·PIB

ASSISTANCE TO STATES TO TACKLE CYBER INCIDENTS

In this note
  1. At a Glance
  2. Why in the News
  3. Background & Evolution
  4. Core Static Facts
  5. Multi-Dimensional Analysis
  6. Recent Developments (last 12-18 months)
  7. Prelims Hooks
  8. Mains Relevance
  9. Related Topics to Study Next
  10. Common Errors / Trap Areas

1. At a Glance

  • CERT-In (Indian Computer Emergency Response Team) is the national nodal agency for responding to cyber security incidents under Section 70B of the IT Act, 2000 [1][2].
  • Topic covers the central government's mechanism to handhold States/UTs — alerts, threat intelligence, capacity building and financial aid — in a domain where "Police" and "Public Order" are State subjects but cyberspace is borderless [1].
  • Cyber incidents have more than doubled in 5 years — from 14.02 lakh (2021) to 29.44 lakh (2025) — making this a high-yield GS-III internal security topic [1].

2. Why in the News

  • Lok Sabha reply by Ministry of Home Affairs (MHA) on 24 March 2026 disclosed five-year cyber incident data and listed CERT-In's assistance measures to States/UTs [1].
  • NCT of Delhi recorded the highest number of reported cyber incidents in the period [1].

3. Background & Evolution

  • IT Act, 2000 enacted; Section 70B inserted by the IT (Amendment) Act, 2008, formally designating CERT-In [1][2].
  • CERT-In operational since 2004 under MeitY [2].
  • Cyber Swachhta Kendra (CSK) — Botnet Cleaning & Malware Analysis Centre — launched 2017 under the Digital India programme [2].
  • National Cyber Coordination Centre (NCCC) operationalised in phases by CERT-In for real-time threat scanning [2].
  • I4C (Indian Cyber Crime Coordination Centre) under MHA established 2018; National Cyber Crime Reporting Portal (cybercrime.gov.in) launched 2019 (parallel MHA track for citizen-level crimes) [2].

4. Core Static Facts

  • Nodal agency for cyber incidents: CERT-In [1].
  • Parent ministry: Ministry of Electronics & Information Technology (MeitY) — NOT MHA [2].
  • Statutory basis: Section 70B, IT Act 2000 [1].
  • Mandatory incident reporting: CERT-In Directions of 28 April 2022 require reporting of specified cyber incidents within 6 hours [3].
  • Year-wise cyber security incidents tracked by CERT-In [1]:
  • 2021 — 14,02,809
  • 2022 — 13,91,457
  • 2023 — 15,92,917
  • 2024 — 20,41,360
  • 2025 — 29,44,248

  • Highest reporting region: NCT of Delhi [1].

  • Financial loss data: NOT maintained by CERT-In [1].

Assistance instruments to States/UTs [2]:

  • Alerts/advisories on threats and vulnerabilities.
  • NCCC — scans cyberspace, shares threat intel with States and sectoral agencies.
  • Automated cyber threat exchange platform for tailored alerts.
  • Cyber Swachhta Kendra (CSK) — detects malware/botnets and offers free clean-up tools.
  • Joint training programmes with industry to upskill Government (Central + State), public & private workforce.
  • Financial assistance to States/UTs for LEA capacity building under various schemes.

5. Multi-Dimensional Analysis

Administrative / Federal

  • "Police" & "Public Order" are State List (List II, Entries 1 & 2) subjects; cyber crime investigation rests with State police — Centre's role is supplementary via advisories, tools, training and grants [1][2].
  • Coordination gap: CERT-In (MeitY) handles incidents; I4C (MHA) handles cyber crime — aspirants must distinguish the two silos [2].

Legal / Constitutional

  • Statutory umbrella: IT Act 2000 + IT (CERT-In) Rules 2013; Section 70B(6) empowers CERT-In to call for information and give directions [1].
  • April 2022 Directions mandated 6-hour reporting, 180-day log retention, KYC by VPN/VPS providers [3].

Scientific / Technological

  • NCCC acts as the operational cyber situational-awareness backbone [2].
  • CSK provides free bot-removal tools (e.g., USB Pratirodh, AppSamvid, M-Kavach) for end-users [2].

Economic / Sectoral

  • Financial sector flagged as high-risk; CERT-In–Mastercard MoU (2024) targets financial-sector cyber resilience [4].
  • Loss-data vacuum (CERT-In doesn't maintain financial-loss figures) handicaps cost-benefit policy assessment [1].

Strategic / Security

  • Surge from 14 lakh → 29 lakh incidents in five years signals expanding attack surface (UPI, IoT, critical infra) [1].
  • Sectoral CERTs (CERT-Fin under RBI, NCIIPC under NTRO for Critical Information Infrastructure u/s 70A) complement CERT-In [2].

6. Recent Developments (last 12-18 months)

  • 24 Mar 2026 — MHA tabled five-year incident data and States-assistance framework in Parliament [1].
  • Jan 2026 — PIB feature "CERT-In: India's Frontline Defender against Cyber Threats" published [5].
  • 2024CERT-In–Mastercard India MoU signed for financial-sector cyber collaboration [4].
  • Feb–Mar 2025 — PIB releases on government measures to strengthen cyber preparedness and protect critical infrastructure [6][7].
  • Mar 2025 — CERT-In released "Cyber Security Handbook for Mahila Suraksha" on International Women's Day [8].

7. Prelims Hooks

  • CERT-In is the national agency for cyber incident response under Section 70B, IT Act 2000 [1].
  • CERT-In functions under MeitY, not MHA [2].
  • NCCC is implemented by CERT-In (not by NTRO or MHA) [2].
  • NCIIPC (Critical Information Infrastructure protection) operates under Section 70A, IT Act — distinct from CERT-In's 70B mandate [2].
  • Cyber incidents reported in 2025: 29,44,248; 2024: 20,41,360 [1].
  • Highest cyber incident reporting region: NCT of Delhi [1].
  • Cyber Swachhta Kendra = Botnet Cleaning and Malware Analysis Centre, launched 2017 [2].
  • CERT-In Directions of 28 April 2022 mandate cyber incident reporting within 6 hours [3].
  • I4C is under MHA, whereas CERT-In is under MeitY [2].
  • CERT-In does NOT maintain estimated financial loss data [1].
  • National Cyber Crime Reporting Portal = cybercrime.gov.in under MHA/I4C [2].
  • CERT-In–Mastercard MoU (2024) targets financial sector resilience [4].

8. Mains Relevance

  • GS-III — Internal Security: "Basics of cyber security; role of media and social networking sites… Money-laundering and its prevention."
  • GS-II — Governance: Centre-State coordination on a Concurrent/State-subject overlap.
  • Probable question stems: 1. "Cyber crime is local but cyber threat is national." Examine the institutional architecture for Centre-State coordination on cyber incidents in India. (15 marks) 2. Critically evaluate the role of CERT-In under Section 70B of the IT Act, 2000 in light of the steep rise in reported cyber incidents between 2021 and 2025. (10 marks) 3. Distinguish between CERT-In, NCIIPC and I4C, and discuss whether their mandates need consolidation. (15 marks)

9. Related Topics to Study Next

  • NCIIPC & Section 70A IT Act — sister agency for critical info infrastructure.
  • I4C & National Cyber Crime Reporting Portal — MHA's citizen-facing arm.
  • IT Act 2000 + 2008 Amendment — statutory backbone.
  • Digital Personal Data Protection Act, 2023 — adjacent data-security regime.
  • Budapest Convention on Cybercrime — India's non-signatory status.
  • National Cyber Security Policy 2013 — overarching policy framework.
  • CERT-Fin & RBI cyber framework — sectoral CERT.
  • GIs (Cybersecurity) — Quad cyber initiatives, India–US iCET.

10. Common Errors / Trap Areas

  • CERT-In ≠ I4C. CERT-In (MeitY, incident response) vs I4C (MHA, cyber crime coordination).
  • NCCC is run by CERT-In, not by NTRO; NTRO houses NCIIPC.
  • Section 70A vs 70B — 70A = NCIIPC/CII; 70B = CERT-In.
  • Assuming CERT-In tracks financial losses — it explicitly does not [1].
  • Confusing Cyber Swachhta Kendra (botnet cleanup) with Cyber Surakshit Bharat (CISO training under MeitY/NeGD).
  • Treating cyber crime as a Union subject — investigation lies with States under List II.

Sources

  1. 1ASSISTANCE TO STATES TO TACKLE CYBER INCIDENTSpib.gov.in · tier 1
  2. 2MeitY — ICERT pagemeity.gov.in · tier 1
  3. 3CERT-In issues directions on cyber incident reportingpib.gov.in · tier 1
  4. 4CERT-In & Mastercard India sign MoUpib.gov.in · tier 1
  5. 5CERT-In: India's Frontline Defender against Cyber Threats (PIB feature, Jan 2026)static.pib.gov.in · tier 1
  6. 6Government Taking Measures to Strengthen National Preparedness Against Cybersecurity Threatspib.gov.in · tier 1
  7. 7Government of India Taking Measures to Protect Critical Infrastructure and Private Datapib.gov.in · tier 1
  8. 8CERT-In releases Cyber Security Handbook for Mahila Surakshapib.gov.in · tier 1

Also on 24 March

All 24 March articles →