Science & Technology
Cyber Threats and Cyber Security
CERT-In does not stop cyberattacks, it watches, warns and coordinates the response, and knowing that its power is legal and informational rather than technical is the whole answer to most questions about it.
Syllabus Prelims: General ScienceMains GS3: Communication networks, media, cyber security, External state and non-state actors
CERT-In: watch, warn, coordinate, not fight directly
The Indian Computer Emergency Response Team (CERT-In), operating under the Ministry of Electronics and Information Technology, is India's designated national agency for cyber incident response, mandated by Section 70B of the Information Technology Act, 2000.
Its role is best understood by what it actually does: real-time monitoring of cyber threats across the country, prevention through advisories and guidelines issued to organisations, and coordination between affected parties and stakeholders during an actual incident to contain and mitigate it. CERT-In is not a technical strike force that goes and neutralises an attacker's infrastructure directly; it is the nerve centre for detection, warning, and organising a coordinated response, which is a legal and coordinating role rather than a purely technical one. This distinction, between watching and warning versus actively fighting, is worth holding precisely because it is the detail a question is most likely to probe.
CERT-In has also issued binding directions on information security practices, requiring organisations to report specified categories of cyber incidents within a fixed time window and to maintain logs for a set retention period, which converts its advisory role into an enforceable one for the categories the directions cover.
The Digital Personal Data Protection Act, 2023: what it actually regulates
The Digital Personal Data Protection Act, 2023 is India's comprehensive law governing how digital personal data is processed, built to balance an individual's right to have their personal data protected against the legitimate need for lawful data processing by businesses and government.
The Digital Personal Data Protection Rules, 2025, notified in November 2025, are what actually operationalise the Act, since the Act itself sets out principles while the rules specify the detailed procedures organisations must follow to comply. This two-stage structure, a principles-based Act followed by detailed operational rules, is a common pattern in Indian digital-governance legislation and is worth recognising as a pattern rather than memorising as a one-off feature of this particular Act.
The overlap worth being precise about
CERT-In and the Data Protection Act address two related but genuinely distinct problems, and a question can test whether you keep them apart. CERT-In's job is responding to and coordinating against active cyber incidents and threats, regardless of whether personal data is involved at all. The Data Protection Act's job is governing the lawful processing of personal data, regardless of whether a cyberattack is involved at all. A data breach caused by a cyberattack triggers both frameworks simultaneously, one covering the incident response, the other covering the data-handling obligations that were violated, but the two exist to answer different questions.
Quick revision points
- CERT-In: under MeitY, mandated by Section 70B of the IT Act, 2000. Its role is monitoring, prevention (advisories) and coordination during an incident, not directly neutralising an attacker's infrastructure. Issues binding directions requiring incident reporting within a fixed window and log retention.
- Digital Personal Data Protection Act, 2023: governs processing of digital personal data, balancing individual protection against lawful business/government use. The DPDP Rules, 2025 (notified November 2025) operationalise the Act's principles into detailed procedures, a common Act-then-rules pattern in Indian digital law.
- Keep the two frameworks apart: CERT-In addresses cyber incidents generally; the DPDP Act addresses lawful personal-data processing generally. A breach can trigger both at once, but they answer different questions.
Put it into practice
Practise 2 questions on Cyber Threats and Cyber Security
Test your grasp of Cyber Security Governance with real UPSC Prelims questions, each with a detailed explanation and its reference-book chapter.
Practise now →Sources