The Engine of a New India
From buying vegetables with a quick UPI scan to accessing government services with a biometric login, India's digital economy has expanded at a breathtaking pace. Initiatives like Digital India have spurred the adoption of technology across every facet
of society, with over 950 million internet subscribers and a digital economy projected to reach nearly one trillion US dollars by 2030. This rapid digitization has powered innovation, financial inclusion, and incredible convenience. However, this very success has also created a vast and attractive target for cyber threats, turning a story of progress into one with significant, often invisible, risks.
What 'Critical Services' Really Means
When experts talk about critical infrastructure, they aren't just referring to online banking. The term encompasses the vast, interconnected network of systems that modern India relies on. This includes the power grids that light our homes, the logistics networks that manage our supply chains, the digital records in our hospitals, and the command systems for our transport networks. A successful cyberattack on any of these could have a devastating ripple effect, crippling communications, disrupting essential services, and eroding public trust. The lines have also blurred between government and private systems; an attack on a software vendor or cloud provider can be as damaging as a direct assault on a national asset.
The 'Built-In' vs. 'Bolt-On' Approach
For years, many organizations treated cybersecurity as an afterthought—a 'bolt-on' solution like adding a lock to a door after the house is built. Experts argue this is no longer sufficient. The call is for 'security by design', a principle where safety is embedded into the very foundation of a system from its first line of code. This means building privacy protections, data encryption, and access controls into the core architecture of services like UPI and Aadhaar, a foundational approach India has already applied to its Digital Public Infrastructure (DPI). It's the difference between designing a fortress and simply placing guards outside a tent. The fortress is inherently stronger because security is part of its structure.
An Evolving and Sophisticated Threat
The threats facing India are no longer simple viruses. They are sophisticated, often state-sponsored attacks, complex ransomware, and AI-powered phishing campaigns designed to trick even savvy users. Cybercriminals are now targeting the entire supply chain, compromising a trusted software provider to gain access to all its clients. The Indian Computer Emergency Response Team (CERT-In) reported handling nearly 3 million cyberattacks in 2025 alone. The increasing use of AI not only helps defenders but also supercharges attackers, allowing them to launch more complex and personalized attacks at a massive scale.
From Policy to Practice
Recognizing the urgency, the Indian government has strengthened its stance. CERT-In has issued stringent directives, including a mandatory six-hour window for reporting breaches and requirements for companies to maintain extensive system logs. Recent guidelines have also made annual third-party cybersecurity audits mandatory for all enterprises, not just critical infrastructure, to enforce accountability. However, experts note that the challenge is shifting from merely deploying security tools to operating them effectively. There remains a significant shortage of skilled cybersecurity professionals, and many organizations struggle to manage the operational complexity of securing distributed, cloud-based systems.














