
Cyber Resilience in the Age of AI and Digital Transformation
#GS-3 #Economy #Infrastructure #Science & Technology #ICT #Cyber Security #Government Policies & Interventions #Internal Security #Artificial Intelligence #Digital Personal Data Protection (DPDP) Act, 2023
Why in News
- A recent editorial published in The Business Standard argues that India must treat cybersecurity as a vital institutional pillar rather than a minor technical issue.
- As the digital economy grows rapidly, securing networks becomes essential to protect the nation against advanced digital risks.
Key Cyber Security Threats Confronting India
- The rapid progress of artificial intelligence (AI) and Large Language Models (LLMs) allows criminals to run highly customized phishing campaigns.
- Fraudsters utilize deepfake voice and video technology to pose as company bosses or family members to trick people into sending money.
- Criminals execute "digital arrest" scams by using deepfake video calls to impersonate law enforcement officers and demand money to resolve fake criminal cases.
- According to reports cited in judicial proceedings, including a Supreme Court suo moto petition, victims across India have lost close to ₹3,000 crore to digital arrest scams.
- Financial fraud remains the most common threat because India leads the world in digital payments, leading to unauthorized bank access and online scams targeting UPI and net-banking.
- During the first nine months of FY 2025-26, Indian banks reported over 17,000 fraud cases involving more than ₹36,000 crore.
- The government has recently blocked over 9.42 lakh SIM cards that were linked to cyber fraud activities.
- Ransomware attacks use malicious software to lock an organization's data while attackers demand payment for the decryption key.
- These dangerous software attacks can completely paralyze critical infrastructure, medical facilities, and government web portals.
- During the HDFC Asset Management Breach (May 2026), the "Morpheus" ransomware group stole over 680 GB of sensitive investor data containing PAN card details, bank information, and portfolio reports, threatening to leak them online and forcing the company to approach the Bombay High Court.
- Hackers increasingly target third-party vendors or software service providers instead of attacking the primary target directly.
- By breaking into a trusted software update or a common service provider, hackers can infiltrate thousands of downstream clients.
- Recent concerns regarding third-party portals like the CBSE’s OnMark portal demonstrate how outside service providers can act as open gateways for data breaches.
- India's critical information infrastructure (CII), which includes power networks, transport systems, and banking databases, remains a major target for state-linked actors and organized criminals.
- A clear example of a potential cyber sabotage attempt against Indian infrastructure is the 2020 Mumbai Power Outage, which caused a massive regional grid failure that stopped trains, affected hospitals, and disrupted essential services for hours.
- A report by Recorded Future indicated that a China-linked state-sponsored group known as "RedEcho" had attacked India's power sector using malicious software injections.
- Phishing continues to be a classic yet effective method used by hackers to gain initial entry into corporate and government computer networks.
- Fraudsters routinely send text messages or emails pretending to represent major Indian banking institutions like SBI, HDFC, or ICICI.
- These fraudulent messages create a false sense of panic by claiming that accounts or debit cards will be blocked unless users complete urgent KYC updates.
- Because the Reserve Bank of India regularly asks users to update their KYC details, people expect such messages and naturally lower their guard.
- Storing large amounts of citizen information in cloud storage buckets and government servers creates serious privacy risks.
- Poorly configured cloud storage setups or database leaks expose sensitive personal records and official identity documents.
- The 2016 Hitachi payment gateway compromise stands out as one of the largest data breaches in Indian banking history.
- That specific security failure exposed up to 3.2 million debit cards across several major commercial banks.
- The growing use of artificial intelligence across finance, healthcare, governance, and defense has spawned a new class of threats aimed directly at AI models and training data.
- Cybercriminals deploy tactics like prompt injection, data poisoning, and model manipulation to compromise artificial intelligence platforms, generate false answers, bypass security controls, and steal sensitive data.
- Such attacks weaken the reliability of automated decision-making, disrupt essential services, and expose institutions to financial and operational risks.
- Protecting artificial intelligence systems against adversarial attacks is turning into a major challenge for national cybersecurity.
Key Measures India is Adopting to Strengthen Cyber Resilience
- In May 2026, CERT-In published a detailed blueprint designed specifically to fight AI-assisted cyberattacks, shifting organizations away from static security toward adaptive defense models.
- Institutions are urged to use artificial intelligence to defend against AI-driven threats by focusing on fast threat detection and automated vulnerability fixes.
- CERT-In has advised organizations to patch known security flaws on internet-facing systems within 12 hours of discovery wherever possible.
- The Ministry of Electronics and Information Technology launched a four-stage summit to build a unified cybersecurity policy for all 36 States and Union Territories.
- This ensures that sensitive citizen records managed by state governments receive protection as a legal requirement rather than a choice.
- The Digital Personal Data Protection (DPDP) Act, 2023 turns basic cybersecurity into a strict legal obligation for organizations handling data.
- The National Critical Information Infrastructure Protection Centre (NCIIPC) serves as the main agency protecting vital sectors like power, banking, and telecommunications.
- The NCIIPC has upgraded from basic checklist reviews to demanding real-time monitoring of industrial control networks like SCADA systems.
- Organizations running critical facilities must now install advanced sensors that detect unusual traffic, such as attempts by outside IP addresses to change plant cooling temperatures.
- The agency operates under the Information Technology Act, 2000 to coordinate threat tracking and prevent infrastructure sabotage.
- India has empaneled over 231 cybersecurity audit firms to perform regular vulnerability checks and penetration testing for public and private organizations.
- CERT-In’s Cyber Swachhta Kendra (CSK) has helped users complete 89.55 lakh downloads of free botnet-removal tools to clean infected gadgets.
- The Indian Cybercrime Coordination Centre (I4C) suspect registry has successfully blocked over ₹8,000 crore in financial fraud, caught numerous mule accounts, and assisted in arrests.
- Government guidelines and official advisories strongly encourage the adoption of Zero-Trust architecture across networks.
- This security approach includes Multi-Factor Authentication (MFA) and network micro-segmentation, operating strictly on the rule of verifying every single request.
- During the year 2025 alone, CERT-In processed over 29.44 lakh cyber incidents while issuing 1,530 technical alerts and 390 vulnerability notes to secure systems.
- The Trusted Telecom Portal forces telecom operators to buy 5G and core network hardware exclusively from verified and approved vendors.
- India joined international programs like Project Glasswing, giving security agencies access to advanced AI models such as Anthropic’s Mythos.
- This allows security experts to find software weaknesses at scale before malicious hackers can exploit them.
- The early 2026 India-Israel Special Strategic Partnership brought advanced cybersecurity technology transfers to the country.
- Indian firms like Redington India Limited partnered with Israeli companies such as Check Point to bring advanced security solutions to Indian MSMEs.
- Through events like CERT-In SAMVAAD, the government connects policymakers, corporate security officers, and independent researchers.
- The National Awards for e-Governance now include prizes for innovations in cybersecurity to encourage local bodies to build secure digital systems.
- In June 2026, C3iHub at IIT Kanpur launched the CyberSuraksha Initiative to train military personnel in protecting critical national infrastructure.
- The IT Amendment Rules, 2026 introduced a strict 3-hour takedown window for identified deepfakes and synthetic misinformation.
- This quick action aims to stop cognitive warfare, control false narratives, and safeguard the digital information space.
Challenges
- Traditional encryption methods used in banking and government communication face severe risks from upcoming quantum computing technologies.
- The Quantum Safe Ecosystem in India report sets a clear target to achieve quantum resiliency across all critical infrastructure by 2029.
- Organizations must deploy crypto-agile Public Key Infrastructure systems that adapt easily as quantum-resistant codes become standard.
- India must combine its IT and OT security frameworks through unified risk management and network segmentation to stop cyber-physical attacks.
- The National Critical Information Infrastructure Protection Centre requires real-time monitoring of industrial SCADA networks to prevent office computer breaches from shutting down power grids.
- Threat intelligence and response operations remain split across CERT-In, NCIIPC, and I4C, showing the need for a singular command center.
- Static security audits are no longer enough, requiring organizations to continuously test defenses using proactive red teaming methods.
- Exercises like Bharat NCX 2025 focused on real-world simulations involving deepfakes, AI threats, and industrial control system security.
- Current legal frameworks struggle to assign accountability for AI-generated fraud and deepfakes, necessitating updates to the IT Act, 2000.
- The DPDP Act, 2023 serves as a foundation for drafting new accountability clauses that hold online platforms responsible for fraud-enabling algorithms.
- Programs like CyberShikshaa help upskill the workforce to manage automated security tools instead of relying entirely on manual checks.
- Financial institutions need to adopt Zero-Trust Access (ZTA) frameworks as promoted by the Data Security Council of India (DSCI) to secure machine-to-machine communications.
Way Forward
- India needs to unify its institutional response by creating an Apex Cyber Command that consolidates threat intelligence into a single dashboard.
- The country must accelerate its transition toward Post-Quantum Cryptography before quantum computers render current encryption obsolete.
- Private enterprises and government bodies must embrace an assume breach mindset where security teams focus on fast containment rather than false perfection.
- Policymakers must tighten legal accountability for tech platforms whose algorithms allow large-scale financial frauds and deepfake scams to spread.