India’s digital population crossed 100 crore internet connections in 2025, up from just 25 crore in 2014. That explosive growth has brought enormous economic benefits – but it has also turned India into one of the most targeted cyber landscapes in the world. Ransomware, phishing, AI-powered scams, and large-scale data breaches are now routine. Protecting this vast digital surface is not a one-agency job. India relies on a multi-layered framework of specialised agencies, each handling a different dimension of cyber security – from incident response and critical infrastructure protection to cybercrime coordination and data privacy enforcement.
Table of Contents
- CERT-In: the frontline of India’s cyber defence
- Cyber Swachhta Kendra and proactive threat mitigation
- Drills, audits, and global recognition
- National Cyber Coordination Centre (NCCC): real-time situational awareness
- NCIIPC: protecting the nation’s critical infrastructure
- Core functions of NCIIPC
- Indian Cybercrime Coordination Centre (I4C): tackling cybercrime
- Key components of I4C
- Data Protection Board of India: safeguarding personal data
- Role and powers of the Data Protection Board
- The National Security Council Secretariat: strategic coordination at the top
- How these agencies work together
- Challenges ahead
CERT-In: the frontline of India’s cyber defence
The Indian Computer Emergency Response Team (CERT-In) is the country’s primary cyber security agency. Established in 2004 under Section 70B of the Information Technology Act, 2000, it functions under the Ministry of Electronics and Information Technology (MeitY). CERT-In serves as the national nodal agency for responding to cyber security incidents. Its core mandate covers collecting and analysing information on cyber incidents, issuing alerts and advisories, coordinating responses with law enforcement and internet service providers, and publishing vulnerability notes on emerging threats.
The scale of its operations is significant. In 2025, CERT-In handled over 29.44 lakh cyber security incidents, issued 1,530 security alerts, and published 390 vulnerability notes. It also empanelled 231 certified audit organisations to strengthen the vulnerability assessment capacity of critical ICT infrastructure across the country.
Cyber Swachhta Kendra and proactive threat mitigation
One of CERT-In’s flagship initiatives is the Cyber Swachhta Kendra (CSK) – a Botnet Cleaning and Malware Analysis Centre. This programme works with internet service providers and product companies to detect malware infections on devices across the country. It provides free botnet-removal tools that citizens and organisations can download. According to government data, CSK now covers 98 per cent of India’s digital population and has recorded over 89 lakh downloads of its removal tools. The centre tracks networks of compromised devices – computers, smartphones, IoT gadgets, and routers – and sends large-scale notifications to affected users.
Drills, audits, and global recognition
CERT-In does not limit itself to reactive incident response. It conducts regular cybersecurity drills and exercises to test preparedness across both government and private sectors. In 2025, the agency ran 122 cybersecurity exercises, including tabletop simulations for over 1,570 organisations spanning defence, finance, telecom, power, oil and gas, and space sectors. CERT-In’s growing use of AI-driven threat detection has earned it global attention – the World Economic Forum highlighted its real-time threat intelligence capabilities in the Global Cybersecurity Outlook 2025, and it co-signed a joint report on AI and cyber risk with France’s national cybersecurity agency (ANSSI).
In July 2025, CERT-In also issued comprehensive Cyber Security Audit Policy Guidelines, mandating annual third-party cybersecurity audits for public and private enterprises. These guidelines require audits aligned with international standards like ISO/IEC 27001 and introduce stricter breach-reporting timelines, with organisations required to report incidents within six hours of detection.
National Cyber Coordination Centre (NCCC): real-time situational awareness
While CERT-In focuses on incident response and advisory functions, the National Cyber Coordination Centre (NCCC) is tasked with generating real-time situational awareness of cyber threats across the country. The NCCC was approved by the government in 2015 and is implemented by CERT-In under MeitY. It derives its authority from Section 69B of the IT Act, 2000.
The NCCC operates as India’s first layer for cyber threat monitoring. It scans internet traffic and communication metadata entering and leaving the country to detect malicious activity. It works in virtual contact with the control rooms of internet service providers (ISPs) and monitors traffic at international gateways. When it identifies threats, it shares information with relevant government agencies, state governments, and sector-specific stakeholders so they can take timely preventive or protective action.
The key components of the NCCC include a cybercrime prevention strategy, cybercrime investigation training modules, and a framework for reviewing outdated laws. It coordinates with multiple security and intelligence agencies – including the National Technical Research Organisation (NTRO), the National Critical Information Infrastructure Protection Centre (NCIIPC), and various intelligence bodies – to ensure that cyber threat intelligence flows in real time across the administration.
NCIIPC: protecting the nation’s critical infrastructure
Some systems are so essential that their disruption can have a devastating impact on national security, public health, or the economy. These are classified as Critical Information Infrastructure (CII) under the IT Act. The agency responsible for protecting them is the National Critical Information Infrastructure Protection Centre (NCIIPC).
NCIIPC was established in January 2014 under Section 70A of the IT Act, 2000. It operates as a unit of the NTRO and comes under the Prime Minister’s Office (PMO). NCIIPC has broadly identified several critical sectors that fall under its protection: power and energy, banking and financial services, telecom, transport, government, strategic and public enterprises, and health.
Core functions of NCIIPC
NCIIPC’s role involves identifying all critical information infrastructure elements and getting them notified by the government, developing protection strategies and policies, conducting vulnerability assessments, and issuing advisories and guidelines. It shares cyber incident data and coordinates with CERT-In and other organisations in the field. In the event of a threat to critical infrastructure, NCIIPC has the authority to call for information and issue directions to the entities operating that infrastructure.
The centre also maintains a 24×7 help desk for reporting incidents, runs a Responsible Vulnerability Disclosure Programme inviting ethical hackers and security researchers to identify weaknesses in CII, and operates a CII Range that simulates real-world threats for training purposes. NCIIPC works closely with private sector partners, academic institutions, and international agencies to share threat intelligence and develop joint protection frameworks.
Indian Cybercrime Coordination Centre (I4C): tackling cybercrime
Cyber security and cybercrime are closely related, but they require different approaches. While CERT-In and NCIIPC focus on securing systems and infrastructure, the Indian Cybercrime Coordination Centre (I4C) focuses on the criminal dimension – coordinating law enforcement responses to digital offences across the country.
I4C was approved by the Ministry of Home Affairs in October 2018 with an outlay of ₹415.86 crore and was officially inaugurated in January 2020. It acts as the national nodal point for fighting cybercrime, bringing together law enforcement agencies, industry experts, academia, and citizens onto a common platform.
Key components of I4C
I4C operates through seven integrated components. The National Cybercrime Reporting Portal (cybercrime.gov.in), paired with the toll-free helpline number 1930, allows citizens to report cyber incidents – especially financial fraud – directly. The National Cybercrime Threat Analytics Unit generates threat intelligence reports and organises discussions on emerging cybercrime trends. A dedicated National Cybercrime Forensic Laboratory supports digital evidence analysis, while the National Cybercrime Training Centre builds the capacity of police officers, prosecutors, and judicial officers across states and union territories.
I4C has also launched several initiatives to strengthen its reach. The Cyber Fraud Mitigation Centre (CFMC), inaugurated by the Home Minister, brings together representatives of banks, payment aggregators, telecom companies, and law enforcement in a single room to respond to financial fraud in real time. The Samanvay platform serves as a centralised data repository for cybercrime data sharing and analytics across jurisdictions. And the Pratibimb module uses geographic information systems to track the location of active mobile numbers used in cybercrime operations.
In 2025, I4C was also empowered to share and receive information with the Enforcement Directorate under the anti-money laundering law, enabling it to trace the financial trails of cybercriminals more effectively. It has blocked over 295,000 fraudulent SIM cards, 46,000 IMEI numbers, and thousands of malicious websites and apps.
Data Protection Board of India: safeguarding personal data
Cyber security is not just about stopping hackers – it is also about protecting people’s personal data from misuse. For this, India now has a dedicated legal and institutional framework under the Digital Personal Data Protection Act, 2023 (DPDP Act).
The DPDP Act received Presidential assent in August 2023, and its implementing rules – the DPDP Rules, 2025 – were notified by MeitY on 13 November 2025, bringing the law fully into force. The Act establishes clear obligations for organisations (called Data Fiduciaries) on how they collect, process, store, and delete digital personal data. It also defines the rights of individuals (Data Principals), including the right to access, correct, and erase personal data, and the right to withdraw consent at any time.
Role and powers of the Data Protection Board
The central enforcement authority under the DPDP Act is the Data Protection Board of India (DPBI). Established through the November 2025 notification, the Board is designed to be a fully digital body – conducting its proceedings through techno-legal processes without requiring physical presence. Citizens can file complaints online and track cases through a dedicated portal and mobile application.
The DPBI’s functions include investigating complaints and breaches of the Act, adjudicating disputes between individuals and organisations, and imposing financial penalties. The Board can levy penalties of up to ₹250 crore for severe violations. Organisations classified as Significant Data Fiduciaries – based on the volume and sensitivity of data they process – will eventually be required to appoint a Data Protection Officer, conduct periodic impact assessments, and undergo independent audits. Appeals against the Board’s decisions are heard by the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).
The National Security Council Secretariat: strategic coordination at the top
With so many agencies involved – each under a different ministry – coordination is critical. At the apex level, the National Security Council Secretariat (NSCS), functioning under the Prime Minister’s Office, provides overall strategic direction for cyber security in India.
The role of the NSCS was formalised through an amendment to the Allocation of Business Rules in September 2024. This amendment explicitly designated “cybersecurity” as a separate item under the NSCS’s responsibilities and tasked it with providing coordination and strategic direction across all relevant departments and ministries. The National Cyber Security Coordinator (NCSC), housed within the NSCS, acts as the nodal point of contact for cybersecurity matters. The NCSC advises the Prime Minister on cybersecurity issues, coordinates with the MEA on international cyber partnerships, and organises national-level exercises like the Bharat National Cyber Security Exercise.
The Ministry of Home Affairs has also set up the Cyber Multi Agency Centre (CyMAC) under the Multi Agency Centre platform, with participation from agencies including CERT-In, I4C, NCIIPC, the Intelligence Bureau, and others. CyMAC serves as a unified platform for real-time monitoring, threat intelligence sharing, and coordinated response to cybersecurity risks across all participating agencies.
How these agencies work together
India’s cyber security architecture is deliberately layered. Each agency has a defined mandate, but their work overlaps and interconnects at multiple points. CERT-In detects and responds to security incidents, while the NCCC provides the real-time threat intelligence that feeds into those responses. NCIIPC secures the most critical digital assets in sectors like banking, energy, and defence. I4C handles the law enforcement side – investigating and prosecuting cybercrimes with the help of state police and international partners. The Data Protection Board ensures that organisations comply with data privacy obligations. And the NSCS sits at the top, aligning all these efforts with national security priorities.
The Union Budget 2025-26 allocated ₹782 crore for cybersecurity, reflecting the government’s recognition that securing cyberspace is not optional – it is a national imperative. The Indian cybersecurity industry itself is now valued at approximately $20 billion, with over 400 startups and a workforce of 6.5 lakh professionals contributing to this ecosystem.
Challenges ahead
Despite this robust institutional structure, significant challenges remain. Functional overlaps between agencies – particularly between CERT-In and I4C – still create coordination gaps. The Parliamentary Standing Committee on Communications and IT has flagged the need for more effective inter-agency coordination. The fast-evolving nature of threats, especially those powered by AI, requires constant adaptation. Rural and semi-urban populations remain particularly vulnerable to digital fraud and often lack awareness about the reporting mechanisms available to them. And with the DPDP Act still in a phased rollout – full compliance for Significant Data Fiduciaries is not expected until May 2027 – data protection enforcement will take time to mature.
The privacy implications of surveillance tools like the NCCC also deserve attention. Civil society groups have raised concerns about the potential for mass surveillance in the absence of strong parliamentary oversight of intelligence agencies, an issue that remains unresolved even as India’s cybersecurity capabilities expand.
What do you think? With so many agencies sharing overlapping responsibilities, can India’s multi-layered cyber security framework avoid coordination breakdowns when facing a large-scale, sophisticated attack? And as digital infrastructure reaches deeper into rural India, what more should be done to ensure cyber awareness and protection reach every citizen?
References
- https://www.pib.gov.in/PressReleasePage.aspx?PRID=2217537®=3&lang=1
- https://practiceguides.chambers.com/practice-guides/cybersecurity-2025/india/trends-and-developments/O20301
- https://carnegieendowment.org/research/2025/09/mapping-indias-cybersecurity-administration-in-2025?lang=en
- https://www.mondaq.com/india/new-technology/1661386/strengthening-indias-cyber-defence-cert-ins-new-cyber-security-audit-guidelines-decoded
- https://www.pib.gov.in/PressReleseDetailm.aspx?PRID=2197529®=3&lang=1
- https://en.wikipedia.org/wiki/National_Cyber_Coordination_Centre
- https://en.wikipedia.org/wiki/National_Critical_Information_Infrastructure_Protection_Centre
- https://nciipc.gov.in/about_us.html
- https://www.mha.gov.in/en/division_of_mha/cyber-and-information-security-cis-division/Details-about-Indian-Cybercrime-Coordination-Centre-I4C-Scheme
- https://www.pib.gov.in/PressReleaseIframePage.aspx?PRID=2053438
- https://www.ey.com/en_in/insights/cybersecurity/decoding-the-digital-personal-data-protection-act-2023
- https://www.roedl.com/en/insights/indias-dpdpa-2023-activates-with-2025-rules-revolutionizing-data-privacy-enforcement/
Leave a Reply