**Executive Summary**
This document is the answer given by the Minister of State for Electronics and Information Technology in response to questions raised in the Lok Sabha regarding the strategy for mandatory security audits, ransomware attack management, establishment of a National Cyber Resilience Fund, expansion of the cybersecurity talent pool, and scaling up of Cyber Suraksha Kendras. The response outlines several initiatives and measures undertaken by the government to strengthen the nation's cyber resilience. It indicates the answer date as of 17.12.2025.
**Key Points / Main Content**
* **Cybersecurity Strategy and Audits:**
* The government's policies aim to ensure a safe, trusted, and accountable cyberspace.
* CERT-In and NCIIPC safeguard digital services, conduct regular monitoring and vulnerability audits.
* CERT-In issued Comprehensive Cyber Security Audit Policy Guidelines in July 2025 for conducting consistent, effective, and secure audits.
* Cyber security audits are conducted at least annually by empanelled security auditing organizations.
* **Ransomware and Cybercrime Management:**
* CERT-In is the national agency for responding to cyber security incidents.
* Issues alerts and advisories on cyber threats/vulnerabilities with AI countermeasures.
* Advises remedial measures and coordinates incident response.
* NIC conducts annual security audits for critical infrastructure through CERT-In empanelled agencies.
* Implements Zero Trust Security and cybersecurity awareness programs for government employees.
* **Cyber Threat Intelligence and Response:**
* CERT-In operates an automated cyber threat intelligence exchange platform.
* Cyber security mock drills are conducted regularly.
* Sector-specific CSIRTs (e.g., CSIRT-Fin, CSIRT-Power) have been established.
* A Cyber Crisis Management Plan (CCMP) has been formulated.
* 213 CCMP sensitisation workshops have been conducted.
* **Indigenous Development:**
* The Centre for Development of Advanced Computing develops indigenous cybersecurity tools.
* **Cybersecurity Talent Pool Expansion:**
* The ISEA program raises awareness among internet users (website: https://www.infosecawareness.in).
* The CSPAI program, launched by CERT-In, equips cybersecurity professionals with AI skills.
* **Cyber Swachhta Kendra (CSK):**
* It is a citizen-centric service from CERT-In to detect malicious programs.
* Provides cybersecurity tips and best practices.
* Sends daily alerts on botnet/malware infections.
**Impact Analysis**
**Stakeholder:** Critical Infrastructure Entities
* **Impact:** Mandatory Security Audits are required for these entities.
* **Action Required:** Need to comply with the CERT-In Comprehensive Cyber Security Audit Policy Guidelines to conduct annual audits.
**Stakeholder:** Government Organizations and Employees
* **Impact:** Subject to regular cybersecurity awareness programs and audits by NIC.
* **Action Required:** Implement Zero Trust Security, participate in awareness programs, and follow security guidelines.
**Stakeholder:** Cybersecurity Professionals
* **Impact:** Opportunity to enhance skills in AI-related cybersecurity through the CSPAI program.
* **Action Required:** Consider participating in the CSPAI program to acquire skills in securing AI systems.
**Stakeholder:** Citizens/Internet Users
* **Impact:** Benefit from increased cybersecurity awareness through the ISEA program and Cyber Swachhta Kendra (CSK).
* **Action Required:** Utilize the resources provided by ISEA and CSK to improve personal cybersecurity practices.
Key Entities Referenced
Indian Computer Emergency Response Team (CERT-In): National agency designated for responding to cyber security incidents, responsible for issuing alerts, advisories, and conducting audits.
Information Technology Act, 2000: The primary legislation under which CERT-In operates and conducts security audits.
Ministry of Electronics and Information Technology: The government ministry overseeing cybersecurity initiatives and CERT-In.
National Cyber Resilience Fund: A fund intended to support industry efforts to harden their systems against cyber threats.
Cyber Crisis Management Plan (CCMP): A plan for all Government bodies to counter cyber-attacks and enable coordinated recovery.
GOVERNMENT OF INDIA
MINISTRY OF ELECTRONICS AND INFORMATION TECHNOLOGY
LOK SABHA
UNSTARRED QUESTION NO. 2823
TO BE ANSWERED ON: 17.12.2025
NATIONAL CYBER RESILIENCE FUND
2823. DR. JAYANTA KUMAR ROY:
Will the Minister of ELECTRONICS AND INFORMATION TECHNOLOGY be pleased to state:
(a) the strategy for Mandatory Security Audits for critical infrastructure entities under CERT-In;
(b) the manner in which the Government is addressing the rise of ransomware attacks and cross-border
cyber-crime incidents;
(c) whether a National Cyber Resilience Fund has been established to support industry hardening
efforts;
(d) the steps being taken by the Government to increase the talent pool of certified cyber security
professionals nationwide; and
(e) the manner in which the Cyber Suraksha Kendras are being scaled up to provide effective regional
cyber incident response?
ANSWER
MINISTER OF STATE FOR ELECTRONICS AND INFORMATION TECHNOLOGY
(SHRI JITIN PRASADA)
(a) to (e): The policies of the Government of India aim to ensure a safe, trusted, and accountable
cyberspace. It remains vigilant and fully conscious of the cyber threat to India’s digital infrastructure.
Indian Computer Emergency Response Team (CERT-In) and National Critical Information
Infrastructure Protection Centre (NCIIPC) work continuously to safeguard digital services, including
the critical sectors.
These agencies regularly monitor incidents, support timely response and ensure restoration. They
conduct security and vulnerability audits under the Information Technology Act and Rules made under.
In this regard, CERT-In has developed and issued a Comprehensive Cyber Security Audit Policy
Guidelines in July 2025 to carry out cyber security audits. These audits are done in a consistent,
effective, and secure manner across sectors including critical infrastructure.
As per the guidelines, cyber security audit are conducted at least once in a year. It has empanelled 231
security auditing organizations to support and audit implementation of Information Security Best
Practices.
In addition, the Government has undertaken several measures to strengthen security of cyber ecosystem
including against ransomware and Cross-Border Cybercrime:
1. CERT-In is designated as the national agency for responding to cyber security incidents under
the provisions of section 70B of the Information Technology Act, 2000.2. It issues alerts & advisories regarding latest cyber threats/vulnerabilities including malicious
attacks using AI and countermeasures regularly.
3. It advises remedial measures to affected organisations and coordinates incident response
measures.
4. National Informatics Centre (NIC) carries out comprehensive security audit annually for its
Critical Infrastructure to address the increasing number of ransomware attacks through CERT-
In empanelled agencies including:
a) Information and Communication Technology infrastructure Audit of Central
Ministries/Departments, States /UTs and National Data Centres.
b) Comprehensive Security Audit of Critical Web applications /databases/platforms.
c) Deployment of Unified Endpoint Management, Endpoint Detection and Response solutions
across central ministries and departments for endpoint protection.
d) Removal of obsolete and legacy systems from the network.24×7 monitoring, detection, and
mitigation of cyber threats using AI/ML and advanced security tools.
e) Continuous vulnerability assessments, system hardening, and proactive identification of
application/system weaknesses.
f) Implementation of Zero Trust Security across NIC’s ICT infrastructure.
g) Regular cybersecurity awareness programs for government employees.
5. CERT-In operates an automated cyber threat intelligence exchange platform for sharing tailored
alerts with organisations across sectors for proactive threat mitigation.
6. Cyber security mock drills are conducted regularly to enable assessment of cyber security
posture and preparedness of various organisations.
7. Establishment of sector-specific Computer Security Incident Response Teams (CSIRTs), such
as CSIRT-Fin (Finance) and CSIRT-Power, to monitor & respond to cyber incidents within
respective sectors.
8. Formulation of the Cyber Crisis Management Plan (CCMP) for all Government bodies to
counter cyber-attacks and enable coordinated recovery.
9. 213 CCMP sensitisation workshops have been conducted to strengthen preparedness across
organisations.
10. Development of indigenous cybersecurity tools by Centre for Development of Advanced
Computing to reduce dependence on foreign solutions.
Expanding Cybersecurity Talent Pool
• Information Security Education & Awareness (“ISEA”) program has been launched to generate
awareness among users while using internet.
o A dedicated website has been created for information security awareness that generates
and upgrades relevant awareness material on a regular basis and can be accessed at
https://www.infosecawareness.in.
• Certified Security Professional in Artificial Intelligence (CSPAI) program launched by CERT-
In in September 2024 equips cybersecurity professionals with the skills to secure AI systems.o It helps in addressing AI-related threats, and ultimately ensure trustworthy AI
deployment in business environments.
Cyber Swachhta Kendra (CSK)
It is a citizen-centric service provided by CERT-In, which extends the vision of Swachh Bharat to the
Cyber Space
• It is the Botnet Cleaning and Malware Analysis Centre and helps to detect malicious programs
and provides free tools to remove the same
• It also provides cyber security tips and best practices for citizens and organisations
• Alerts regarding botnet/malware infections and vulnerable services are sent on a daily basis to
organizations across sectors along with remedial measures.
******