Cyber Secure India Latest News

Cyber incidents in India rise to 29.44 lakh in 2025 as government strengthens digital security

India recorded 29.44 lakh cyber security incidents in 2025, up sharply from 20.41 lakh in 2024, as the government expands threat intelligence, audits, cyber drills and public awareness.

Cyber incidents in India rise to 29.44 lakh in 2025 as government strengthens digital security
Digital India Times Site Icon
  • PublishedAugust 14, 2026

As more public services, financial transactions and critical infrastructure move onto digital platforms, the ability to detect threats early and coordinate responses across government and industry is becoming a critical component of India's digital infrastructure.
As more public services, financial transactions and critical infrastructure move onto digital platforms, the ability to detect threats early and coordinate responses across government and industry is becoming a critical component of India’s digital infrastructure.

NEW DELHI: India recorded 29,44,248 cybersecurity incidents in 2025, marking a substantial increase from 20,41,360 incidents in 2024 and 15,92,917 in 2023, according to data reported to and tracked by the Indian Computer Emergency Response Team (CERT-In).

The figures were provided by Union Minister of State for Electronics and IT Jitin Prasada in the Lok Sabha on Friday, as the government outlined a range of measures to strengthen the cybersecurity preparedness of central government digital platforms and citizen service portals.

The government said it is committed to maintaining an open, safe, trusted and accountable cyberspace and has implemented legal, technical and administrative measures to protect digital infrastructure and enhance cyber resilience.

CERT-In has been designated as the national agency for responding to cybersecurity incidents under Section 70B of the Information Technology Act, 2000. When cyber incidents are observed, CERT-In advises concerned organisations on remedial measures and coordinates response measures with affected organisations, service providers, sector regulators and law enforcement agencies.

At the national level, the government has institutionalised an integrated and coordinated system for dealing with cyber attacks.

The National Cyber Security Coordinator under the National Security Council Secretariat is responsible for coordination on cyber security among different agencies. The National Cyber Coordination Centre, implemented by CERT-In, examines cyberspace to detect cybersecurity threats and shares threat intelligence with organisations, state governments and stakeholder agencies for appropriate action.

The National Critical Information Infrastructure Protection Centre has been established under Section 70A of the Information Technology Act, 2000, for protecting critical information infrastructure.

NCIIPC provides near real-time threat intelligence and situational awareness, issues alerts and advisories to critical information infrastructure and protected system entities, and periodically undertakes vulnerability and risk assessments.

The government has also expanded sector-specific incident response capabilities. The Finance sector Computer Security Incident Response Team, CSIRT-Fin, has been operational under CERT-In since May 2022 to coordinate cyber incident response in the banking and financial sector.

CSIRT-Power has been operational since September 2024 as an extended arm of CERT-In for coordinating cybersecurity issues within the power sector.

CERT-In also operates an automated cyber threat intelligence exchange platform for sharing tailored alerts with organisations across sectors to facilitate proactive threat mitigation.

A Cyber Crisis Management Plan has been formulated for implementation by ministries, departments, State Governments and their organisations to counter cyber attacks and cyber terrorism. Regular cybersecurity mock drills are conducted to assess the preparedness and cybersecurity posture of government and critical-sector organisations.

The government has also created a panel of 237 Information Security Auditing Organisations for auditing computer systems, networks, websites and applications, including vulnerability assessments and penetration testing.

Government websites and applications are required to undergo cybersecurity audits before hosting, with regular audits also conducted after hosting.

CERT-In continuously issues alerts and advisories on emerging cyber threats, vulnerabilities and countermeasures to protect computers, networks and data.

The government is simultaneously strengthening the data protection framework. The Digital Personal Data Protection Act, 2023 provides a statutory framework, with rules aimed at ensuring that the sharing and processing of citizens’ digital personal data for law enforcement purposes is undertaken in a lawful, secure and accountable manner.

Cyber security awareness is another major component of the government’s strategy. The Ministry of Electronics and Information Technology is implementing the Information Security Education and Awareness project to develop human resources in information security and promote awareness about cyber hygiene and cyber security.

According to the government, 6,650 awareness workshops have been conducted across the country, covering more than 11.37 lakh participants, including students, teachers, law enforcement personnel, government officials and members of the general public. This includes 70 workshops in Kerala covering 9,481 participants.

Multilingual awareness materials, including handbooks, short videos, posters and cartoon stories for children, are being disseminated through print, electronic media and social media.

The government also conducts nationwide cybersecurity awareness activities, including National Cyber Security Awareness Month in October, Safer Internet Day on the second Tuesday of February, Swachhta Pakhwada from February 1 to 15 and Cyber Jaagrookta Diwas on the first Wednesday of every month.

CERT-In is also conducting cybersecurity training programmes in collaboration with industry partners to strengthen the cybersecurity workforce in government, public and private organisations. During 2025 and 2026 up to June, 32 and 13 training programmes respectively were conducted, covering 20,799 and 12,109 participants.

The sharp increase in reported cyber incidents underscores the growing scale and complexity of India’s digital threat landscape. At the same time, the government’s response is increasingly moving beyond incident response towards continuous monitoring, threat intelligence, vulnerability assessment, cyber drills, workforce development and citizen awareness.

As more public services, financial transactions and critical infrastructure move onto digital platforms, the ability to detect threats early and coordinate responses across government and industry is becoming a critical component of India’s digital infrastructure.

Author

Leave a Reply

Your email address will not be published. Required fields are marked *