India’s digital ecosystem is massive and growing fast. With over 970 million internet subscribers and a digital economy contributing more than $400 billion to the country’s GDP, the stakes for keeping cyberspace safe have never been higher. But who exactly is responsible for protecting this vast digital landscape? The answer lies in a network of specialised agencies – each with a distinct mandate – working together to detect threats, respond to incidents, protect critical assets, and safeguard personal data. Understanding these agencies is essential for anyone studying digital media, policy, or cybersecurity governance in India.

Table of Contents

The foundation: India’s cybersecurity policy landscape

India’s cybersecurity governance is rooted in the Information Technology Act, 2000, the country’s foundational legislation for regulating digital activity. The IT Act established the legal framework for e-governance, electronic commerce, data protection, and cybercrime. Over time, several amendments – notably in 2008 – expanded its scope to cover critical infrastructure protection, incident reporting, and the creation of dedicated cybersecurity bodies.

In 2013, the government released the National Cyber Security Policy, which articulated a vision for building a secure and resilient cyberspace for citizens, businesses, and government entities. The policy aimed to protect information infrastructure, build capacity to respond to threats, and reduce vulnerabilities through a combination of institutional frameworks, processes, technology, and international cooperation.

A significant development came in September 2024, when the government amended the Allocation of Business (AoB) Rules, clarifying responsibilities across agencies. The Ministry of Electronics and Information Technology (MeitY) was formally assigned all matters relating to cybersecurity, the Ministry of Home Affairs (MHA) was assigned cybercrime, and the Department of Telecommunications (DoT) was given charge of telecom network security. At the apex, the National Security Council Secretariat (NSCS) was tasked with providing overall coordination and strategic direction.

CERT-In: India’s first responder for cyber incidents

The Indian Computer Emergency Response Team (CERT-In) is the backbone of India’s cybersecurity response infrastructure. Established in 2004 under Section 70B of the IT Act, it functions under MeitY and serves as the national agency for collecting, analysing, and disseminating information about cybersecurity incidents.

Key functions of CERT-In

CERT-In’s mandate is broad. It monitors and detects cybersecurity threats, coordinates incident response across government and private sector organisations, issues alerts and advisories on emerging vulnerabilities, and publishes guidelines on information security practices. It also empanels cybersecurity auditing organisations – over 200 as of 2025 – that perform periodic audits of government and critical sector IT infrastructure.

In 2025, CERT-In handled over 29 lakh cyber incidents, issued more than 1,500 alerts, 390 vulnerability notes, and 65 advisories. These numbers reflect the agency’s massive operational scale. It also operates the Cyber Swachhta Kendra, a botnet cleaning and malware analysis centre that works with internet service providers to detect threats and provide free malware removal tools to citizens. By 2025, this initiative covered roughly 98% of the digital population.

Mandatory incident reporting

One of CERT-In’s most impactful directives came in April 2022, when it mandated all Indian companies, service providers, intermediaries, and data centres to report cybersecurity incidents within six hours of detection. This directive significantly improved India’s ability to track and respond to threats in near real-time. CERT-In also formulated a Cyber Crisis Management Plan to counter cyber attacks and cyber terrorism, which is implemented across all central and state government departments as well as critical sectors.

International engagement

CERT-In does not operate in isolation. It engages with international counterparts through bilateral cyber dialogues and holds memorandums of understanding with countries including Japan, the United Kingdom, Brazil, and Vietnam. In early 2025, it co-signed a joint report on AI-related cyber risks with France’s National Cybersecurity Agency (ANSSI), demonstrating its growing role in global cybersecurity governance.

NCIIPC: guarding India’s critical infrastructure

While CERT-In handles cybersecurity broadly, the National Critical Information Infrastructure Protection Centre (NCIIPC) focuses specifically on protecting the country’s most vital digital assets. Created under Section 70A of the IT Act through a gazette notification in January 2014, NCIIPC is a unit of the National Technical Research Organisation (NTRO), which operates under the Prime Minister’s Office.

What is critical information infrastructure?

The IT Act defines Critical Information Infrastructure (CII) as computer resources whose incapacitation or destruction would have a debilitating impact on national security, economy, public health, or safety. NCIIPC has identified several critical sectors: banking, finance and insurance, power and energy, telecommunications, transport, health, and strategic and public enterprises. The Department of Financial Services, for example, coordinates with NCIIPC to identify and notify critical infrastructure within the financial sector.

NCIIPC’s core responsibilities

NCIIPC identifies and designates critical information infrastructure elements, provides threat intelligence and situational awareness to CII organisations, and issues alerts and advisories for preventive action against cyber attacks. It also develops guidelines for procurement, best practices, and security standards for CII entities. The agency conducts vulnerability assessments and cybersecurity audits, and runs training programmes for information security personnel across government and private sectors.

The agency maintains connectivity with over 200 sites across critical sectors for threat intelligence sharing. It also runs a Responsible Vulnerability Disclosure Programme, encouraging ethical hackers and security researchers to report vulnerabilities in critical infrastructure.

Why NCIIPC matters

The importance of NCIIPC becomes evident when you consider real-world incidents. The ransomware attacks on the All India Institute of Medical Sciences (AIIMS) in 2022 and 2023 demonstrated how vulnerable health infrastructure can be. A 2020 power outage in Mumbai raised concerns about potential cyber intrusion into India’s power grid. These events underline the necessity of a dedicated agency focused on shielding critical assets from increasingly sophisticated threats.

National Cyber Coordination Centre (NCCC): the situational awareness hub

The National Cyber Coordination Centre (NCCC) is an operational cybersecurity and e-surveillance agency designed to serve as India’s first layer for cyber threat monitoring. Its primary role is to scan internet traffic flowing through the country – at entry and exit points including international gateways – to detect cyber threats in real time and alert relevant agencies and internet service providers for timely action.

How NCCC operates

The NCCC generates situational awareness of existing and potential cybersecurity threats and enables timely intelligence sharing across agencies. It is in virtual contact with the control rooms of all major ISPs and monitors metadata to identify patterns indicating malicious activity. The centre coordinates between intelligence agencies, law enforcement, and sectoral regulators, functioning as a centralised hub for processing and disseminating threat intelligence.

Phase-I of the NCCC became operational in August 2017, focusing on real-time monitoring and threat awareness. Led by the Director General of CERT-In, it coordinates between government agencies and provides cyber intelligence to support incident response and mitigation efforts. The centre derives its powers from Section 69B of the IT Act, 2000.

Challenges and concerns

The NCCC’s internet monitoring capabilities have raised important questions about privacy and civil liberties. Since it screens communication metadata across the country’s networks, some legal experts and civil society groups have expressed concern about the potential for mass surveillance. The centre was initially classified as a government project without a dedicated legal framework, which critics argued could be counterproductive. As India strengthens its data protection regime, the interplay between cybersecurity monitoring and individual privacy rights will remain an ongoing debate.

Data Protection Board of India: enforcing the DPDP Act

Data protection is a crucial pillar of cybersecurity governance. India’s Digital Personal Data Protection Act, 2023 (DPDP Act) – the country’s first comprehensive data protection law – was enacted in August 2023 and became operational with the notification of the Digital Personal Data Protection Rules 2025 on 13 November 2025.

From DPA to Data Protection Board

Earlier drafts of data protection legislation had proposed a Data Protection Authority (DPA) as the enforcement body. The final version of the DPDP Act instead established the Data Protection Board of India (DPB). Under Section 18 of the DPDP Act, the DPB adjudicates disputes between individuals whose data has been processed and the entities that process it. It has the power to investigate violations, impose penalties of up to โ‚น250 crore in severe cases, mandate remediation actions, and oversee grievance redressal.

Key provisions of the DPDP Act

The DPDP Act applies to all digital personal data collected or processed within India and also has extra-territorial applicability for foreign entities offering goods and services to Indian residents. Key principles include lawful and transparent data processing, purpose limitation, data minimisation, and reasonable security safeguards. Organisations must obtain explicit and informed consent from individuals before processing their data, and individuals have rights to access, correct, and erase their data.

The law is being implemented in a phased manner. The establishment of the Data Protection Board and administrative provisions took effect in November 2025. Consent manager registrations open in November 2026, and all operative provisions – including consent, privacy notice, and security requirements – become mandatory by May 2027.

Why it matters for cybersecurity

Data protection and cybersecurity are deeply interlinked. A data breach is both a cybersecurity incident and a violation of data protection obligations. Under the DPDP Act, organisations must report all personal data breaches to the Data Protection Board, irrespective of their severity. This creates a legal obligation that complements CERT-In’s incident reporting requirements, ensuring comprehensive oversight of digital threats from both security and privacy perspectives.

Other key players in India’s cybersecurity ecosystem

Indian Cybercrime Coordination Centre (I4C)

Operating under the Ministry of Home Affairs, the I4C was established to improve coordination between law enforcement agencies across jurisdictions for dealing with cybercrime. It runs the National Cybercrime Reporting Portal, which has been used over 140 million times since its inception. The I4C also operates the National Cyber Forensic Laboratory, the Cyber Fraud Mitigation Centre that connects financial institutions and telecom companies with law enforcement, and seven Joint Cybercrime Coordination Teams for interstate information sharing.

Defence Cyber Agency (DCyA)

The Defence Cyber Agency, established in 2019 under the Ministry of Defence, is an integrated tri-services agency responsible for the cybersecurity of defence infrastructure. It coordinates joint cyber operations of the Indian Armed Forces and implements the “Joint Doctrine for Cyberspace Operations” released in 2024. Each branch of the armed forces also operates its own CERT that works with the DCyA on incident response.

National Security Council Secretariat (NSCS)

At the apex, the NSCS under the Prime Minister’s Office provides overall coordination and strategic direction for India’s cybersecurity efforts. The National Cyber Security Coordinator, housed within the NSCS, advises the Prime Minister on cybersecurity matters and acts as the nodal point of contact for all cybersecurity issues. This role was established in 2015 and gained further clarity through the 2024 AoB amendment. The coordinator also heads the national cybersecurity secretariat, comprising secretaries from various ministries, and is responsible for drafting national cybersecurity policies such as the National Cybersecurity Reference Framework released in 2024.

How these agencies work together

India’s cybersecurity administration follows what can be described as a “hub and spoke” model. The NSCS acts as the hub, providing strategic coordination, while ministries and agencies serve as spokes handling specific domains – MeitY for cybersecurity, MHA for cybercrime, and DoT for telecom network security. CERT-In functions as the operational backbone, coordinating incident response across sectors and supporting state-level and sector-level CSIRTs for power, finance, and telecom.

However, this structure is not without challenges. Functional overlaps persist – for instance, both CERT-In and the DoT’s Telecom Security Operation Centre monitor threats to telecom infrastructure. Similarly, I4C and CERT-In share some overlapping responsibilities around cybercrime and cybersecurity. A Carnegie India analysis noted that while the AoB amendment clarified broad responsibilities, ambiguity remains about inter-agency coordination protocols, especially when a critical infrastructure incident involves multiple jurisdictions and agencies simultaneously.

The road ahead: challenges and emerging priorities

India’s cybersecurity landscape is evolving rapidly. The country is the second most targeted nation globally for cyber attacks, facing rising threats from ransomware, phishing, supply chain attacks, and AI-powered intrusions. Between 2019 and 2023, cyber attacks on the Indian government increased by 138 percent.

Several challenges demand attention. First, the expanding digital surface – with new technologies like AI, IoT, and quantum computing – requires constant recalibration of cybersecurity strategies and agency mandates. Second, the shortage of skilled cybersecurity professionals remains a bottleneck, though the country now has over 6.5 lakh professionals and more than 400 cybersecurity startups contributing to a growing $20 billion industry. Third, balancing cybersecurity monitoring with data privacy and civil liberties will require ongoing legal and institutional refinement, especially as both the NCCC and the DPDP Act mature operationally.

India secured Tier 1 status in the ITU’s Global Cybersecurity Index in 2024, recognising strong legal, technical, and capacity-building measures. The index also flagged organisational measures as an area for potential growth – reinforcing the need for clearer inter-agency frameworks and a more unified institutional approach.

What do you think? With so many agencies involved in cybersecurity governance, do you think India’s “hub and spoke” model is effective enough to address the scale and speed of modern cyber threats? And as surveillance capabilities grow alongside data protection laws, how should the country balance security with individual privacy?

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

We are sorry that this post was not useful for you!

Let us improve this post!

Tell us how we can improve this post?

References
  1. https://www.upguard.com/blog/cybersecurity-regulations-india
  2. https://carnegieendowment.org/research/2025/09/mapping-indias-cybersecurity-administration-in-2025?lang=en
  3. https://www.pib.gov.in/PressReleasePage.aspx?PRID=2217537&reg=3&lang=1
  4. https://www.csk.gov.in/
  5. https://en.wikipedia.org/wiki/National_Critical_Information_Infrastructure_Protection_Centre
  6. https://financialservices.gov.in/beta/en/page/cii
  7. https://en.wikipedia.org/wiki/National_Cyber_Coordination_Centre
  8. https://www.pib.gov.in/PressReleaseIframePage.aspx?PRID=1556474&reg=3&lang=2
  9. https://www.hoganlovells.com/en/publications/indias-digital-personal-data-protection-act-2023-brought-into-force-
  10. https://en.wikipedia.org/wiki/Digital_Personal_Data_Protection_Act,_2023
  11. https://www.roedl.com/en/insights/indias-dpdpa-2023-activates-with-2025-rules-revolutionizing-data-privacy-enforcement/
  12. https://cybercrime.gov.in/

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

Digital Media

1 Internet as a Medium

  1. Internet as a Medium of Communication
  2. Conceptual Framework of Cyberspace
  3. Functional Dimensions of Cyberspace
  4. Characteristics of Cyberspace
  5. Types of Internet-Based Communication
  6. Dynamics of Communication Process in CMC
  7. Forms of Computer-Mediated Communication
  8. Virtual Communities

2 Digital Media and Society

  1. Digital Media in Society
  2. Understanding Digital Media
  3. Evolution and Development of Digital Media
  4. Concepts and Theories of Digital Media
  5. Medium Specific Trends
  6. Revolution within the Media Landscape
  7. Effects of Digital Media

3 Issues of Access and Participation

  1. Digital (In)Equality: Conceptual Framework
  2. Evolution and Development of ICT
  3. Growth and Diffusion of ICT
  4. Digital Divide
  5. Initiatives to Bridge the Digital Divide in India

4 Policy Framework and Regulation

  1. Digital Media Framework in India
  2. ICT Policies of India
  3. Regulatory Body
  4. IT Laws and Rules
  5. Agencies Involved in Cyber Security
  6. Social Media Guidelines

5 Spectrum of Social Media

  1. Understanding Social Media
  2. Social Media in India
  3. Social Media Etiquettes
  4. Uses of Social Media
  5. Socio Cultural and Economic Impact of Social Media

6 Online News Sharing

  1. Social Media and Interactivity
  2. Content Sharing
  3. Social Media Tools and Engagement
  4. Impact of News Sharing on Mainstream Media
  5. Fake News on Social Media

7 Social Media Audience

  1. Audience – The Term and Concept
  2. Social Media Audience
  3. Theories of Audience
  4. Marketing and Social Media Audience

8 Applications of Social Media

  1. Social Media and Governance
  2. Social Media and Business Organisations
  3. Social Media Politics and Development
  4. Social Media Arts Culture and Education

9 Internet and Marginalised sections

  1. Understanding Marginalisation and the Marginalised
  2. Digital Media Platforms: Conceptual Understanding
  3. Representations and Presentations
  4. Internet and Marginalised Sections: Case Studies

10 Praticipatory Online Media

  1. Approaches to Participation
  2. Online Participation and Engagement
  3. Youth Participatory Culture and Media Literacy
  4. Digital Media and Empowerment
  5. Role of Social Media in Online Participatory Communication
  6. Experiments/Stories from India

11 Online Activism

  1. Understanding Online Activism
  2. Activism and Social Movements
  3. Technology and Activism/Social Movements
  4. Characteristics of Online Activism
  5. Online Activism and Social Change

12 Democracy and Digital Media

  1. Understanding Concepts of Democracy
  2. Linkages between Democracy and Digital Media
  3. Avenues of Linkages
  4. Citizen Journalism and Social Change
  5. Experiences of Interplay

13 ICT for Education

  1. Scope of ICT in Education
  2. ICT in Education: Major Requirements
  3. ICT in Education: Indian Scenario
  4. Integration of ICT in Education: Issues and Challenges

14 Health and ICT

  1. Health Sector and ICT
  2. Health Information Online
  3. Strategies for Health Communication
  4. Skill Acquisition in Health-Theory and Models
  5. Barriers to Health Information Literacy

15 E-Goverance

  1. Concept of E-governance
  2. Stages of E-governance
  3. Models of E-governance
  4. Legal and Policy Framework
  5. Significance of E-governance
  6. Challenges and Opportunities

16 Entrepreneurship and Digital Media

  1. Entrepreneurship
  2. Digital Media
  3. Opportunities and Challenges for a Media Student
  4. Critique of Technology Aided Business Model