Evaluate the institutional architecture of cyber incident response in India (CERT-In, sectoral CSIRTs) and identify gaps in coordination.

Q. Evaluate the institutional architecture of cyber incident response in India (CERT-In, sectoral CSIRTs) and identify gaps in coordination. (15 marks, 250-350 words)

India's cyber incident response rests on CERT-In, the national nodal agency under MeitY (Section 70B, IT Act 2000), supported by sector-specific CSIRTs such as CSIRT-Fin (finance) and CSIRT-Power [3]. The architecture has matured into a layered, partnership-driven model, yet coordination gaps limit its speed against machine-speed threats.

Strengths of the architecture - Statutory backbone and reach: CERT-In's mandate enables directions, audits and empanelment — over 9,700 audits across critical sectors in 2024–25, including 7,547 in BFSI, through 200 empanelled auditing organisations [3]. - Sectoral specialisation: CSIRT-Fin delivers finance-domain incident response that a generalist body cannot, mirroring the CII-protection logic of NCIIPC [3]. - Public-private partnership: The Digital Threat Report series — CERT-In, CSIRT-Fin and private firm SISA — pools forensic intelligence with regulatory oversight [2]; its second edition (July 2026) flags "AI asymmetry" and offers an 18-month resilience roadmap [1]. - Capacity building: The CERT-In–SISA CSPAI, an ANAB-accredited AI security certification, addresses the skills deficit [4].

Coordination gaps - Threat-intelligence latency: Six of seven predictions from the 2024 edition materialised, as exploitation windows compressed from years to weeks — faster than advisory-driven response cycles [1]. - Overlapping mandates: CERT-In, NCIIPC, sectoral CSIRTs and regulators like RBI issue parallel requirements, causing duplication and reporting fatigue for entities. - Uneven sectoral coverage: CSIRTs exist for finance and power, leaving health, telecom and logistics comparatively unshielded; audit volumes remain skewed towards BFSI [3]. - Compliance-centric posture: Reliance on periodic audits rather than continuous risk assessment, with limited AI-aware detection capacity [1].

The architecture is institutionally sound but operationally fragmented — strong at the apex, thin at the seams. Extending the CSIRT model to all critical sectors, adopting real-time intelligence sharing, and implementing the report's 18-month roadmap under a unified national cyber coordination framework can convert this network into genuine resilience for India's digital economy.

(~320 words)

Sources: 1. MeitY releases 2nd edition of the Digital Threat Report 2025-26 for India's BFSI Sector in Collaboration with SISA, PIB — AI asymmetry, 18-month roadmap, 6 of 7 predictions materialised 2. India launches first Digital Threat Report 2024 to support cybersecurity in the BFSI sector, PIB — CERT-In–CSIRT-Fin–SISA public-private collaboration 3. Government Strengthens Cybersecurity Across Critical Sectors; Over 9,700 CERT-In Audits Conducted in 2024–25, PIB — audit figures, empanelled auditors, sectoral CSIRTs (CSIRT-Fin, CSIRT-Power) 4. CERT-In & SISA Launches First of its kind ANAB-Accredited AI Security Certification (CSPAI) Program, PIB — CSPAI capacity-building initiative