India has no updated national cybersecurity policy since 2013, no accountable cyber regulatory body, no consequences for security auditors who certify poor cybersecurity systems, and companies don’t lose anything if they deny a breach. These are some of the problems in India’s cybersecurity ecosystem that we identified after speaking to several experts.
Here are the ten problems they have highlighted:
- CERT-In answers to nobody, so anything it fixes is a favour rather than an accountable duty
Every interviewee, without prompting, raised the accountability concerns of Cert-In as an organisation, which is India’s designated national cybersecurity agency, and there is no mechanism in law that requires it to act on what it receives or answer for what it ignores.
“Just like how no regulator is accountable in India, the cyber regulator is also not accountable in India. So it’s not a problem specific to cybersecurity. Usually, abroad, you will see regulators are held accountable by parliamentary committees and things like that. In India, that structure is only present on paper.” – Srikanth L, Cashless Consumer
“CERT-In does not actually have teeth to say that, ‘you have not acted upon this, so you need to shut down’, or ‘we will basically make this vulnerability public and make the public aware.’ CERT-In basically says that, ‘okay, somebody gave us this thing’, and asks ‘can you fix it if it’s possible?’ But, CERT-In is under no legal obligation to go beyond.” – Srikanth L
Kiran Jonnalagadda, co-founder of HasGeek, draws the same conclusion from his long-standing experience of dealing with CERT-In, and frames it as the difference between a service and a privilege.
“Everything with CERT-In is like it’s a privilege. If they feel like it, they will do something. If you cannot hold them responsible for delivering the service, then it’s not a service. It’s a privilege… Anything that works in CERT-In is a lucky accident because there is no requirement for any of it to work in their setup.” – Kiran Jonnalagadda
Independent security researcher Karan Saini, who has spent years reporting vulnerabilities to government agencies, has arrived at the harshest position of the three.
“I don’t know why CERT-In exists, really…. In a recent piece I wrote, I was initially going to suggest it be closed. I was going to say, let’s shut down CERT-In and have another existing institution assume its responsibilities.” – Karan Saini
What can be done: Jonnalagadda’s prescription is statutory. “Go get an Act of Parliament passed that makes Cert accountable for services… It should be like RTI, that they have to act or there are consequences for not acting on it.” He argues there are only two workable models such as being answerable to Parliament or to public. He cites the US CERT Coordination Center, which comes under the Carnegie Mellon University outside government control, but acts as a coordination organisation for cybersecurity incidents as proof the second model that could work for India.
It is important to note that CERT-CC is different from US-CERT, which is a federal government agency under the Department of Homeland Security that aims to protect US national cybersecurity infrastructure.
- The blackhole problem of CERT-in where the public must disclose everything but receive nothing in return
Beyond the accountability gap sits a deliberate design choice where CERT-In collects all the reports and returns nothing, and its founding director described that as a feature. Jonnalagadda recalls a consultation where Gulshan Rai, the agency’s first head, defended such an architecture.
“By design, CERT-In will tell you nothing, but you tell CERT-In everything. That would have been fine if CERT-In had something holding it accountable for its confidentiality. But where in the law is anything that says CERT-In is accountable for the confidentiality of the report it receives? All of that is a black hole… They simply are a data demander. It is not obvious why any company should ever bother reporting to CERT-In.” – Kiran Jonnalagadda
Saini’s reporting history bears this out across agencies. His most recent CERT-In report, on a master password exposure in the Maharashtra State Board’s portal, produced a response that claimed a false fix, where in fact the fix has not been implemented.
“They said it was fixed, but it wasn’t. They just moved the affected website to another domain. I just did not respond to that because at that point, you’re wasting your own energy trying to get them to respond.” – Karan Saini
He notes the problem extends past CERT-In. National Critical Information Infrastructure Protection Centre (NCIIPC), the agency responsible for critical infrastructure, acknowledged his report on a vulnerability in the Telecom Regulatory Authority of India (TRAI) portal, said it was verifying, and never wrote back.
“None of these agencies are as transparent as they expect the [incident] reporters or the people who are finding the issues to be.” – Karan Saini
A cybersecurity professional who previously worked as an analyst at global information security firm SISA, a working security professional, could not describe what happens after a report is filed, which highlights how CERT-In is currently positioned and how much importance the industry gives it.
“When you report to CERT-In, I honestly don’t know what happens… What’s the government role in this, that even I don’t know. There’s no recourse. Basically, the conclusion is there’s no proper recourse to this.” – ex-SISA analyst
What can be done: Jonnalagadda wants CERT-In rebuilt as a coordination agency on the model of the US CVE (Common Vulnerabilities and Exposures) system, where a reported vulnerability gets a confidential window for fixing and then mandatory publication. “There has to be a confidentiality period where you mitigate the risk for users before you go public. But going public has to be mandatory.” He points to what a functioning system enables downstream: because the CVE database is dependable, services like GitHub’s Dependabot can automatically alert and upgrade dependencies for developers worldwide.
“When you can depend on an institution to behave properly, then you can create downstream services that ride on the dependency and make life better for everyone.” – Kiran Jonnalagadda
- India’s cybersecurity disclosure regime makes denying a breach the safer legal option for companies than making themselves accountable
The two problems above produce a third. If reporting brings liability and returns nothing, companies deny. If everyone denies, the true scale of the problem is unknowable, and the resulting secrecy is itself a security failure.
“In every single breach that I have experienced, I have not had the company ever acknowledge it.” – Kiran Jonnalagadda
He traces the incentive precisely to CERT-In’s proposed rules, which demand disclosure and create liability for non-disclosure while offering nothing in return, including an acknowledgement.
“The incentive is structured towards denial and not towards disclosure… Denying the breach is legally the safest thing to do for a company. Because what is the user going to do? Nothing in the law keeps them accountable if a breach happens, if they never told CERT-In and if they never accepted a breach.” – Kiran Jonnalagadda
The ex-SISA analyst confirms the pattern from inside the industry and cites the Pine Labs case as an example of public denial after a real breach. In August 2021, then Pine Labs’ CTO denied the data breach that was reported by cybersecurity firm Cyble Research Lab. The research firm claimed that over 5,00,000 unique records, including sensitive information such as phone numbers, names, and email IDs were breached and the company responded saying, “our systems continue to be fully secure and our production systems continue to operate as usual and all customer data is safe.”
“I think a lot of companies do not self-report… In the public segment, some companies might completely deny it. But in reality, they might actually have been breached and there might be a data dump that occurred. The only time in India we hear about breaches is where somebody dumps the data on the dark web and some researcher or some activist finds it and reports on it.” – ex-SISA analyst
One of the speakers we spoke to for this story, who requested anonymity, admitted that a person who runs a cybersecurity firm said, “Speaking up is bad for their cybersecurity business.”
What can be done: The analyst’s answer is enforcement with real cost, on the pattern of the US and EU, where companies face heavy fines for failing to report within fixed windows. “It shouldn’t be an incentive. It should be a penalty, a fine, legal action.” Security researcher Saini agrees on the mechanism and is blunt about the trigger: “Until some news headlines break that, oh, this company was fined 10 crores or 100 crores, nothing’s going to happen, I think.”
- India has had no updated national cybersecurity policy for more than a decade
The last published National Cybersecurity Policy dates to 2013. Read the document here : Original PDF | Archived PDF
“India hasn’t had a new cybersecurity policy since 2013. At least it’s not public. We are doing everything without strategy.” – Karan Saini
Venkata Satish Guttula, independent cybersecurity and information systems (IS) audit consultant, describes the same vacuum in structural terms.
“CERT-In rules, sectoral frameworks and mission programmes are all real, but they point in different directions. Without a single strategy that sets direction and accountability, no individual initiative can carry the load, and sovereign efforts stall in committees.” – Venkata Satish Guttula
He further cites sovereign cloud as the clearest casualty, a concept that “keeps being studied and moved between bodies on long timelines,” even as dependence on foreign providers continues to grow. This is much more true and relevant when the US government can decide which countries can have access to which models at what time.
Saini contrasts this with the US, where even policy he considers flawed shows evidence of some background process. “Even the rubbish executive orders are still well-reasoned. Someone is doing the scientific thinking behind it… We are not even doing that,” he added.
What can be done: Guttula asks for “a published national cybersecurity strategy that names the objective and the owner, and a ring-fenced statutory authority for sovereign infrastructure with its own mandate and funding, rather than repeated bureaucratic transfers.”
- Too many cyber agencies leading to duplication of efforts because of less or no coordination between them and a lack of a specialised recruitment pipeline for specialists.
Saini’s critique of state capacity runs across three fronts: agency sprawl, broken recruitment, and wasted public spending.
He said that agencies like CERT-In, National Critical Information Infrastructure Protection Centre (NCIIPC), under the National Technical Research Organisation (NTRO), Indian Cybercrime Coordination Centre (I4C), which operates under the Ministry of Home Affairs (MHA) and several individual state police cyber cells overlap without coordination, and even if they do, with very little efficiency. This results in duplication of effort without the intended results.
“Just as far as agencies go, I think we’ve created too many. They’re conflating cybercrime and cybersecurity. They’ve become one thing… There is no one agency doing any of this in a coordinated manner. So duplication of efforts exists.” – Karan Saini
His worked example is the I4C portal for reporting child sexual abuse material, which accepts one URL at a time. To report 165 abusive domains he had to zip a password-protected text file, upload it, and paste the password into the complaint’s comment box.
On recruitment, there is no open hiring route into these agencies for security specialists, especially if the entry runs through state or central generalist civil-service examinations.
“Recruitment is the absolute worst. If you are a security geek, why would you be in UPSC circles? If you can become a Babu, why would you want to become a key presser?” – Karan Saini
He can name only one technically minded security professional who cracked the government route, a former UIDAI CISO, and that person has since left India altogether.
On spending, he reviewed the cybersecurity components of the Viksit Bharat 2047 roadmaps during a stint at a policy organisation and found nothing to show for the money.
“Public money on cybersecurity in India is largely wasted. I can’t think of anything which has come out of any of these big projects.” – Karan Saini
He points to C-DAC (Centre for Development of Advanced Computing)-funded projects that “appear to be doing some things which we will have no use for” and money “funnelled into all these IITs to fund nonsense proof of concepts which don’t go anywhere.”
What can be done: Saini’s fix for recruitment already exists inside the same ministry. “MeitY hires consultants. They hire consultants for law, for taxation, but not for security. At least CERT-In could literally do it because it comes under MeitY.” Guttula suggests a similar route on the regulatory side: rotating practitioner representation on task forces, drawn from CERT-In empanelled auditors and independent CISOs with hands-on incident response, alongside the institutional members. ‘A five-year CISO cannot defend against a Mythos class capability,’ he says.
6. Empanelled auditors certify vulnerable infrastructure and keep their empanelment anyway
CERT-In maintains a panel of approved security auditors, and RBI regulation requires regulated entities to file an empanelled auditor’s certificate at least once a year. The infrastructure Srikanth investigated had carried its vulnerability for 13 months, through what should have been multiple audit cycles.
“Somebody would have audited this site. How does one justify a company issuing a cybersecurity audit certificate for an infra that had so many vulnerabilities? Should they be allowed to audit? Or what value do you take on their audit certificate?” – Srikanth L
He draws the parallel with financial auditing, where the same failure mode exists but at least a consequence mechanism has been built.
“Every company that has gone through major financial irregularities would have anyway been audited by a popular audit firm before that… and then the auditor faces a liability punishment. There’s no accountability on the part of auditors [in cyber]. The same thing happens in some other verticals, say a doctor, where the person is incompetent and the incompetence is costing and that is proven, their licenses would be revoked. And that is not happening here.” – Srikanth L
Jonnalagadda’s one direct experience of the audit industry matches this.
“The only experience I’ve had is where I had to call out a cybersecurity audit firm that gave a clean chit in a breach that really happened, where their report said no such thing happened… If I have proof of a breach and the cybersecurity audit firm denies the breach despite my proof, then are we still talking about error of judgment or malice?” – Kiran Jonnalagadda
What can be done: Srikanth points to the financial sector, where a dedicated regulator for audit firms now exists with powers including withdrawing an auditor’s licence, and argues cyber auditing needs “the similar thing.” Guttula notes the regulatory tightening has already begun on the financial side: NFRA inspections of the Big 4 network firms “have repeatedly flagged deficiencies in independence, documentation and professional skepticism,” the RBI now requires IT Strategy Committees led by independent directors with substantial IT expertise, and ICAI is moving to formal Information Systems Audit Standards
7. A compliance security certificate has become the norm and replaced the security standard that it was supposed to represent.
The audit problem above has a mirror inside companies. Compliance is performed for the certificate, and the certificate has become the legal definition of security. Saini traces the loop to the IT Act’s requirement of “reasonable security measures,” a phrase courts and companies have filled with paperwork.
“Reasonable security measures have been interpreted to mean adherence with security standards. ISO 27001, SOC 2, all of this is stemming from the fact that reasonable security measures could mean anything. They don’t have a security program, but they have a certification. So that’s reasonable security measures done.” – Karan Saini
“There are a number of certificate mills where you pay 10,000 rupees and you get your SOC2 and ISO certificate. That’s it.” – Karan Saini
The ex-SISA analyst, who worked at a compliance-and-security firm, describes how the certification is obtained.
“Just to show on paper, they will establish something, but in reality, there won’t be real data protection or continuous monitoring or security infrastructure in place, in a lot of the cases that I’ve seen at least.” – ex-SISA analyst
Guttula, who audits regulated entities for a living, dissects the mechanics from the auditor’s chair.
“Two habits do the damage. First, checklist auditing, where a junior asks whether a patch management policy exists, receives a 50-page document, ticks the box, and never traces whether the critical vulnerability was actually patched. Second, the split reality at audit time: the SOC telemetry lives in one tool while the audit evidence pack lives in a parallel spreadsheet maintained by a junior analyst at month end. The two are joined only for the audit, and the join adds no defensive value.” – Venkata Satish Guttula
“An organisation can look completely secure on paper and remain fundamentally exposed. Green dashboards mask real architectural vulnerabilities, and that gap is exactly where a capable attacker lives. Threat actors do not have a checklist.” – Venkata Satish Guttula
He draws these insights from the research paper he authored in June 2026, titled “The Illusion of Competence: Title Inflation, Juniorization, and the Crisis in Cybersecurity Governance and ICT Auditing.” You can read the paper for free here.
What can be done: Guttula proposes making telemetry the evidence. Telemetry refers to the automated collection and transmission of data from distributed or remote sources to a centralised system, according to IBM. He suggests to have a cybersecurity detection events from Security Operations Centers in a common standardised language that can be understood by everyone. In his opinion, this will enable the auditors to identify the issues and the audit becomes an extract from live telemetry rather than a reconstruction assembled separately while auditing. However, this can only apply for detective controls that generate telemetry and design or governance controls might still need their own framework.
Detection events from the M-SOC and entity SOCs can be tagged at source using a common vocabulary mapped to other cyber-related institutes like Cybersecurity and Cyber Resilience Framework (CSCRF), National Critical Information Infrastructure Protection Centre (NCIIPC) and CERT-In.
8. Outside the regulated banking sector, Indian companies treat cybersecurity as a lowest priority and an additional cost that needs to be minimised.
Most of the speakers agreed that several companies in India treat cybersecurity as their least priority and
“In most enterprises, the problem with security is it costs money. The top guy, the CEO, will be focused on building the business and the marketing side of things. Security will be a low priority for a lot of these people.” – ex-SISA analyst
“It is entirely a market concern where if you are not part of a regulated industry where you know you’ll be taken by the collar, which is only banks. Because there are no stakes, even with the Digital Personal Data Protection Act, who cares?” – Karan Saini
Jonnalagadda emphasises the overall community advantages of good coordination in knowledge sharing, arguing that lack of community benefits is also disincentivising companies from public disclosures.
“It is not a technical cost, it’s an HR cost… Unlike the US system, in India, nobody helps you. Therefore, everybody is watching their own back when it comes to security. Which is a lot of labor.” – Kiran Jonnalagadda
Srikanth complicates the cost argument from the engineering side. In his experience the expense is a function of organisational maturity, but disappears team-level that builds things.
“There are organizations where this is seen as extra cost. And then there are organizations where, by the quality of hires and the quality of tools and processes, these costs are basically auto-absorbed. So it doesn’t cost anything extra to ensure that security guarantee.” – Srikanth L
9. Basic security awareness is missing at every layer of the software supply chain, from developers to procurement to end users
Srikanth’s dissection of the bank.in portal vulnerability found no single point of failure; nobody in the chain applied elementary security thinking.
“This is a very rookie thing… In the entire organization, in that private company that’s the vendor here, there is nobody who had basic security consciousness. And this consciousness has to basically come from education. Why will you leave an unauthenticated endpoint?” – Srikanth L
The ex-SISA analyst saw the same pattern in the recent CBSE case, where credentials sat in plain sight in the page source.
“They’ve openly left the master key or password just open there, which is not even a hack. It’s basically you’re opening a book and reading it.” – ex-SISA analyst
What can be done: Srikanth said that the security consciousness “has to come from education,” and built into how developers are trained, so that standard secure practices become second nature the way type-checking now runs in an editor, at no marginal cost.
10. Attackers have already put AI into their workflow, while defenders might have to wait for budget cycles and circulars
With AI, every weakness above is now exposed to adversaries operating at machine speed. Srikanth, who used AI tooling in his own recent disclosure of security vulnerabilities in Bank.in domains, describes what has changed.
“The thing that models bring in is the agility with which they can detect vulnerabilities, how they can quickly compound vulnerabilities which would have taken days and months for humans to compound. If you do it on an agentic speed, you’re basically doing it several orders of magnitude faster.” – Srikanth L
His own case supplies the arithmetic. The investigation and the 30-page report that would once have taken him ten days took a couple of days with AI orchestration; the fix, which he describes as trivial, took the operator 16 days.
The ex-SISA analyst identifies the same shift as the present threat, ahead of speculative ones like quantum computing.
“Given that AI is advancing, people can automate certain tasks and build malware just out of prompts and stuff. That’s a whole different threat which really exists, which is the real threat that exists now.” – ex-SISA analyst
Guttula also highlights this institutional asymmetry through the possible bureaucratic hurdles that the government institutions have to face.
“Attackers have already pulled capable AI into their workflow. They do not take management approval, run a change board, or write a risk register entry before they act. Defenders wait for a budget cycle and a circular. The asymmetry is no longer subtle.” – Venkata Satish Guttula
What can be done: Guttula’s core proposal is to build internal AI capabilities across five key areas: detection, triage (where the most urgent problems are dealt with first), threat-intelligence correlation, log analysis, and red teaming. His specific recommendations are as follows:
- Strengthen advisory language: He argues that phrases like “where suitable” and “where possible” are effectively treated as optional and should therefore be replaced with firmer, more directive wording.
- Make AI models the default cyber hygiene maintainers with human intervention: He also suggested that AI-assisted assessment should become the default expectation for cybersecurity, with human validation and data-boundary controls, and a documented justification to opt out.
- Mandate data residency and an Indian data plane: ‘Given the RBI’s April 2018 localisation mandate where payment data is involved, and the cross-border transfer restrictions under Section 16 of the DPDP Act, expected to commence in 2027.
- Deploy ensembles of genuinely diverse AI models that encourage human intervention: When a high-fidelity model sharply disagrees with the rest of the ensemble, that divergence should trigger a human-led investigation, rather than being dismissed as noise.
- Establish behavioural baselines over both short and extended windows: Guttula cautions that “a Mythos‑class capability does not leave neat single‑event signatures,” meaning that threat detection cannot rely solely on immediate alerts. Instead, systems should monitor activity across both narrow timeframes and extended 30‑to‑90‑day horizons to expose latent, persistent intrusions.
Also Read: