{
"authors": [],
"type": "event",
"centerAffiliationAll": "",
"centers": [
"Carnegie Endowment for International Peace",
"Carnegie India"
],
"englishNewsletterAll": "",
"nonEnglishNewsletterAll": "",
"primaryCenter": "Carnegie India",
"programAffiliation": "",
"programs": [],
"projects": [
"Technology and Society"
],
"regions": [
"India"
],
"topics": [
"Technology"
]
}Assessing India’s Cybersecurity Administration and Strategy
Mon, October 21st, 2024
Zoom
Carnegie India organized a virtual closed-door discussion titled “Assessing India’s Cybersecurity Administration and Strategy” on October 21, 2024. The discussion was attended by cyber policy experts and former cybersecurity officials from government, tech companies, and start-ups. The closed-door discussed India’s current cybersecurity administration structure, identified some current and emerging threats to India’s cybersecurity and discussed possible ways for India to address them. Below are the takeaways from the event:
The State of Cybersecurity Administration in India: India’s cybersecurity administration has several institutional mechanisms like the National Cyber Security Secretariat under the National Security Council Secretariat (NSCS), the Indian Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs, and the Defence Cyber Agency under the Ministry of Defence. The Computer Emergency Response Team India (CERT-In) serves as the primary responder for cyber incidents across private sector and government, while the National Critical Information Infrastructure Protection Centre (NCIIPC) specifically handles critical infrastructure protection. It was noted that India’s cybersecurity framework currently operates under the National Cybersecurity Policy 2013 that has several limitations. Decision-making regarding cybersecurity involves different agencies that are working in silos and there is duplication in functions. To address this, the NSCS had formulated a draft National Cybersecurity Strategy in 2021 but is yet to be implemented. However, a significant development occurred in September 2024 when the Cabinet Secretariat amended the Government of India (Allocation of Business) Rules, 1961, distributing cybersecurity responsibilities across multiple ministries, but making the NSCS the nodal agency to coordinate and provide strategic direction. Further sectoral CERTs (like FinCERT, RailwayCERT, and PowerCERT) and a cyber crisis management plan at each ministerial level are also emerging. In addition, guidelines have been issued by the Ministry of Electronics and Information Technology (MeitY) for government organizations to allocate 10 percent of their budget for cybersecurity.
Bolstering India’s Cyber Offense and Defence Capabilities: The military perspective on cybersecurity extends beyond traditional cybercrimes to address threats from adversary nations, particularly regarding attacks on critical information infrastructure (CII). Such attacks constitute aggression that needs to be addressed by India. The discussion highlighted three strategic approaches. Firstly, a defensive stance based on the global commons view where the private sector manages the CII and the state plays the macro role of identifying threats, issuing advisories and carrying out post-attack investigations. Secondly, a cyber sovereignty approach like China’s Great Firewall, that incorporates additional security layer for its national cyberspace. Thirdly, an offensive-defence stance that focuses on causing disruption in adversaries’ CII when attacked, needed for cyberspace deterrence. While India’s National Technical Research Organization has some cyber offense capability, it was noted that India needs a formally enunciated one similar to some nations like the U.S. Cyber Command or China’s PLA Cyberspace Force. India’s current position in global cyber capabilities (ranked twenty-sixth in the Belfer National Cyber Power index) contrasts sharply with China’s (ranked second), highlighting the scope for improvement. The Russia-Ukraine conflict demonstrated significant asymmetric advantages possible through cyber capabilities, emphasizing the necessity for India to develop a comprehensive national cyber strategy that prioritizes capabilities for full-spectrum cyber operations. A key recommendation towards this is to establish a cyber command and develop a specialized cyber cadre within the Indian military. Additionally, it was highlighted that the Indian military must develop secure cloud infrastructure to leverage emerging technologies like AI for data management and analysis.
Private Sector as the Net Security Provider for India’s Cybersecurity: The private sector’s role in India’s cybersecurity landscape is becoming increasingly crucial. CERT-In maintains a network of 700 Chief Information Security Officers (CISOs) embedded within the private sector for threat intelligence sharing. However, it was noted that there is hesitation among private sector players regarding cybersecurity investments and involvement. The private sector’s cybersecurity is primarily driven by regulatory requirements rather than proactive initiatives. However, the participation of private companies like Microsoft or Starlink in maintaining cyber resilience in Ukraine in conflict demonstrates the potential for public-private partnerships and emphasizes the need to view the private sector as a net security provider. A significant concern raised was the lack of general awareness around cybersecurity issues, with most private sector clients following a reactive approach for cybersecurity assistance instead of a proactive approach.
India’s Cyber Diplomacy Efforts So Far: India has adopted a pragmatic approach to global cyber governance, carefully navigating ideological contests witnessed since the 1990s. Rather than becoming entangled in controversial debates about binding versus non-binding norms, India has focused on practical areas like capacity building, critical infrastructure protection, and supply chain resilience. This approach has enabled productive engagement through initiatives like the QUAD senior cyber group and CERT-CERT collaborations (like CERT-In collaboration with U.S CERT). On a diplomatic level, the Ministry of External Affairs’ cyber diplomacy division has been taking the lead, while CERT-In has established valuable partnerships through MoUs and joint exercises with countries like the UK and Singapore respectively. Notably, the MeitY succeeded in negotiating a cyber security declaration during the G20 Summit 2023, demonstrating India’s growing influence in international cyber diplomacy.
Emerging Cyber Threats and Attack Patterns in India: The discussion identified several critical trends in cyber threats faced by India. It was pointed that Chinese state-sponsored attacks on critical infrastructure have become increasingly common, as evidenced by incidents like the AIIMS ransomware attack and the targeting of pharmaceutical companies like Serum Institute of India and Bharat Biotech. These attacks often serve multiple objectives, from cyber espionage to undermining commercial competitiveness. Additionally, the rise of Internet of Things (IoT)-based attacks, as seen in recent conflicts in Ukraine and Iran, introduces new vulnerabilities that require regulatory attention. The advent of quantum computing will necessitate a complete overhaul of existing cyber infrastructure and security systems. The integration of AI, especially generative AI, in cybersecurity presents both opportunities (such as running security simulations) and challenges (access to advanced malware codes).
The Need for Indigenized Technology Infrastructure and Data Sovereignty: A concern was expressed about India’s dependence on foreign cloud infrastructure. This dependency raises further security concerns, where rapid CII migration to foreign cloud might be necessary to protect them from kinetic attacks during conflicts. There was an emphasis on indigenous cloud capabilities and “atmanirbharta” (self-reliance) in critical technology infrastructure. The discussion also emphasized how data has become the fourth factor of production in addition to land, labor, and capital, making digital sovereignty crucial for national security.
The Way Forward: The discussion identified several forward-looking concerns that require immediate attention. There is a significant gap in public awareness about cybersecurity and critical data protection. The lack of coherence between different regulatory requirements and the challenge of coordination, enforcement, and duplication across multiple agencies were identified as key institutional challenges. The discussion suggested coordination, practicing a “Zero Trust” approach, building a cyber-dome, and forging partnerships for increased domain awareness to identify threat actors who exploit gaps between the implementation of new cyber solution.
Carnegie India does not take institutional positions on public policy issues; the views represented herein are those of the author(s) and do not necessarily reflect the views of Carnegie, its staff, or its trustees.