Resilient India
Why cyber resilience must become the invisible national security shield
Antara Jha
There was a time when national security was measured by the number of soldiers guarding borders, the strength of military equipment, and the strategic positioning of defence forces. Today, however, a nation’s sovereignty can be challenged without a single soldier crossing its territorial boundaries. A malicious line of code can interrupt electricity, disrupt banking transactions, halt transportation systems, compromise healthcare services, manipulate public information, and undermine citizens’ confidence in governance. Modern conflicts increasingly unfold in cyberspace, where attribution is difficult, the actors may remain anonymous, and the consequences can be profound.
India’s rapid digital transformation has accelerated economic growth, expanded digital governance, strengthened financial inclusion, and enhanced public service delivery. Initiatives such as Digital India, widespread adoption of digital payments, expanding cloud infrastructure, smart cities, and increasing digitisation of critical sectors have positioned India as one of the world’s fastest-growing digital economies. While these developments have generated immense opportunities, they have simultaneously expanded the country’s cyber-attack surface.
In this evolving environment, cybersecurity alone is no longer sufficient. The national objective must extend beyond preventing cyberattacks to ensuring that essential services continue to function even when attacks occur. This broader capability is known as cyber resilience, and it should increasingly be viewed as an extension of India’s national security doctrine. Cyber resilience does not merely focus on defence; it encompasses preparation, resistance, recovery, adaptation, and continuous improvement. It reflects the understanding that complete prevention of cyber threats is unrealistic, but minimising disruption and ensuring continuity are both achievable and strategically essential.
Kinetic Doctrine Meets Digital Reality
India’s traditional national security doctrine has historically rested on three visible pillars: military deterrence, diplomatic alignment, and internal security. Cyber resilience does not sit comfortably alongside these because it lacks the theatre of a uniformed adversary. Yet, the strategic logic is identical. Just as India maintains redundant airbases, dispersed missile batteries, and layered air defence to avoid a single catastrophic strike, it must now maintain redundant data centres, segmented operational technology networks, and diversified vendor ecosystems to avoid a single catastrophic cyber strike.
The legal architecture that governs this space in India is still catching up to this strategic reframing. The Information Technology Act, 2000, under Section 70, empowers the government to declare certain systems as ‘protected systems,’ and Section 70A created the National Critical Information Infrastructure Protection Centre (NCIIPC) as the nodal agency for safeguarding Critical Information Infrastructure, or CII. This is a sound foundation, but it was conceived in an era when cyber law was thought of as an extension of commercial and criminal law dealing with hacking, data theft, and online fraud rather than as an extension of national security law, sitting alongside the Unlawful Activities (Prevention) Act or the National Security Act in seriousness.
The lesson from Operation Sindoor’s cyber shadow war is that this conceptual gap must close. India’s cyber threat landscape is entering a phase where AI-driven attacks can autonomously detect and exploit vulnerabilities at machine speed, compressing the entire attack cycle into minutes, with over 265 million cyberattacks recorded in 2025 alone, nearly 60 percent originating from what analysts describe as the China-Pakistan axis. A doctrine that treats this as an ordinary law-and-order matter, handled by cybercrime cells and consumer-protection style breach notifications, will always be a step behind an adversary that treats it as a theatre of pre-positioned strategic advantage.
Cyber Resilience
Cybersecurity traditionally concentrates on protecting systems from unauthorised access, malware, ransomware, phishing, insider threats, and other forms of cybercrime. Cyber resilience adopts a wider perspective. It recognises that sophisticated adversaries may occasionally penetrate even well-protected systems. The real measure of resilience therefore lies in an organisation’s ability to anticipate attacks, maintain critical operations during incidents, recover rapidly, preserve public trust, and strengthen defences through lessons learned.
A useful analogy illustrates this distinction. A sturdy lock on a door represents cybersecurity. A building equipped with emergency exits, backup power, fire suppression systems, alternative communication channels, disaster recovery plans, and trained emergency responders represents cyber resilience. The first seeks to prevent intrusion; the second ensures survival and continuity when prevention alone is insufficient. For a nation like India, cyber resilience means that banking networks continue processing transactions, hospitals continue treating patients, power grids continue supplying electricity, transportation networks remain operational, and government services remain accessible even while responding to cyber incidents.
Redundancy as a Legal Duty
To understand why redundancy matters, imagine a single highway connecting two cities, with all trade, ambulances, and troop movements dependent on it. A single landslide could paralyse an entire region. Now imagine three parallel highways, each independently maintained, so that damage to one simply reroutes traffic to another. This is exactly the logic of cyber redundancy except the highways are power transmission SCADA networks, financial clearing systems, and telecom backbones, and the landslide is a line of malicious code.
Technically, redundancy in critical infrastructure means several layered things working together, and each deserves plain explanation. First, there is network segmentation keeping the ‘IT’ systems that run emails and websites completely separate from the ‘OT’ or operational technology systems that physically control turbines, valves, and circuit breakers, so that a breach of the former cannot cascade into control of the latter. Second, there is geographic and vendor diversification not relying on a single data centre location, a single cloud provider, or a single hardware vendor for an entire sector, because a vulnerability in one vendor’s equipment, once discovered, becomes a master key to every installation using it. Third, there is what engineers call ‘air-gapping’ or physical isolation for the most sensitive control systems, ensuring that even if the internet-facing side of an organisation is compromised, the machinery that actually keeps the lights on cannot be touched remotely. Fourth, there is failover capacity genuinely independent backup systems, not merely backup copies sitting on the same compromised network that can take over operations within minutes of a primary system going down.
The convergence of IT and OT has created a systemic risk where a single breach in a utility provider can cascade into a nationwide service blackout, and legacy OT systems are increasingly being connected to the internet without adequate segmentation, effectively creating backdoors into national security assets. This is precisely the vulnerability that a redundancy-focused legal doctrine must close, not by drafting more advisories, but by making resilience an enforceable obligation with consequences attached, in the same way that fire-safety codes make sprinkler systems mandatory rather than optional in commercial buildings.
The Indian government has taken meaningful steps here already, and it would be both inaccurate and unfair to suggest otherwise. Under the Information Technology Act, 2000, CERT-In has been designated the national agency for responding to cyber security incidents, NCIIPC has been established to protect critical information infrastructure including the power sector, and a dedicated Computer Security Incident Response Team for the power sector, CSIRT-Power, was set up in April 2023. Sectoral CERTs have also been established for thermal, hydro, transmission, distribution, grid operation, and renewable energy sub-sectors, and GRID-INDIA has established a Security Operation Centre to monitor security events across the country. This layered institutional design mirrors, in spirit, exactly the kind of redundancy this article argues for. The question now is whether the legal obligations attached to these bodies carry enough enforceable weight, particularly for privately-owned CII operators who may treat compliance as a cost centre rather than a national duty.
National Security in the Digital Era
The concept of national security has evolved considerably over the past several decades. Contemporary security concerns now include economic security, technological sovereignty, energy security, food security, health security, environmental security, and cyber security. Since virtually all these sectors depend on interconnected digital infrastructure, cyber resilience has emerged as a foundational element supporting every other dimension of national security.
India’s critical infrastructure encompasses sectors such as energy, telecommunications, finance, transportation, healthcare, defence production, space, water supply, and digital public infrastructure. Increasing integration of cloud computing, artificial intelligence, Industrial Control Systems (ICS), Operational Technology (OT), and Internet of Things (IoT) devices has improved operational efficiency while also introducing new vulnerabilities.
Recognising these realities, India has progressively strengthened its cyber governance ecosystem through institutional mechanisms, policy initiatives, sectoral guidelines, and enhanced incident response capabilities. These developments demonstrate a growing understanding that cyber preparedness contributes directly to national resilience and strategic stability.
A Case Study in Silent Risk
Consider a scenario familiar to any student of ecology before we translate it to cyberspace. A forest planted entirely with a single species of tree is efficient to manage, but catastrophically vulnerable to one pathogen, and the entire forest dies together. A forest with mixed species survives the same pathogen because diversity itself is a defence. Indian critical infrastructure has, for decades, quietly built monoculture forests: single dominant vendors for telecom equipment, single dominant cloud platforms for government workloads, single dominant SCADA software suites across entire power distribution circles.
This is not hypothetical anxiety. Threat groups linked to China, tracked under names like RedEcho and SideWinder, have focused specifically on critical infrastructure such as power grids and ports, using supply chain compromises and zero-day exploits, with objectives that include pre-positioning within critical infrastructure for potential future disruption. The word ‘pre-positioning’ deserves particular attention here, because it describes something more chilling than theft; it describes an adversary planting a foothold today, patiently, with no intention of using it until a future crisis demands it.
This is not a uniquely Indian anxiety either. Washington has been remarkably candid about facing the identical threat. In a joint February 2024 advisory, the Cybersecurity and Infrastructure Security Agency, the Federal Bureau of Investigation (FBI), and the National Security Agency confirmed that Chinese state-sponsored actors linked to a group called Volt Typhoon had compromised American critical infrastructure networks and were seeking to maintain long-term access specifically for disruptive or destructive effects during a future crisis, not for routine espionage. FBI Director Christopher Wray described this bluntly: ‘China’s hackers are targeting American civilian critical infrastructure, pre-positioning to cause real-world harm to American citizens and communities in the event of conflict.’ Security firm Dragos confirmed this activity continued through 2025 and remains active today, and disturbingly, agencies found that some intrusions had maintained undetected access to victim networks for at least five years. In one documented case, the group was found inside a small Massachusetts utility’s system for 10 months before discovery.
The parallel for India’s legal doctrine is direct and urgent. A five-year undetected dwell time inside critical infrastructure is not primarily a technology failure, it is a governance failure, an audit failure, and ultimately a legal accountability failure because no statute currently imposes a clear, personally enforceable duty on any named officer to verify, on a recurring and mandatory basis, that CII systems are free of dormant unauthorised access. Section 70 of the IT Act criminalises unauthorised access after the fact; it does not mandate proactive, continuous threat-hunting as a legal duty of care before the fact. This is the redundancy gap that Indian cyber law must close, not merely punishing intrusion, but legally mandating the defensive architecture that makes long-dwell intrusion statistically improbable in the first place.
The Legal Architecture
India’s legal framework provides several important pillars for cybersecurity and cyber resilience, although the rapidly evolving threat landscape continues to require regular policy refinement.
The Information Technology Act, 2000, remains the foundational legislation governing cyberspace in India. It recognises electronic governance, prescribes penalties for cyber offences, establishes adjudicatory mechanisms, and empowers authorities to respond to cyber incidents. Section 70 empowers the government to declare certain computer resources as protected systems, while Section 70B establishes the Indian Computer Emergency Response Team (CERT-In) as the national agency for cyber incident response and coordination.


CERT-In’s incident reporting directions have strengthened national cyber situational awareness by encouraging timely reporting of specified cyber incidents, facilitating coordinated responses, and supporting forensic investigations.
The Digital Personal Data Protection Act, 2023 complements cybersecurity by promoting responsible handling of personal data, reducing privacy risks and encouraging stronger organisational security practices. While primarily focused on data protection, it also contributes indirectly to national cyber resilience by improving trust within the digital ecosystem.
Sector-specific regulators have likewise strengthened cyber governance. The Reserve Bank of India has issued cybersecurity frameworks for banks and payment systems. Financial institutions increasingly maintain Security Operations Centres (SOCs), disaster recovery sites, and cyber crisis management mechanisms. Similar regulatory initiatives are visible in the power, telecommunications and securities sectors.
The National Cyber Security Policy, 2013, although formulated in an earlier technological era, laid the foundation for developing national capabilities, promoting public-private collaboration, encouraging capacity building, and protecting critical information infrastructure. Discussions regarding an updated national cyber strategy reflect the need to address emerging technologies and evolving geopolitical realities.
India has also established the NCIIPC to safeguard critical sectors whose disruption could significantly impact national security, economic stability, public health, or public safety. This institution represents an important element of India’s resilience architecture.
The Missing Statute
India is far from alone in wrestling with this challenge, and there is genuine, humble value in studying how other jurisdictions have chosen to legislate their way toward resilience, without India needing to import any model wholesale.
The European Union’s second Network and Information Security Directive, known as NIS2, took effect in October 2024 and represents perhaps the world’s most comprehensive attempt to convert redundancy from a best practice into a binding legal obligation. NIS2 substantially expands the number of sectors treated as ‘essential’ and ‘important’, extending well beyond energy and finance into wastewater management, space, food supply chains, and public administration, precisely the kind of sectoral expansion that India’s own CII notifications have been comparatively slower to embrace. Crucially, NIS2 imposes direct, personal liability on management bodies of covered entities for inadequate cybersecurity risk-management measures, converting board-level accountability from a corporate governance nicety into an enforceable legal exposure, with fines reaching into tens of millions of euros for the largest operators.

The US, for its part, has relied less on a single omnibus statute and more on a sector-specific patchwork anchored by Presidential Policy Directive 21 and the Cybersecurity and Infrastructure Security Agency’s coordinating role, supplemented since 2022 by mandatory incident reporting requirements under the Cyber Incident Reporting for Critical Infrastructure Act, which requires covered entities to report substantial cyber incidents within 72 hours. Israel, facing perhaps the most sustained real-world cyber conflict pressure of any democracy, established the Israel National Cyber Directorate with sweeping powers to mandate specific technical controls, including data localisation and redundancy requirements, directly on operators of essential services, treating cyber defence architecture with the same regulatory bluntness as building codes for earthquake resistance.
Australia offers perhaps the most instructive recent example for India specifically, because it too faces a persistent, patient state-linked adversary. In November 2025, Australian intelligence reported pre-positioning activity within critical infrastructure across the telecom and water sectors, assessed as preparation for regional sabotage and disruption of essential services. In direct legislative response, Australia’s Security of Critical Infrastructure Act was substantially strengthened to require mandatory risk-management programmes, government ‘step-in’ powers during serious incidents, and positive security obligations across an expanded list of sectors including data storage and processing, a model India’s policymakers would do well to study closely, not to copy verbatim, but to adapt to India’s own federal structure and private-sector ownership patterns.
Learning from Real-World Cyber Incidents
The importance of cyber resilience becomes clearer when examining recent global experiences.
The Colonial Pipeline ransomware attack in the US in 2021 temporarily disrupted fuel supplies across several states. Although the malware primarily affected business IT systems rather than operational pipelines, precautionary shutdowns resulted in fuel shortages, public panic buying, and significant economic disruption. The incident demonstrated how cyberattacks against digital infrastructure can produce cascading effects extending well beyond technology.
The SolarWinds supply chain compromise revealed how trusted software updates could become vehicles for sophisticated cyber espionage. Rather than attacking thousands of organisations individually, adversaries exploited a single trusted software provider to infiltrate numerous government agencies and private organisations worldwide. This incident reshaped global thinking regarding software supply chain security and vendor risk management.
The MOVEit Transfer vulnerabilities exploited in 2023 similarly illustrated how widely used software products can become gateways affecting governments, financial institutions, universities, healthcare providers, and multinational corporations simultaneously. Such incidents highlight that resilience requires continuous monitoring of third-party dependencies alongside internal security measures.
The WannaCry ransomware outbreak of 2017 affected more than 150 countries, disrupting hospitals, businesses, and government agencies. The United Kingdom’s National Health Service experienced cancellations of appointments and operational challenges. Importantly, many affected systems had delayed applying available security updates, illustrating how routine cyber hygiene remains an essential component of resilience.
Closer to India, the AIIMS New Delhi cyber incident in 2022 disrupted hospital information systems, affecting patient services for several days. While healthcare professionals continued delivering essential medical care through alternative procedures, the incident underscored the importance of resilient backup systems, offline operational capabilities, disaster recovery planning, and timely restoration mechanisms in protecting public health.
These incidents collectively demonstrate that resilience is not merely a technical aspiration but an operational necessity.
International Law & Policy
Cyberspace transcends national borders, making international cooperation indispensable.
The UNGGE and the Open-Ended Working Group (OEWG) have contributed significantly to developing voluntary norms for responsible state behaviour in cyberspace. These initiatives affirm that international law, including the Charter of the United Nations, applies to state conduct in cyberspace and encourage responsible behaviour that protects critical infrastructure.
The Budapest Convention on Cybercrime remains the first international treaty specifically addressing cybercrime, promoting harmonisation of criminal laws, digital evidence cooperation, and international investigation mechanisms. Although India is not a party to the Convention, it actively cooperates internationally through bilateral and multilateral channels while advocating inclusive global frameworks that reflect the interests of a broader range of states.
The Tallinn Manual, prepared by an independent group of international legal experts, provides influential academic analysis regarding the application of international law to cyber operations. While not legally binding, it contributes substantially to scholarly and policy discussions concerning sovereignty, state responsibility, due diligence, and the law of armed conflict in cyberspace.
The Budapest Convention’s Second Additional Protocol, adopted to facilitate cross-border access to electronic evidence, reflects growing recognition that cybercrime investigations increasingly require rapid international cooperation.
Regional and multilateral organisations including the G20, Shanghai Cooperation Organisation (SCO), BRICS, Quad, and the International Telecommunication Union (ITU) have also emphasised cyber capacity building, information sharing, secure digital infrastructure, and collaborative approaches to emerging cyber threats.
Emerging Global Challenges
The cyber threat landscape continues to evolve at remarkable speed. AI is transforming both cyber defence and cyber offence. AI assists defenders by detecting anomalies, automating incident response, and predicting threats. Conversely, malicious actors increasingly exploit AI to generate sophisticated phishing campaigns, automate vulnerability discovery, produce convincing deepfakes, and enhance social engineering attacks. Supply chain vulnerabilities have become one of the most significant global concerns.
Organisations increasingly depend on interconnected vendors, cloud providers, managed service providers, and software developers. A compromise affecting one trusted supplier may cascade across thousands of organisations. Operational Technology environments controlling electricity generation, water treatment, manufacturing, and transportation increasingly face sophisticated cyber threats. Unlike conventional IT systems, disruptions in OT environments may produce immediate physical consequences affecting public safety. The rapid expansion of IoTs devices further increases the attack surface. Poorly secured connected devices may become entry points into larger organisational networks if not appropriately managed. These developments reinforce the importance of integrating legal governance, technical safeguards, organisational preparedness, and international cooperation into a comprehensive resilience strategy.
India’s Cyber Resilience
India’s future cyber resilience will depend upon sustained collaboration among government institutions, private industry, academia, civil society, and international partners. Legally, periodic review of cyber legislation should continue to ensure that evolving technologies such as artificial intelligence, quantum computing, cloud infrastructure, and critical digital platforms receive appropriate regulatory attention. Harmonisation of sector-specific cybersecurity requirements would improve consistency across critical infrastructure operators.

Institutionally, greater information sharing between public authorities and private operators can improve situational awareness while respecting confidentiality and commercial interests. Regular national cyber exercises involving multiple sectors can strengthen coordinated incident response capabilities. Technically, organisations should continue adopting zero trust architectures, multi-factor authentication, encryption, network segmentation, continuous vulnerability management, secure software development practices, resilient backup systems, and regular recovery testing. Resilience should be evaluated not only by the ability to prevent attacks but also by the speed of recovery and continuity of essential services. Capacity building remains equally important. Cyber resilience depends upon skilled professionals, informed leadership, trained employees, cybersecurity education, digital literacy, and continuous professional development. Human awareness often remains the strongest defence against social engineering attacks.
Internationally, India can continue strengthening cyber diplomacy, promoting responsible state behaviour, participating in capacity-building initiatives, encouraging trusted technology partnerships, and contributing constructively to the development of global cyber governance frameworks that are equitable, transparent, and respectful of national sovereignty.
Conclusion
The defining characteristic of 21st century national security is not merely the ability to defend borders but the ability to ensure that society continues to function despite increasingly complex digital threats. Cyber resilience reflects this new strategic reality. It represents the convergence of law, technology, governance, diplomacy, institutional preparedness, and public trust.
India’s expanding digital economy, ambitious technological initiatives, and growing global influence make cyber resilience not simply a technical objective but a strategic national imperative. A resilient nation is one that anticipates disruption without fearing it, withstands attacks without losing confidence, recovers rapidly without prolonged paralysis, and continuously evolves to meet emerging challenges.
Ultimately, cyber resilience should be understood not as an isolated cybersecurity objective but as an enduring extension of India’s broader national security doctrine. It safeguards not only digital networks but also economic stability, democratic governance, essential public services, and national development. In an age where cyber threats are persistent and borders increasingly digital, resilience is no longer merely a defensive strategy, it is a defining attribute of a secure, confident, and future-ready nation.

VIDEO