·PIB·15 marks·250–350 words

Evaluate the institutional architecture of cyber incident response in India (CERT-In, sectoral CSIRTs) and identify gaps in coordination.

In this answer
  1. Strengths of the architecture
  2. Coordination gaps

India's cyber incident response rests on CERT-In, the national nodal agency under MeitY (Section 70B, IT Act 2000), supported by sector-specific CSIRTs such as CSIRT-Fin (finance) and CSIRT-Power [3]. The architecture has matured into a layered, partnership-driven model, yet coordination gaps limit its speed against machine-speed threats.

Strengths of the architecture

  • Statutory backbone and reach: CERT-In's mandate enables directions, audits and empanelment — over 9,700 audits across critical sectors in 2024–25, including 7,547 in BFSI, through 200 empanelled auditing organisations [3].
  • Sectoral specialisation: CSIRT-Fin delivers finance-domain incident response that a generalist body cannot, mirroring the CII-protection logic of NCIIPC [3].
  • Public-private partnership: The Digital Threat Report series — CERT-In, CSIRT-Fin and private firm SISA — pools forensic intelligence with regulatory oversight [2]; its second edition (July 2026) flags "AI asymmetry" and offers an 18-month resilience roadmap [1].
  • Capacity building: The CERT-In–SISA CSPAI, an ANAB-accredited AI security certification, addresses the skills deficit [4].

Coordination gaps

  • Threat-intelligence latency: Six of seven predictions from the 2024 edition materialised, as exploitation windows compressed from years to weeks — faster than advisory-driven response cycles [1].
  • Overlapping mandates: CERT-In, NCIIPC, sectoral CSIRTs and regulators like RBI issue parallel requirements, causing duplication and reporting fatigue for entities.
  • Uneven sectoral coverage: CSIRTs exist for finance and power, leaving health, telecom and logistics comparatively unshielded; audit volumes remain skewed towards BFSI [3].
  • Compliance-centric posture: Reliance on periodic audits rather than continuous risk assessment, with limited AI-aware detection capacity [1].

The architecture is institutionally sound but operationally fragmented — strong at the apex, thin at the seams. Extending the CSIRT model to all critical sectors, adopting real-time intelligence sharing, and implementing the report's 18-month roadmap under a unified national cyber coordination framework can convert this network into genuine resilience for India's digital economy.

Sources

  1. 1MeitY releases 2nd edition of the Digital Threat Report 2025-26 for India's BFSI Sector in Collaboration with SISA, PIBAI asymmetry, 18-month roadmap, 6 of 7 predictions materialised
  2. 2India launches first Digital Threat Report 2024 to support cybersecurity in the BFSI sector, PIBCERT-In–CSIRT-Fin–SISA public-private collaboration
  3. 3Government Strengthens Cybersecurity Across Critical Sectors; Over 9,700 CERT-In Audits Conducted in 2024–25, PIBaudit figures, empanelled auditors, sectoral CSIRTs (CSIRT-Fin, CSIRT-Power)
  4. 4CERT-In & SISA Launches First of its kind ANAB-Accredited AI Security Certification (CSPAI) Program, PIBCSPAI capacity-building initiative

More from this note