Q. In India, it is legally mandatory for which of the following to report on cyber security incidents?

  1. Service providers
  2. Data centers
  3. Body corporate

Select the correct answer using the codes given below:

  • 1 only
  • 1 and 2 only
  • 3 only
  • 1, 2 and 3

Answer: (d) 1, 2 and 3

Cybersecurity incidents
  • Cybersecurity incidents mean any real and suspected adverse event in relation to cybersecurity that violates an explicitly or implicitly applicable security policy resulting in unauthorized access, denial of services, unauthorised used of computer resources for processing or storage of data or changes in data without authorization.
  • In India, section 70-B of the Information Technology Act, 2000 (the “IT Act”) gives the Central Government the power to appoint an agency of the government to be called the Indian Computer Emergency Response Team (CERT) to report such incidents.
  • Rule 12 of the CERT Rules gives every person, company or organisation have the option to report cybersecurity incidents to the CERT-In.
  • It also places an obligation on them to mandatorily report the following kinds of incidents as early as possible:
    • Targeted scanning/probing of critical networks/systems;
    • Compromise of critical system/information;
    • Unauthorized access to IT system/data;
    • Defacement of website or intrusion into a website and unauthorized changes such as inserting malicious code, links to external websites, etc.;
    • Malicious code attacks such as spreading of virus/worm/Trojan/botnets/spyware;
    • Attacks on servers such as database, mail, and DNS and network devices such as routers;
    • Identity theft, spoofing and phishing attacks;
    • Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks;
    • Attacks on critical infrastructure, SCADA systems and wireless networks;
    • Attacks on applications such as e-governance, e-commerce, etc’s.
Challenges Posed by Cyber Attacks on India
  • Critical Infrastructure Vulnerability: India’s critical infrastructure, such as power grids, transportation systems, and communication networks, is vulnerable to cyber attacks that can disrupt essential services and endanger public safety and national security.
    • For example, in October 2019, there was an attempted cyber-attack on the Kudankulam Nuclear power plant.
  • Financial Sector Threats: The financial sector in India faces a high risk of cyberattacks from cybercriminals who seek to profit from stealing or extorting money. Attacks on banks, financial institutions, and online payment systems can cause financial losses, identity theft, and a loss of trust in the financial system.
    • For instance, in March 2020, a malware attack on the City Union Bank’s SWIFT system led to unauthorised transactions worth USD 2 million.
  • Data Breaches and Privacy Concerns: As India moves towards a digital economy, the amount of personal and government data stored online increases. This also increases the risk of data breaches, where hackers access and leak sensitive information. Data breaches can have serious consequences for the privacy and security of individuals and organisations.
    • For example, in May 2021, the personally identifiable information (PII) and test results of 190,000 candidates for the 2020 Common Admission Test (CAT), used to select applicants to the IIMs, were leaked and put up for sale on a cybercrime forum.
  • Cyber Espionage: Cyber espionage is the use of cyber attacks to spy on or sabotage the interests of other countries or entities. India, like other countries, is a target for cyber espionage activities that aim to steal confidential information and gain a strategic edge. Cyber espionage can affect India’s national security, foreign policy, and economic development.
    • For example, in 2020, a cyber espionage campaign called Operation SideCopy (a Pakistani threat actor) was uncovered, which targeted Indian military and diplomatic personnel with malware and phishing emails.
  • Advanced Persistent Threats (APTs): APTs are complex and prolonged cyber attacks, usually carried out by well-resourced and skilled groups. These attacks are designed to infiltrate and remain hidden in the target’s network for a long time, allowing them to steal or manipulate data, or cause damage.
    • APTs are difficult to detect and counter, as they use advanced techniques and tools to evade security measures.
    • For example, in February 2021, a cyber security firm called RedEcho revealed that a China-linked APT group had targeted 10 entities in India’s power sector, with malware that could potentially cause power outages.
  • Supply Chain Vulnerabilities: Supply chain vulnerabilities refer to the weaknesses in the software or hardware components that are used by government and businesses for their operations. Cyber attackers can exploit these vulnerabilities to compromise the systems and services that depend on these components, and cause widespread damage.
    • For example, in December 2020, a global cyberattack on SolarWinds, a US-based software company that provides network management tools, affected several Indian organisations, including the National Informatics Centre (NIC), the Ministry of Electronics and Information Technology (MeitY), and Bharat Heavy Electricals Limited (BHEL).
Initiatives Regarding Cyber Security
  • Indian Initiatives:
    • National Cyber Security Policy: This policy aims to build a secure and resilient cyberspace for citizens, businesses, and the government. It outlines various objectives and strategies to protect cyberspace information and infrastructure, build capabilities to prevent and respond to cyber attacks, and minimise damages through coordinated efforts of institutional structures, people, processes, and technology.
    • Cyber Surakshit Bharat Initiative: This initiative was launched to raise awareness about cyber crimes and create safety measures for Chief Information Security Officers (CISOs) and frontline IT staff across all government departments.
    • Indian Cyber Crime Coordination Centre (I4C): This centre was established to provide a framework and eco-system for law enforcement agencies to deal with cyber crimes in a comprehensive and coordinated manner. It has seven components, namely:
      • National Cyber Crime Threat Analytics Unit
      • National Cyber Crime Reporting Portal
      • National Cyber Crime Training Centre
      • Cyber Crime Ecosystem Management Unit
      • National Cyber Crime Research and Innovation Centre
        National Cyber Crime Forensic Laboratory Ecosystem
      • Platform for Joint Cyber Crime Investigation Team.
    • Cyber Swachhta Kendra (Botnet Cleaning and Malware Analysis Centre): This centre was launched in 2017 to create a secure cyberspace by detecting botnet infections in India and notifying, enabling cleaning and securing systems of end users to prevent further infections.
    • Computer Emergency Response Team – India (CERT-In): It is an organisation of the MeitY which collects, analyses and disseminates information on cyber incidents, and also issues alerts on cybersecurity incidents.
    • Critical information infrastructure (CII): It is defined as a computer resource, the destruction of which, shall have debilitating impact on national security, economy, public health or safety.
      • The government has established the National Critical Information Infrastructure Protection Centre (NCIIPC) to protect the CII of various sectors, such as power, banking, telecom, transport, government, and strategic enterprises.
    • Defence Cyber Agency (DCyA): The DCyA is a tri-service command of the Indian Armed Forces that is responsible for handling cyber security threats. It has the capability to conduct cyber operations, such as hacking, surveillance, data recovery, encryption, and countermeasures, against various cyber threat actors.
  • Global Initiatives:
    • Budapest Convention on Cybercrime: It is an international treaty that seeks to address Internet and computer crime by harmonizing national laws, improving investigative techniques, and increasing cooperation among nations. It came into force on 1st July 2004. India is not a signatory to this convention.
    • Internet Governance Forum (IGF): It brings together all stakeholders i.e., government, private sector and civil society on the Internet governance debate.
    • UNGA Resolutions: The United Nations General Assembly established two processes on the issues of security in the information and communication technologies (ICT) environment.
      • The Open-ended Working Group (OEWG) through resolution by Russia
      • The Group of Governmental Experts (GGE) through resolution by USA