council Secretariat (NSCS) to coordinate national strategy across ministries.
International Engagements and Global Norms
India links domestic cybersecurity priorities with diplomatic engagement in multilateral forums and regional groupings. The broad aim is to shape norms on cyberspace, cross-border threats, and data governance.
- UN GGE and OEWG: India participates in the United Nations Group of Governmental Experts and the Open-Ended Working Group on security of and in the use of information and communications technologies.
- Position on international law: India maintains that existing international law, including the UN Charter and principles of state sovereignty, applies to cyberspace.
- UN Cybercrime Convention: India participated in the drafting of the UN Convention against Cybercrime adopted by the UN General Assembly in December 2024.
- Purpose of the convention: It provides a global framework for cross-border electronic evidence collection.
- Budapest Convention: India is not a signatory to the Council of Europe’s 2001 Budapest Convention on Cybercrime.
- Reason for stand: India has cited concerns related to its non-participation in the initial drafting and international data-sharing rules affecting national sovereignty.
- Quad Cyber Group: Works with the United States, Japan, and Australia on software supply chain security, critical infrastructure protection, and regional workforce capabilities in the Indo-Pacific.
- Bilateral dialogues: India maintains cyber security dialogues with the United States, European Union, United Kingdom, Japan, France, and Australia.
- Regional platforms: India also participates in the SCO Expert Working Group on International Information Security and the BRICS Working Group on Security in the Use of ICTs.
| Agency / Entity | Administrative Ministry / Parent Body | Primary Operational Role |
| CERT-In | Ministry of Electronics and Information Technology (MeitY) | National incident response, vulnerability issuance, cyber advisories |
| NCIIPC | National Technical Research Organisation (NTRO) | Securing designated Critical Information Infrastructure (CII) |
| I4C | Ministry of Home Affairs (MHA) | Law enforcement coordination, citizen cybercrime reporting portal, 1930 financial helpline |
| Defence Cyber Agency | Ministry of Defence (MoD) | Tri-service military cyber defence and strategic network operations |
| Cyber Diplomacy Division | Ministry of External Affairs (MEA) | International cyber policy negotiations and bilateral engagement |
Key Prelims Takeaways
- IT Act, 2000 remains the main legal framework for cybercrime and electronic commerce in India.
- Section 70B empowers CERT-In, which is the statutory cyber incident response agency under MeitY.
- Cyber incident reporting to CERT-In must be done within six hours under the 2022 directions.
- 180-day log retention is mandatory for service providers, data centres, and intermediaries.
- DPDP Act, 2023 strengthens personal data protection and creates the Data Protection Board of India.
- NCIIPC is the nodal agency for protecting Critical Information Infrastructure under NTRO.
- I4C and 1930 helpline are important institutional mechanisms for reporting cybercrime and financial fraud.