India’s National Cyber Security Strategy 2020: Assessing Institutional Gaps and the Need for a New Strategy

Policy Update
Neha
Kumari

1. Background

India’s first national cybersecurity policy was the National Cyber Security Policy (NCSP) 2013, which came into effect on July 2, 2013. The main aim of the policy was to make India’s cyberspace safer, build trust in online transactions, and protect government and private systems from cyberattacks. It also focused on improving coordination between different departments, developing cybersecurity institutions, and promoting indigenous security technologies. 

Since 2013, India’s digital world has changed a lot. The Digital India programme, launched in 2015, pushed for more use of digital tools like Aadhaar, UPI, DigiLocker and CoWIN. Internet use has also grown rapidly, from around 200 million users in 2013 to more than 900 million by 2025 (PIB, 2025). Digital payments also grew very fast, crossing 15,000 crore transactions in 2025, up from just over 2,000 crore in 2018-19 (NPCI, 2025). 

This growth has brought many benefits, but it has also created new cybersecurity risks. Banks, power systems, transport networks, hospitals and government offices now depend heavily on digital systems. At the same time, technologies such as cloud computing, 5G, the Internet of Things (IoT) and artificial intelligence have created new opportunities as well as new vulnerabilities. Cyber threats have also changed. Earlier threats were often associated with viruses, basic hacking and website attacks. Today, India has to deal with ransomware, supply-chain attacks, cyber espionage, online financial fraud and attacks that use artificial intelligence.

Because of these changes, a National Cyber Security Strategy (NCSS) 2020 was proposed around 2020. It was meant to guide India’s cybersecurity efforts from 2020 to 2025 (NSCS, 2020). However, NCSS 2020 remained a proposed strategy and was not formally adopted as a national cybersecurity policy. This distinction is important because the developments discussed in this article between 2020 and 2026 cannot be treated as direct implementation of NCSS 2020. Instead, they represent developments in India’s wider cybersecurity framework during and after the period for which the proposed strategy was intended. The proposed strategy wanted to update the 2013 policy to deal with new technologies, threats and dependencies. 

It focused on protecting critical infrastructure, making supply chains safer, improving preparation in different sectors, building cybersecurity capacity in states, and encouraging research and innovation in cybersecurity.

This distinction forms the starting point of this policy update. The article does not assess the “implementation” of NCSS 2020 because the strategy was never formally adopted. Instead, it asks whether developments in India’s cybersecurity institutions and policies since 2020 have addressed the problems identified in the proposed strategy, what institutional gaps remain in 2026, and whether these gaps justify the need for a new formally adopted national cyber strategy. 

Now, five years after the intended 2020-25 period, the main question is: what has India achieved since the NCSS 2020 proposal, what gaps remain in its cybersecurity system, and why is there a need for a new national cyber strategy?

2. Understanding the National Cyber Security Strategy 2020

The proposed NCSS 2020 was meant to be a strategic plan to guide India’s cybersecurity work from 2020 to 2025. It recognised that NCSP 2013 policy needed to be updated because of changes in technology, cyber threats and India’s growing dependence on digital systems.

The proposed strategy also followed a whole-of-government and whole-of-society approach. This meant involving central ministries, state governments, private companies, academic institutions and citizens rather than treating cybersecurity as the responsibility of only one government department.

The proposed strategy should therefore be understood as a strategic framework rather than a programme that was directly implemented through a single government institution. Its importance today lies in the problems it identified and in examining how far those problems have been addressed through subsequent policies, institutions and programmes. 

Some important areas were: 

  • Critical information infrastructure: These are important digital systems used in areas such as power, banking, transport, telecom, health and government services. The strategy wanted better protection for these systems through more sectors being designated as critical, regular security checks, and clear plans for responding to incidents.
  • Supply-chain security: Hardware, software and digital services are often obtained from different companies and countries. A weakness in one part of this chain can affect the larger system. The strategy therefore focused on security checks, safer vendors and greater development of Indian alternatives. 
  • Digital payment security: The rapid growth of UPI, cards and other digital payment systems created a need for stronger security. The strategy focused on measures such as encryption, fraud detection and public awareness. 
  • Sectoral preparedness: Different sectors such as banking, energy, telecom and health face different cyber risks. They therefore need sector-specific guidelines, training and regular security exercises. 
  • State-level cybersecurity: States play an important role in dealing with cybercrime and protecting their own government systems. The strategy therefore proposed stronger cybersecurity capacity at the state level, including incident response teams, security operations centres and trained officials. 
  • Cybersecurity of MSMEs: Small and medium enterprises often lack resources for cybersecurity, making them vulnerable. The strategy wanted to support them with affordable security tools, awareness programmes and technical help.
  • Capacity building and R&D: The strategy also focused on increasing cybersecurity education, training, research and innovation through government, universities and industry. 
  • Incident and crisis management: Cyber incidents cannot always be prevented. The strategy wanted stronger national and sectoral incident response, with clear escalation paths, coordination mechanisms and recovery plans.
  • Cyber diplomacy: Cyber threats often cross national borders. India therefore needs cooperation with other countries on cyber norms, threat intelligence, capacity building and investigation. 
  • Cyber insurance: Cyber insurance can help businesses manage some of the financial losses caused by cyber incidents. 
  • Public-private cooperation: The strategy encouraged information sharing, joint research, standards development and capacity building between the government and the private sector.

The proposed strategy recognised that cybersecurity is not only a technical issue. It is also connected with governance, coordination, skills and institutional capacity. However, the NCSS 2020 remained a proposed strategy and was not formally adopted as national policy.

3. Five Years On: What Has Changed?

The cyber environment in 2026 is quite different from the one India faced around 2020. 

  • Artificial intelligence and generative AI: Artificial intelligence is now being used in cybersecurity to identify threats and unusual activities. At the same time, attackers can also use AI to create convincing phishing messages, fake images, deepfakes and fraud content. This makes some cyberattacks easier to carry out at a larger scale. 
  • Ransomware: Ransomware has become a serious concern for governments, businesses and critical sectors. CERT-In handled more than 29.44 lakh cyber incidents in 2025, compared with 13.91 lakh in 2022. The increasing number of incidents shows the growing scale of cybersecurity challenges in India. 

However, the increase in reported incidents should not by itself be treated as proof that cybersecurity has become worse. Higher reporting and detection can also contribute to an increase in recorded incidents. This is why incident numbers should be assessed together with indicators of detection, response, recovery and prevention. 

  • Cloud computing: More organisations now use cloud platforms to store data and operate services. While cloud systems provide flexibility, they also create security concerns related to access control, data protection and responsibility for securing the system. 
  • 5G and IoT: The expansion of 5G and IoT is connecting more devices and systems. This also increases the number of possible entry points for attackers. Many IoT devices may not have strong security features, making them easier targets. 
  • Digital payments: Digital payment adoption has increased rapidly, with UPI transactions crossing 15,000 crore in 2025 (NPCI, 2025). This has made payments easier but has also created new opportunities for cyber fraud. Stronger fraud detection, cybersecurity measures and public awareness are therefore becoming more important. 
  • Cyber espionage and supply-chain attacks: Governments, defence organisations and critical infrastructure can be targeted for sensitive information or strategic advantage. Attacks through software, hardware and other parts of the supply chain can also affect organisations without directly attacking them. 
  • AI-enabled cyber threats: AI can help attackers automate activities, personalise social engineering and make some attacks harder to detect. This creates a new challenge for cybersecurity agencies. 

The cyber environment in 2026 is more complex, interconnected and threat-prone than in 2020. This raises the question of whether India’s cybersecurity framework has kept pace.

The key analytical point is that the problem is not simply that India faces more cyber threats. The more important issue is whether India’s institutions have developed the coordination, skills, technical capacity and resilience required to manage these changing threats. 

4. India’s Cybersecurity Institutional Architecture

India has developed a substantial cybersecurity institutional system over the past decade. Several organisations now deal with different parts of cybersecurity and cybercrime. 

  • Ministry of Electronics and Information Technology (MeitY): MeitY is the main ministry responsible for cybersecurity policy, digital governance and several cybersecurity programmes. It also oversees CERT-In and works on cybersecurity guidelines, capacity building and related policies. 
  • Ministry of Home Affairs (MHA): MHA has an important role in the cybercrime side of cybersecurity, particularly because policing and public order are state subjects. Through institutions such as I4C, MHA supports coordination, cybercrime reporting, investigation and capacity building. 
  • CERT-In: The Indian Computer Emergency Response Team, established under Section 70B of the Information Technology Act, 2000, is the national agency for responding to cyber incidents. In 2025, CERT-In handled more than 29.44 lakh cyber incidents and also issued security alerts, vulnerability notes and advisories (PIB, 2025). It conducts security audits and operates the Cyber Swachhta Kendra for malware detection and cleaning. 
  • National Cyber Security Coordinator (NCSC): The NCSC, located under the National Security Council Secretariat, works on coordination of cybersecurity matters across ministries, agencies and states. Its role is important because cybersecurity responsibilities are spread across different parts of government. 
  • National Critical Information Infrastructure Protection Centre (NCIIPC): The National Critical Information Infrastructure Protection Centre, established under Section 70A of the IT Act, 2000, is responsible for protecting critical information infrastructure in sectors such as power, banking, telecom and transport. NCIIPC conducts audits, issues guidelines and coordinates with sectoral agencies.
  • National Cyber Coordination Centre (NCCC): The NCCC is operated by CERT-In and works on monitoring cyber threats, coordination and sharing of threat information with relevant stakeholders. 
  • Indian Cyber Crime Coordination Centre (I4C): I4C was established by the Ministry of Home Affairs in 2020 to improve coordination in dealing with cybercrime. It operates the National Cyber Crime Reporting Portal and the Citizen Financial Cyber Fraud Reporting and Management System (CFCFRMS). From 2021 to 2025, over 65.89 lakh financial fraud complaints were reported, with total losses exceeding ₹55,050 crore (PIB 2025). The 1930 helpline and real-time intervention system saved over ₹11,158 crore by June 2026 (The 420, 2026).

The roles of these institutions are complementary but not identical. CERT-In primarily deals with technical cyber incidents and response; NCIIPC focuses on critical information infrastructure; I4C focuses on cybercrime coordination and law-enforcement support; the NCSC has a strategic coordination role; MeitY has an important policy and regulatory role; MHA deals substantially with cybercrime and policing coordination; and state agencies carry out much of the ground-level investigation and enforcement.

This institutional structure means that cybersecurity depends on coordination across technical agencies, policy institutions, intelligence mechanisms, law enforcement and state governments. A cyber incident can therefore move across institutional boundaries; for example, from a technical incident handled through CERT-In to a criminal investigation involving state police and I4C. The effectiveness of the system depends not only on the capacity of each organisation but also on how well these organisations share information and coordinate their responses.

  • State cybersecurity institutions: Some states have developed cyber police stations, security operations centres and incident response teams. However, the level of infrastructure, staffing and technical expertise varies across states, creating differences in their ability to investigate cybercrime and implement national cybersecurity measures. 
  • Sector-specific mechanisms: Banking, telecom, power and other important sectors also have their own cybersecurity requirements and response mechanisms. 
  • Law-enforcement institutions: Police cyber cells, state cybercrime branches and central agencies investigate cybercrimes, often with support from organisations such as I4C and CERT-In. 

Therefore, India’s institutional challenge is less about the complete absence of organisations and more about the coordination of institutions with different mandates, levels of authority and technical capacities. 

5. Institutional Gaps in India’s Cybersecurity Framework

The institutional gaps identified in this article are grouped into four categories: coordination gaps, capacity gaps, implementation gaps and cyber-resilience gaps. This classification helps distinguish between problems related to institutional relationships, available resources, execution of policies and the ability to withstand and recover from cyber incidents.

Coordination Gaps

  • Fragmented institutional responsibilities: Different organisations deal with different parts of cybersecurity. MeitY, MHA, NCSC, CERT-In, NCIIPC and sectoral regulators all have important roles. The existence of multiple institutions is not itself a weakness, but overlapping responsibilities can create coordination challenges if information and response mechanisms are not clearly defined.
  • Centre–State cybersecurity differences: Cybersecurity capacity is not the same across all states. Some states have dedicated cyber police stations and security operations centres, while others have more limited resources.

Since policing and public order are state subjects, state police agencies have an important role in cybercrime investigation. This means that national-level cybersecurity institutions cannot by themselves ensure uniform implementation across the country. Differences in trained personnel, cyber police stations, forensic laboratories, digital infrastructure and incident-response capacity can affect how quickly and effectively cyber incidents are investigated at the state level.

For example, a national cybercrime reporting or intelligence mechanism may identify a pattern of fraud, but investigation, evidence collection and prosecution often require action by state-level law-enforcement agencies. Differences in state capacity can therefore affect the final outcome of national cybercrime initiatives.

  • Information sharing: Threat intelligence sharing across agencies, states and sectors has improved through mechanisms such as CERT-In and I4C, but the extent to which information is shared consistently across all relevant agencies and sectors requires continued assessment. Evidence should therefore focus on documented coordination mechanisms, information-sharing arrangements and response exercises rather than simply stating that information sharing is “not systematic”.
  • Public-private coordination: A large part of India’s digital infrastructure is connected with private companies. Information sharing between government and private organisations has improved, but concerns about reputation, liability and confidentiality can still limit the sharing of cyber incident information.

Capacity Gaps

  • Shortage of specialised cybersecurity personnel: India faces a significant shortage of skilled cybersecurity professionals. A 2025-26 report by the Data Security Council of India and SANS Institute found that 73 per cent of enterprises and 68 per cent of service providers reported limited availability of qualified cybersecurity talent. This shortage affects the ability of organisations to recruit and retain specialised cybersecurity teams.
  • Cyber-forensics capacity: Cybercrime investigations require specialised tools, laboratories and trained personnel. Differences in the availability of forensic laboratories, trained investigators and technical experts across states can affect the speed and quality of cybercrime investigations. This issue should be assessed through available state-level data on cyber forensic facilities, staffing and training rather than treated as a uniform national condition.
  • MSME capacity: MSMEs may face difficulty investing in security tools, professional cybersecurity personnel and regular security assessments. This creates a capacity gap because national cybersecurity standards may be difficult for smaller organisations to implement without affordable technical support.

Implementation Gaps

  • Critical infrastructure protection: While NCIIPC conducts audits and issues guidelines, the number of audits or guidelines issued represents an institutional output and does not automatically demonstrate that vulnerabilities have been reduced. Evidence of improved protection should also consider remediation of identified vulnerabilities, compliance levels, security exercises and the ability of critical organisations to maintain services during incidents.
  • Incident response: While CERT-In and I4C have improved incident response, many organisations may still lack clear incident response plans. This should be assessed through indicators such as response time, reporting compliance, participation in cyber exercises and the ability to restore essential services after incidents.
  • Implementation of regulations: India has introduced several cybersecurity requirements and data-protection measures. The main challenge is increasingly moving from policy creation to consistent implementation across government departments, businesses and states. Smaller organisations may face greater constraints because of limited financial and technical resources.

Cyber-Resilience Gaps

  • Cyber resilience: Cybersecurity is not only about preventing an attack. Organisations also need to continue essential services and recover quickly after an incident. Backup systems, recovery plans and business continuity arrangements therefore need greater attention.

A resilient cybersecurity system should therefore be judged not only by whether attacks are prevented but also by how quickly organisations detect, contain, recover from and learn from incidents. This is particularly important for critical infrastructure and digital public services, where even a temporary disruption can affect large numbers of citizens.

These four categories show why the case for a new national strategy is not simply about creating another policy document. The more important requirement is to create a framework that connects national coordination with state capacity, implementation and resilience.

6. Performance 

India has made significant progress in cybersecurity since 2020, though challenges remain.

  • CERT-In: CERT-In has expanded its incident response and security assessment capacity. It handled more than 29.44 lakh cyber incidents in 2025, compared with 13.91 lakh in 2022 (PIB, 2025). It has empanelled 231 cybersecurity audit organisations and conducted nearly 10,000 audits in FY 2024-25 across critical sectors (Indian Republic, 2026). The Cyber Swachhta Kendra covers 98 per cent of the digital population for malware detection.
  • NCIIPC: NCIIPC has designated critical sectors, issued guidelines and carried out security assessments. These activities are important for improving the protection of critical information infrastructure. 
  • I4C: I4C has strengthened cybercrime response, with over 65.89 lakh financial fraud complaints reported from 2021 to 2025 and over ₹11,158 crore saved through real-time intervention (The 420, 2026). The 1930 helpline and NCRP have improved citizen reporting and response.
  • Cybersecurity regulations: India has strengthened cybersecurity requirements through regulations and guidelines covering government departments, telecom networks, critical sectors and service providers. These measures include requirements related to security monitoring, incident reporting, audits and protection of digital infrastructure. However, their effectiveness depends on consistent implementation and enforcement. 
  • Government cybersecurity guidelines: Government departments are required to follow security measures, conduct audits and report incidents. The Cyber Surakshit Bharat programme provides training and awareness for government officials.
  • Capacity building: Cybersecurity education and training have expanded through academic institutions, industry programmes and government initiatives. However, the shortage of skilled professionals remains a major challenge. 
  • Research and Development: Indian cybersecurity research and development has also grown, with companies and startups working on areas such as threat detection, encryption and secure communication. 
  • State-level initiatives: Several states have developed cyber police stations, security operations centres and training programmes. However, the level of preparedness remains different across states. 
  • Data protection: The Digital Personal Data Protection Act, 2023, and the DPDP Rules, 2025, have established a framework for protecting personal data and regulating data processing. The rules provide the implementation framework for different provisions of the Act. However, effective implementation and compliance will take time, making institutional capacity and enforcement important areas for attention. 
  • Critical infrastructure security: Security audits and guidelines have increased across critical sectors. However, continuous implementation and regular testing remain necessary. 

Overall, India’s cybersecurity performance shows considerable institutional progress, but available data are stronger on outputs than on outcomes. India can report the number of incidents handled, audits conducted, complaints received and people trained more easily than it can demonstrate the reduction in vulnerabilities, improvement in investigation outcomes or resilience of critical systems. This gap between measuring activity and measuring results is itself an important institutional issue. 

7. Impact 

The gaps in India’s cybersecurity system can affect several areas. 

  • National security: Weak coordination and limited capacity can make India more vulnerable to state-sponsored attacks, espionage and organised cybercrime. 
  • Critical infrastructure: A successful attack on power, banking, transport or health systems can disrupt essential services and create wider economic and social problems. 
  • Economic security: Cyberattacks on businesses, especially MSMEs, can cause financial losses, operational disruptions and reputational damage. The total reported cyber fraud losses exceeded ₹55,050 crore from 2021 to 2025 (PIB, 2025).
  • Financial systems: Banks and digital payment systems handle large amounts of money and sensitive information. Major cyber incidents can therefore affect both financial stability and public confidence. 
  • Digital public infrastructure: Attacks on Aadhaar, UPI, DigiLocker and other digital public infrastructure can affect millions of citizens and disrupt essential services.
  • Government services: Cyberattacks on government systems can compromise citizen data, disrupt services and undermine public trust.
  • Businesses and MSMEs: Smaller businesses may find it difficult to recover from a major cyberattack because of limited financial and technical resources. 
  • Citizens and personal data: Data breaches can expose personal information, leading to identity theft, fraud and privacy violations. The DPDP Rules, 2025, aim to strengthen data protection, but implementation will take time.
  • Defence and strategic systems: Cyberattacks against defence and strategic systems can create serious national security risks. 
  • Public trust: Repeated cyber incidents can reduce public trust in digital systems. This can affect the wider process of digital adoption. 

The impact is therefore closely connected to institutional capacity. For example, a cyber fraud mechanism may successfully identify and freeze suspicious transactions at an early stage, but effective investigation and prosecution may still depend on the capacity of state police and forensic agencies. Similarly, a critical infrastructure audit may identify a vulnerability, but the security outcome depends on whether the organisation has the resources and systems to correct it. 

These impacts show that cybersecurity is not only a technical issue. It is closely connected with national security, economic stability, public services and public trust. 

8. Emerging Cybersecurity Challenges:

Several emerging challenges require attention.

  • AI-enabled cyberattacks: Attackers can use AI to create convincing phishing content, automate activities and improve social engineering. India will need both skilled professionals and better technology to respond to these threats. 
  • Ransomware: Ransomware continues to pose a major risk to businesses, government agencies and critical sectors. The growth of ransomware-as-a-service has also made such attacks accessible to people with limited technical skills. 
  • Cloud security: As more organisations move their services and data to cloud platforms, securing cloud environments and controlling access become increasingly important. 
  • 5G and 6G: New generations of communication networks will connect more devices and services. Protecting the networks themselves, as well as the devices and applications that depend on them, will be important. 
  • IoT: The growing number of connected devices creates additional vulnerabilities. Many devices may have weak security and can be used as entry points for attacks. 
  • Supply chain security: India depends on global supply chains for much hardware, software and digital services. Security checks and better vendor management are therefore necessary.  
  • Digital public infrastructure: As digital public infrastructure expands, protecting these systems becomes increasingly important for national security and public trust. 
  • Quantum-related cybersecurity: Future quantum computing could create risks for some existing encryption systems. India therefore needs to prepare for post-quantum cryptography. 
  • Cross-border cybercrime: Cybercriminals can operate from outside India, making international cooperation important for investigation, prosecution and intelligence sharing. 
  • Cybersecurity workforce shortages: The shortage of skilled professionals remains a major constraint. Education, training and retention of cybersecurity personnel need greater attention. 

These emerging threats are not being presented here as separate institutional gaps. Rather, they explain why India’s cybersecurity framework needs to remain adaptable. The institutional gaps discussed earlier, particularly coordination, capacity, implementation and resilience, will determine how effectively India responds to these emerging risks. 

These challenges show that India needs a national approach that can respond not only to existing cyber threats but also to technologies and risks that are still developing. 

9. The Case for a New National Cyber Strategy:

The case for a new strategy does not arise simply because NCSS 2020 was not formally adopted. The stronger argument is that the cybersecurity environment and institutional architecture have changed significantly since the proposed strategy was developed, while several of the underlying problems, coordination, state capacity, implementation and resilience, continue to require attention. 

India now needs a new formally adopted national cyber strategy for several reasons.

  • Clear institutional responsibilities: The new strategy should clearly explain the roles of MeitY, MHA, NCSC, CERT-In, NCIIPC, sectoral regulators and state governments. This can reduce confusion and improve coordination. 
  • Centre–State coordination: The strategy should provide clear mechanisms for cooperation between the Centre and states, including training, resource sharing and joint exercises. 

Because policing and public order are state subjects, the new strategy should specifically establish a stronger centre–state mechanism for cybercrime investigation and capacity building. MHA, in coordination with state governments and relevant technical institutions, could publish minimum capacity standards for cyber police units, cyber-forensic facilities and trained personnel. 

  • Measurable national targets: A new strategy should not only list broad objectives. It should also set measurable targets for areas such as incident response, cybersecurity workforce, audits and critical infrastructure protection. 
  • Critical infrastructure protection: The strategy should strengthen critical infrastructure protection through mandatory audits, incident response plans and resilience requirements.
  • Supply-chain security: India needs better security assessments of important vendors and components, along with stronger vendor management and domestic capabilities where necessary. 
  • AI and emerging technology security: The strategy should address the cybersecurity implications of AI, 5G, IoT and other emerging technologies. 
  • Specialised cyber workforce: More investment is needed in cybersecurity education, training, certification and professional development. Retaining skilled professionals should also be part of the strategy. 
  • Public-private information sharing: Government and private companies should have trusted mechanisms for sharing information about cyber threats and incidents. 
  • Incident response and recovery: A national strategy should focus not only on preventing attacks but also on recovering quickly when attacks occur. 
  • Cybersecurity R&D: India needs continued investment in domestic cybersecurity research and technologies to reduce excessive dependence on foreign solutions. 
  • Cyber diplomacy: India should continue working with other countries on cyber norms, capacity building and intelligence sharing. 
  • Regular review and updating: Cyber threats and technologies change quickly. A new strategy should therefore be reviewed regularly rather than remaining unchanged for many years. 

A new strategy should also establish a clear system for monitoring outcomes rather than only activities. For example, annual reporting could cover incident response time, percentage of critical entities completing remediation after security audits, state-level cyber-forensics capacity, number of trained cyber investigators, recovery time for critical services and participation in national cyber exercises. 

A new national strategy will be useful only if it has clear implementation mechanisms, measurable targets and accountability. 

10. Way Forward:

Based on the above analysis, the following steps can strengthen India’s cybersecurity framework: 

  • Formal adoption of a new national cyber strategy: India should formally adopt a new national cyber strategy with clear objectives, institutional responsibilities, measurable targets and implementation mechanisms. It should build on the experience of NCSP 2013 and the proposed NCSS 2020. 

Responsibility: National Security Council Secretariat, MeitY, MHA and other relevant ministries and agencies.

Expected result: A formally adopted national framework that provides clear strategic direction and assigns responsibilities across institutions.

  • Clearer institutional coordination: A regular coordination mechanism involving MeitY, MHA, NCSC, CERT-In, NCIIPC, sectoral regulators and states can help identify gaps and coordinate responses. 

Responsibility: NCSC, with participation from MeitY, MHA, CERT-In, NCIIPC, sectoral regulators and state governments.

Possible indicator: Regular inter-agency coordination meetings, joint exercises and publication of an annual national cybersecurity coordination report.

  • Stronger Centre-State mechanisms: States should receive greater support for cybersecurity training, infrastructure, cyber police stations, incident response teams and security operations centres. 

Responsibility: MHA, state home departments, state police forces and relevant technical agencies.

Possible indicators: Number of trained cyber investigators, functional cyber-forensic facilities, cyber police capacity and state-level incident-response exercises.

  • Specialised cybersecurity workforce: Cybersecurity education, training and certification should be expanded through universities, industry partnerships and government programmes. Greater attention should also be given to retaining trained professionals. 

Possible indicator: Annual reporting of cybersecurity training capacity, vacancies in specialised government cybersecurity positions and number of trained personnel deployed at national and state levels. 

  • Critical infrastructure and supply-chain security: Critical infrastructure should have regular security audits, incident response plans and recovery mechanisms. Supply-chain risks should be addressed through security assessments, vendor management and domestic capabilities. 

Possible indicators: Audit coverage, percentage of identified vulnerabilities remediated within a defined period, completion of cyber exercises and recovery time for essential services. 

  • Measurable preparedness indicators: India should develop indicators for areas such as incident response time, audit coverage, workforce capacity and critical infrastructure preparedness. Progress should be reviewed regularly. 

The proposed indicators should distinguish between outputs and outcomes. For example, the number of audits is an output, while the percentage of vulnerabilities corrected after those audits is a more useful outcome indicator. Similarly, the number of cybercrime complaints received is an output, while investigation time, recovery of losses and prosecution outcomes provide stronger measures of effectiveness. 

  • Cyber resilience and recovery: Organisations should maintain backup systems, recovery plans and business continuity arrangements. Regular exercises can help identify weaknesses before a major cyber incident occurs. 

Critical infrastructure operators and government departments should conduct periodic recovery exercises and report recovery-time performance for essential services. 

These recommendations are practical and can be implemented within existing institutional frameworks, with additional resources and coordination.

11. Conclusion

India has developed a substantial cybersecurity system since NCSP 2013. Institutions such as CERT-In, NCIIPC, I4C and sector-specific mechanisms now play important roles in protecting India’s digital environment. The proposed NCSS 2020 also recognised that India needed a broader and more updated cybersecurity strategy, but it was not formally adopted.

Five years after the intended 2020-25 period, India’s digital environment has changed considerably. AI, cloud computing, 5G, IoT, digital payments and digital public infrastructure have expanded, while cyber threats have also become more complex.

India has made progress in incident response, cybercrime coordination, security audits and capacity building. However, gaps remain in institutional coordination, Centre–State capacity, skilled personnel, critical infrastructure protection, information sharing and implementation.

The assessment in this article suggests that India’s main challenge is no longer simply the absence of cybersecurity institutions. India has developed a substantial institutional architecture. The larger challenge is ensuring that these institutions work together effectively and have sufficient capacity at both national and state levels. This is particularly important because technical cyber incident response, cybercrime investigation, critical infrastructure protection and enforcement involve different institutions and levels of government.

The distinction between outputs and outcomes is also important. The number of audits, incidents handled, complaints received or people trained demonstrates institutional activity, but it does not by itself show whether vulnerabilities have been reduced, investigations have improved or critical services have become more resilient. A new national strategy should therefore focus on measurable outcomes as well as institutional outputs.

India therefore needs a new, formally adopted and regularly updated national cyber strategy. However, a new strategy document alone will not solve the problem. Its success will depend on stronger coordination between institutions, better centre-state cooperation, improved implementation capacity, adequate cybersecurity personnel, stronger critical infrastructure protection, accountability and greater cyber resilience.

The objective should not only be to prevent cyberattacks. India also needs the ability to detect attacks early, coordinate across institutions, investigate cybercrime effectively, continue essential services and recover quickly after an incident. A national strategy that connects these objectives with measurable targets and clear institutional responsibilities would provide a stronger foundation for India’s cybersecurity in the coming years.  

References

Aspirant Academy. (2026, February 21). 22495 Crore Lost — Investment Scams 76% of Losses. https://aspirant.academy/current-affairs/0d8c7f15-4cf5-4581-b0f8-aa41d33f30c2

Chambers. (2026, March 17). Cybersecurity 2026. https://practiceguides.chambers.com/practice-guides/comparison/1130/18600/29119-29120-29121-29122-29123-29124

Data Security Council of India & SANS Institute. (2026). India Cyber Security Skilling Landscape Report 2025–2026. https://www.sans.org/mlp/india-cyber-security-skilling-landscape-2025-2026

Drishti IAS. (2026, March 14). Shortage of Cybersecurity Talent in India. https://www.drishtiias.com/daily-updates/daily-news-analysis/shortage-of-cybersecurity-talent-in-india

Indian Express. (2026, May 1). India faces cybersecurity talent crunch as AI, cloud drive demand. https://indianexpress.com/article/technology/artificial-intelligence/india-cybersecurity-skills-gap-ai-demand-report-10665764/

Indian Republic. (2026, March 6). How India’s Cybersecurity Architecture Works. https://www.indianrepublic.in/2026/06/how-indias-cybersecurity-architecture-works.html

Ministry of Electronics and Information Technology. (2013, July 2). National Cyber Security Policy 2013. https://www.studocu.com/in/document/university-of-delhi/political-science/meity-notification-on-national-cyber-security-policy-july-2013/141210414

National Payments Corporation of India. (2025). UPI Transaction Statistics 2025. https://www.npci.org.in

National Security Council Secretariat. (2020). Proposed National Cyber Security Strategy 2020

Press Information Bureau. (2025, November 20). Assistance to States to Tackle Cyber Incidents https://www.pib.gov.in/PressReleasePage.aspx?PRID=2244504

Press Information Bureau. (2025, November 20). Over 9700 CERT-In Audits Conducted in 2024–25 https://www.pib.gov.in/PressReleasePage.aspx?PRID=2148943

Press Information Bureau. (2025, November 20). Digital Personal Data Protection (DPDP) Rules, 2025 https://www.pib.gov.in/PressReleasePage.aspx?PRID=2190655

The 420. (2026, July 22). National Cybercrime Mechanism Saves Over ₹11,158 Crore Across India. https://the420.in/india-cybercrime-data-i4c-lok-sabha-fraud-losses/

About the Contributor

Neha Kumari is a Research and Editorial Intern at IMPRI, currently pursuing an M.A. in Defence and Strategic Studies at the Central University of Gujarat. She holds an undergraduate degree in Social Management. Her research interests include geopolitics, national security, international relations, governance, and public policy. She is particularly interested in contemporary security challenges and India’s foreign policy, especially in the context of India’s evolving regional and global role.  

Acknowledgement

I would like to express my sincere gratitude to IMPRI for providing me the opportunity to prepare this article and for fostering a rigorous learning environment that connects research with public policy practice. I also extend my sincere thanks to Sruti Halder and Sneha Kohli for their valuable feedback. 

Reviewers: Gyathry Sanjay Balaram and Shivali Yadav

Publisher: Prisha Sachdeva

Disclaimer

All views expressed in the article belong solely to the author and do not necessarily represent the views or policies of the organisation.

Read More at IMPRI –  

PRADHAN MANTRI VIKSIT BHARAT ROZGAR YOJANA (PMVBRY): ONE YEAR OF EMPLOYMENT LINKED INCENTIVES UNDER MINISTRY OF LABOUR AND EMPLOYMENT

BRICS Education Cooperation under India’s 2026 Chairship: Priorities and Bhubaneswar Declaration, August 2026

Author

Talk to Us