·The Hindu·15 marks·250–350 wordsPolityS&T

The conflict between institutional denial and public accountability was evident in the CBSE data-breach episode. Analyse how India's e-governance framework can be strengthened to ensure data security and transparent breach disclosure.

In this answer
  1. Anatomy of the denial–accountability conflict
  2. Strengthening the e-governance framework

CERT-In's 2022 Directions oblige an entity to report a cyber incident within six hours of noticing it [1]. The 2026 CBSE On-Screen Marking portal episode — a flaw flagged in February, denied, and admitted only after public disclosure in May — shows how institutional denial hollows out this accountability design.

Anatomy of the denial–accountability conflict

  • Disclosure gap: the researcher reported to CERT-In in February 2026, yet CBSE conceded flaws only in June after social-media amplification — reputational self-protection overrode the duty to warn students and evaluators [2].
  • Silo failure: CBSE answers to the Ministry of Education while CERT-In, the nodal agency under Section 70B, IT Act, 2000, sits under MeitY [3] — no single accountability line for a sectoral portal holding millions of students' marks and PII.
  • Reactive remediation: IIT Madras and IIT Kanpur teams camped at CBSE headquarters for a fortnight to patch flaws [2]; expertise arrived after exposure, not by design.
  • Legal chill: Section 66 penalises unauthorised access [4]; absent a safe harbour, good-faith researchers risk prosecution for reporting.

Strengthening the e-governance framework

  • A statutory Coordinated Vulnerability Disclosure policy with safe harbour and government bug-bounty programmes, converting researchers into an early-warning layer.
  • Strict enforcement of CERT-In's six-hour reporting and audit obligations across public bodies [1], with published remediation timelines.
  • Operationalising the DPDP Act, 2023 and Rules — mandatory intimation to affected data principals and a heightened duty of care for children's data [5].
  • Security-by-design procurement: pre-deployment audits by CERT-In-empanelled auditors and cloud configuration baselines, since the exposure arose from a misconfigured cloud storage bucket [3].

Cyber resilience is finally cultural, not merely technical: the JEE (Advanced) precedent of prompt admission and repair shows the better path [2]. Institutionalising disclosure, safe harbour and audited security-by-design would align e-governance with the informational privacy guaranteed in Puttaswamy, making transparency the default rather than the last resort.

Sources

  1. 1CERT-In Directions under Section 70B(6), IT Act, 2000 (28 April 2022)six-hour incident-reporting mandate and audit obligations
  2. 2The Hindu, "CBSE invited ethical hacker to plug security gaps in IT system" (June 2026)CBSE's denial and reversal, IIT Madras–Kanpur remediation team, JEE (Advanced) contrast
  3. 3PIB, "CERT-In: India's Frontline Defender against Cyber Threats"CERT-In's Section 70B mandate under MeitY; national incident-response and audit architecture
  4. 4The Information Technology Act, 2000 (updated), Section 66criminal liability for unauthorised computer access
  5. 5Digital Personal Data Protection Act, 2023, MeitYbreach-notification duty and protection of children's personal data
Practice
4 questions on this article
Check the answer for each question, or reveal all at once.
Practice MCQs →

More from this note

More on Polity