Please enable JavaScript.
Coggle requires JavaScript to display documents.
CYBERSECURITY - Coggle Diagram
CYBERSECURITY
INDIA — CYBER SECURITY ARCHITECTURE
Measures
7 PILLARS
CYBER SECURITY CHALLENGES FOR INDIA
CYBER THREAT SPECTRUM
. LATEST INDIA DATA
CORE IDEA
Cyber Security = Protection of information, devices, networks & systems from
Destruction
Use
Disruption
Unauthorised access
Disclosure
Modification
Why important for India?
Digital India + UPI + Aadhaar + Cloud + 5G + AI
Government increasingly dependent on digital infrastructure
Critical infrastructure increasingly networked
National security → economic security → individual security
KNOW THE ATTACKS — CONCEPT CLARITY
Phishing → deceptive message/email → steals credentials
Smishing → phishing through SMS
Vishing → phishing through voice/VoIP
Spoofing → pretending to be a trusted entity
Trojan → malicious software disguised as legitimate software
Worm → self-replicating malware
Ransomware → encrypt/block access → ransom demand
Spyware → secretly monitors/collects information
DoS → overwhelms system
DDoS → distributed systems overwhelm target
Brute Force → repeated password attempts
Zero-Day → vulnerability exploited before patch/fix
Deepfake → AI-generated/manipulated audio-video-image
Supply Chain Attack → compromise trusted vendor/software → reach final target
Social Engineering → exploit HUMAN behaviour rather than only technology
CYBERCRIME — FINANCIAL FRAUD
Common methods
UPI fraud
Phishing
Fake customer care
Digital arrest scams
Investment scams
Loan app fraud
Identity theft
Mule accounts
Remote-access scams
Why increasing?
Rapid digital payments
Low cyber literacy
Social engineering
Cross-border networks
Anonymisation
Response
1930
NCRP
CFCFRMS
Suspect Registry
Bank-Police-Telecom coordination
Financial intelligence
Cyber awareness
CERT-In reported cyber-security incidents
2021 → 14.03 lakh
2022 → 13.91 lakh
2023 → 15.93 lakh
2024 → 20.41 lakh
2025 → 29.44 lakh
Meaning
Cyber threat surface is expanding rapidly
Do NOT equate incidents with successful attacks/crimes
I4C
1930 → immediate financial fraud reporting
NCRP → national reporting platform
CFCFRMS → freezing/tracing financial fraud proceeds
2026 position
₹11,158+ crore saved through CFCFRMS
32.8+ lakh complaints
Reported till 30 June 2026
Use statistics to establish SCALE — not to create panic
Cyber Crime
Financial fraud
Identity theft
Phishing / Smishing / Vishing
Ransomware
Online stalking
Data theft
Child sexual exploitation
Cyber Espionage
State/non-state actors steal sensitive information
Military + diplomatic + corporate + technological secrets
Supply-chain attacks
Cyber Terrorism
Cyberspace used to intimidate/coerce
Target critical infrastructure
Energy + transport + finance + government
Objective → disruption + fear + strategic pressure
Cyber Warfare
State vs State
Offensive + defensive cyber operations
Cyber can complement conventional warfare
Targets → military systems + CII + communications + satellites
Cyber Extremism
Online radicalisation
Propaganda
Recruitment
Hate speech
Fundraising
Lone-wolf mobilisation
AI — NEW CYBER SECURITY FRONTIER
AI as THREAT
Automated phishing
Highly personalised scams
Deepfakes
Voice cloning
Automated vulnerability discovery
Malware assistance
Social engineering
AI as DEFENCE
Threat detection
Anomaly detection
Automated incident response
Malware analysis
Fraud detection
Deepfake detection
Cyber threat intelligence
Core dilemma
AI reduces cost of attacks
AI also reduces cost of defence
→ "AI vs AI" cybersecurity environment
CRITICAL INFORMATION INFRASTRUCTURE — VERY IMPORTANT
CII = infrastructure whose disruption can seriously affect
National security
Economy
Public health
Public order
Examples
Power grids
Banking & financial systems
Telecom
Transport
Defence
Healthcare
Government digital infrastructure
Why vulnerable?
Interconnected systems
Legacy systems
IoT
Third-party vendors
Human error
Supply-chain dependence
Key concept
Cyber attack can produce PHYSICAL consequences
→ digital-to-physical threat
→ cyber + conventional attack convergence
Technology
Rapid technological change
AI-enabled attacks
IoT vulnerabilities
Cloud dependence
5G/6G complexity
Quantum threat in future
Human
Low cyber awareness
Weak passwords
Social engineering
Insider threats
Institutional
Shortage of skilled manpower
Fragmented databases
Police capacity gaps
Weak cyber forensics
Infrastructure
Legacy systems
Weak network segmentation
Supply-chain vulnerabilities
Legal
Technology evolves faster than law
Cross-border jurisdiction
Attribution problem
Encryption vs lawful investigation
Strategic
State-sponsored attacks
Cyber espionage
Cyber warfare
Geopolitical cyber conflicts
Economic
Ransomware
Digital financial fraud
Data theft
Business disruption
CYBER SECURITY + NATIONAL SECURITY
Cyberspace = 5th/modern strategic domain
Land
Sea
Air
Space
Cyberspace
Strategic effects
Disrupt military command systems
Paralyse communication
Attack power/transport/finance
Steal strategic information
Influence public opinion
Key concept
"Grey Zone"
Below threshold of conventional war
Attribution difficult
Continuous competition
Cyber deterrence requires
Resilience
Attribution capability
Offensive/defensive capability
International cooperation
INTERNATIONAL DIMENSION
Why global cooperation essential?
Cyberspace has no borders
Attackers may operate from another jurisdiction
Data may be stored elsewhere
Cloud infrastructure is transnational
Key forums/frameworks
UN cyber norms
INTERPOL
Budapest Convention
Global Counter Ransomware Initiative
Paris Call
G20
QUAD cyber cooperation
India-EU cyber dialogue
India's broad approach
Strategic autonomy
International cooperation
Capacity building
Cyber norms
Responsible state behaviour
Core challenge
No universally accepted global cyber governance regime
CYBERSECURITY vs CYBER RESILIENCE
Cybersecurity
Prevent attack
Cyber resilience
Prepare
Absorb
Respond
Recover
Continue essential services
Modern approach
Assume breach
Minimise damage
Recover quickly
Build redundancy
Regular cyber drills
Prevention
Cyber hygiene
Secure-by-design
Regular patching
Protection
Zero Trust
Encryption
Multi-factor authentication
Network segmentation
Detection
AI-based monitoring
Threat intelligence
Real-time alerts
Response
CERT-In + I4C + State Police
Crisis protocols
Incident response teams
Recovery
Backups
Business continuity
Disaster recovery
Capacity
Cybersecurity workforce
Cyber forensics
Police training
Academic-industry collaboration
Cooperation
Government + private sector
States + Centre
International partnerships
Information sharing
CONCLUSION
Cybersecurity is NOT merely a technology issue
= National Security
Economic Security
Privacy
Governance
Social Stability
Individual Rights
India's goal
"Open + Safe + Trusted + Resilient Digital India"
Best policy approach
Security without disproportionate surveillance
Innovation without reckless data exploitation
Free speech without weaponised misinformation
Digital growth with digital trust
MeitY
Policy + technology ecosystem
CERT-In
National agency for cyber-security incident response
Incident monitoring
Alerts + advisories
Coordination
Capacity building
NCIIPC
Protection of Critical Information Infrastructure
National nodal agency for CII
NCSC
National-level cyber-security coordination
I4C — Indian Cyber Crime Coordination Centre
MHA
National coordination against cybercrime
National Cyber Crime Reporting Portal
1930 cyber-fraud helpline
Cyber Fraud Mitigation Centre
Cybercrime Threat Analytics
Cyber Forensics
CyTrain
Coordination with States/LEAs
NCRP
cybercrime.gov.in
Citizen reporting
Special focus → women & children
CFCFRMS
Immediate reporting of financial fraud
Bank + police + telecom coordination
NATGRID
Integrated intelligence database/network
NTRO
Technical intelligence
NSCS
Strategic/national security coordination
State Police
Police + Public Order = State subjects
Cybercrime investigation ultimately depends heavily on State capacity
DATA PRIVACY — FROM IT ACT TO DPDP
Constitutional foundation
Puttaswamy judgment, 2017
Right to Privacy
Articles 14 + 19 + 21
Srikrishna Committee, 2018
Comprehensive data protection framework
Individual rights
Accountability
Data protection authority
Consent
Data localisation
DPDP Act, 2023
Data Principal → individual
Data Fiduciary → entity deciding purpose/means of processing
Consent + legitimate uses
Purpose limitation
Data minimisation
Accuracy
Storage limitation
Security safeguards
Accountability
Children's data protection
Data Protection Board
DPDP Rules, 2025
Operationalise DPDP Act
Stronger implementation framework
Citizen rights + organisational obligations
Rules notified November 2025
Core UPSC debate
Privacy vs National Security
Privacy vs Innovation
Data protection vs Ease of Business
Data sovereignty vs Global data flows
SOCIAL MEDIA + INTERNAL SECURITY
SOCIAL MEDIA — SECURITY DIMENSION
Benefits
Information dissemination
Crisis communication
Disaster response
Citizen engagement
Democratic participation
Risks
Misinformation
Disinformation
Malinformation
Hate speech
Communal polarisation
Online radicalisation
Cyber bullying
Identity theft
Deepfakes
Financial scams
Privacy violations
Why spreads rapidly?
Algorithmic amplification
Emotional content
Echo chambers
Confirmation bias
Low verification
Anonymity
Bot networks
FAKE NEWS
Misinformation
False information
No deliberate intent necessarily
Disinformation
False information
Deliberately created/spread
Malinformation
True information
Used maliciously/out of context
Consequences
Communal tension
Mob violence
Election manipulation
Public distrust
Financial fraud
Institutional erosion
Deepfake adds
"Seeing is no longer believing"
Solution
Media literacy
Fact-checking
Platform responsibility
Provenance/authenticity technology
Faster grievance redressal
Accountability without chilling legitimate speech
SOCIAL MEDIA REGULATION — IT RULES
IT Rules 2021
Due diligence by intermediaries
Grievance redressal
Compliance obligations
Digital media ethics framework
SSMI
Significant Social Media Intermediary
Enhanced compliance obligations
Core issues
Content moderation
Traceability
Privacy
Free speech
Platform accountability
User grievance
Constitutional balance
Article 19(1)(a) → speech
Article 19(2) → reasonable restrictions
Article 21 → privacy/life/liberty
2026 update
IT Rules amended for synthetically generated information
Deepfakes + AI-generated content
Need greater transparency/provenance/safeguards
SAFE HARBOUR — UNDERSTAND THE DEBATE
Section 79 IT Act
Intermediary generally gets protection from liability
Subject to statutory conditions/due diligence
Policy dilemma
Too little regulation
→ misinformation + harmful content
Too much regulation
→ chilling effect + excessive censorship
Ideal principle
"Accountability with constitutional safeguards"
IT (Intermediary Guidelines & Digital Media Ethics Code) Rules, 2021
Background
Framed under Information Technology Act, 2000
Superseded IT (Intermediary Guidelines) Rules, 2011
Objective
Make intermediaries more accountable
Address harmful/unlawful online content
Provide grievance redressal
Regulate digital news + OTT platforms
Two Broad Parts
Intermediary Guidelines
Social media platforms
Messaging platforms
Other intermediaries
Digital Media Ethics Code
Digital news publishers
OTT platforms
Online curated content
Key Provisions — Intermediaries
Due Diligence
Publish rules & privacy policy
Inform users about prohibited content
Remove unlawful content when legally required
Grievance Redressal
Grievance Officer
Acknowledge complaint → 24 hours
Resolve complaint → 15 days
Significant Social Media Intermediaries
Enhanced compliance obligations
Grievance Officer
Chief Compliance Officer
Nodal Contact Person
Monthly compliance reports
Message Traceability
Identification of first originator
For specified serious offences
Key debate → privacy vs investigation
Voluntary Verification
Users may verify accounts
Helps distinguish authentic/fake accounts
Removal of Certain Content
Private/intimate content
Nudity/sexual content
Morphed/impersonated content
Prompt action on complaints
Digital Media Ethics Code
Digital News
Code of Ethics
Three-tier grievance mechanism
OTT Platforms
Self-classification
U
U/A 7+
U/A 13+
U/A 16+
A
Parental locks
Content descriptors
2021 Rules — Significance
Internal Security
Online radicalisation
Hate speech
Disinformation
Cybercrime
Governance
Platform accountability
Grievance redressal
Constitution
Article 19(1)(a) → Freedom of speech
Article 19(2) → Reasonable restrictions
Article 21 → Privacy
Key dilemma
Free Speech ↔ Online Safety
Privacy ↔ Traceability
Platform Autonomy ↔ State Regulation
2022 Amendment — Important
Intermediaries required to make reasonable efforts to prevent prohibited content Users' constitutional rights emphasised Articles 14, 19 & 21
Grievance Appellate Committees introduced Users can appeal intermediary decisions
Communalism
Rumours → mobilisation → violence
Terrorism
Propaganda
Recruitment
Radicalisation
Insurgency
Narrative warfare
Disinformation
Election security
Foreign influence
Bot networks
Deepfakes
Organised crime
Recruitment
Financial fraud
Extortion
Women & children
Cyber stalking
Morphing
Sextortion
Identity abuse
Child sexual exploitation