The CBSE ethical-hacking episode of 2026 highlights the absence of a Coordinated Vulnerability Disclosure framework in India. Critically examine India's cybersecurity governance architecture and suggest reforms.
Q. The CBSE ethical-hacking episode of 2026 highlights the absence of a Coordinated Vulnerability Disclosure framework in India. Critically examine India's cybersecurity governance architecture and suggest reforms. (15 marks, 250-350 words)
A 19-year-old researcher reported critical flaws in CBSE's On-Screen Marking portal to CERT-In in February 2026, saw no remedial action for three months, and was invited to help patch the system only after public disclosure [4]. The episode reveals an architecture that is institutionally dense but procedurally reactive.
Strengths of the existing architecture - Statutory nodal agency: CERT-In, designated under Section 70B, IT Act, 2000, handles incident response, alerts and vulnerability notes at national scale [1][2]. - Layered institutions: NCIIPC for critical information infrastructure, the National Cyber Security Coordinator under NSCS for inter-agency coordination, and I4C under MHA for cybercrime [2]. - Tightened compliance: CERT-In's 2022 Directions under Section 70B(6) mandate reporting incidents within six hours of detection [3]. - Deep domestic talent pool: IIT Madras and IIT Kanpur teams were mobilised to remediate CBSE's systems [4].
Critical gaps exposed - No Coordinated Vulnerability Disclosure (CVD) framework: good-faith researchers risk prosecution for unauthorised access under Section 66, IT Act, inverting the incentive to report quietly rather than exploit or stay silent. - Reporting without remediation: mandates cover disclosure to CERT-In, but no enforceable timeline binds the affected entity to fix or notify users. - Denial-first institutional culture: CBSE initially denied any breach before reversing course [4] — a governance failure of transparency, not technology. - Weak security-by-design: sectoral bodies digitising sensitive data lack in-house security capacity, secure cloud-configuration baselines and independent audits.
India therefore possesses the institutions but not the processes of cyber resilience. Reform should proceed on four tracks: a statutory CVD policy with safe harbour and government bug-bounty programmes; time-bound remediation and user-notification obligations alongside operationalised DPDP rules; mandatory CISOs and third-party security audits for public data fiduciaries; and a standing MeitY–line ministry coordination protocol. Treating researchers as partners rather than suspects would align e-governance with the privacy guarantee recognised in K.S. Puttaswamy, making digital India both inclusive and trustworthy.
(~330 words)
Sources: 1. CERT-In: India's Frontline Defender against Cyber Threats — PIB, Jan 2026 — CERT-In's Section 70B mandate and national incident-response capacity 2. Government of India Taking Measures to Protect Critical Infrastructure and Private Data Against Cyber Attacks — PIB — NCIIPC, NCSC and I4C as the layered institutional architecture 3. Indian Computer Emergency Response Team (CERT-In), official website — 2022 Directions under Section 70B(6) mandating six-hour incident reporting 4. "CBSE invited ethical hacker to plug security gaps in IT system" — The Hindu, June 2026 (URL not verifiable at time of writing) — disclosure timeline, CBSE's initial denial, and IIT expert-team remediation