ASSISTANCE TO STATES TO TACKLE CYBER INCIDENTS
In this note
1. At a Glance
- CERT-In (Indian Computer Emergency Response Team) is the national nodal agency for responding to cyber security incidents under Section 70B of the IT Act, 2000 [1][2].
- Topic covers the central government's mechanism to handhold States/UTs — alerts, threat intelligence, capacity building and financial aid — in a domain where "Police" and "Public Order" are State subjects but cyberspace is borderless [1].
- Cyber incidents have more than doubled in 5 years — from 14.02 lakh (2021) to 29.44 lakh (2025) — making this a high-yield GS-III internal security topic [1].
2. Why in the News
- Lok Sabha reply by Ministry of Home Affairs (MHA) on 24 March 2026 disclosed five-year cyber incident data and listed CERT-In's assistance measures to States/UTs [1].
- NCT of Delhi recorded the highest number of reported cyber incidents in the period [1].
3. Background & Evolution
- IT Act, 2000 enacted; Section 70B inserted by the IT (Amendment) Act, 2008, formally designating CERT-In [1][2].
- CERT-In operational since 2004 under MeitY [2].
- Cyber Swachhta Kendra (CSK) — Botnet Cleaning & Malware Analysis Centre — launched 2017 under the Digital India programme [2].
- National Cyber Coordination Centre (NCCC) operationalised in phases by CERT-In for real-time threat scanning [2].
- I4C (Indian Cyber Crime Coordination Centre) under MHA established 2018; National Cyber Crime Reporting Portal (cybercrime.gov.in) launched 2019 (parallel MHA track for citizen-level crimes) [2].
4. Core Static Facts
- Nodal agency for cyber incidents: CERT-In [1].
- Parent ministry: Ministry of Electronics & Information Technology (MeitY) — NOT MHA [2].
- Statutory basis: Section 70B, IT Act 2000 [1].
- Mandatory incident reporting: CERT-In Directions of 28 April 2022 require reporting of specified cyber incidents within 6 hours [3].
- Year-wise cyber security incidents tracked by CERT-In [1]:
- 2021 — 14,02,809
- 2022 — 13,91,457
- 2023 — 15,92,917
- 2024 — 20,41,360
-
2025 — 29,44,248
-
Highest reporting region: NCT of Delhi [1].
- Financial loss data: NOT maintained by CERT-In [1].
Assistance instruments to States/UTs [2]:
- Alerts/advisories on threats and vulnerabilities.
- NCCC — scans cyberspace, shares threat intel with States and sectoral agencies.
- Automated cyber threat exchange platform for tailored alerts.
- Cyber Swachhta Kendra (CSK) — detects malware/botnets and offers free clean-up tools.
- Joint training programmes with industry to upskill Government (Central + State), public & private workforce.
- Financial assistance to States/UTs for LEA capacity building under various schemes.
5. Multi-Dimensional Analysis
Administrative / Federal
- "Police" & "Public Order" are State List (List II, Entries 1 & 2) subjects; cyber crime investigation rests with State police — Centre's role is supplementary via advisories, tools, training and grants [1][2].
- Coordination gap: CERT-In (MeitY) handles incidents; I4C (MHA) handles cyber crime — aspirants must distinguish the two silos [2].
Legal / Constitutional
- Statutory umbrella: IT Act 2000 + IT (CERT-In) Rules 2013; Section 70B(6) empowers CERT-In to call for information and give directions [1].
- April 2022 Directions mandated 6-hour reporting, 180-day log retention, KYC by VPN/VPS providers [3].
Scientific / Technological
- NCCC acts as the operational cyber situational-awareness backbone [2].
- CSK provides free bot-removal tools (e.g., USB Pratirodh, AppSamvid, M-Kavach) for end-users [2].
Economic / Sectoral
- Financial sector flagged as high-risk; CERT-In–Mastercard MoU (2024) targets financial-sector cyber resilience [4].
- Loss-data vacuum (CERT-In doesn't maintain financial-loss figures) handicaps cost-benefit policy assessment [1].
Strategic / Security
- Surge from 14 lakh → 29 lakh incidents in five years signals expanding attack surface (UPI, IoT, critical infra) [1].
- Sectoral CERTs (CERT-Fin under RBI, NCIIPC under NTRO for Critical Information Infrastructure u/s 70A) complement CERT-In [2].
6. Recent Developments (last 12-18 months)
- 24 Mar 2026 — MHA tabled five-year incident data and States-assistance framework in Parliament [1].
- Jan 2026 — PIB feature "CERT-In: India's Frontline Defender against Cyber Threats" published [5].
- 2024 — CERT-In–Mastercard India MoU signed for financial-sector cyber collaboration [4].
- Feb–Mar 2025 — PIB releases on government measures to strengthen cyber preparedness and protect critical infrastructure [6][7].
- Mar 2025 — CERT-In released "Cyber Security Handbook for Mahila Suraksha" on International Women's Day [8].
7. Prelims Hooks
- CERT-In is the national agency for cyber incident response under Section 70B, IT Act 2000 [1].
- CERT-In functions under MeitY, not MHA [2].
- NCCC is implemented by CERT-In (not by NTRO or MHA) [2].
- NCIIPC (Critical Information Infrastructure protection) operates under Section 70A, IT Act — distinct from CERT-In's 70B mandate [2].
- Cyber incidents reported in 2025: 29,44,248; 2024: 20,41,360 [1].
- Highest cyber incident reporting region: NCT of Delhi [1].
- Cyber Swachhta Kendra = Botnet Cleaning and Malware Analysis Centre, launched 2017 [2].
- CERT-In Directions of 28 April 2022 mandate cyber incident reporting within 6 hours [3].
- I4C is under MHA, whereas CERT-In is under MeitY [2].
- CERT-In does NOT maintain estimated financial loss data [1].
- National Cyber Crime Reporting Portal = cybercrime.gov.in under MHA/I4C [2].
- CERT-In–Mastercard MoU (2024) targets financial sector resilience [4].
8. Mains Relevance
- GS-III — Internal Security: "Basics of cyber security; role of media and social networking sites… Money-laundering and its prevention."
- GS-II — Governance: Centre-State coordination on a Concurrent/State-subject overlap.
- Probable question stems: 1. "Cyber crime is local but cyber threat is national." Examine the institutional architecture for Centre-State coordination on cyber incidents in India. (15 marks) 2. Critically evaluate the role of CERT-In under Section 70B of the IT Act, 2000 in light of the steep rise in reported cyber incidents between 2021 and 2025. (10 marks) 3. Distinguish between CERT-In, NCIIPC and I4C, and discuss whether their mandates need consolidation. (15 marks)
9. Related Topics to Study Next
- NCIIPC & Section 70A IT Act — sister agency for critical info infrastructure.
- I4C & National Cyber Crime Reporting Portal — MHA's citizen-facing arm.
- IT Act 2000 + 2008 Amendment — statutory backbone.
- Digital Personal Data Protection Act, 2023 — adjacent data-security regime.
- Budapest Convention on Cybercrime — India's non-signatory status.
- National Cyber Security Policy 2013 — overarching policy framework.
- CERT-Fin & RBI cyber framework — sectoral CERT.
- GIs (Cybersecurity) — Quad cyber initiatives, India–US iCET.
10. Common Errors / Trap Areas
- CERT-In ≠ I4C. CERT-In (MeitY, incident response) vs I4C (MHA, cyber crime coordination).
- NCCC is run by CERT-In, not by NTRO; NTRO houses NCIIPC.
- Section 70A vs 70B — 70A = NCIIPC/CII; 70B = CERT-In.
- Assuming CERT-In tracks financial losses — it explicitly does not [1].
- Confusing Cyber Swachhta Kendra (botnet cleanup) with Cyber Surakshit Bharat (CISO training under MeitY/NeGD).
- Treating cyber crime as a Union subject — investigation lies with States under List II.
Sources
- 1ASSISTANCE TO STATES TO TACKLE CYBER INCIDENTSpib.gov.in · tier 1
- 2MeitY — ICERT pagemeity.gov.in · tier 1
- 3CERT-In issues directions on cyber incident reportingpib.gov.in · tier 1
- 4CERT-In & Mastercard India sign MoUpib.gov.in · tier 1
- 5CERT-In: India's Frontline Defender against Cyber Threats (PIB feature, Jan 2026)static.pib.gov.in · tier 1
- 6Government Taking Measures to Strengthen National Preparedness Against Cybersecurity Threatspib.gov.in · tier 1
- 7Government of India Taking Measures to Protect Critical Infrastructure and Private Datapib.gov.in · tier 1
- 8CERT-In releases Cyber Security Handbook for Mahila Surakshapib.gov.in · tier 1