26 JUL 2025, New Delhi
In a major push to secure the nation’s digital infrastructure, the Government of India has intensified cybersecurity measures across key sectors such as power, transport, and banking. The move comes as part of a broader effort to ensure a safe, trusted, and accountable cyberspace for all users amid rising cyber threats.
During the financial year 2024–25, a total of 9,708 security audits were conducted by the Indian Computer Emergency Response Team (CERT-In) across various critical infrastructure sectors. Additionally, the National Critical Information Infrastructure Protection Centre (NCIIPC) carried out 90 specialized audits under the provisions of the Information Technology Act.
Among the sectors audited, the banking, financial services, and insurance (BFSI) sector saw the highest number of audits, with over 7,500 conducted by CERT-In and 41 by NCIIPC. The power and energy sector followed, with 1,579 audits by CERT-In and 46 by NCIIPC. The transport sector was also reviewed, undergoing 582 audits by CERT-In and 3 by NCIIPC.
To support this large-scale assessment, CERT-In has empaneled 200 cybersecurity organizations to carry out vulnerability and security checks. These audits are aimed at identifying potential weaknesses in digital infrastructure and recommending timely corrective measures.
The government has also launched several initiatives to improve cyber resilience. CERT-In has issued guidelines for the establishment of sector-specific and state-level Computer Security Incident Response Teams (CSIRTs). For example, CSIRT-Fin in the finance sector and CSIRT-Power in the energy sector have been created to coordinate cybersecurity efforts and enhance preparedness within their respective domains.
In another key step, the Centre for Development of Advanced Computing (C-DAC) has developed a suite of indigenous cybersecurity tools focusing on mobile security, digital forensics, log collection, and analytics. These tools aim to reduce dependence on foreign technology and strengthen India’s homegrown cyber defense capabilities.
Further, CERT-In has implemented a Cyber Crisis Management Plan (CCMP) that provides a strategic framework for government bodies to respond effectively to cyber-attacks and cyber terrorism. The plan outlines recovery mechanisms and enhances coordination across sectors in times of crisis. CERT-In has also published guidelines and templates to help states and individual sectors design their own crisis management strategies.
To promote awareness and preparedness, CERT-In has conducted 205 workshops for various government departments and critical institutions. These sessions are designed to familiarize stakeholders with the cyber threat landscape and equip them to implement crisis management protocols effectively.
These updates were shared in the Rajya Sabha on July 25 by Union Minister of State for Electronics and Information Technology, Shri Jitin Prasada. He reiterated the government’s commitment to building robust cyber defenses, particularly in critical sectors that are essential to the country’s functioning and economic security.
With the digital economy growing rapidly, these measures signal a proactive and structured approach by the Indian government to safeguard national interests in the cyber domain.
Source: PIB
