Home India Ministry of Electronics and Information Technology Government’s initiatives to strengthen security of cyber eco...
Date: 2025-12-17 Category: Press Release State: Union Government Country: India

Government’s initiatives to strengthen security of cyber ecosystem, including against ransomware and Cross-Border Cybercrime

Issued by Ministry of Electronics and Information Technology · Not Applicable

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

**Executive Summary** The Government of India is implementing initiatives to strengthen the security of its cyber ecosystem, particularly against ransomware and cross-border cybercrime. CERT-In has developed Comprehensive Cyber Security Audit Policy Guidelines to be implemented by July 2025. These initiatives include cybersecurity audits, threat intelligence sharing, and awareness programs. **Key Points / Main Content** * **Cybersecurity Audits and Best Practices:** * CERT-In developed Comprehensive Cyber Security Audit Policy Guidelines to carry out audits across sectors, including critical infrastructure, by July 2025. * Cybersecurity audits are conducted at least once a year, supported by 231 empanelled security auditing organizations. * **CERT-In and National Cyber Security Initiatives:** * CERT-In is designated as the national agency for responding to cyber security incidents. * CERT-In issues alerts and advisories regarding cyber threats, vulnerabilities, and countermeasures regularly. * CERT-In advises remedial measures and coordinates incident response. * **NIC Security Measures:** * NIC carries out comprehensive security audits annually for its critical infrastructure. * Includes ICT infrastructure audits for Central Ministries/Departments, States/UTs, and National Data Centres. * Includes security audits of web applications, databases, and platforms. * Includes deployment of Endpoint Management and Endpoint Detection and Response solutions. * Includes removal of obsolete systems and 24/7 monitoring using AI/ML. * Includes vulnerability assessments, system hardening, and proactive identification of weaknesses. * Includes Implementation of Zero Trust Security. * Includes regular cybersecurity awareness programs for government employees. * **Threat Intelligence and Incident Response:** * CERT-In operates an automated cyber threat intelligence exchange platform. * Cybersecurity mock drills are regularly conducted. * Sector-specific Computer Security Incident Response Teams (CSIRTs) have been established, for example, CSIRT-Fin (Finance) and CSIRT-Power. * **Cyber Crisis Management and Preparedness:** * A Cyber Crisis Management Plan (CCMP) is formulated for all Government bodies. * CCMP sensitisation workshops have been conducted. * **Indigenous Cybersecurity Tools:** * Development of indigenous cybersecurity tools by Centre for Development of Advanced Computing. * **Expanding Cybersecurity Talent Pool:** * Information Security Education & Awareness (“ISEA”) program has been launched. * A dedicated website has been created for information security awareness: https://www.infosecawareness.in. * Certified Security Professional in Artificial Intelligence (CSPAI) program launched by CERT-In in September 2024. * **Cyber Swachhta Kendra (CSK):** * CSK is a citizen-centric service provided by CERT-In. * CSK is the Botnet Cleaning and Malware Analysis Centre. * Provides cybersecurity tips and best practices. * Sends alerts regarding botnet/malware infections. **Impact Analysis** **Government of India:** * **Impact:** Enhanced cybersecurity posture, improved incident response capabilities, reduced dependence on foreign solutions, and increased awareness among government employees. * **Action Required:** Implement the Cyber Crisis Management Plan (CCMP), participate in sensitisation workshops, adopt indigenous cybersecurity tools, and promote cybersecurity awareness programs. **Indian Citizens and Organizations:** * **Impact:** Increased awareness about cybersecurity risks and best practices, access to free tools for malware removal, and improved protection against cyber threats. * **Action Required:** Utilize the Cyber Swachhta Kendra (CSK) services, follow cybersecurity tips and best practices, and stay informed about cyber threats through alerts and advisories. **Cybersecurity Professionals:** * **Impact:** Increased opportunities for professional development through programs like Certified Security Professional in Artificial Intelligence (CSPAI) and enhanced skills in securing AI systems. * **Action Required:** Participate in training programs, stay up-to-date with the latest cybersecurity threats and trends, and apply best practices to secure AI systems.

Key Entities Referenced

Indian Computer Emergency Response Team (CERT-In): National agency for responding to cyber security incidents and developing guidelines, including the Comprehensive Cyber Security Audit Policy Guidelines. Information Technology Act, 2000: The Act under which CERT-In is designated as the national agency for responding to cyber security incidents, specifically under section 70B. Cyber Crisis Management Plan (CCMP): A plan for all Government bodies to counter cyber-attacks and enable coordinated recovery. Cyber Swachhta Kendra (CSK): A citizen-centric service provided by CERT-In, which extends the vision of Swachh Bharat to the Cyber Space by providing tools and information to detect and remove malware. National Critical Information Infrastructure Protection Centre (NCIIPC): Agency that works with CERT-In to safeguard digital services and critical sectors.
Official Source Record View Original Source →
See Full Document Text
Ministry of Electronics & IT Government’s initiatives to strengthen security of cyber ecosystem, including against ransomware and Cross-Border Cybercrime प्रव तथ: 17 DEC 2025 12:51PM by PIB Delhi The policies of the Government of India aim to ensure a safe, trusted, and accountable cyberspace. It remains vigilant and fully conscious of the cyber threat to India’s digital infrastructure. Indian Computer Emergency Response Team (CERT-In) and National Critical Information Infrastructure Protection Centre (NCIIPC) work continuously to safeguard digital services, including the critical sectors. These agencies regularly monitor incidents, support timely response and ensure restoration. They conduct security and vulnerability audits under the Information Technology Act and Rules made under. In this regard, CERT-In has developed and issued a Comprehensive Cyber Security Audit Policy Guidelines in July 2025 to carry out cyber security audits. These audits are done in a consistent, effective, and secure manner across sectors including critical infrastructure. As per the guidelines, cyber security audit are conducted at least once in a year. It has empanelled 231 security auditing organizations to support and audit implementation of Information Security Best Practices. In addition, the Government has undertaken several measures to strengthen security of cyber ecosystem including against ransomware and Cross-Border Cybercrime: 1. CERT-In is designated as the national agency for responding to cyber security incidents under the provisions of section 70B of the Information Technology Act, 2000. 2. It issues alerts & advisories regarding latest cyber threats/vulnerabilities including malicious attacks using AI and countermeasures regularly. 3. It advises remedial measures to affected organisations and coordinates incident response measures. 4. National Informatics Centre (NIC) carries out comprehensive security audit annually for its Critical Infrastructure to address the increasing number of ransomware attacks through CERT-In empanelled agencies including: a) Information and Communication Technology infrastructure Audit of Central Ministries/Departments, States /UTs and National Data Centres. b) Comprehensive Security Audit of Critical Web applications /databases/platforms. c) Deployment of Unified Endpoint Management, Endpoint Detection and Response solutions across central ministries and departments for endpoint protection. d) Removal of obsolete and legacy systems from the network.24×7 monitoring, detection, and mitigation of cyber threats using AI/ML and advanced security tools.e) Continuous vulnerability assessments, system hardening, and proactive identification of application/system weaknesses. f) Implementation of Zero Trust Security across NIC’s ICT infrastructure. g) Regular cybersecurity awareness programs for government employees. 5. CERT-In operates an automated cyber threat intelligence exchange platform for sharing tailored alerts with organisations across sectors for proactive threat mitigation. 6. Cyber security mock drills are conducted regularly to enable assessment of cyber security posture and preparedness of various organisations. 7. Establishment of sector-specific Computer Security Incident Response Teams (CSIRTs), such as CSIRT-Fin (Finance) and CSIRT-Power, to monitor & respond to cyber incidents within respective sectors. 8. Formulation of the Cyber Crisis Management Plan (CCMP) for all Government bodies to counter cyber-attacks and enable coordinated recovery. 9. 213 CCMP sensitisation workshops have been conducted to strengthen preparedness across organisations. 10. Development of indigenous cybersecurity tools by Centre for Development of Advanced Computing to reduce dependence on foreign solutions. Expanding Cybersecurity Talent Pool Information Security Education & Awareness (“ISEA”) program has been launched to generate awareness among users while using internet. A dedicated website has been created for information security awareness that generates and upgrades relevant awareness material on a regular basis and can be accessed at https://www.infoseca wareness.in. Certified Security Professional in Artificial Intelligence (CSPAI) program launched by CERT-In in September 2024 equips cybersecurity professionals with the skills to secure AI systems. It helps in addressing AI-related threats, and ultimately ensure trustworthy AI deployment in business environments. Cyber Swachhta Kendra (CSK) It is a citizen-centric service provided by CERT-In, which extends the vision of Swachh Bharat to the Cyber Space It is the Botnet Cleaning and Malware Analysis Centre and helps to detect malicious programs and provides free tools to remove the same It also provides cyber security tips and best practices for citizens and organisations Alerts regarding botnet/malware infections and vulnerable services are sent on a daily basis to organizations across sectors along with remedial measures. This information was submitted by Union Minister of State for Electronics and Information Technology Shri Jitin Prasada in Lok Sabha on 17.12.2025. *** MSZ (रलीज़ आईडी: 2205047) आगंतुक पटल : 1106 इस वज्ञ को इन भाषाओ ंम पढ़: Marathi , ही , Tamil

Continue your research