Minimalist IAS
2021 GS Paper III

UPSC CSE (Main) 2021 · GS Paper III · Question 10

Keeping in view India’s internal security, analyse the impact of cross-border cyber attacks. Also discuss…

Syllabus line: Cyber security, media & money-laundering — “Challenges to internal security through communication networks, role of media and social networking sites in internal security challenges, basics of cyber security; money-laundering and its prevention.”

GS Paper III 2021 · Q10

10 marks · 150 words Cyber security, media & money-laundering

Keeping in view India’s internal security, analyse the impact of cross-border cyber attacks. Also discuss defensive measures against these sophisticated attacks.

Approach · directive: “analyse / discuss”

What it asks · Analyse how cross-border cyber attacks threaten internal security (infrastructure, espionage, crime and terror, information) and discuss the defensive measures available.

The question has 2 parts — answer each

  1. Analyse the impact of cross-border cyber attacks on India's internal security: infrastructure, espionage, crime and terror, information, attribution
  2. Discuss defensive measures against these attacks: institutions, law, technology and the way forward

Open with · India's growing digital dependence has made cyberspace a domain where hostile states and non-state actors can strike across borders with deniability.

Cover

  • Critical infrastructure: attacks on power, nuclear, ports, banks and telecom can disrupt services; in 2019 malware was found in the Kudankulam plant's administrative network, which NPCIL said was isolated from plant control systems.
  • Espionage and data theft: state-linked groups target defence, government and strategic sectors; stolen data weakens military and diplomatic security.
  • Crime, terror and information war: ransomware, online fraud and crypto payments fund crime and terror; social media spreads radicalisation and disinformation to trigger unrest.
  • Attribution problem: attacks are routed through proxies and non-state groups, so deterrence and legal response are hard; evidence and jurisdiction lie abroad.
  • Institutions: CERT-In for incident response, NCIIPC (2014) for critical information infrastructure, the Defence Cyber Agency (established 2018) for military networks and I4C (inaugurated January 2020) for cybercrime coordination.
  • Law and technology: IT Act provisions including cyber terrorism (s.66F), security audits, trusted-source rules for telecom, blocking of hostile apps and a data-protection law.
  • Way forward: sector CERTs, mandatory incident reporting, skilled workforce, indigenous hardware and software, and partnerships on norms and evidence sharing.

Close with · Resilience, not only prevention, is the goal: assume breaches, detect early, recover fast and build deterrence with partners.

Add value (verified)

Question: UPSC's CS (Main) 2021, GS Paper III — paper ↗. Approach: Minimalist IAS, checked 30 Sept 2026 (how we verify) — UPSC publishes no model answers. ·

Model answer · 222 words (UPSC limit 150) · Minimalist IAS

As grids, payments, governance and defence go digital, hostile states and proxies can strike India from abroad with deniability, making cyberspace an internal-security front.

Impact on internal security

  • Critical infrastructure: attacks on power, nuclear, ports, banks and telecom can halt services; in 2019 malware was found in the Kudankulam plant's administrative network, isolated from control systems according to NPCIL.
  • Espionage: state-linked groups target defence, government and strategic sectors; stolen data erodes military and diplomatic advantage.
  • Crime and terror: ransomware, online fraud and crypto channels fund crime and terror networks.
  • Information war: disinformation and radicalisation on social media aim to trigger unrest and communal tension.
  • Attribution: attacks routed through proxies and foreign servers leave evidence and jurisdiction abroad, weakening deterrence and prosecution.

Defensive measures

  • Institutions: CERT-In, the national agency under the IT Act for incident response; NCIIPC (2014) for critical information infrastructure; the Defence Cyber Agency (2018) for military networks; I4C (January 2020) for cybercrime coordination.
  • Law: IT Act section 66F on cyber terrorism, mandatory security audits, trusted-source rules for telecom equipment, blocking of hostile apps and a data-protection law.
  • Way forward: sectoral CERTs and mandatory incident reporting, a skilled workforce, indigenous hardware and software, regular drills, and partnerships on cyber norms and evidence sharing.

Resilience, not prevention alone, is the goal: assume breaches, detect early, recover fast and build deterrence with partners.

Written by Minimalist IAS from facts checked at source (how we verify) — a little fuller than exam length, so every part of the question is covered; in the hall, keep the structure and trim the detail. UPSC publishes no model answers: compare your structure and coverage with this, then write your own.

Also asked on this syllabus line

All questions on Cyber security, media & money-laundering →

Build the base: Prelims PYQs on this