India's cybersecurity gap widens as digital growth surges: Report
Synopsis
Key Takeaways
India's rapid digital expansion has significantly outpaced its cybersecurity readiness, according to a new report, which flags a sharp rise in ransomware, phishing, data breaches, and cyber espionage as mounting threats to critical infrastructure, financial systems, and ordinary citizens. The findings underscore a widening vulnerability gap at a time when India is among the world's fastest-growing digital economies.
Key Findings
The report, published by India Narrative, identified a critical shortage of skilled cybersecurity professionals and called on universities and technical institutes to integrate cybersecurity into mainstream curricula and expand specialised training programmes. It also flagged the growing menace of financial fraud tied to digital payments, noting that government websites, healthcare databases, and even power infrastructure have faced attempted cyber intrusions.
A separate recent report added further weight to the concern, revealing that credential theft and identity compromise have emerged as the primary entry points for large-scale cyber attacks against Indian IT firms, with 265.52 million detections recorded across over 8 million endpoints. The report warned that India's IT sector is particularly exposed due to its extensive use of cloud platforms, remote access systems, and third-party integrations — where a single compromised credential can cascade across multiple environments.
Institutional Response and Its Limits
Institutions including the Indian Computer Emergency Response Team (CERT-In), the National Critical Information Infrastructure Protection Centre (NCIIPC), and the National Cyber Security Coordinator have strengthened India's institutional response mechanisms. However, the India Narrative report cautioned that the scale and sophistication of current threats demand a far more comprehensive and coordinated national strategy than what is presently in place.
Notably, many organisations — both in the public and private sectors — continue to operate with outdated software, weak encryption, and inadequate data protection practices. The report stressed that stronger cybersecurity standards and mandatory compliance frameworks, particularly for sectors handling critical infrastructure and sensitive user data, are essential to reducing systemic risk.
Digital Literacy and Legal Reform
Beyond technical fixes, the report called for large-scale digital literacy campaigns to promote safe online practices and cyber hygiene. This is especially urgent as digital services increasingly reach rural and semi-urban populations, where many first-time internet users remain highly vulnerable to fraud and social engineering attacks.
On the policy front, the report argued that existing laws often struggle to keep pace with the rapidly evolving nature of cybercrime.