Discuss the potential threats of Cyber attack and the security framework to prevent it.
Approach · directive: “discuss”
What it asks · Describe the kinds of cyber attack India faces and the legal, institutional and technical framework meant to prevent them.
The question has 2 parts — answer each
- Discuss the potential threats of cyber attack
- Discuss the security framework to prevent it
Open with · As banking, power, transport and government services move online, cyber attacks can steal data, freeze services and even damage critical infrastructure.
Cover
- Threats: ransomware such as WannaCry (2017), malware, phishing, denial-of-service attacks and financial fraud.
- Larger threats: attacks on critical infrastructure such as power grids, telecom and banking, state-sponsored espionage and cyber terrorism.
- Vulnerabilities: dependence on imported hardware and software, low awareness, weak passwords, shortage of skilled staff and poor reporting.
- Law: the Information Technology Act, 2000 (amended 2008) penalises hacking and cyber terrorism and provides for protected systems.
- Institutions: CERT-In for incident response, NCIIPC for critical information infrastructure, a National Cyber Security Coordinator and the National Cyber Security Policy, 2013.
- Practice: sectoral security guidelines such as RBI's, audits, cyber-crime cells and the Cyber Swachhta Kendra.
- Gaps: no dedicated data protection law in 2017, few trained officials and weak international cooperation; needs capacity building and stronger public-private partnership.
Close with · Cyber security needs strong law, alert institutions, skilled people and aware citizens working together, since the weakest link decides the strength of the chain.
Question: UPSC's CS (Main) 2017, GS Paper III — paper ↗. Approach: Minimalist IAS, checked 30 Sept 2026 (how we verify) — UPSC publishes no model answers. ·
Model answer · 232 words (UPSC limit 150) · Minimalist IAS
As banking, power, transport and government services move online under Digital India, cyber attacks can steal data, freeze services and even damage critical infrastructure.
Potential threats
- Malware and ransomware: WannaCry (2017) locked systems worldwide; phishing, denial-of-service attacks and financial fraud target banks and citizens.
- Critical infrastructure: attacks on power grids, telecom, banking and transport can paralyse the economy; state-sponsored espionage and cyber terrorism threaten national security.
- Data theft: the 2016 debit card breach forced Indian banks to block and reissue cards on a large scale.
- Vulnerabilities: imported hardware and software, weak passwords, low awareness, shortage of skilled staff and poor incident reporting.
Security framework
- Law: the Information Technology Act, 2000 (amended 2008) penalises hacking (Section 66) and cyber terrorism (Section 66F), shields designated 'protected systems' (Section 70) and makes firms liable for lax data security (Section 43A).
- Institutions: CERT-In for incident response, NCIIPC for critical information infrastructure, a National Cyber Security Coordinator, and the National Cyber Security Policy, 2013.
- Practice: RBI's cyber security framework for banks (2016), sectoral audits, police cyber-crime cells and the Cyber Swachhta Kendra (2017) for cleaning infected devices.
- Gaps: no data protection law in 2017 (the Justice B.N. Srikrishna committee was set up that year), few trained officials, and India outside the Budapest Convention on cybercrime.
Strong law, alert institutions, skilled people and aware citizens must work together, because the weakest link decides the strength of the chain.
Written by Minimalist IAS from facts checked at source (how we verify) — a little fuller than exam length, so every part of the question is covered; in the hall, keep the structure and trim the detail. UPSC publishes no model answers: compare your structure and coverage with this, then write your own.