Minimalist IAS
GS Paper III

Mains · GS Paper III · 16 questions

Cyber security, media & money-laundering

Every question UPSC has set on this line of the GS Paper III syllabus, newest first — with an approach for each.

Questions per year: 2016: 1, 2017: 2, 2018: 1, 2019: 1, 2020: 1, 2021: 2, 2022: 1, 2023: 1, 2024: 2, 2025: 0, 2026: 2 Asked in 10 of 11 years

UPSC syllabus (verbatim): “Challenges to internal security through communication networks, role of media and social networking sites in internal security challenges, basics of cyber security; money-laundering and its prevention.”

2026

GS Paper III 2026 · Q9

10 marks · 150 words

Explain how fake news and disinformation pose threat to Internal Security and Public Order in Indian context ? In this regard, discuss salient features of amendments in respect of Information Technology (Intermediatory Guidelines and Digital Media Ethics Code) Rules 2021.

Approach · directive: “explain / discuss”

What it asks · Explain how fake news and disinformation endanger internal security and public order in India, and outline the main amendments made to the IT Rules, 2021.

The question has 2 parts — answer each

  1. Explain how fake news and disinformation threaten internal security and public order in India
  2. Discuss the salient features of the amendments to the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021

Open with · Falsehoods now travel faster than corrections; in India, rumours on messaging apps have triggered lynchings, riots and panic.

Cover

  • Public order: mob violence over rumours (child-lifting messages), communal incitement, panic buying and vaccine hesitancy.
  • Internal security: propaganda and radicalisation by hostile states and terror groups, especially during conflicts; deepfakes impersonating leaders and officials.
  • Institutions: election misinformation and erosion of trust in agencies, media and courts.
  • 2022 amendment: Grievance Appellate Committees to hear users' appeals against platform decisions; stronger due-diligence duties on intermediaries.
  • 2023 amendment: online gaming rules and a government Fact Check Unit — the latter struck down by the Bombay High Court in 2024.
  • 2025 amendment: takedown notices under Rule 3(1)(d) only from senior officers (Joint Secretary or DIG), stating the legal basis, with monthly Secretary-level review.
  • 2026 amendment: defines synthetically generated information; mandatory labels and metadata for AI content; takedown within three hours of a court order or government intimation.

Close with · Countering disinformation needs law, fast fact-checking, platform accountability and media literacy — without chilling free speech under Article 19.

Add value (verified)

  • The February 2026 amendment requires platforms to label permissible AI-generated content and attach traceable metadata. PIB — MeitY reply in Lok Sabha (25 March 2026) ↗“Platforms are also required to ensure clear labelling and traceable metadata for permissible AI-generated content, so that users can easily identify synthetically generated material and prevent deception or misuse”
  • Unlawful content must now be removed within three hours of a court order or a reasoned government intimation. PIB — MeitY reply in Lok Sabha (25 March 2026) ↗“Social media platforms and other intermediaries are required to remove unlawful content within three hours of the receipt of an order of a court of competent jurisdiction or a reasoned intimation by the Appropriate Government or its agency”

Question: UPSC's CS (Main) 2026, GS Paper III — paper ↗. Approach: Minimalist IAS, checked 30 Sept 2026 (how we verify) — UPSC publishes no model answers. ·

Model answer · 213 words (UPSC limit 150) · Minimalist IAS

Falsehoods now travel faster than corrections: in India, rumours on messaging apps have triggered lynchings, riots and panic within hours.

Threat to internal security and public order

  • Public order: child-lifting rumours have led to mob lynchings; doctored videos incite communal violence; false alerts trigger panic buying and vaccine hesitancy.
  • Internal security: hostile states and terror groups run propaganda and radicalisation campaigns, most intensely during conflicts; deepfakes impersonate leaders and officials.
  • Institutions: election misinformation and manufactured distrust in agencies, media and courts erode the legitimacy on which order rests.

Amendments to the IT Rules, 2021

  • 2022: Grievance Appellate Committees to hear users' appeals against platform decisions, and stronger due-diligence duties on intermediaries.
  • 2023: rules for online gaming and a government Fact Check Unit to flag false content about the Union government; the Bombay High Court struck the unit down in 2024.
  • 2025: takedown notices under Rule 3(1)(d) only from officers of Joint Secretary or DIG rank, stating the legal basis, with monthly review at Secretary level.
  • 2026: 'synthetically generated information' defined; mandatory labels and traceable metadata for AI-generated content; unlawful content to be removed within three hours of a court order or reasoned government intimation.

Countering disinformation needs law, fast fact-checking, platform accountability and media literacy, without chilling the free speech Article 19 protects.

Written by Minimalist IAS from facts checked at source (how we verify) — a little fuller than exam length, so every part of the question is covered; in the hall, keep the structure and trim the detail. UPSC publishes no model answers: compare your structure and coverage with this, then write your own.

GS Paper III 2026 · Q20

15 marks · 250 words

Discuss counterfeit currency and money laundering as major sources of terror funding in India. State the actions being taken at International level to check these menaces. Highlight the role of Financial Action Task Force (FATF) and methods of compliance by its member states in preventing terror funding.

Approach · directive: “discuss / state / highlight”

What it asks · Discuss counterfeit currency and money laundering as channels of terror finance in India, the international measures against them, FATF's role and how member states comply.

The question has 3 parts — answer each

  1. Discuss counterfeit currency and money laundering as major sources of terror funding in India
  2. State the actions being taken at the international level to check these menaces
  3. Highlight the role of FATF and the methods of compliance by its member states in preventing terror funding

Open with · Terror groups need money for recruitment, weapons and propaganda; choking finance is as important as neutralising cadres.

Cover

  • Counterfeit currency: high-quality fake notes printed abroad and pushed through porous borders fund terror and weaken the economy.
  • Money laundering: hawala, cash smuggling, misuse of charities and NGOs, shell companies, trade-based laundering, narco-terror links, crypto-assets.
  • India's response: UAPA, PMLA, NIA's terror-funding cell, FICN coordination group, FIU-India, cooperation with neighbours.
  • International: UN Convention for the Suppression of the Financing of Terrorism (1999), UNSC Resolutions 1373 and 2462, Egmont Group, 'No Money for Terror' (Delhi, 2022).
  • FATF (1989): 40 Recommendations, peer mutual evaluations, grey and black lists that press non-compliant states such as Pakistan.
  • Compliance methods: national risk assessments, criminalising terror financing, targeted financial sanctions, beneficial ownership, KYC and suspicious transaction reports, regulating virtual assets.
  • India's 2024 mutual evaluation placed it in 'regular follow-up'; faster prosecutions and oversight of non-profits remain priorities.

Close with · Financial intelligence, international cooperation and swift prosecution together can cut the money lifelines of terror.

Add value (verified)

Question: UPSC's CS (Main) 2026, GS Paper III — paper ↗. Approach: Minimalist IAS, checked 30 Sept 2026 (how we verify) — UPSC publishes no model answers. ·

Model answer · 270 words (UPSC limit 250) · Minimalist IAS

Terror groups need money for recruitment, weapons and propaganda; choking that money is as important as neutralising cadres.

Counterfeit currency and money laundering

  • Counterfeit currency: high-quality fake Indian currency notes printed abroad and pushed through porous borders finance terror while eroding trust in the currency.
  • Money laundering: hawala transfers, cash smuggling, misuse of charities and NGOs, shell companies, trade-based laundering, narco-terror networks and, increasingly, crypto-assets.
  • India's response: UAPA and PMLA, NIA's terror-funding cell, the FICN coordination group, FIU-India's financial intelligence and cooperation with neighbours.

International action

  • The UN Convention for the Suppression of the Financing of Terrorism (1999); UNSC Resolutions 1373 (2001) and 2462 (2019), which oblige states to criminalise and prevent terror finance; the Egmont Group of financial intelligence units; the 'No Money for Terror' ministerial conference hosted in Delhi in 2022.

FATF's role

  • Set up in 1989, FATF sets the global standard through its 40 Recommendations, assesses countries through peer mutual evaluations, and uses its grey and black lists to press non-compliant states, Pakistan being the prominent example.

Methods of compliance by member states

  • Prevention: national risk assessments; criminalising terror financing as a standalone offence; beneficial-ownership transparency; KYC, record-keeping and suspicious transaction reports by banks and other reporting entities; regulation of virtual asset service providers.
  • Enforcement: targeted financial sanctions that freeze designated persons' assets without delay; supervision of non-profits vulnerable to abuse; cross-border cooperation and extradition.
  • India: the 2024 mutual evaluation placed it in 'regular follow-up', a category shared with only four other G20 countries; faster prosecutions and oversight of non-profits remain priorities.

Financial intelligence, international cooperation and swift prosecution together can cut the money lifelines of terror.

Written by Minimalist IAS from facts checked at source (how we verify). UPSC publishes no model answers: compare your structure and coverage with this, then write your own.

2024

GS Paper III 2024 · Q10

10 marks · 150 words

Describe the context and salient features of the Digital Personal Data Protection Act, 2023.

Approach · directive: “describe”

What it asks · Explain why India needed a data-protection law and list its main provisions.

The question has 2 parts — answer each

  1. Describe the context of the DPDP Act 2023: the privacy judgment, committee, earlier Bills and the digital economy's needs
  2. Describe its salient features: scope, consent, rights, duties, children, cross-border transfer, Board, penalties and exemptions

Open with · The Supreme Court's recognition of privacy as a fundamental right in K.S. Puttaswamy (2017) made a data-protection law a constitutional necessity.

Cover

  • Context: a large digital economy, data breaches, the Justice B.N. Srikrishna Committee (2018) and the withdrawn 2019 Bill.
  • Scope: digital personal data processed in India, and abroad if it involves offering goods or services to people in India.
  • Consent and notice, with defined 'legitimate uses'; Data Principals get rights to access, correction, erasure, grievance redress and nomination.
  • Data Fiduciaries must secure data and report breaches; Significant Data Fiduciaries need a data protection officer, audits and impact assessments.
  • Children's data needs verifiable parental consent; tracking and targeted advertising at children are barred.
  • Cross-border transfer allowed except to notified countries; Data Protection Board adjudicates; wide exemptions for the State are criticised.

Close with · The Act is a strong start; its credibility will depend on an independent Board, narrow State exemptions and careful implementation.

Add value (verified)

Question: UPSC's CS (Main) 2024, GS Paper III — paper ↗. Approach: Minimalist IAS, checked 30 Sept 2026 (how we verify) — UPSC publishes no model answers. ·

Model answer · 214 words (UPSC limit 150) · Minimalist IAS

The Supreme Court's recognition of privacy as a fundamental right in K.S. Puttaswamy (2017) made a data-protection statute a constitutional necessity; the Digital Personal Data Protection Act, 2023 is India's first such law.

Context

  • A vast digital economy — Aadhaar, UPI and platforms processing personal data — with recurring breaches; the Justice B.N. Srikrishna Committee (2018), whose draft became the 2019 Bill, withdrawn in 2022 after a Joint Parliamentary Committee review.

Salient features

  • Scope: digital personal data processed in India, and abroad when goods or services are offered to people in India.
  • Consent-based processing with clear notice, plus defined 'legitimate uses'; Data Principals get rights of access, correction, erasure, grievance redress and nomination.
  • Duties: Data Fiduciaries must secure data and report breaches; Significant Data Fiduciaries need a data protection officer, audits and impact assessments.
  • Children: verifiable parental consent, with tracking and targeted advertising barred.
  • Cross-border transfer allowed except to countries the Centre notifies.
  • Enforcement: a Data Protection Board adjudicates; penalties up to ₹250 crore for failing to prevent breaches.
  • Concerns: wide exemptions for the State, an executive-appointed Board, and dilution of the RTI Act's personal-information clause.

The Act is a strong start (its Rules were notified on 14 November 2025); its credibility now rests on an independent Board, narrow State exemptions and careful implementation.

Written by Minimalist IAS from facts checked at source (how we verify) — a little fuller than exam length, so every part of the question is covered; in the hall, keep the structure and trim the detail. UPSC publishes no model answers: compare your structure and coverage with this, then write your own.

GS Paper III 2024 · Q20

15 marks · 250 words

Social media and encrypting messaging services pose a serious security challenge. What measures have been adopted at various levels to address the security implications of social media? Also suggest any other remedies to address the problem.

Approach · directive: “what / suggest”

What it asks · Explain the security risks of social media and encrypted messaging, list legal, institutional and platform-level measures, and suggest further remedies.

The question has 3 parts — answer each

  1. Explain the security challenge posed by social media and encrypted messaging
  2. What measures have been adopted at various levels: legal, institutional, platform and international
  3. Suggest other remedies to address the problem

Open with · Social media and end-to-end encrypted apps have become channels for radicalisation, disinformation and covert coordination that the State cannot easily see.

Cover

  • Challenges: fake news and deepfakes triggering violence, terror recruitment, cross-border propaganda, and encrypted planning.
  • Legal: IT Act 2000 — Section 69A blocking (upheld in Shreya Singhal, 2015); IT Rules 2021 on due diligence, grievance officers and takedowns.
  • Institutional: CERT-In, the Indian Cyber Crime Coordination Centre (I4C), cyber cells, and Grievance Appellate Committees.
  • Platform level: content moderation, fact-checking partnerships, and in-country compliance officers for large platforms.
  • Remedies: digital and media literacy, AI tools to detect deepfakes and coordinated campaigns, and faster MLAT-based cooperation.
  • Balance: any lawful access must be narrow, judicially overseen and consistent with the privacy right and the DPDP Act.

Close with · Security in the digital age needs smart regulation, capable agencies and alert citizens — without trading away privacy and free speech.

Add value (verified)

Question: UPSC's CS (Main) 2024, GS Paper III — paper ↗. Approach: Minimalist IAS, checked 30 Sept 2026 (how we verify) — UPSC publishes no model answers. ·

Model answer · 278 words (UPSC limit 250) · Minimalist IAS

Social media and end-to-end encrypted apps have become channels for radicalisation, disinformation and covert coordination that the State cannot easily see — a security challenge that sits uneasily beside the right to privacy.

The security challenge

  • Fake news and deepfakes that trigger communal violence; terror recruitment and propaganda; cross-border influence operations; encrypted planning that evades interception; and cyber-frauds run through platforms.

Measures adopted

  • Legal: Section 69A of the IT Act 2000 for blocking (upheld in Shreya Singhal, 2015) and Section 69 for lawful interception; the IT Rules 2021 requiring due diligence, grievance officers, timely takedowns and, for large messaging platforms, identification of the first originator for serious offences; the Telecommunications Act 2023 and the DPDP Act 2023.
  • Institutional: CERT-In for incident response, the Indian Cyber Crime Coordination Centre (I4C) with the 1930 helpline and reporting portal, State cyber cells, and Grievance Appellate Committees (2023).
  • Platform level: content moderation, fact-checking partnerships, in-country compliance officers for significant intermediaries, and transparency reports.
  • International: mutual legal assistance treaties and cooperation through Interpol and the UN process on a cybercrime convention.

Further remedies

  • Digital and media literacy in schools and communities to blunt disinformation at its source.
  • AI tools to detect deepfakes and coordinated inauthentic behaviour, with mandatory labelling of synthetic media.
  • Faster, treaty-based access to evidence held by foreign platforms, and a dedicated cyber cadre in State police.
  • Narrow, judicially overseen lawful-access rules that keep encryption intact rather than weaken it for everyone.
  • Independent oversight of blocking orders and periodic government transparency reports to sustain public trust.

Security in the digital age needs smart regulation, capable agencies and alert citizens — without trading away the privacy and free speech the Constitution protects.

Written by Minimalist IAS from facts checked at source (how we verify) — a little fuller than exam length, so every part of the question is covered; in the hall, keep the structure and trim the detail. UPSC publishes no model answers: compare your structure and coverage with this, then write your own.

2023

GS Paper III 2023 · Q20

15 marks · 250 words

Give out the major sources of terror funding in India and the efforts being made to curtail these sources. In the light of this, also discuss the aim and objective of the ‘No Money for Terror (NMFT)’ Conference recently held at New Delhi in November 2022.

Approach · directive: “give out / discuss”

What it asks · Identify the main sources of terror funding, the measures taken to cut them, and explain the aim and objectives of the November 2022 'No Money for Terror' conference in New Delhi.

The question has 3 parts — answer each

  1. Identify the main sources of terror funding in India
  2. Set out the measures taken to curtail those sources
  3. Discuss the aim and objectives of the November 2022 'No Money for Terror' Conference in New Delhi

Open with · Terror groups depend on money as much as on weapons, so choking their funds is central to counter-terrorism.

Cover

  • Sources: state sponsorship and cross-border support, hawala and informal channels, fake currency, drug trafficking and smuggling, extortion, and misuse of charities and non-profits.
  • New channels: crowdfunding, virtual assets and online payment platforms, and shell companies.
  • Legal steps: UAPA (amended in 2004 and 2019) makes terror financing an offence; PMLA 2002 (virtual asset providers brought in 2023); action by FIU-IND, the NIA's terror-funding and fake-currency cell, ED and NCB.
  • Policy steps: KYC and reporting norms, monitoring of hawala, demonetisation (2016) against fake currency, and India's FATF membership since 2010.
  • NMFT conference (18-19 November 2022): the third ministerial conference after Paris (2018) and Melbourne (2019), aimed at reviewing the global counter-terror-financing regime and agreeing coordinated steps.
  • Objectives: examine global trends in terror financing, formal and informal fund channels, emerging technologies, and international cooperation; India offered to host a permanent NMFT secretariat.
  • Way forward: tighter action against state sponsors, FATF-style peer pressure, regulation of virtual assets, and intelligence and legal cooperation.

Close with · Sustained international cooperation and strict domestic enforcement are needed to deny terrorists the money that sustains them.

Add value (verified)

Question: UPSC's CS (Main) 2023, GS Paper III — paper ↗. Approach: Minimalist IAS, checked 30 Sept 2026 (how we verify) — UPSC publishes no model answers. ·

Model answer · 275 words (UPSC limit 250) · Minimalist IAS

Terror groups need money as much as weapons, for recruits, arms, safe houses and propaganda, so choking their funds is central to counter-terrorism.

Major sources of terror funding

  • State sponsorship and cross-border support routed through handlers.
  • Hawala and other informal value-transfer channels.
  • Fake Indian currency notes pushed across the border.
  • Drug trafficking and smuggling, especially narco-terror through Punjab and Jammu and Kashmir.
  • Extortion by insurgent and Maoist groups.
  • Misuse of charities and non-profits, and newer channels: crowdfunding, virtual assets, online payment platforms and shell companies.

Efforts to curtail them

  • Law: UAPA, amended in 2004 and 2019, makes terror financing an offence; PMLA 2002 targets laundering, with virtual-asset service providers brought under it in 2023.
  • Agencies: FIU-IND tracks suspicious transactions; the NIA's terror-funding and fake-currency cell investigates; ED and NCB act on laundering and narcotics.
  • Policy: KYC and reporting norms for banks and payment firms, monitoring of hawala, demonetisation in 2016 against fake currency, and FATF membership since 2010 for peer review.

The No Money for Terror Conference, November 2022

  • Aim: the third ministerial conference (18-19 November 2022), after Paris (2018) and Melbourne (2019), reviewed the global regime against terror financing and sought coordinated action among states.
  • Objectives: examine global trends in terror financing; map formal and informal fund channels; address emerging technologies such as virtual assets; and deepen international cooperation.
  • India offered to host a permanent NMFT secretariat to keep the effort continuous.

Way forward

  • Sustained pressure on state sponsors, FATF-style peer review, regulation of virtual assets, and faster intelligence and legal cooperation across borders.

Denying terrorists their money needs strict domestic enforcement and sustained international cooperation, the very agenda the New Delhi conference set.

Written by Minimalist IAS from facts checked at source (how we verify). UPSC publishes no model answers: compare your structure and coverage with this, then write your own.

2022

GS Paper III 2022 · Q19

15 marks · 250 words

What are the different elements of cyber security ? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy.

Approach · directive: “what / examine the extent”

What it asks · List the elements of cyber security, then assess how far India has built a comprehensive national cyber security strategy in view of current challenges.

The question has 2 parts — answer each

  1. What: the different elements of cyber security
  2. Examine, keeping the challenges in view, the extent to which India has developed a comprehensive National Cyber Security Strategy: what exists, what is missing and a verdict

Open with · Cyber security protects networks, devices and data across government, business and citizens, and a national strategy ties the technical, legal and institutional pieces together.

Cover

  • Technical elements: network, application, endpoint and cloud security, identity and access control, data protection and encryption, incident response and recovery, and user awareness.
  • National elements: protection of critical information infrastructure, law and policy, institutions, a skilled workforce, research and international cooperation.
  • Challenges: state-linked and criminal attacks, ransomware and data breaches, dependence on foreign hardware and software, IoT and 5G expansion, skill shortages and under-reporting.
  • India's framework: IT Act, 2000 (amended 2008), CERT-In, NCIIPC for critical infrastructure, National Cyber Security Policy 2013, the Indian Cyber Crime Coordination Centre and the Defence Cyber Agency.
  • Gaps: the 2013 policy is dated and a full national strategy was still awaited at the time of the paper; agency roles overlap, and state capacity and private-sector obligations are limited.
  • Way forward: a published, funded strategy with clear roles, mandatory incident reporting, standards and audits, indigenous technology, skilling, public-private partnership and treaty cooperation.

Close with · India has built many of the pieces; what remains is a single, well-resourced strategy with clear accountability.

Add value (verified)

  • CERT-In directions of 28 April 2022 (under section 70B(6) of the IT Act, 2000): service providers, intermediaries, data centres, body corporates and government organisations must report cyber incidents to CERT-In within 6 hours of noticing them. Directions under sub-section (6) of section 70B of the Information Technology Act, 2000 — CERT-In, 28 April 2022 ↗“Any service provider, intermediary, data centre, body corporate and Government organisation shall mandatorily report cyber incidents as mentioned in Annexure I to CERT-In within 6 hours of noticing such incidents or being brought to notice about such incidents.”

Question: UPSC's CS (Main) 2022, GS Paper III — paper ↗. Approach: Minimalist IAS, checked 30 Sept 2026 (how we verify) — UPSC publishes no model answers. ·

Model answer · 270 words (UPSC limit 250) · Minimalist IAS

Cyber security protects the networks, devices and data of government, business and citizens; a national strategy ties the technical, legal and institutional pieces into one plan with clear accountability.

Elements of cyber security

  • Technical: network, application, endpoint and cloud security; identity and access control; data protection and encryption; incident response and recovery.
  • Human: user awareness, a skilled workforce and a security culture in organisations.
  • National: protection of critical information infrastructure, law and policy, institutions, research and international cooperation.

Challenges

  • State-linked and criminal attacks, ransomware and data breaches, dependence on foreign hardware and software, the wider attack surface of IoT and 5G, skill shortages and under-reporting of incidents.

How far India has a comprehensive strategy

  • Building blocks exist: the IT Act, 2000 (amended 2008); CERT-In for incident response; NCIIPC for critical infrastructure; the National Cyber Security Policy 2013; the Indian Cyber Crime Coordination Centre; and the Defence Cyber Agency.
  • Recent tightening: CERT-In's directions of April 2022 require service providers, intermediaries, data centres, companies and government bodies to report cyber incidents within six hours.
  • Gaps: the 2013 policy is dated and a full national strategy was still awaited at the time of the paper; agency roles overlap; State police capacity is thin; private-sector obligations remain limited.
  • Verdict: India has assembled many of the pieces, but not yet a single, funded and comprehensive strategy that fixes accountability.

Way forward

  • A published, funded strategy with clear roles; mandatory incident reporting enforced through audits and standards; indigenous technology; skilling; public-private partnership; and treaty cooperation.

India has built most of the parts; a single, well-resourced strategy with clear accountability is what would make them a system.

Written by Minimalist IAS from facts checked at source (how we verify). UPSC publishes no model answers: compare your structure and coverage with this, then write your own.

2021

GS Paper III 2021 · Q9

10 marks · 150 words

Discuss how emerging technologies and globalisation contribute to money laundering. Elaborate measures to tackle the problem of money laundering both at national and international levels.

Approach · directive: “discuss / elaborate”

What it asks · Explain how new technologies and open borders help launderers, then set out the national and international measures against money laundering.

The question has 3 parts — answer each

  1. Discuss how emerging technologies and globalisation contribute to money laundering
  2. Elaborate the measures to tackle money laundering at the national level
  3. Elaborate the measures at the international level

Open with · Money laundering disguises the criminal origin of funds through placement, layering and integration, and technology and open borders make each stage faster and harder to trace.

Cover

  • Technology: crypto assets and mixers, digital wallets and mule accounts, online gaming, shell companies formed online and dark-web trade give speed, anonymity and layering.
  • Globalisation: open capital flows, offshore financial centres, correspondent banking and trade misinvoicing let funds cross jurisdictions faster than agencies can trace them.
  • National law: the Prevention of Money-laundering Act, 2002 defines the offence, allows attachment of proceeds of crime and binds reporting entities; the Enforcement Directorate investigates.
  • Detection: FIU-India (set up 2004) analyses suspicious and cash transaction reports; KYC and beneficial-ownership norms oblige banks and intermediaries to detect and report.
  • Related laws: Benami Transactions (Prohibition) Amendment Act 2016 (in force November 2016), Black Money Act 2015 and Fugitive Economic Offenders Act 2018 close routes for hiding illicit wealth.
  • International: FATF standards and peer reviews, including for virtual assets; Egmont Group of FIUs; UN conventions; treaties for legal assistance and tax-information exchange.
  • Way forward: regulate virtual assets, use analytics and AI, share data across agencies in real time, and deepen global cooperation.

Close with · Since criminals adapt quickly, laws, technology and international cooperation must be updated together.

Add value (verified)

Question: UPSC's CS (Main) 2021, GS Paper III — paper ↗. Approach: Minimalist IAS, checked 30 Sept 2026 (how we verify) — UPSC publishes no model answers. ·

Model answer · 224 words (UPSC limit 150) · Minimalist IAS

Money laundering turns proceeds of crime into apparently clean assets through placement, layering and integration; technology and open borders speed up every stage and blur the trail.

How technology and globalisation help launderers

  • Crypto assets and mixers move value outside banks; wallets, mule accounts and online gaming split sums into fast, small transfers that evade thresholds.
  • Shell companies can be formed online across jurisdictions, hiding beneficial owners.
  • Open capital flows, offshore centres, correspondent banking and trade misinvoicing move funds across borders faster than agencies can trace; uneven laws create havens.

National measures

  • PMLA 2002: section 3 defines the offence broadly, from concealment to projecting proceeds as untainted; it allows attachment of proceeds, binds reporting entities and is enforced by the ED.
  • FIU-India (2004) analyses suspicious and cash transaction reports; KYC and beneficial-ownership norms make banks and intermediaries detect and report.
  • Supporting laws: Benami Transactions (Prohibition) Amendment Act 2016, Black Money Act 2015 and Fugitive Economic Offenders Act 2018.
  • Regulate virtual assets, deploy analytics and AI for transaction monitoring, and share data across agencies in real time.

International measures

  • FATF standards and mutual evaluations, now extended to virtual assets, with grey-listing as pressure; the Egmont Group for FIU-to-FIU intelligence exchange.
  • UN conventions, mutual legal assistance treaties and tax-information exchange agreements.

Criminals adapt faster than statutes, so laws, technology and cross-border cooperation must be upgraded together.

Written by Minimalist IAS from facts checked at source (how we verify) — a little fuller than exam length, so every part of the question is covered; in the hall, keep the structure and trim the detail. UPSC publishes no model answers: compare your structure and coverage with this, then write your own.

GS Paper III 2021 · Q10

10 marks · 150 words

Keeping in view India’s internal security, analyse the impact of cross-border cyber attacks. Also discuss defensive measures against these sophisticated attacks.

Approach · directive: “analyse / discuss”

What it asks · Analyse how cross-border cyber attacks threaten internal security (infrastructure, espionage, crime and terror, information) and discuss the defensive measures available.

The question has 2 parts — answer each

  1. Analyse the impact of cross-border cyber attacks on India's internal security: infrastructure, espionage, crime and terror, information, attribution
  2. Discuss defensive measures against these attacks: institutions, law, technology and the way forward

Open with · India's growing digital dependence has made cyberspace a domain where hostile states and non-state actors can strike across borders with deniability.

Cover

  • Critical infrastructure: attacks on power, nuclear, ports, banks and telecom can disrupt services; in 2019 malware was found in the Kudankulam plant's administrative network, which NPCIL said was isolated from plant control systems.
  • Espionage and data theft: state-linked groups target defence, government and strategic sectors; stolen data weakens military and diplomatic security.
  • Crime, terror and information war: ransomware, online fraud and crypto payments fund crime and terror; social media spreads radicalisation and disinformation to trigger unrest.
  • Attribution problem: attacks are routed through proxies and non-state groups, so deterrence and legal response are hard; evidence and jurisdiction lie abroad.
  • Institutions: CERT-In for incident response, NCIIPC (2014) for critical information infrastructure, the Defence Cyber Agency (established 2018) for military networks and I4C (inaugurated January 2020) for cybercrime coordination.
  • Law and technology: IT Act provisions including cyber terrorism (s.66F), security audits, trusted-source rules for telecom, blocking of hostile apps and a data-protection law.
  • Way forward: sector CERTs, mandatory incident reporting, skilled workforce, indigenous hardware and software, and partnerships on norms and evidence sharing.

Close with · Resilience, not only prevention, is the goal: assume breaches, detect early, recover fast and build deterrence with partners.

Add value (verified)

Question: UPSC's CS (Main) 2021, GS Paper III — paper ↗. Approach: Minimalist IAS, checked 30 Sept 2026 (how we verify) — UPSC publishes no model answers. ·

Model answer · 222 words (UPSC limit 150) · Minimalist IAS

As grids, payments, governance and defence go digital, hostile states and proxies can strike India from abroad with deniability, making cyberspace an internal-security front.

Impact on internal security

  • Critical infrastructure: attacks on power, nuclear, ports, banks and telecom can halt services; in 2019 malware was found in the Kudankulam plant's administrative network, isolated from control systems according to NPCIL.
  • Espionage: state-linked groups target defence, government and strategic sectors; stolen data erodes military and diplomatic advantage.
  • Crime and terror: ransomware, online fraud and crypto channels fund crime and terror networks.
  • Information war: disinformation and radicalisation on social media aim to trigger unrest and communal tension.
  • Attribution: attacks routed through proxies and foreign servers leave evidence and jurisdiction abroad, weakening deterrence and prosecution.

Defensive measures

  • Institutions: CERT-In, the national agency under the IT Act for incident response; NCIIPC (2014) for critical information infrastructure; the Defence Cyber Agency (2018) for military networks; I4C (January 2020) for cybercrime coordination.
  • Law: IT Act section 66F on cyber terrorism, mandatory security audits, trusted-source rules for telecom equipment, blocking of hostile apps and a data-protection law.
  • Way forward: sectoral CERTs and mandatory incident reporting, a skilled workforce, indigenous hardware and software, regular drills, and partnerships on cyber norms and evidence sharing.

Resilience, not prevention alone, is the goal: assume breaches, detect early, recover fast and build deterrence with partners.

Written by Minimalist IAS from facts checked at source (how we verify) — a little fuller than exam length, so every part of the question is covered; in the hall, keep the structure and trim the detail. UPSC publishes no model answers: compare your structure and coverage with this, then write your own.

2020

GS Paper III 2020 · Q9

10 marks · 150 words

Discuss different types of cyber crimes and measures required to be taken to fight the menace.

Approach · directive: “discuss”

What it asks · Classify cyber crimes with examples, and list the legal, institutional, technical and awareness measures needed to check them.

The question has 2 parts — answer each

  1. Discuss the different types of cyber crime, with examples
  2. Discuss the measures required to fight the menace

Open with · Cyber crime is an unlawful act in which a computer or network is the tool, the target or both; India's main law on it is the Information Technology Act, 2000.

Cover

  • Against individuals: identity theft, phishing and online fraud, cyber stalking and bullying, sextortion, morphed images and data theft.
  • Against organisations and infrastructure: ransomware and malware, denial-of-service attacks, hacking, data breaches, and attacks on power grids, banks and hospitals.
  • Against the State and society: cyber terrorism, espionage, fake news and hate spread through social media, radicalisation, and cyber warfare.
  • Legal: the IT Act, 2000 (Sections 66C, 66D, 66F cover identity theft, cheating by personation, cyber terrorism) and penal law on fraud and stalking.
  • Institutions: CERT-In for incident response, NCIIPC for critical infrastructure, the Indian Cyber Crime Coordination Centre (I4C) and the national cyber crime reporting portal.
  • Prevention: cyber hygiene and public awareness, two-factor authentication, security audits, trained police and forensic labs, and cooperation with platforms and other countries.
  • Gaps: low reporting and conviction, cross-border jurisdiction, fast-changing technology, and a data-protection law that came late (Digital Personal Data Protection Act, 2023).

Close with · Fighting cyber crime needs sound law, capable institutions and alert citizens together, because technology changes faster than legislation.

Question: UPSC's CS (Main) 2020, GS Paper III — paper ↗. Approach: Minimalist IAS, checked 30 Sept 2026 (how we verify) — UPSC publishes no model answers. ·

Model answer · 223 words (UPSC limit 150) · Minimalist IAS

Cyber crime is an unlawful act in which a computer or network is the tool, the target or both; India's main law on it is the Information Technology Act, 2000.

Types of cyber crime

  • Against individuals: identity theft, phishing and online financial fraud, cyber stalking and bullying, sextortion and morphed images.
  • Against organisations and infrastructure: ransomware and malware, denial-of-service attacks, hacking and data breaches, and attacks on power grids, banks and hospitals.
  • Against the State and society: cyber terrorism and espionage, fake news and hate spread through social media, online radicalisation and cyber warfare.

Measures needed

  • Law: enforce the IT Act, 2000 (Sections 66C, 66D and 66F on identity theft, cheating by personation and cyber terrorism) and penal provisions on fraud and stalking, plus a data-protection law (enacted since as the DPDP Act, 2023).
  • Institutions: CERT-In for incident response, NCIIPC for critical information infrastructure, the Indian Cyber Crime Coordination Centre (I4C) and the national cyber crime reporting portal, with trained police and forensic labs in every state.
  • Technology: two-factor authentication, regular security audits, secure-by-design systems and prompt patching.
  • People: cyber hygiene and awareness, especially for first-time internet users, women and children.
  • Cooperation: with platforms for quick takedowns and with other countries on evidence and jurisdiction.

Fighting cyber crime needs sound law, capable institutions and alert citizens together, because technology changes faster than legislation.

Written by Minimalist IAS from facts checked at source (how we verify) — a little fuller than exam length, so every part of the question is covered; in the hall, keep the structure and trim the detail. UPSC publishes no model answers: compare your structure and coverage with this, then write your own.

2019

GS Paper III 2019 · Q10

10 marks · 150 words

What is CyberDome Project? Explain how it can be useful in controlling internet crimes in India.

Approach · directive: “what / explain how”

What it asks · Say what CyberDome is, Kerala Police's cyber centre of excellence, and explain how such a hub, and the model behind it, can help India control internet crimes.

The question has 2 parts — answer each

  1. What CyberDome is
  2. Explain how it can be useful in controlling internet crimes in India

Open with · CyberDome, Kerala Police's cyber centre of excellence at Technopark, Thiruvananthapuram, brings police, industry, academia and ethical hackers together to prevent and investigate cyber crime.

Cover

  • What it is: a high-tech public-private partnership of Kerala Police with departments, industry, academia, ethical hackers and international agencies for proactive handling of cyber crime.
  • Prevention: threat intelligence, monitoring and awareness campaigns against frauds and abuse, and a Counter Child Sexual Exploitation centre that traces offenders and removes abusive material.
  • Investigation: ethical hackers and technical experts assist police in forensics and tracing, and a drone forensic lab extends skills to new technology.
  • Capacity: training for police, research and new software tools fill skill gaps in local policing, and volunteer experts add scarce technical manpower.
  • Nationwide use: replicate the model in each state and link it to CERT-In, the Indian Cyber Crime Coordination Centre and the national reporting portal.
  • Limits: a state-level pilot cannot cover cross-border crime, encrypted or foreign-held data; it needs legal backing, privacy safeguards and cooperation with platforms and foreign agencies.

Close with · CyberDome shows that police, industry and academia working together can prevent and solve cyber crime; scaled up with legal backing and privacy safeguards, it can be a national template.

Add value (verified)

  • Kerala Police's own description states the project's purpose and its public-private design. Cyberdome, Kerala Police Centre of Excellence (official website) ↗“Cyberdome is a Cyber Centre of Excellence of Kerala Police, envisaged as a high-tech public-private partnership centre of collaboration for different stakeholders in the domain of cyber security and handling of cyber crimes — in a proactive manner.”

Question: UPSC's CS (Main) 2019, GS Paper III — paper ↗. Approach: Minimalist IAS, checked 30 Sept 2026 (how we verify) — UPSC publishes no model answers. ·

Model answer · 201 words (UPSC limit 150) · Minimalist IAS

CyberDome is Kerala Police's cyber centre of excellence at Technopark, Thiruvananthapuram: a public-private partnership that pools police, government departments, industry, academia, ethical hackers and international agencies to prevent and investigate cyber crime.

How it helps control internet crime

  • Prevention: threat intelligence, monitoring and awareness campaigns against online fraud and abuse; its Counter Child Sexual Exploitation centre traces offenders and gets abusive material removed.
  • Investigation: volunteer ethical hackers and forensic experts help trace offenders and secure evidence; a drone forensic lab extends skills to new technology.
  • Capacity: police training, threat research and in-house tools fill skill gaps in ordinary policing, with volunteer expertise adding scarce manpower at little cost.
  • National template: each state could run such a hub linked to CERT-In, the Indian Cyber Crime Coordination Centre and the national cyber-crime reporting portal, giving a common front against crime that crosses state lines.

Limits

  • A state pilot cannot reach cross-border crime or encrypted and foreign-held data; it needs statutory backing, privacy safeguards for citizens' data, and cooperation from platforms and foreign agencies.

CyberDome shows that police, industry and academia working together can prevent and solve cyber crime; scaled up with legal backing and privacy safeguards, it can serve as a national model.

Written by Minimalist IAS from facts checked at source (how we verify) — a little fuller than exam length, so every part of the question is covered; in the hall, keep the structure and trim the detail. UPSC publishes no model answers: compare your structure and coverage with this, then write your own.

2018

GS Paper III 2018 · Q19

15 marks · 250 words

Data security has assumed significant importance in the digitized world due to rising cyber crimes. The Justice B. N. Srikrishna Committee Report addresses issues related to data security. What, in your view, are the strengths and weaknesses of the Report relating to protection of personal data in cyber space?

Approach · directive: “what are the strengths and weaknesses”

What it asks · Assess the Committee's report and draft Personal Data Protection Bill: its strengths (rights-based, consent, regulator, penalties) and weaknesses (State exemptions, localisation, oversight, autonomy).

The question has 3 parts — answer each

  1. Strengths of the Report in protecting personal data: coverage, rights, enforcement
  2. Weaknesses of the Report: State exemptions, localisation, oversight and other gaps
  3. Your view: a verdict and what should change before enactment

Open with · Set up in July 2017 and reporting in July 2018 with a draft Bill, the Srikrishna Committee followed the Supreme Court's 2017 ruling that privacy is a fundamental right, and aimed at a 'free and fair digital economy'.

Cover

  • Strength, coverage: one law for government and private data fiduciaries, with principles of consent, purpose and collection limitation, data minimisation and transparency, and reach over processing linked to business in India.
  • Strength, rights: individuals get access, correction, portability and a limited right to be forgotten; fiduciaries owe a duty of fair and reasonable processing, with privacy by design.
  • Strength, enforcement: an independent Data Protection Authority, breach reporting, impact assessments for significant fiduciaries, and penalties of up to ₹15 crore or 4 per cent of global turnover.
  • Weakness, State exemptions: wide grounds such as security of the State and public order, without prior judicial approval, weaken protection against the State itself, the largest data holder.
  • Weakness, localisation: a mandatory local copy of all personal data and local-only storage of 'critical' data raise costs for firms, and may not improve security; the Centre defines what is critical.
  • Weakness, gaps: the proposed change to the RTI Act's personal-information exemption may weaken transparency, and the regulator's independence from the executive was questioned.
  • Way forward: tighter checks on State access (necessity, proportionality, oversight), a truly independent regulator, workable localisation rules, and public consultation before the Bill is enacted.

Close with · The report is a solid base for a rights-based regime; its credibility will depend on tighter checks on State access, a truly independent regulator and workable localisation rules.

Add value (verified)

Question: UPSC's CS (Main) 2018, GS Paper III — paper ↗. Approach: Minimalist IAS, checked 30 Sept 2026 (how we verify) — UPSC publishes no model answers. ·

Model answer · 313 words (UPSC limit 250) · Minimalist IAS

Set up in July 2017 and reporting in July 2018 with a draft Personal Data Protection Bill, the Srikrishna Committee followed the Supreme Court's 2017 ruling that privacy is a fundamental right, and aimed at a 'free and fair digital economy'.

Strengths

  • Coverage: one law binds government and private data fiduciaries alike, built on consent, purpose and collection limitation, data minimisation and transparency, and reaching processing linked to business in India.
  • Rights: individuals get access, correction, portability and a limited right to be forgotten; fiduciaries owe a duty of fair and reasonable processing, with privacy by design.
  • Enforcement: an independent Data Protection Authority, breach reporting, impact assessments for significant fiduciaries, and penalties of up to ₹15 crore or 4 per cent of global turnover give the law teeth.
  • Constitutional footing: it answers the Court's call, repeated in the Aadhaar judgment of September 2018, for a robust data protection regime that balances individual interests with legitimate State concerns.

Weaknesses

  • State exemptions: wide grounds such as security of the State and public order, without prior judicial approval, leave the largest data holder least constrained.
  • Localisation: a mandatory local copy of all personal data and local-only storage of 'critical' data raise costs for firms without clearly improving security, and the Centre alone defines what is critical.
  • Oversight and transparency: the regulator's independence from the executive was questioned, and the proposed change to the RTI Act's personal-information exemption could weaken transparency.
  • Process: the draft was framed without wide public consultation on its final text.

My view

  • The report is a sound, rights-based foundation, but its credibility rests on tighter checks on State access (necessity, proportionality, oversight), a truly independent regulator, workable localisation rules and open consultation before enactment.

A data protection law is only as strong as its limits on the State; with those limits fixed, the Committee's framework can turn the privacy right into everyday protection.

Written by Minimalist IAS from facts checked at source (how we verify) — a little fuller than exam length, so every part of the question is covered; in the hall, keep the structure and trim the detail. UPSC publishes no model answers: compare your structure and coverage with this, then write your own.

GS Paper III 2018 · Q20

15 marks · 250 words

India’s proximity to two of the world’s biggest illicit opium-growing states has enhanced her internal security concerns. Explain the linkages between drug trafficking and other illicit activities such as gunrunning, money laundering and human trafficking. What counter-measures should be taken to prevent the same?

Approach · directive: “explain / what counter-measures”

What it asks · Explain how narcotics trafficking links with gunrunning, money laundering, human trafficking and terror around India, and suggest counter-measures.

The question has 2 parts — answer each

  1. Explain the linkages between drug trafficking and gunrunning, money laundering, human trafficking and terror funding
  2. What counter-measures should be taken: enforcement, borders, financial tracking, regional cooperation and demand reduction

Open with · India lies between the Golden Crescent (Afghanistan, Pakistan, Iran) and the Golden Triangle (Myanmar, Laos, Thailand), the two main opium-producing regions, which makes it both a transit route and a destination.

Cover

  • Terror link: drug money is used to fund insurgent and terrorist groups (narco-terrorism), and drugs are sometimes bartered for weapons, as reported along the western border and in the north-east.
  • Gunrunning: the routes and networks that bring heroin across the western and eastern borders also move arms, ammunition and explosives.
  • Money laundering: proceeds move through hawala, front companies, real estate and trade-based laundering, and can fund terror and other crime.
  • Human trafficking: the same organised networks exploit porous, unfenced borders to traffic women and children, and use victims as drug couriers; corruption in enforcement helps them.
  • Enabling factors: difficult terrain and open stretches on the Punjab-Pakistan and Myanmar borders, the Myanmar free movement regime, weak coastal surveillance, corruption, and domestic demand.
  • Counter-measures, enforcement: the NDPS Act, 1985 and PIT-NDPS Act, 1988; the Narcotics Control Bureau; the Prevention of Money Laundering Act, 2002 and FIU-India; joint action by NCB, BSF, customs, the Coast Guard and State police.
  • Counter-measures, wider: border fencing and surveillance, coastal security, financial tracking, intelligence-sharing with neighbours and UN conventions, and demand reduction, treatment and alternative livelihoods in poppy areas.

Close with · Since drugs, arms, money and trafficking form one criminal system, the response must be equally joined up: border control, financial tracking, regional cooperation and demand reduction.

Question: UPSC's CS (Main) 2018, GS Paper III — paper ↗. Approach: Minimalist IAS, checked 30 Sept 2026 (how we verify) — UPSC publishes no model answers. ·

Model answer · 286 words (UPSC limit 250) · Minimalist IAS

India lies between the Golden Crescent (Afghanistan, Pakistan, Iran) and the Golden Triangle (Myanmar, Laos, Thailand), the world's two main opium-producing regions, which makes it both a transit route and a destination for narcotics.

The linkages

  • Narco-terrorism: drug money funds insurgent and terrorist groups, and drugs are at times bartered for weapons, as reported along the western border and in the north-east.
  • Gunrunning: the same routes, carriers and handlers that bring heroin across the western and eastern borders move arms, ammunition and explosives, so a drug network is a weapons network.
  • Money laundering: proceeds are washed through hawala, front companies, real estate and trade-based laundering, and the cleaned money finances further crime and terror.
  • Human trafficking: organised networks exploit porous, unfenced borders to traffic women and children, and use victims as drug couriers; corruption in enforcement keeps the chain intact.
  • Enablers: difficult terrain on the Punjab-Pakistan and Myanmar borders, the free movement regime with Myanmar, weak coastal surveillance, corruption and rising domestic demand.

Counter-measures

  • Law and agencies: enforce the NDPS Act, 1985 and PIT-NDPS Act, 1988 through the Narcotics Control Bureau, with joint operations by BSF, customs, the Coast Guard and State police.
  • Follow the money: the Prevention of Money Laundering Act, 2002 and FIU-India to trace hawala and trade-based flows, and confiscate assets.
  • Borders: fencing, surveillance technology and coastal security, and a review of the free movement regime.
  • Regional cooperation: intelligence-sharing with neighbours and under the UN drug conventions, since supply lies across the border.
  • Demand side: treatment and de-addiction, awareness, and alternative livelihoods in poppy-growing areas.

Drugs, arms, money and trafficked people move through one criminal system, so the response must be equally joined up: sealed borders, tracked money, regional cooperation and less demand.

Written by Minimalist IAS from facts checked at source (how we verify) — a little fuller than exam length, so every part of the question is covered; in the hall, keep the structure and trim the detail. UPSC publishes no model answers: compare your structure and coverage with this, then write your own.

2017

GS Paper III 2017 · Q9

10 marks · 150 words

Discuss the potential threats of Cyber attack and the security framework to prevent it.

Approach · directive: “discuss”

What it asks · Describe the kinds of cyber attack India faces and the legal, institutional and technical framework meant to prevent them.

The question has 2 parts — answer each

  1. Discuss the potential threats of cyber attack
  2. Discuss the security framework to prevent it

Open with · As banking, power, transport and government services move online, cyber attacks can steal data, freeze services and even damage critical infrastructure.

Cover

  • Threats: ransomware such as WannaCry (2017), malware, phishing, denial-of-service attacks and financial fraud.
  • Larger threats: attacks on critical infrastructure such as power grids, telecom and banking, state-sponsored espionage and cyber terrorism.
  • Vulnerabilities: dependence on imported hardware and software, low awareness, weak passwords, shortage of skilled staff and poor reporting.
  • Law: the Information Technology Act, 2000 (amended 2008) penalises hacking and cyber terrorism and provides for protected systems.
  • Institutions: CERT-In for incident response, NCIIPC for critical information infrastructure, a National Cyber Security Coordinator and the National Cyber Security Policy, 2013.
  • Practice: sectoral security guidelines such as RBI's, audits, cyber-crime cells and the Cyber Swachhta Kendra.
  • Gaps: no dedicated data protection law in 2017, few trained officials and weak international cooperation; needs capacity building and stronger public-private partnership.

Close with · Cyber security needs strong law, alert institutions, skilled people and aware citizens working together, since the weakest link decides the strength of the chain.

Question: UPSC's CS (Main) 2017, GS Paper III — paper ↗. Approach: Minimalist IAS, checked 30 Sept 2026 (how we verify) — UPSC publishes no model answers. ·

Model answer · 232 words (UPSC limit 150) · Minimalist IAS

As banking, power, transport and government services move online under Digital India, cyber attacks can steal data, freeze services and even damage critical infrastructure.

Potential threats

  • Malware and ransomware: WannaCry (2017) locked systems worldwide; phishing, denial-of-service attacks and financial fraud target banks and citizens.
  • Critical infrastructure: attacks on power grids, telecom, banking and transport can paralyse the economy; state-sponsored espionage and cyber terrorism threaten national security.
  • Data theft: the 2016 debit card breach forced Indian banks to block and reissue cards on a large scale.
  • Vulnerabilities: imported hardware and software, weak passwords, low awareness, shortage of skilled staff and poor incident reporting.

Security framework

  • Law: the Information Technology Act, 2000 (amended 2008) penalises hacking (Section 66) and cyber terrorism (Section 66F), shields designated 'protected systems' (Section 70) and makes firms liable for lax data security (Section 43A).
  • Institutions: CERT-In for incident response, NCIIPC for critical information infrastructure, a National Cyber Security Coordinator, and the National Cyber Security Policy, 2013.
  • Practice: RBI's cyber security framework for banks (2016), sectoral audits, police cyber-crime cells and the Cyber Swachhta Kendra (2017) for cleaning infected devices.
  • Gaps: no data protection law in 2017 (the Justice B.N. Srikrishna committee was set up that year), few trained officials, and India outside the Budapest Convention on cybercrime.

Strong law, alert institutions, skilled people and aware citizens must work together, because the weakest link decides the strength of the chain.

Written by Minimalist IAS from facts checked at source (how we verify) — a little fuller than exam length, so every part of the question is covered; in the hall, keep the structure and trim the detail. UPSC publishes no model answers: compare your structure and coverage with this, then write your own.

GS Paper III 2017 · Q19

15 marks · 250 words

Mob violence is emerging as a serious law and order problem in India. By giving suitable examples, analyze the causes and consequences of such violence.

Approach · directive: “analyse”

What it asks · Analyse why mob violence is rising and what it does to society and the State, citing examples.

The question has 2 parts — answer each

  1. Analyse the causes of mob violence, with suitable examples
  2. Analyse the consequences of mob violence, with suitable examples

Open with · Mob violence is the collective, unlawful use of force against a person or group, often on the basis of rumour or suspicion, and it bypasses courts and the police.

Cover

  • Rumours and social media: false messages on child-lifting and cattle smuggling spread quickly; child-lifting rumours led to killings in Jharkhand in 2017.
  • Identity and vigilantism: self-styled cow protection groups, as in Dadri (2015) and Alwar (2017), target minorities and Dalits.
  • Weak law enforcement: slow trials, low conviction, police inaction and political patronage produce a sense of impunity.
  • Social factors: distrust of the police, prejudice, unemployment and frustration among youth, and a mob's anonymity reduce individual guilt.
  • Consequences: loss of life, fear among targeted groups, communal polarisation and damage to the State's monopoly over force.
  • Consequences: harm to the rule of law, livelihoods such as cattle trade, India's image and investment climate.
  • Response: quick FIRs and fast-track trials, accountable district officials, curbs on rumours online and fresh law; the Supreme Court gave directions in Tehseen Poonawalla (2018).

Close with · Mob violence is best checked by swift, impartial policing and justice, accountability of officials and public education against rumours and hatred.

Question: UPSC's CS (Main) 2017, GS Paper III — paper ↗. Approach: Minimalist IAS, checked 30 Sept 2026 (how we verify) — UPSC publishes no model answers. ·

Model answer · 313 words (UPSC limit 250) · Minimalist IAS

Mob violence is the unlawful use of force by a crowd against a person or group, usually on rumour or suspicion, which substitutes the crowd's verdict for the courts and the police.

Causes

  • Rumour on social media: WhatsApp messages about child-lifters led to several people being beaten to death in Jharkhand in May 2017; forwarding outruns any police response.
  • Identity-based vigilantism: self-styled cow protectors killed Mohammad Akhlaq in Dadri (2015) and Pehlu Khan in Alwar (2017) and flogged Dalits in Una (2016); Junaid Khan was killed on a train near Ballabhgarh in June 2017.
  • Impunity: slow trials, low conviction, police delay or complicity and political patronage teach crowds that violence carries no cost.
  • Distrust of justice: crowds seek 'instant justice' against suspected thieves, rapists and witches, as when a rape accused was dragged from jail and lynched in Dimapur (2015).
  • Crowd psychology: anonymity dissolves individual guilt, while prejudice, unemployment and frustration among young men supply the tinder.

Consequences

  • Life and liberty: killings and injuries, fear among minorities and Dalits, families uprooted; Article 21 rendered hollow for the victims.
  • Rule of law: the State's monopoly over force erodes, the police lose credibility, and each unpunished case invites the next.
  • Social fabric: communal polarisation, cycles of retaliation and distrust between communities.
  • Economy: cattle trade, dairy, leather and transport disrupted; investors and tourists read lynchings as State failure.
  • Politics and image: governance discredited at home and India's human-rights record questioned abroad.

Way forward

  • Prompt FIRs and fast-track trials, personal accountability of station officers and district magistrates, rumour-busting with platforms and local media, community policing and victim compensation (since then, the Supreme Court in Tehseen Poonawalla (2018) laid down preventive, remedial and punitive measures and urged Parliament to consider a special law).

Mob violence recedes only when policing is swift and impartial, officials answer for inaction, and rumour and hatred are countered before they turn into crowds.

Written by Minimalist IAS from facts checked at source (how we verify) — a little fuller than exam length, so every part of the question is covered; in the hall, keep the structure and trim the detail. UPSC publishes no model answers: compare your structure and coverage with this, then write your own.

GS Paper III 2017 · Q20

15 marks · 250 words

The scourge of terrorism is a grave challenge to national security. What solutions do you suggest to curb this growing menace ? What are the major sources of terrorist funding ?

Approach · directive: “what solutions / what are the major sources”

What it asks · Suggest measures to curb terrorism and name the main sources of terrorist funding.

The question has 2 parts — answer each

  1. Suggest solutions to curb terrorism
  2. Identify the major sources of terrorist funding

Open with · Terrorism attacks the State's core duty of keeping citizens safe, and it survives on money, weapons, ideology and safe havens.

Cover

  • Sources of funds: hawala and illegal money transfers, counterfeit currency, drug trafficking, smuggling, and extortion or ransom demands.
  • Sources of funds: misuse of charities and donations, state sponsorship, cyber fraud, front companies and, in some regions, extortion in mining and construction.
  • Intelligence and policing: better sharing among agencies and States, NIA and NATGRID, strong local police and border and coastal surveillance.
  • Legal and financial action: the Unlawful Activities (Prevention) Act provisions on raising funds, Prevention of Money Laundering Act, financial intelligence and FATF norms.
  • Countering radicalisation: community engagement, deradicalisation, monitoring of online recruitment, and education and jobs for vulnerable youth.
  • Diplomacy: pressure through the UN, FATF and bilateral cooperation to end safe havens; capacity building and quick response forces such as the NSG.
  • Balance: measures must respect due process and human rights so that action against terrorism does not erode trust of the affected communities.

Close with · Terrorism needs a combined response: sharp intelligence, tight financial controls, fair justice and community trust, backed by global cooperation.

Question: UPSC's CS (Main) 2017, GS Paper III — paper ↗. Approach: Minimalist IAS, checked 30 Sept 2026 (how we verify) — UPSC publishes no model answers. ·

Model answer · 345 words (UPSC limit 250) · Minimalist IAS

Terrorism strikes at the State's first duty, the safety of its citizens, and it lives on money, arms, ideology and safe havens; curbing it means cutting each of these lifelines.

Solutions

  • Intelligence: strengthen the Multi-Agency Centre and NATGRID, integrate State intelligence, invest in human sources and technical surveillance, and share actionable inputs in real time.
  • Policing and borders: modernise State police as first responders, fence and electronically watch borders, complete coastal security with marine police and the Coast Guard, and keep NSG hubs ready for rapid response.
  • Law and courts: use the Unlawful Activities (Prevention) Act, fast-track terror trials, protect witnesses, and give the National Investigation Agency the reach to pursue cross-State cases.
  • Financial choke: the Prevention of Money Laundering Act, the Financial Intelligence Unit and FATF standards to trace and freeze funds.
  • Countering radicalisation: monitor online recruitment, engage community and religious leaders, run deradicalisation and rehabilitation programmes, and expand education and jobs in Jammu and Kashmir, the Northeast and left-wing extremism districts.
  • Diplomacy: press for the Comprehensive Convention on International Terrorism at the UN, use FATF and UN sanctions listings against sponsors, and deepen intelligence pacts with partners.
  • Rights and trust: due process, no collective punishment and accountable security forces, so that counter-terrorism does not create the next recruit.

Major sources of terrorist funding

  • Hawala and other informal transfers that leave no banking trail.
  • Fake Indian currency notes pushed in through neighbouring countries.
  • Narcotics from the Golden Crescent and Golden Triangle, and smuggling of gold and arms.
  • Extortion, ransom and 'levies' on contractors, mining and transport, especially by left-wing extremists in central India.
  • State sponsorship by hostile agencies.
  • Charities, NGOs and diaspora donations diverted from their stated purpose.
  • Cyber fraud, front companies and, increasingly, virtual currencies.
  • India's counters: the Terror Funding and Fake Currency cell of the NIA, FCRA scrutiny of foreign funding, demonetisation (2016) aimed partly at counterfeit notes, and the UAPA offence of raising funds for terrorism.

Terrorism yields to a combined response: sharp intelligence, dried-up finance, fair and fast justice and communities that trust the State, backed by cooperation across borders.

Written by Minimalist IAS from facts checked at source (how we verify) — a little fuller than exam length, so every part of the question is covered; in the hall, keep the structure and trim the detail. UPSC publishes no model answers: compare your structure and coverage with this, then write your own.

2016

GS Paper III 2016 · Q20

12½ marks · 200 words

Use of Internet and social media by non-state actors for subversive activities is a major security concern. How have these been misused in the recent past? Suggest effective guidelines to curb the above threat.

Approach · directive: “how / suggest”

What it asks · Describe how terrorists, insurgents and other non-state actors have misused the internet and social media, and suggest guidelines that reduce the threat without harming freedom of speech.

The question has 2 parts — answer each

  1. How: the internet and social media have been misused by non-state actors in the recent past
  2. Suggest: effective guidelines to curb the threat without harming free speech

Open with · The internet lets small groups reach millions cheaply and anonymously, which suits propaganda, recruitment, coordination and rumour as much as it suits ordinary users.

Cover

  • Misuse, radicalisation: propaganda videos, online recruitment and grooming of young people by terror groups such as ISIS, including through encrypted messaging apps.
  • Misuse, rumours and hate: fake news and doctored videos that incite panic and communal violence, as in the 2012 exodus of northeast people from some cities.
  • Misuse, mobilisation and crime: coordination of protests and violence, funding through crowdfunding and crypto assets, arms and drug trade on the dark web, and cyber attacks and hacking.
  • Legal tools: the Information Technology Act, 2000, including blocking under section 69A with safeguards, monitoring and interception, and the Unlawful Activities (Prevention) Act.
  • Guidelines, platforms: due diligence, quick takedown and grievance redressal by intermediaries, cooperation on user information, and transparency, as in the 2021 IT Rules.
  • Guidelines, capacity: strong cyber units, CERT-In and a national cyber crime coordination centre, monitoring of extremist content and counter-narratives, and digital literacy.
  • Safeguards: any restriction must be lawful, necessary and proportionate, since free speech can be restricted only on the grounds listed in Article 19(2).

Close with · Security and freedom online can be balanced through clear law, accountable platforms, trained agencies and public awareness.

Add value (verified)

Question: UPSC's CS (Main) 2016, GS Paper III — paper ↗. Approach: Minimalist IAS, checked 30 Sept 2026 (how we verify) — UPSC publishes no model answers. ·

Model answer · 303 words (UPSC limit 200) · Minimalist IAS

The internet lets a handful of people reach millions cheaply and anonymously, which serves propaganda, recruitment and rumour as readily as it serves commerce and education.

Misuse in the recent past

  • Radicalisation and recruitment: ISIS used videos, online magazines and encrypted messaging apps to draw recruits, including a few Indian youth.
  • Rumour and communal violence: in 2012 doctored images and mass messages triggered the exodus of north-eastern people from Bengaluru and other cities; a fake video helped ignite the 2013 Muzaffarnagar riots.
  • Mobilisation: separatist groups use social media to organise stone-pelting and protests, as in Kashmir in 2016.
  • Crime and finance: crowdfunding and virtual currencies for terror funds, dark-web markets for arms and drugs, defacement of government websites, and honey-trapping of defence personnel for espionage.

Guidelines to curb the threat

  • Law: apply the IT Act, 2000, with blocking under section 69A and the safeguards upheld in Shreya Singhal (2015), which struck down the vague section 66A; use the UAPA against terror content.
  • Platforms: due diligence by intermediaries, time-bound takedown on lawful orders, grievance officers and cooperation on user data through mutual legal assistance (since then, the IT Rules, 2021 codified these duties).
  • Capacity: a national cyber crime coordination centre, CERT-In, cyber cells and forensic labs in every state police, and social media monitoring to detect rumours early.
  • Counter-narrative: credible official information during crises, engagement with community leaders, and de-radicalisation programmes for returnees and sympathisers.
  • Awareness and cooperation: digital literacy to verify before forwarding, and international cooperation on servers and evidence located abroad.
  • Safeguards: every restriction must fall within Article 19(2), be necessary and proportionate, and face judicial or independent oversight; blanket internet shutdowns should be the rare exception.

Security and freedom online can coexist when clear law, accountable platforms, trained agencies and an informed public work together against those who exploit the medium.

Written by Minimalist IAS from facts checked at source (how we verify) — a little fuller than exam length, so every part of the question is covered; in the hall, keep the structure and trim the detail. UPSC publishes no model answers: compare your structure and coverage with this, then write your own.

The same ground in Prelims