Replying in the Lok Sabha on 12 August 2026, the Ministry of Electronics and IT reported that cyber security incidents tracked by CERT-In rose from 15,92,917 in 2023 to 20,41,360 in 2024 and 29,44,248 in 2025 — an increase of about 85% over two years.
CERT-In is the national agency for responding to cyber security incidents, designated under Section 70B of the Information Technology Act, 2000.
All Central Government websites and applications are audited for cyber security before hosting and on a regular basis afterwards; CERT-In has empanelled 237 information security auditing organisations to carry out this work, including vulnerability assessment and penetration testing.
The institutional architecture listed includes the National Cyber Security Coordinator under the National Security Council Secretariat, the National Cyber Coordination Centre implemented by CERT-In, the NCIIPC established under Section 70A of the IT Act, the Cyber Swachhta Kendra, and sectoral response teams CSIRT-Fin (operational since May 2022) and CSIRT-Power (since September 2024).
Under the Information Security Education and Awareness project, 6,650 workshops have covered over 11.37 lakh participants.
Designates CERT-In as the national agency for responding to cyber security incidents, giving it the authority to collect and analyse incident data, issue advisories, and call for information from service providers and intermediaries.
Provides for the National Critical Information Infrastructure Protection Centre as the nodal agency for protecting Critical Information Infrastructure. Section 70A was inserted by the IT (Amendment) Act, 2008, and NCIIPC was created by gazette notification on 16 January 2014.
Empowers the appropriate government to declare any computer resource that affects a Critical Information Infrastructure facility to be a 'Protected System' — the category referred to in the reply as CII/PS entities.
Provides the statutory framework for processing digital personal data; the reply notes that rules framed under it govern the sharing and processing of citizens' digital personal data for law enforcement purposes in a lawful, secure and accountable manner.
The national incident response agency. It tracks incidents, advises remedial measures, coordinates response with affected organisations, service providers, sector regulators and law enforcement, issues alerts and advisories, runs mock drills, empanels security auditors, operates an automated threat intelligence exchange platform, and has formulated the Cyber Crisis Management Plan for all ministries, departments and state governments.
Protects Critical Information Infrastructure. It provides near real-time threat intelligence and situational awareness, issues alerts and advisories to CII and Protected System entities, and periodically conducts vulnerability and risk assessments with feedback to the entities concerned.
Scans cyberspace to detect cyber security threats and shares threat intelligence with concerned organisations, state governments and stakeholder agencies. It is implemented by CERT-In.
Coordinates cyber security across the different agencies of government. The post was created in 2014.
A citizen-facing service run by CERT-In described as extending the vision of Swachh Bharat to cyberspace. It is the Botnet Cleaning and Malware Analysis Centre, detecting malicious programs, providing free removal tools, and publishing cyber security tips and best practices.
Extended arms of CERT-In for specific critical sectors. CSIRT-Fin has coordinated incident response in the banking and financial sector since May 2022; CSIRT-Power has done the same for power sector entities since September 2024.
The complementary body on the crime side rather than the security side — it coordinates law enforcement action against cybercrime through a seven-vertical framework covering threat analytics, joint investigation, forensics, capacity building, research, ecosystem management and citizen reporting.
Critical Information Infrastructure is defined in the Information Technology Act as a computer resource whose incapacitation or destruction would have a debilitating impact on national security, the economy, public health or safety. Once identified, such a resource can be declared a 'Protected System' under Section 70, which makes unauthorised access to it a distinct and more serious offence and brings the entity under NCIIPC's advisory and audit regime. India's usual CII sectors are power and energy, banking and financial services, telecommunications, transport, government and strategic and public enterprises — which explains why the two sectoral CSIRTs created so far cover finance and power. The distinction that matters for the exam is that CERT-In handles the general internet and all organisations, while NCIIPC handles only this narrow set of critical systems — and they sit under different parents, MeitY and NTRO respectively.
Simple Analogy: CERT-In is the country's general emergency service, taking every call; NCIIPC is the dedicated security detail assigned only to installations whose failure would stop the country.
| Aspect | CERT-In | NCIIPC | I4C |
|---|---|---|---|
| Statutory or executive basis | Section 70B, IT Act 2000 | Section 70A, IT Act 2000 | An executive scheme, not a statutory body |
| Parent | Ministry of Electronics and Information Technology | National Technical Research Organisation | Ministry of Home Affairs |
| Mandate | Incident response across all organisations and the general internet | Protection of Critical Information Infrastructure and Protected Systems | Coordinating law enforcement response to cybercrime |
| Set up | Operational since 2004 | Notified 16 January 2014 | Launched January 2020 |
| Citizen-facing arm | Cyber Swachhta Kendra | Alerts and advisories to CII entities | National Cyber Crime Reporting Portal |
Cyber security and data protection are converging: a breach is simultaneously an incident reportable to CERT-In and a personal data breach with obligations under the DPDP Act.
The Cyber Crisis Management Plan is implemented by state governments and their organisations as well as by central ministries, and NCCC shares threat intelligence with states — cyber security is coordinated centrally but executed across the federal structure.
The creation of CSIRT-Power in September 2024 follows global experience that grid operators are prime targets; power and finance are the two sectors India has so far given dedicated response teams.
As citizen services move onto government platforms, the pre-hosting audit requirement becomes the main preventive control protecting large-scale service delivery.
The ISEA project and CERT-In's training programmes sit alongside MeitY's broader digital skilling effort, addressing the shortage of trained security professionals that the empanelment of 237 audit organisations is meant to bridge.
GS Paper 3 > Internal Security > Cyber Security; GS Paper 2 > Statutory and Regulatory Bodies
General Awareness > Government Bodies and Current Affairs
General Awareness > Cyber Security in Banking and Regulators
General Awareness > Current Affairs
Which Article of the Indian Constitution states that there shall be a Comptroller and Auditor General (CAG) of India?
Answer: Article 148
Cyber security institutions appear in Prelims and Mains most years; the section numbers and parent bodies are the details that decide the mark.
Indian Computer Emergency Response Team, the national incident response agency under Section 70B of the IT Act, 2000, functioning under MeitY since 2004.
A computer resource whose incapacitation would have a debilitating impact on national security, the economy, public health or safety.
A computer resource declared under Section 70 of the IT Act, unauthorised access to which is a distinct offence.
A network of compromised computers controlled remotely; the Cyber Swachhta Kendra is India's Botnet Cleaning and Malware Analysis Centre.
Computer Security Incident Response Team — a sector-specific extended arm of CERT-In; CSIRT-Fin covers finance and CSIRT-Power covers electricity.