Policy Update
Vinita Sharma
Background
The modern international security context demands a reconsideration of the ideas and institutions that have traditionally governed statecraft and national security. Traditional security thinking focused primarily on state security, identifiable adversary states, military means, territorial defence, and deterrence. However, advances in information and communication technologies (ICT), artificial intelligence, computing, and precision weaponry have transformed conflict. Contemporary threats can originate from state and non-state actors, transcend territorial boundaries, and affect political, economic, and social spheres without conventional military force.
This transformation was reflected in the evolution of security studies after 1945, particularly following the end of the Cold War. Security expanded beyond defence and interstate warfare to include political, societal, economic, and non-military threats. As Buzan and Hansen (2009) explain, this represented a shift towards treating “security” rather than simply “defence” or “war” as the central object of study. The terrorist attacks of 11 September 2001 further demonstrated the capacity of decentralized and transnational non-state actors to generate significant security threats.
Cyberspace has consequently emerged as a domain of strategic competition. ICT has altered how states exercise power, conduct intelligence and surveillance, communicate during military operations, and influence or disrupt adversaries. This has contributed to “no contact war”, in which operations can be conducted remotely in the information domain. The IDSA Task Force Report (2012) noted that such operations are characterized by ambiguity and deniability, making attribution and response difficult. Cyberspace has also blurred the boundaries between war and peace, military and civilian targets, and state and non-state actors.
The consequences of cyber threats extend beyond cyberspace. Digital systems support banking, telecommunications, electricity, transportation, healthcare, government, and defence. Cyberattacks against such systems can disrupt critical services, cause economic losses, threaten national security and erode public trust. Cybersecurity has therefore evolved from a technical and law-enforcement concern into an important national security and strategic stability issue.
These developments are particularly relevant to India. The expansion of Digital India, digital public infrastructure, online financial services, telecommunications, and interconnected government systems has created developmental opportunities while increasing the country’s cyber-attack surface. As dependence on digital infrastructure grows, cyber incidents can affect economic activity, public services, critical infrastructure, and national security. This environment creates a need for national-level cyber monitoring, threat intelligence, and coordination, providing the broader strategic context for the establishment and development of the National Cyber Coordination Centre (NCCC) as part of India’s proactive cyber defence approach.
Evolution & Timeline
India has been evolving a multi-layered cybersecurity framework that includes institutions like the Indian Computer Emergency Response Team (CERT-In), National Critical Information Infrastructure Protection Centre (NCIIPC), National Cyber Security Coordinator (NCSC), Defence Cyber Agency (DCA), and Indian Cyber Crime Coordination Centre (I4C), acknowledging the evolving nature of these threats. The NCCC is an important initiative at the national level to enhance cyber situational awareness and coordination. The NCCC was conceptualized as part of India’s national cyber-security architecture, and Phase-I was operationalized in July 2017 as a platform for tracking cyber threats, analyzing the metadata of the traffic, sharing information, and coordinating responses to threats in India’s cyberspace.
The establishment of the NCCC marks a shift in the concept of national security, which was previously limited to the protection of a state’s territory and military assets, to the protection of the digital infrastructure, information systems, and interconnected networks on which modern states and societies rely.
This paper discusses the development, institutional structure, and functions of the NCCC; its role in the Indian cyber defence landscape; critical issues in cyber coordination, privacy, technological dynamics, and institutional interoperability; and recommends policy interventions to enhance India’s cyber resilience in the fast-changing digital landscape.
| Year | Major NCCC development |
| 2017 | Cyber Swachhta Kendra launched; NCCC Phase-I operationalised in July |
| 2018 | Government confirmed Phase I operationalization and continued development of national cyber situational awareness |
| 2020 | Director, NCCC, designated as an officer under the IT Act’s Section 69A blocking framework |
| 2022 | Government continued to identify Phase I as operational. |
| 2023 | The NCCC Phase-III traffic-flow project was approved in November |
| 2024 | NCCC expansion and cyber exercises continued; 99 exercises were conducted with about 1,260 organisations, according to MeitY. |
| 2025 | Parliamentary oversight focused on the progress of Phase II and Phase III |
| 2025 – 2026 | The government continued describing NCCC as an operational national cyber-monitoring and information-sharing mechanism. |
| 2026 | NCCC remains part of India’s integrated national cyber-security architecture. |
Functioning of the National Cyber Coordination Centre
The National Cyber Coordination Centre (NCCC) is a cyber situational awareness and coordination platform at the national level in India’s cyber-security architecture. CERT-In, under the Ministry of Electronics and Information Technology (MeitY), is responsible for monitoring cyberspace, alerting to any cyber threats, and disseminating actionable information to government agencies, state governments, and other stakeholders.
The NCCC takes a proactive stance towards cybersecurity by monitoring cyber activity and detecting trends and indicators that could signal a malicious or emerging threat. The government’s sources have also detailed the application of metadata in cyberspace for threat detection and mitigation. This will help the system to evolve from reacting to individual incidents to putting together a larger national picture of cyber threats. It functions in addition to other institutions like CERT-In, NCSC, NCIIPC, and I4C, with distinct roles. CERT-In is primarily responsible for cyber-incident response, NCIIPC for critical information infrastructure protection, and I4C for cybercrime, with NCSC being responsible for broader coordination. The NCCC will augment these institutions with national-level cyberspace monitoring and threat intelligence.
It operates on a general process of monitoring, analysis, information sharing, and mitigation. Any threats that are detected during monitoring are analyzed, and information collected by the NCCC is shared with relevant organizations to facilitate preventive or remedial action. However, the effectiveness of this process depends on both the timely detection of threats and the capacity of receiving organizations to respond swiftly and effectively.
The system is being expanded in phases: Phase II involves the integration of 250 sites, while Phase III involves the collection, storage, and analysis of traffic-flow data at Internet Service Provider (ISP) gateways.
Phase III was approved in November 2023 and is currently under implementation. The NCCC is also complemented by the NCCC’s broader work in cyber-security, such as vulnerability assessments, security audits, advisories and cyber-security exercises. A total of 99 cybersecurity exercises, involving approximately 1,260 organizations, were conducted in 2024-25 across a range of sectors, including defence, telecommunications, finance, power and transportation.
Therefore, NCCC’s operations are responding to a new trend in cyber defence, from reactive to proactive threat detection and coordinated prevention. But its efficacy ultimately relies on the coordination of institutions, timely sharing of information, and the ability of government and other private sector organizations to turn threat intelligence into mitigations.
Performance
A holistic overview of cyber-security outcomes achieved by MeitY and CERT-In can be used to evaluate the performance of the National Cyber Coordination Centre (NCCC), while no performance indicators are available with enough detail and granularity to evaluate NCCC-specific outcomes. In the past several years, the NCCC has helped boost cyber situational awareness, threat intelligence, and preparedness in critical sectors in India. An important measure is the growth of cyber-security preparedness and exercises.
In 2024-25, CERT-In organized 99 cyber-security exercises with approximately 1,260 organizations in various sectors, including defence, space, telecom, finance, power, oil and gas, transportation, and state data centres, according to the Annual Report, 2024-25, of the agency of the Ministry of Electronics and Information Technology. These drills allow institutions to simulate the response they would have to a potentially real incident and determine vulnerabilities before they are faced with an actual attack.
CERT-In’s threat-intelligence function is also a sign of the evolving role of the cyber-security ecosystem in India. In 2024, CERT-In published 959 alerts, 72 advisories, and 360 vulnerability notes that shared information on emerging vulnerabilities and threats to organizations. The National Cyber Coordination Centre (NCCC) supports these activities with a national perspective on cyber threats.
The cyber-security incidents reported to CERT-In have also seen a significant rise, with the number of reports rising from 13.91 lakh in 2022 to 29.44 lakh in 2025. The increase cannot be taken as an indication of failure on the part of the NCCC, as improved monitoring, detection, and reporting can also lead to increased counts. It does, however, illustrate the rapid growth of the threat landscape in which the NCCC works.
A continuing increase in the activities of the NCCC has also been noted by the Parliamentary Committee on Communications and Information Technology. The investment in national cyber-monitoring capabilities continues, at least, with the integration of 250 sites (Phase II) and the collection and analysis of traffic-flow data from ISP gateways (Phase III). The NCCC has overall performed well in improving cyber situational awareness, coordination, and preparedness as an institution.
Its ultimate performance is more difficult to measure, however, because there are no specific metrics in publicly available government documents that measure the number of threats detected by the NCCC, threat response time, vulnerabilities mitigated, or attacks prevented as a direct result of NCCC interventions. Therefore, the biggest shortfall is that there is no clear outcome-based evaluation framework. Assessments need to be conducted in the future to gauge the volume of threats detected, as well as the effectiveness of NCCC intelligence in translating to timely mitigation and cyber resilience.
Impact
The National Cyber Coordination Centre (NCCC) has strengthened India’s cybersecurity framework by supporting national-level monitoring of cyberspace, threat detection, and information sharing. Established under CERT-In, the NCCC functions as a coordination mechanism involving agencies such as the Telecom Security Operations Centre (TSOC), the Indian Cybercrime Coordination Centre (I4C), and the National Critical Information Infrastructure Protection Centre (NCIIPC).
Through this coordination, the NCCC assists in identifying threats and facilitating prompt preventive or remedial action by concerned agencies and state governments. The government has stated that the NCCC, along with other agencies, successfully prevented cyberattacks during the G20 Summit and other major events (Ministry of Electronics and Information Technology [MeitY], 2025).
The NCCC’s impact is also reflected in the expansion of India’s national cyber-monitoring network. Phase II aims to integrate 250 sites, and the Ministry has indicated that 92 per cent of these sites will have been integrated by June 2025. Phase III involves the collection, storage and analysis of traffic-flow data at Internet Service Provider (ISP) gateways. This phase was approved in November 2023 and is currently being implemented.
However, the NCCC’s direct impact remains difficult to measure because no publicly available government data clearly identifies the number of attacks prevented or losses avoided as a direct result of its interventions. Its most visible contribution has therefore been institutional and capability-based: enhancing national cyber situational awareness, threat intelligence and coordination. Consequently, its effectiveness should not be assessed only through the number of cyberattacks prevented but also through improvements in information-sharing, early warning, inter-agency coordination and response capacity.
Privacy, Metadata and Accountability
Because the NCCC involves the analysis of traffic-flow information and metadata, privacy and accountability require particular consideration. Although metadata generally does not reveal the full content of communications, it may disclose sensitive information about individuals, organizations, and patterns of activity. Such information can indicate who communicates with whom, when and how frequently, as well as which digital services or networks are being accessed.
The collection and retention of metadata should therefore follow the principles of necessity, proportionality and data minimization. Information should be collected only for clearly defined cybersecurity purposes, retained for no longer than necessary, and accessed only by authorized personnel. Appropriate safeguards should include encryption, role-based access controls, audit trails, regular security assessments, and procedures for addressing misuse or unauthorized disclosure.
The NCCC’s impact should consequently be evaluated through two connected dimensions. The first is its security function, including the improvement of cyber situational awareness, threat intelligence, and coordination among relevant agencies. The second is its governance function, which requires expanded monitoring to be conducted lawfully, responsibly, and with adequate protection for privacy. A system that detects threats effectively but lacks sufficient safeguards could create new security and civil-liberties risks while attempting to address existing ones. Public trust and institutional accountability are therefore essential to the long-term legitimacy of the NCCC.
Emerging Challenges
- The first major challenge is the measurement of outcomes. The government is reporting cyber incidents, alerts, and advisories, as well as the expansion of infrastructure, while there is limited public information on indicators that are related to NCCCs, including detection time, response time, and successful mitigation.
- India’s burgeoning cyber-security architecture, comprising NCCC, CERT-In, NCSC, NCIIPC, I4C and other specialized bodies, must be made more interoperable, and the coordination mechanisms defined. The success of the NCCC hinges on the speed at which intelligence is shared between and delivered to these institutions and organizations with the capability of acting.
- Technology is changing so quickly that new challenges have emerged. The availability of new technologies and tools, supply chain attacks and threats, and the constant changes in AI-powered attacks and deepfakes necessitate constant upgrades to national cyber monitoring capabilities.
- As network and metadata are becoming more commonplace in cyber threat detection, there are privacy, data governance and accountability concerns to consider. Meanwhile, the lack of cyber-security capacity in certain states and organizations may lead to misalignment between the national-level threat assessment and real mitigation. The overall challenge to the NCCC is thus to move away from threat detection to timely, measurable and coordinated action when a threat is detected.
Way Forward
The future of the National Cyber Coordination Centre (NCCC) should focus on converting its existing monitoring and coordination capabilities into measurable improvements in cyber resilience. The Parliamentary Committee has already highlighted delays in site integration and recommended the use of emerging technologies such as AI to improve implementation.
- Complete NCCC Phase-II and Phase-III Integration: The government should complete the remaining NCCC Phase-II integrations and accelerate Phase III. The latest Parliamentary material records that 92% of the targeted 250 Phase-II sites had been integrated, while Phase III involves the collection, storage, and analysis of traffic-flow data from ISP gateways. Timely completion should remain a priority, with clear milestones and regular monitoring of implementation.
- Expand AI and Advanced Analytics: The NCCC should increasingly adopt AI and advanced analytics for anomaly detection, threat classification, and predictive cyber intelligence. This would help the system respond to increasingly sophisticated threats while also addressing some of the implementation and monitoring challenges identified by the Parliamentary Committee.
- Strengthen Inter-Agency Interoperability: Greater interoperability between NCCC, CERT-In, NCSC, NCIIPC, I4C, state authorities, and critical-sector organizations is required. The objective should be to create a seamless chain from threat detection and analysis to information sharing, mitigation, and feedback.
- Introduce Outcome-Based Performance Indicators: The government should introduce an outcome-based performance framework for the NCCC. Instead of measuring only infrastructure created or threats identified, indicators such as detection time, alert dissemination time, response rate, and vulnerabilities mitigated could be used. This would make the Centre’s contribution to national cyber resilience more measurable while protecting sensitive operational information.
- Build State-Level and Sectoral Cyber Capacity: The NCCC should strengthen state-level and sectoral cyber capacity. National threat intelligence is useful only when the receiving organization has the technical capability and resources to act upon it. Greater training, cyber exercises, and standardized incident-response protocols can help bridge this gap
- Strengthen Privacy and Data-Governance Safeguards: Finally, the expansion of cyber-monitoring capabilities should be accompanied by strong privacy, data governance, and accountability safeguards. As the NCCC’s analytical capabilities grow, maintaining public trust will be essential for India’s wider digitalization agenda.
Overall, the next phase of the NCCC should move from expanding infrastructure to improving outcomes – using advanced technology, stronger institutional coordination, timely implementation and measurable performance standards to build a more resilient and trusted digital ecosystem for India.
References
CERT-In. (2025). Annual report 2024–25. Indian Computer Emergency Response Team, Ministry of Electronics and Information Technology, Government of India. https://www.meity.gov.in/static/uploads/2024/12/10fcadec462c330211502fed3d24ea83.pdf
Ministry of Electronics and Information Technology. (2023). Annual report 2022–23. Government of India. https://www.meity.gov.in/static/uploads/2024/02/AR_2022-23_English_24-04-23-1.pdf
Buzan, B., & Hansen, L. (2009). The evolution of international security studies. Cambridge University Press. https://www.cambridge.org/core/books/the-evolution-of-international-security-studies/BB04557E83B673F58799E2B62FA83DA1?utm
India’s cybersecurity challenge: IDSA task force report. Institute for Defence Studies and Analyses. https://www.idsa.in/system/files/book_indiacybersecurity.pdf?utm
Ministry of Electronics and Information Technology. (n.d.). National Cyber Coordination Centre (NCCC). Government of India. Retrieved August 24, 2026, from https://www.meity.gov.in/content/national-cyber-coordination-centre-nccc
Ministry of Electronics and Information Technology. (2000). The Information Technology Act, 2000 (Act No. 21 of 2000). Government of India. https://www.indiacode.nic.in/bitstream/123456789/13116/1/it_act_2000_updated.pdf
Ministry of Electronics and Information Technology. (2009). Information Technology (Procedure and Safeguards for Blocking for Access of Information by Public) Rules, 2009. Government of India. https://www.indiacode.nic.in/
National Critical Information Infrastructure Protection Centre. (n.d.). About NCIIPC. Government of India. Retrieved August 24, 2026, from https://nciipc.gov.in/
Indian Computer Emergency Response Team. (n.d.). Advisories and vulnerability notes. Ministry of Electronics and Information Technology, Government of India. Retrieved August 24, 2026, from https://www.cert-in.org.in/
Indian Computer Emergency Response Team. (2025). Digital threat report 2024 for the BFSI sector. Ministry of Electronics and Information Technology, Government of India. https://www.cert-in.org.in/s2cMainServlet?pageid=PUBADV01&CACODE=CICA-2025-3388
Ministry of Home Affairs. (n.d.). Indian Cyber Crime Coordination Centre (I4C). Government of India. Retrieved August 24, 2026, from https://i4c.mha.gov.in/
Ministry of Defence. (n.d.). Defence Cyber Agency. Government of India. Retrieved August 24, 2026, from https://mod.gov.in/
About the author
Vinita Sharma is a Research & Editorial Intern at IMPRI. She is currently pursuing a master’s degree in Defence & Strategic Studies at Central University of Gujarat, Vadodara. Her research interests include national security, defence studies, international relations, and geopolitics.
Acknowledgement
The author extends sincere gratitude to the reviewers, Kavin and Tanisha, and the IMPRI India team for their valuable guidance, support, and review of this Policy Update
Publisher: Neha Kumari
Disclaimer
All views expressed in the article belong solely to the author and not necessarily to the organization.




