Close Menu

    Sign Up for updates

    Get the latest news from QUATRO HIVE about law, policy, technology and innovation.

    By signing up, you agree to our terms and privacy policy agreement.

    Trending Now

    Pixels with a Price: Who Owns Your Images in the Age of AI Editing?

    October 29, 2025

    #SheInspires: Anurita Das, Co-Founder and CEO, Genovation Solutions

    October 24, 2025

    RBI issues draft norms to enable banks to fund acquisitions

    October 24, 2025
    Email WhatsApp LinkedIn Instagram Facebook
    LinkedIn Instagram Facebook
    Quatro Hive
    •  LOGIN
    SIGN UP
    • Experts Speak
      • #FinGurus
      • #NextStar
      • #SheInspires
      • #DesiDisruptors
      • #TheSpotlight
    • Dialogues
      • #CyberClout
      • #FinGurus
      • #NextStar
      • #SheInspires
      • #DesiDisruptors
      • #TheSpotlight
    • Directory
      • Tech Solution Providers
      • Universities
    • Resource Library
      • HiveBuzz
      • BuzzQ
      • Bulletin
    • News
      • Industry Updates
      • Media
    • Events & Partnerships
    • Sign Up
    • Login
    Quatro Hive
    Home » Government of India Taking Measures to Protect Critical Infrastructure and Private Data Against Cyber Attacks
    Bulletin

    Government of India Taking Measures to Protect Critical Infrastructure and Private Data Against Cyber Attacks

    March 28, 2025By QH Editorial Team
    Share
    Facebook Twitter LinkedIn WhatsApp

    Government of India is cognizant of the increasing frequency and sophistication of cyberattacks in the country. Government has taken several legal, technical, and administrative policy measures for addressing cyber security challenges in the country. The Government has also institutionalised a nationwide integrated and coordinated system to deal with cyber-attacks in the country which, inter alia, includes:

    1. National Cyber Security Coordinator (NCSC) under the National Security Council Secretariat (NSCS) to ensure coordination amongst different agencies.
    1. Under the provisions of section 70B of the Information Technology (IT) Act, 2000, the Indian Computer Emergency Response Team (CERT-In) is designated as the national agency for responding to cyber security incidents.
    2. National Cyber Coordination Centre (NCCC) implemented by the CERT-In serves as the control room to scan the cyberspace in the country and detect cyber security threats. NCCC facilitates coordination among different agencies by sharing with them the metadata from cyberspace for taking actions to mitigate cyber security threats.
    3. Cyber Swachhta Kendra (CSK) is a citizen-centric service provided by CERT-In, which extends the vision of Swachh Bharat to the Cyber Space. Cyber Swachhta Kendra is the Botnet Cleaning and Malware Analysis Centre and helps to detect malicious programs and provides free tools to remove the same. It also provides cyber security tips and best practices for citizens and organisations.
    4. Ministry of Home Affairs (MHA) has created Indian Cybercrime Coordination Centre (I4C) to deal with cybercrimes in a coordinated and effective manner.
    5. Under the provisions of section 70A of the IT Act, 2000, the Government has established National Critical Information Infrastructure Protection Centre (NCIIPC) for protection of critical information infrastructure in the country.

    As per the information reported to and tracked by CERT-In, the total number of cyber security incidents in the last three years are given below:

    Year

    Total number of cyber security incidents

    2022

    13,91,457

    2023

    15,92,917

    2024

    20,41,360

    The policies of the Government are aimed at ensuring an Open, Safe and Trusted and Accountable Internet for its users. National Cyber Security Policy (NCSP) was published by the Government with the vision of building a secure and resilient cyberspace for citizens, businesses and Government and a mission to protect information and information infrastructure in cyberspace, build capabilities to prevent and respond to cyber threats, reduce vulnerabilities and minimize damage from cyber incidents through a combination of institutional structures, people, processes, technology and cooperation.

    Government has taken following steps for protecting critical infrastructure and private data against cyber threats, which, inter-alia, includes:

    1. NCIIPC provides threat intelligence, situational awareness, alerts & advisories and information on vulnerabilities to organisations having Critical Information Infrastructures (CIIs)/ Protected Systems (PSs) for taking preventive measures against cyber-attacks and cyber terrorism. It also provides all cyber security related advice to these organisations, whenever asked for. Further, it follows up with concerned organisations for compliance of the IT (Information Security Practices & Procedures for Protected Systems) Rules, 2018 to improve their cyber security posture. It also organises training/awareness sessions for employees of entities having CIIs/PSs.
    2. The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information), 2011 (“SPDI Rules”) made under section 43A of the IT Act has prescribed reasonable security practices and procedures to protect sensitive personal data of users.
    3. The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (“IT Rules, 2021”) under the IT Act prescribes that the intermediary shall take all reasonable measures to secure its computer resource and information contained therein following the reasonable security practices and procedures as prescribed in the SPDI Rules.
    4. The Digital Personal Data Protection Act, 2023 (DPDPA) provides for the processing of digital personal data in a manner that recognizes both the rights of the individuals to protect their personal data and processing of personal data of individuals for lawful purposes by the Data Fiduciaries.
    5. CERT-In issued Cyber Security Directions in April 2022 under sub-section (6) of section 70B of Information Technology Act, 2000 relating to information security practices, procedure, prevention, response and reporting of cyber incidents for Safe & Trusted Internet.
    6. CERT-In issued guidelines on information security practices for government entities in June 2023 covering domains such as data security, network security, identity and access management, application security, third-party outsourcing, hardening procedures, security monitoring, incident management and security auditing.
    7. CERT-In has issued an advisory to various Ministries in November 2023 outlining the measures to be taken for strengthening the cyber security by all entities that are processing the digital personal data or information including sensitive personal data or information.
    8. CERT-In operates an automated cyber threat intelligence exchange platform for proactively collecting, analysing and sharing tailored alerts with organisations across sectors for proactive threat mitigation actions by them.
    9. CERT-In provides leadership for the Computer Security Incident Response Team-Finance Sector (CSIRT-Fin) operations under its umbrella for responding to and containing and mitigating cyber security incidents reported from the financial sector.
    10. CERT-In has formulated a Cyber Crisis Management Plan for countering cyber attacks and cyber terrorism for implementation by all Ministries/ Departments of Central Government, State Governments and their organizations and critical sectors.
    11. Cyber security mock drills are conducted regularly to enable assessment of cyber security posture and preparedness of organisations and enhance resilience in Government and critical sectors. 109 such drills have so far been conducted by CERT-In where 1438 organizations from different States and sectors participated.
    12. CERT-In has empanelled 200 security auditing organisations to support and audit implementation of Information Security Best Practices.
    13. CERT-In conducts regular training programmes for network and system administrators and Chief Information Security Officers of government and critical sector organisations regarding securing information technology infrastructure and mitigating cyber-attacks. A total of 12,014 officials have been trained in 23 training programs in 2024.
    14. CERT-In regularly conducts various activities for awareness and citizen sensitization with respect to cyber-attacks and cyber frauds.
    15. The Ministry of Electronics and Information Technology conducts programmes to generate information security awareness. Awareness material in the form of handbooks, short videos, posters, brochures, cartoon stories for children, advisories, etc. on various aspects of cyber hygiene & cyber security including deepfakes are disseminated through portals such as www.staysafeonline.in,www.infosecawareness.in and www.csk.gov.in.

    This information was given by the Union Minister of Railways, Information & Broadcasting and Electronics & Information Technology Shri Ashwini Vaishnaw in Rajya Sabha today.

    Know More

    Author

    • QH Editorial Team
      QH Editorial Team

      View all posts
    Resource Library

    Comments are closed.

    Share. Facebook Twitter LinkedIn WhatsApp

    Related Posts

    Bureau of Police Research and Development (BPR&D) concludes CCTV Surveillance Hackathon 2.0 to Strengthen Innovation in Law Enforcement and Digital Forensics

    September 30, 2025By QH Editorial Team

    BSNL’s Indigenous 4G stack embodies Swadeshi spirit

    September 28, 2025By QH Editorial Team

    CSIR-AMPRI designed & developed SODAR system facility inaugurated at IMD

    September 27, 2025By QH Editorial Team
    ads
    Experts Speak

    Pixels with a Price: Who Owns Your Images in the Age of AI Editing?

    October 29, 2025

    India’s Data Centre Policy Landscape : Balancing Incentives with Complexity

    October 27, 2025

    Power Plays: How the SCO Summit Could Transform BRICS’ Energy & Tech Leadership

    October 23, 2025

    From Farm to Fork: Can Agritech Solve India’s ₹1.5 Lakh Crore Food Waste Problem?

    October 15, 2025
    ads
    Stay In Touch
    • Twitch
    • WhatsApp
    • LinkedIn
    • Instagram
    • Facebook

    Quatro Hive is a media and knowledge platform built on four pillars which are law, policy, technology and innovation. In collaboration with key industry players, we are dedicated to cultivating a new era of innovation across industries.

    Address: D-65, Ground Floor, #ZBC-042, Defence Colony, New Delhi – 110024
    Email Us: reach@quatrohive.com
    Contact: +91 11 4121 2828, +91 9311 398 140

    Dribbble WhatsApp LinkedIn Instagram Facebook
    Quick Links
    • Experts Speak
    • Dialogues
    • Directory
    • HiveBuzz
    • BuzzQ
    • Bulletin
    • Industry Updates
    • Media
    • Events & Partnerships
    Newsletter

    Sign Up for updates

    Get the latest news from QUATRO HIVE about law, policy, technology and innovation.

    By signing up, you agree to our terms and privacy policy agreement.

    • Terms and Conditions
    • Privacy Policy
    © 2025 Quatro Hive.

    Type above and press Enter to search. Press Esc to cancel.

    Welcome Back!

    Login below or Register Now.

    Forgot Password?

    Register Now!

    Already registerd? Login.

    Lost your password? Please enter your username or email address. You will receive a link to create a new password via email.