NIELIT launches Cyber Kushti 2026 hackathon to test AI-era security judgment

Share:
Audio Loading voice…
NIELIT launches Cyber Kushti 2026 hackathon to test AI-era security judgment

Synopsis

India's cybersecurity training body NIELIT has flipped the hackathon script: instead of racing to find vulnerabilities, teams in Cyber Kushti 2026 must audit a deliberately flawed AI-generated security report — earning points for dismissing false positives as much as for spotting real threats. It is a direct response to the false-positive crisis that plagues enterprise security operations.

Key Takeaways

NIELIT launched CYBER KUSHTI 2026 on 17 August 2026 from New Delhi as a nationwide cybersecurity and AI hackathon.
Registration is free and open from 15 August to 10 September 2026 for student and researcher teams of three .
All teams receive an identical, intentionally flawed Security Assessment Package containing AI-generated, false, duplicate, and genuine findings.
Scoring rewards correct dismissal of inaccurate findings, not just identification of real vulnerabilities.
The event is the official technical track of NCCDFI 2026 , with CERT-In as knowledge partner and ISAC Foundation as co-organiser.

The National Institute of Electronics and Information Technology (NIELIT), operating under the Ministry of Electronics and Information Technology (MeitY), on Sunday, 17 August 2026, formally launched CYBER KUSHTI 2026 — a nationwide cybersecurity and Artificial Intelligence (AI) hackathon designed to measure participants' capacity for human judgment in security assessments, not merely their ability to flag vulnerabilities. The competition was announced from New Delhi and registrations are open from 15 August through 10 September 2026.

What CYBER KUSHTI 2026 Is

CYBER KUSHTI 2026 serves as the official parallel technical track of the 3rd National Conference on Cyber Security, Digital Forensics and Intelligence (NCCDFI 2026). It is being organised in collaboration with the Information Sharing and Analysis Center (ISAC Foundation) under the National Security Database (NSD), with CERT-In serving as the knowledge partner. Participation is free of cost and open to students and independent researchers competing in teams of three.

How the Format Works

Unlike conventional cybersecurity contests centred on vulnerability hunting or Capture The Flag (CTF) challenges, this competition hands every team an identical, deliberately imperfect Security Assessment Package. The package contains AI-generated findings, source code, application logs, architecture documents, static analysis reports, dependency scans, and secrets scans. Crucially, organisers have intentionally embedded false, duplicated, and genuine findings — while omitting some real vulnerabilities — to stress-test participants' analytical rigour.

Teams must produce a corrected and prioritised security assessment, explaining and defending each decision. Participants earn credit not only for surfacing real threats but also for correctly dismissing inaccurate or duplicate findings generated by automated tools.

Why This Approach Matters

Organisers say the competition reflects a widening gap in the cybersecurity workforce: the ability to distinguish genuine threats from false positives produced by automated scanning systems. As AI-driven security tools proliferate, the risk of alert fatigue and misplaced priorities grows — making calibrated human judgment a premium skill.

Speaking at the launch, Prof. Tripathi noted that the cybersecurity landscape has evolved from merely finding issues to determining which findings are most critical and require immediate attention. He added that while machines can generate security findings at scale, human judgment remains essential in verifying their accuracy and prioritising responses.

Key Details at a Glance

Registration opened on 15 August 2026 and closes on 10 September 2026. The competition is free to enter and structured around teams of three. All teams work from the same assessment package, ensuring a level playing field focused entirely on analytical quality rather than tooling advantage. This is the first edition of CYBER KUSHTI under the NCCDFI umbrella, positioning it as a recurring benchmark for AI-era security talent in India.

Point of View

And the false-positive rate in automated scans routinely exceeds 50%. By rewarding teams that correctly dismiss bad findings, NIELIT is training for the actual job — not the idealised version of it. The question is whether a single annual hackathon can meaningfully shift workforce culture, or whether it needs to be embedded in formal curricula under MeitY's skilling mandates to have lasting impact.
NationPress
17 Aug 2026

Frequently Asked Questions

What is CYBER KUSHTI 2026?
CYBER KUSHTI 2026 is a free, nationwide cybersecurity and AI hackathon launched by NIELIT under MeitY, designed to test participants' ability to evaluate and prioritise security findings from a deliberately flawed AI-generated assessment package. It runs as the official technical track of the 3rd National Conference on Cyber Security, Digital Forensics and Intelligence (NCCDFI 2026).
Who can participate in CYBER KUSHTI 2026?
The competition is open to students and independent researchers who form teams of three. Participation is entirely free of cost, and registration runs from 15 August to 10 September 2026.
How is CYBER KUSHTI 2026 different from a standard CTF competition?
Unlike Capture The Flag contests that focus on finding vulnerabilities, Cyber Kushti 2026 gives all teams the same imperfect Security Assessment Package and rewards them for correctly prioritising real threats and dismissing false or duplicate AI-generated findings. The emphasis is on analytical judgment, not speed of discovery.
Which organisations are behind CYBER KUSHTI 2026?
NIELIT is the lead organiser, with the ISAC Foundation under the National Security Database (NSD) as co-organiser and CERT-In serving as the knowledge partner.
Why is human judgment being emphasised in a cybersecurity competition?
Organisers say automated security tools increasingly generate large volumes of false positives, and the ability to distinguish genuine threats from noise is now a critical professional skill. The competition is designed to build and benchmark that capacity among the next generation of Indian cybersecurity professionals.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 1 month ago
  2. 1 month ago
  3. 1 month ago
  4. 2 months ago
  5. 4 months ago
  6. 9 months ago
  7. 10 months ago
  8. 1 year ago
Google Prefer NP
On Google