The Man and The Message
Sachhin Gajjaer, the founder and CEO of cybersecurity firm Sattrix, has made a bold declaration: cybersecurity must be treated as critical national infrastructure. With a background that includes roles at HCL and Accenture before founding his own company,
Gajjaer's perspective is shaped by years on the front lines of digital defence. His call isn't just a technical recommendation; it's a strategic argument that as India's economy and society become inextricably linked with digital systems, the security of those systems becomes as vital as physical infrastructure like power grids and highways. A major cyber incident, he warns, could trigger systemic economic and societal disruption, not just a temporary IT problem.
More Than Just an IT Problem
So, what does it mean to classify cybersecurity as 'national infrastructure'? In India, infrastructure has traditionally referred to physical assets like roads, railways, ports, and power lines—the foundational services required for the economy to function. These sectors are part of the National Infrastructure Pipeline (NIP), a massive government initiative to plan and fund projects crucial for national growth. Currently, cybersecurity is often viewed through the lens of IT policy or as an operational cost for individual businesses. Gajjaer's argument is that this approach is no longer sufficient. When digital platforms underpin everything from banking and stock exchanges to healthcare and public services, protecting them is a matter of national stability. The World Economic Forum has echoed similar sentiments, describing digital public infrastructure (DPI) like Aadhaar and UPI as 'digital superhighways' that require the same level of protection as physical ones.
The High Stakes for a Digital India
The risks of inaction are immense. Cybercrime is estimated to cost the Indian economy billions of dollars annually, with ransomware attacks and data breaches on the rise. According to one report from CERT-In, ransomware incidents alone cost the Indian economy over $1 billion in a single year, with a 53% year-over-year increase in reported cases. These attacks don't just cause financial loss; they erode trust in the digital economy, disrupt supply chains, and can lead to the theft of valuable intellectual property. A successful cyberattack on a critical asset, such as a power grid or a major financial institution, could have a cascading effect, crippling communications, transport, and essential services for millions of citizens.
What a 'National Infrastructure' Approach Means
Elevating cybersecurity to this status would trigger significant practical changes. First, it would likely lead to increased and more centralized government funding and strategic planning, similar to how the NIP directs funds to transport and energy. It would necessitate a more robust regulatory framework, mandating stringent security standards across all critical sectors, not just banking or government. Gajjaer suggests this could lead to centralized threat intelligence and monitoring, where a national body like CERT-In or the NCIIPC would have a more proactive role in coordinating sector-wide defences rather than institutions acting in isolation. This aligns with the stated mission of India's National Cyber Security Policy, which aims to protect critical information infrastructure through a combination of institutional structures, technology, and cooperation.
The Road Ahead: Challenges and Opportunities
While India has a National Cyber Security Policy in place since 2013 and is working on an updated strategy, the framework is still evolving. Implementing a true infrastructure-level approach would require immense coordination between the central government, state bodies, and a vast private sector. It would mean treating cybersecurity resilience as a public good, ensuring that even smaller companies integral to the national supply chain have access to robust defence mechanisms. The challenge is significant, but the opportunity is greater: to build a secure, resilient, and trustworthy digital ecosystem. This would not only protect the nation from economic and social disruption but also solidify India's position as a global leader in the digital age, where security is built-in by design, not treated as an afterthought.














