CERT-In's Widening Mandate and India's Still-Emerging Cybersecurity Posture
From breach reporting rules to VPN data mandates, India's cyber authority has grown more assertive even as basic institutional coordination gaps persist.
In November 2022, AIIMS Delhi, India's premier public hospital, suffered a ransomware attack that took its servers offline for close to two weeks, disrupting patient records, billing and appointment systems at one of the country's busiest medical institutions and reportedly compromising sensitive health data for lakhs of patients. It was one of a string of headline-grabbing breaches in Indian institutions over recent years, spanning banks, insurance companies, government databases and telecom providers, that has kept cybersecurity in the public conversation even as the underlying institutional response has evolved in ways that are simultaneously more assertive on paper and still uneven in practice.
CERT-In's expanding regulatory reach
The Indian Computer Emergency Response Team, CERT-In, functioning under the Ministry of Electronics and Information Technology, is India's designated national agency for cybersecurity incident response, and in April 2022 it issued directions that significantly expanded its regulatory footprint. The new rules mandated that a wide range of entities, including data centres, virtual private network service providers, cloud service providers and cryptocurrency exchanges, report cybersecurity incidents to CERT-In within six hours of detection, a notably short window compared to reporting timelines in other jurisdictions, and required VPN providers to retain customer data including names, IP addresses and usage patterns for a minimum period, a requirement that ran directly counter to the no-log privacy model that many VPN services market as their core value proposition.
The reaction from parts of the technology industry was immediate and, in the case of several major VPN providers, resulted in companies including ExpressVPN and NordVPN removing their physical servers from India rather than comply with data retention requirements they viewed as fundamentally incompatible with their privacy commitments to users. This episode captures a genuine tension in CERT-In's expanded mandate: rules designed to give law enforcement and security agencies visibility into potential misuse of VPN infrastructure for cybercrime or terrorism financing also reduce the privacy protections available to ordinary users and journalists who rely on VPNs for legitimate reasons, and the six-hour reporting window, while intended to enable rapid national-level response coordination, has been criticised by security researchers as too tight for organisations to conduct even preliminary incident triage before facing a compliance deadline, potentially incentivising superficial or premature reporting rather than accurate initial assessment.
Breaches keep happening despite tighter rules
Whatever the merits of the specific reporting and retention rules, their existence has not visibly reduced the frequency or severity of major breaches affecting Indian institutions. Beyond the AIIMS attack, breaches have been reported or alleged at major public sector banks, telecom operators, and government portals holding sensitive citizen data, with cybersecurity researchers and media investigations periodically surfacing that enormous volumes of Indian personal data, from Aadhaar-linked records to COVID vaccination data, have appeared for sale on dark web forums following breaches at various points in the data pipeline, from hospitals and testing labs to government contractors.
This pattern reflects a structural reality that regulatory reporting mandates alone cannot fix: breach reporting rules govern what happens after a compromise is detected, but they do nothing to address the underlying technical debt, outdated legacy systems, inconsistent patching practices, weak authentication protocols and inadequate network segmentation, that makes many Indian institutions, particularly public hospitals, state government departments and smaller financial institutions, vulnerable in the first place. India's public digital infrastructure has expanded extraordinarily fast through initiatives like Aadhaar, the Unified Payments Interface and various e-governance portals, but the cybersecurity investment and institutional maturity underpinning that infrastructure has not always scaled at the same pace as the infrastructure's reach and the sensitivity of the data it handles.
A fragmented institutional landscape
India's cybersecurity governance is also notably fragmented across multiple agencies whose mandates overlap in ways that can create both redundancy and gaps. CERT-In handles general incident response and reporting; the National Critical Information Infrastructure Protection Centre, under the National Technical Research Organisation, is separately responsible for protecting critical infrastructure sectors like power, banking and telecommunications; the Reserve Bank of India maintains its own cybersecurity framework and reporting requirements for banks; and the Ministry of Home Affairs runs the Indian Cyber Crime Coordination Centre for law enforcement coordination on cybercrime. Each of these bodies has a legitimate institutional rationale, but the absence of a single, clearly empowered national cybersecurity authority with the power to coordinate across sectors during a major incident, as some other countries have established, has been flagged repeatedly by parliamentary standing committees and independent security experts as a structural weakness that could slow coordinated response during a genuinely large-scale, cross-sectoral cyber incident.
The skills and capacity gap beneath the policy layer
Perhaps the deepest constraint on India's cybersecurity posture is not regulatory design but the acute shortage of trained cybersecurity professionals relative to the scale of digital infrastructure that needs securing. Industry estimates have repeatedly pointed to a shortfall running into the hundreds of thousands of skilled cybersecurity roles unfilled across Indian government and industry, and public sector institutions in particular, including state government IT departments and smaller public hospitals, often lack dedicated, adequately compensated cybersecurity staff at all, relying instead on general IT personnel with limited specialised security training to defend systems against increasingly sophisticated, often state-linked, threat actors.
A fair defence of the current trajectory
It would be unfair to characterise India's cybersecurity institutions as merely reactive or performative. CERT-In's incident response capability has genuinely improved over the past decade, its advisories on emerging threats are technically credible and closely watched by industry security teams, and the broader push toward mandatory reporting, whatever its imperfections, has at minimum made previously invisible incidents visible to regulators in ways that were not happening a decade ago, creating at least the data trail necessary for eventually building a more accurate national threat picture. The National Cyber Security Strategy, though delayed in formal release for years, has informed incremental improvements across ministries, and sectors like banking, under the Reserve Bank's comparatively assertive supervisory approach, have shown measurably better cybersecurity hygiene than less regulated public sector domains, suggesting that where genuine regulatory teeth and compliance monitoring exist, institutional behaviour does improve.
Closing the gap between mandate and capacity
The clearest lesson from India's cybersecurity trajectory over the past several years is that regulatory assertiveness, mandatory reporting windows, data retention rules and incident disclosure requirements, is necessary but insufficient without a parallel and much larger investment in the technical capacity of the institutions being regulated. Public hospitals, state government departments and smaller financial institutions need dedicated funding for cybersecurity infrastructure and staffing, not merely a shorter reporting deadline for the breaches that under-resourced systems will otherwise continue to suffer. Consolidating the current fragmented institutional landscape into clearer lines of authority for cross-sectoral incident response, and closing the skills gap through sustained investment in cybersecurity training pipelines, would do more to reduce the frequency of AIIMS-style breaches than any further tightening of the reporting rules governing what happens after such a breach has already occurred.

