·The Hindu·15 marks·250–350 wordsPolityS&T

The CBSE ethical-hacking episode of 2026 highlights the absence of a Coordinated Vulnerability Disclosure framework in India. Critically examine India's cybersecurity governance architecture and suggest reforms.

In this answer
  1. Strengths of the existing architecture
  2. Critical gaps exposed

A 19-year-old researcher reported critical flaws in CBSE's On-Screen Marking portal to CERT-In in February 2026, saw no remedial action for three months, and was invited to help patch the system only after public disclosure [4]. The episode reveals an architecture that is institutionally dense but procedurally reactive.

Strengths of the existing architecture

  • Statutory nodal agency: CERT-In, designated under Section 70B, IT Act, 2000, handles incident response, alerts and vulnerability notes at national scale [1][2].
  • Layered institutions: NCIIPC for critical information infrastructure, the National Cyber Security Coordinator under NSCS for inter-agency coordination, and I4C under MHA for cybercrime [2].
  • Tightened compliance: CERT-In's 2022 Directions under Section 70B(6) mandate reporting incidents within six hours of detection [3].
  • Deep domestic talent pool: IIT Madras and IIT Kanpur teams were mobilised to remediate CBSE's systems [4].

Critical gaps exposed

  • No Coordinated Vulnerability Disclosure (CVD) framework: good-faith researchers risk prosecution for unauthorised access under Section 66, IT Act, inverting the incentive to report quietly rather than exploit or stay silent.
  • Reporting without remediation: mandates cover disclosure to CERT-In, but no enforceable timeline binds the affected entity to fix or notify users.
  • Denial-first institutional culture: CBSE initially denied any breach before reversing course [4] — a governance failure of transparency, not technology.
  • Weak security-by-design: sectoral bodies digitising sensitive data lack in-house security capacity, secure cloud-configuration baselines and independent audits.

India therefore possesses the institutions but not the processes of cyber resilience. Reform should proceed on four tracks: a statutory CVD policy with safe harbour and government bug-bounty programmes; time-bound remediation and user-notification obligations alongside operationalised DPDP rules; mandatory CISOs and third-party security audits for public data fiduciaries; and a standing MeitY–line ministry coordination protocol. Treating researchers as partners rather than suspects would align e-governance with the privacy guarantee recognised in K.S. Puttaswamy, making digital India both inclusive and trustworthy.

Sources

  1. 1CERT-In: India's Frontline Defender against Cyber Threats — PIB, Jan 2026CERT-In's Section 70B mandate and national incident-response capacity
  2. 2Government of India Taking Measures to Protect Critical Infrastructure and Private Data Against Cyber Attacks — PIBNCIIPC, NCSC and I4C as the layered institutional architecture
  3. 3Indian Computer Emergency Response Team (CERT-In), official website2022 Directions under Section 70B(6) mandating six-hour incident reporting
  4. 4"CBSE invited ethical hacker to plug security gaps in IT system" — *The Hindu*, June 2026 (URL not verifiable at time of writing) — disclosure timeline, CBSE's initial denial, and IIT expert-team remediation
Practice
4 questions on this article
Check the answer for each question, or reveal all at once.
Practice MCQs →

More from this note

More on Polity