💥Join UPSC 2027,2028 Mentorship (July Batch) + XFactor Notes & Microthemes PDF

GS Paper: Cyber Security

  • [13th August 2024] The Hindu Op-ed: Disinformation, AI and ‘cyber chakravyuh’

    [13th August 2024] The Hindu Op-ed: Disinformation, AI and ‘cyber chakravyuh’

    PYQ Relevance:

    Mains: 

    Q. Discuss different types of cyber crimes and measures required to be taken to fight the menace. (UPSC IAS/2020)
    Q. “The emergence of the Fourth Industrial Revolution (Digital Revolution) has initiated e-Governance as an integral part of government”. Discuss. (UPSC IAS/2020)

    Note4Students: 

    Mains: Challenges due to AI in 2024;

    Mentor comment: Concerns in 2024 were fueled by fears of new threats from Artificial Intelligence (AI), including Generative AI and Artificial General Intelligence (AGI). The growing potential for disinformation and cyber threats made the outlook particularly grim. The 33rd Summer Olympic Games in France during July-August 2024 were seen as prime targets for digital criminals, prompting experts to prepare for unprecedented attacks. Fortunately, the Games concluded peacefully, without any major incidents. However, the absence of a significant attack shouldn’t lead to complacency, as new digital threats continue to emerge, requiring ongoing vigilance from security agencies.

    Let’s learn!

    __

    Why in the News?

     As 2024 began, there were warnings of new security threats on the horizon, and security experts around the world were preparing for a series of attacks across various areas.

    Challenges due to AI in 2024: 

    • Increased Disinformation: The year began with a surge in disinformation, particularly surrounding the Taiwanese elections in January 2024. The atmosphere was rife with fake posts and videos, largely attributed to external influences, notably China.  
    • National Security Concerns: The combination of AI-generated disinformation and cyber attacks poses a serious threat to national security. This is particularly evident in the ongoing conflict in Ukraine, where both sides have employed disinformation tactics, leading to disruptions in critical infrastructure such as telecommunications and power grids.
    • Global Electoral Impact: As elections are scheduled in at least 64 countries in 2024, the potential for AI to disrupt electoral processes has raised alarms.  

    A recent software glitch in Microsoft Windows

    • Global Outage: The outage began on July 19, 2024, affecting Microsoft’s Azure cloud service and quickly spreading to various regions, including the United States and India.
      • It disrupted critical operations such as flight schedules, air traffic control, and stock exchanges, showcasing the vulnerability of interconnected systems.
    • Severity Rating: The Indian Computer Emergency Response Team (CERT-IN) issued a ‘critical’ severity rating for the incident, indicating the serious nature of the disruption, even though a cyberattack did not cause it.
    • Impact on Devices: Microsoft reported that over eight million Windows devices experienced failures due to the glitch, leading to widespread operational issues.
      • Many users encountered the Blue Screen of Death (BSOD), which trapped them in boot loops and rendered their devices inoperable.
    Do you know?

    This incident recalls previous significant cyberattacks, such as WannaCry in 2017, which infected over 230,000 computers globally, and Stuxnet in 2010, which specifically targeted Iran’s nuclear program.
    Steps taken by the Indian government: 

    Indian Cyber Crime Coordination Centre (I4C):  Established to provide a comprehensive framework for law enforcement agencies (LEAs) to address cyber crimes effectively. It includes various components such as the National Cyber Crime Threat Analytics Unit and the National Cyber Crime Reporting Portal, facilitating state coordination.
    Indian Computer Emergency Response Team (CERT-In): It acts as the central agency to help control cybersecurity incidents and disseminate alerts.
    Cyber Surakshit Bharat Initiative: Launched to raise awareness about cyber crimes and improve safety measures for Chief Information Security Officers (CISOs) and IT staff across government departments.
    Cyber Swachhta Kendra: This initiative focuses on detecting and removing malicious botnet programs from computers.

    Way forward: 

    • Strengthening Cybersecurity Infrastructure: The government should focus on enhancing the existing cybersecurity frameworks and expanding the capabilities of agencies like CERT-In and I4C.  
    • Public Awareness and Education: The need to increase awareness about the risks associated with AI-generated disinformation and cyber threats is crucial. Initiatives like Cyber Surakshit Bharat should be expanded to include broader public education campaigns. 
  • Southeast Asia origin of at least 45% cyber frauds targeting Indians

    Why in the News?

    Over 5,000 unemployed/employed Indians are reportedly trapped in Cambodia and forced to work into cyber fraud, resulting in an estimated Rs 500 crore loss in India over six months.

    Present Cybersecurity Status of India:

    • India has secured 10th rank in the Global Cybersecurity Index (GCI) 2020 by ITU (International Telecommunication Union) by moving up 37 places.
    • The US topped (1st), followed by the UK (United Kingdom) and Saudi Arabia tied for the second position together.
    • India secured the fourth position in the Asia Pacific region.

    What is the Budapest Convention? Is India a party to it?

    • The Council of Europe’s (CoE) Cybercrime Convention, commonly known as the Budapest Convention, was opened for signature in 2001 and came into force in 2004.
    • It is the only legally binding international multilateral treaty on cybercrime, coordinating investigations between nations and criminalizing specific cybercrime activities.
    • Budapest Convention is supplemented by a Protocol addressing xenophobia and racism committed through computer systems.
    • As of now, the Convention has 56 member countries, including the US and UK. However, India is not a party to the Budapest Convention.

    Indian Nationals vs. Organised Crimes in the South Asian Region:

    • Most web applications use the Chinese language to perform financial fraud, thereby not ruling out the Chinese connection.
    • Financial crimes such as digital arrest, stock market scams, investment scams, and romance or dating scams account for a loss of over ₹1,776 crores in 89,054 cases in the first four months of the year spurt in organized crime from Southeast Asia.
    • Numerous Indian nationals employed within a suspected fraudulent operation based in Sihanouk City, Cambodia, have voiced their grievances against their employers.

    What are the causes of the increase in Organized Financial Fraud?

    • Weak Prevention Measures:  Online Platforms in India at present account for 89% of all fraud incidents, with 40% of companies losing over $1 million.
    • Rapid Digitization and Payment Systems: After the pandemic, there was a massive shift, with the average Indian company now operating at least more than two online platforms in the normal course of business.
      • This has made it easier for fraudsters to operate anonymously and target a large number of victims.
    • Informal Investigation and Prosecution: India lacks the standardized data formats protocol system from the core banks itself. This makes it difficult to track devices and jurisdictional issues in interstate cases.
    • Lack of Deterrence: With only 26% of victims able to recover lost funds, fraudsters are encouraged to target individuals and organizations. The total value of frauds reported in 2021-22 was a staggering ₹60,414 crore.
    • Lack of Awareness: Sharing sensitive financial details with others or storing them insecurely it makes a common man vulnerable to fraud.

    What are the Initiatives taken by the government to tackle cyber crimes in India?

    • National Cyber Security Strategy 2020: Currently being formulated to enhance cyber awareness and strengthen cybersecurity through more rigorous audits.
    • Draft Personal Data Protection Bill, 2018: Based on the recommendations of the Justice BN Srikrishna Committee, this bill aims to secure citizens’ data.
    • Indian Cyber Crime Coordination Centre (I4C): Approved in October 2018, this initiative addresses all types of cybercrimes in a comprehensive and coordinated manner.
    • National Computer Emergency Response Team (CERT-In): Functions as the nodal agency for coordinating all cybersecurity efforts, emergency responses, and crisis management.
    • National Critical Information Infrastructure Protection Centre (NCIIPC): Established to protect and ensure the resilience of critical information infrastructure.

    Way Forward:

    • Update and Enforce Laws: Regularly update the Information Technology Act and other relevant laws to address emerging cyber threats and ensure strict enforcement.
    • Upgrade Cyber Defense Systems: Invest in advanced cybersecurity technologies and infrastructure to protect critical information systems.
    • Training Law Enforcement: Provide specialized training for law enforcement agencies to equip them with the skills needed to investigate and prosecute cybercrimes.
    • Collaborate with Industry: Foster partnerships between the government and private sector to share threat intelligence and best practices.

    Mains question for practice:

    Q Discuss the current challenges of cybersecurity in India, citing examples of recent trends in cybercrime. What measures have been taken by the Indian government to address these challenges? 15M

    Mains PYQ

    Q What are the different elements of cyber security? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy.(UPSC IAS/2022)

  • What is Doxxing and what can you do if it happens to you?

    Why in the news?

    In mid-February, a woman reported an incident of doxxing to Mumbai Police after a man shared a video of her dancing and subjected her to harassment online.

    What is Doxxing?

    • Doxxing involves publicly disclosing an individual’s private information without consent, including personal details like addresses, phone numbers, and more.
    • It can lead to severe consequences, including physical, digital, and emotional harm, such as stalking, threats, and loss of privacy.

    Legality and Intentions

    • While sharing public content may be legal, the intentions behind sharing such content can be malicious and harmful.
    • Social media platforms like X take action against users who share information with abusive intent or to harass others.

    Consequences of Doxxing

    • Victims of doxxing may face numerous challenges, including securing their physical location, clarifying situations with employers, and dealing with a barrage of threats.
    • Security measures such as changing passwords, enabling two-factor authentication, and reporting incidents to social media platforms are crucial for safeguarding against doxxing.

    Legal Remedy Against Doxxing

    • Victims of doxxing can report incidents through platforms like the:
    1. National Cyber Crime Reporting Portal and
    2. File FIRs (with law enforcement authorities).
    • Social media companies like Meta and Google have tools and mechanisms in place to assist individuals who have been doxxed.

    PYQ:

    [2020] In India, under cyber insurance for individuals, which of the following benefits are generally covered, in addition to payment for the loss of funds and other benefits?

    1.    Cost of restoration of the computer system in case of malware disrupting access to one’s computer

    2.    Cost of a new computer if some miscreant willfully damages it, if proved so

    3.    Cost of hiring a specialized consultant to minimize the loss in case of cyber extortion

    4.    Cost of defence in the Court of Law if any third-party files a suit

    Select the correct answer using the code given below:

    (a) 1, 2 and 4 only

    (b) 1, 3 and 4 only

    (c) 2 and 4 only

    (d) 1, 2, 3, and 4

  • India ranks number 10 in World Cybercrime Index

    Why in the news?

    A new research effort, the ‘World Cybercrime Index,’ sheds light on the global cybercrime scenario, ranking India in the 10th position worldwide.

    About the World Cybercrime Index

    • The World Cybercrime Index has been developed as a joint partnership between the University of Oxford and University of New South Wales, Sydney.
    • It has been funded by CRIMGOV, a European Union-supported project.
    • The index was developed to identify major cybercrime hotspots globally by ranking countries based on the significant sources of cybercrime at a national level.
    • The study ‘Mapping the global geography of cybercrime with the World Cybercrime Index’ has been published in the journal PLOS ONE.

    The five major categories of cybercrime assessed by the study were:

    1. Technical products/services (e.g. malware coding, botnet access, access to compromised systems, tool production).
    2. Attacks and extortion (e.g. denial-of-service attacks, ransomware).
    3. Data/identity theft (e.g. hacking, phishing, account compromises, credit card comprises).
    4. Scams (e.g. advance fee fraud, business email compromise, online auction fraud).
    5. Cashing out/money laundering (e.g. credit card fraud, money mules, illicit virtual currency platforms).

    Key Findings of the Report

    • India occupies the 10th position in the cybercrime rankings, with scams involving advance fee payments being the most prevalent type.
    • Russia leads the index, followed by Ukraine, China, the US, Nigeria, and Romania, with North Korea, the UK, and Brazil rounding out the top positions.
    • Russia and Ukraine emerged as highly technical cybercrime hubs, while Nigerian cybercriminals primarily engaged in less technical forms of cybercrime.

    PYQ:

    [2018] The terms ‘Wanna Cry, Petya and Eternal Blue’ sometimes mentioned in the news recently are related to:

    (a) Exo-planets

    (b) Crypto-currency

    (c) Cyber attacks

    (d) Mini-satellites

  • Downloading child pornography is an offence

    Voice out for Child Cyber Safety and Against Child Pornography - Prime Infoserv LLP

     

    Central Idea:

    The article discusses a recent judgment by the Madras High Court quashing judicial proceedings against an individual accused of downloading child pornography. It highlights the court’s interpretation of relevant legal provisions and challenges the court’s decision in light of the existing legal framework.

     

    Key Highlights:

    • The Madras High Court’s decision in S. Harish vs Inspector of Police quashed proceedings against an accused who downloaded child pornography.
    • The court’s interpretation suggests that merely downloading and watching child pornography in private may not constitute an offense.
    • The article highlights the flaw in citing a precedent case from the Kerala High Court, which dealt with adult pornography, not child pornography.
    • It discusses the necessity of differentiating between adult pornography and child sexual abuse materials (CSAM) in legal terminology.
    • The article emphasizes the need for consistency between the Protection of Children from Sexual Offences (POCSO) Act and the Information Technology (IT) Act.

     

    Key Challenges:

    • Interpretation of legal provisions regarding the definition and offense of child pornography.
    • Ensuring consistency between different legal frameworks, particularly the POCSO Act and the IT Act.
    • Addressing the complexities of cybercrimes and the exploitation of children online.
    • Balancing the protection of children with individual rights and privacy concerns.
    • Clarifying the scope and application of legal precedents in cases involving child pornography.

     

    Key Terms and Phrases:

    • Child pornography
    • Information Technology (IT) Act
    • Protection of Children from Sexual Offences (POCSO) Act
    • CyberTipline reports
    • Child Sexual Abuse Materials (CSAM)

     

    Key Quotes:

    • “The High Court categorically said that watching child pornography per se was not an offence…”
    • “The Madras High Court used its inherent powers under Section 482 of the Criminal Procedure Code (CrPC)…”
    • “The National Crime Records Bureau… regularly gets geo-tagged CyberTipline reports…”
    • “It is important to mention here that Section 67 read with Sections 67A and 67B of the IT Act are a complete code…”

     

    Key Examples and References:

    • Case of S. Harish vs Inspector of Police in the Madras High Court.
    • Interpretation of legal provisions under Section 67B of the IT Act.
    • Precedent case from the Kerala High Court regarding adult pornography.
    • Use of CSAM terminology in addressing child exploitation online.
    • Guidelines from the Supreme Court in State of Haryana vs Bhajan Lal (1992).

     

    Key Facts and Data:

    • Section 67B of the IT Act criminalizes various acts related to child pornography.
    • The National Crime Records Bureau collaborates with the American National Center for Missing & Exploited Children.
    • The article suggests an amendment to the POCSO Act to address inconsistencies with the IT Act.
    • The Madras High Court’s decision was based on an interpretation of legal provisions.

     

    Critical Analysis:

    The article provides a critical analysis of the Madras High Court’s decision regarding child pornography and raises valid concerns about its interpretation of relevant legal provisions. It highlights the need for consistency in legal frameworks and suggests potential amendments to address existing inconsistencies. However, it also acknowledges the complexities of cybercrimes and the challenges in balancing child protection with individual rights.

     

    Way Forward:

    • Ensure clarity in legal terminology and definitions related to child pornography.
    • Address inconsistencies between different legal frameworks, particularly the POCSO Act and the IT Act.
    • Enhance collaboration between law enforcement agencies and organizations combating online child exploitation.
    • Consider amendments to existing laws to adapt to evolving challenges in cyberspace.
    • Encourage public awareness and education on the prevention of child exploitation online.
  • Chameleon Trojan: Compromising Biometric Security on Android Devices

    Chameleon Trojan

    Central Idea

    • Security researchers have identified an updated version of the ‘Chameleon Trojan’ malware, capable of disabling biometric authentication methods.

    Chameleon Trojan

    • The malware’s primary objective is to steal the phone’s PIN by bypassing fingerprint and face unlock security features.
    • This trojan attaches itself to legitimate Android applications, such as Google Chrome, to evade detection.
    • It operates in the background and is reportedly undetectable during runtime, bypassing Google Protect alerts and other security software.
    • It exploits the Accessibility service on Android 12 and earlier versions, while on newer versions, it circumvents Google’s security restrictions through different methods.

    Modus Operandi of Chameleon Trojan

    • To bypass new restrictions, the malware displays an HTML page instructing users to enable the Accessibility service for the app, compromising device security.
    • Once active, it captures on-screen content, navigates using gestures, and steals PINs and passwords, subsequently accessing more sensitive data like credit card details and login credentials.
    • The malware also tracks app usage habits to time its attacks when the device is least likely to be in use.

    Protection against Chameleon Trojan

    • Users are advised to avoid installing Android apps from unofficial sources to reduce the risk of malware infection.
    • Be wary of enabling the Accessibility service for apps that are not well-known or trusted.
    • Conducting regular security scans on the device can help in identifying and mitigating threats.
    • Ensuring that Google Play Protect is enabled at all times is recommended for continuous monitoring and protection against malware.
  • We want a Digital India. Just not the one we are living in

    Dark Web Investigations: Risk Academy Certification to check - Indiaforensic

    Central idea 

    The increasing frequency of data breaches in India, exemplified by the recent dark web sale of sensitive personal information of 815 million citizens, underscores a pressing cybersecurity challenge. India’s inadequate incident response strategies, lack of transparency, and failure to prioritize cybersecurity pose risks to individuals and national security. A comprehensive approach, focusing on prevention, detection, and transparency, is imperative for building a resilient and secure digital infrastructure in India.

    Key Highlights:

    • Resecurity, a US company, revealed the sale of sensitive personal data of around 815 million Indians on the dark web.
    • The data included Aadhaar numbers, passport information, and addresses, posing a significant threat to individuals.
    • Previous instances of data leaks in India, such as the CoWin website breach and AIIMS ransomware attack, highlight a recurring issue.

    Key Challenges:

    • India faces a rising trend of data breaches, with the potential for severe consequences like identity theft and financial scams.
    • Lack of effective incident response strategies in India compared to countries like the US, where cybersecurity standards are being strengthened.

    Key Terms:

    • Dark web, Aadhaar, Passport number, Ransomware, Cybersecurity, Data breach, Incident response.

    Key Phrases:

    • “Leaking of sensitive information poses a severe threat to individuals’ financial well-being.”
    • “India’s mobile phone usage, enhanced banking access, and growing market size make it an attractive target for bad actors.”

    Key Quotes:

    • “The constant flow of news about data breaches is normalizing massive losses of personal data.”
    • “India’s response to data breaches is criticized for its lack of transparency, accountability, and effective incident response.”

    Key Statements:

    • “Data breaches are at an all-time high globally, and India is particularly vulnerable due to its economic growth and large population.”
    • “Incident response strategies in India are characterized by denials and lack of transparent communication with affected citizens.”

    Key Examples and References:

    • Resecurity’s revelation of the sale of Indians’ personal data on the dark web.
    • Previous data breaches in India, including the CoWin website leak and the AIIMS ransomware attack.

    Key Facts:

    • The data set on the dark web contained personally identifiable information of approximately 815 million Indian citizens.
    • India lacks a long-term cybersecurity strategy, leading to inadequate handling of data breaches.

    Key Data:

    • The sensitive personal data of 815 million Indians was available on the dark web for a price of $80,000.

    Critical Analysis:

    • India’s response to data breaches is criticized for its lack of transparency, accountability, and effective incident response.
    • The Data Protection Act in India is deemed insufficient, especially in addressing sensitive health information.

    Way Forward:

    • Prioritize the prevention, detection, assessment, and remediation of cyber incidents in India.
    • Establish a cybersecurity board with government and private sector participation for concrete recommendations.
    • Adopt a zero-trust architecture and mandate a standardized playbook for responding to cybersecurity vulnerabilities.
    • Inform and empower citizens immediately, taking responsibility for their protection and remediation in the aftermath of cyber incidents.
  • RBI enhances Digital Payment Security with CoFT through Banks

    Central Idea

    • The Reserve Bank of India (RBI) has expanded the scope of card-on-file tokenisation (CoFT) services to include card-issuing banks and institutions, enhancing the security of digital payments.
    • Previously, tokenisation services were primarily provided through merchants. The RBI’s recent notification marks a significant shift in this approach.

    Understanding CoFT and Its Importance

    • Card-on-File (CoF) Concept: Traditionally, merchants stored customer card details (CoF) on their platforms, posing risks to financial data security.
    • Tokenisation Solution: To mitigate data breach risks, the RBI introduced tokenisation, where a unique token replaces actual card details at the merchant’s end.
    • Regulatory Measures: In March 2020, RBI mandated that payment aggregators and merchants should not store actual card data, aiming to minimize system vulnerabilities. The deadline for compliance was extended to December 2021 following industry requests.

    Implementation of CoFT by Card Issuers

    • Channels for Token Generation: Customers can generate CoFT tokens through mobile and internet banking, offering a convenient and secure method for digital transactions.
    • Consent and Authentication: Token generation requires explicit customer consent and Additional Factor of Authentication (AFA) validation, ensuring user control and security.
    • Flexibility for Cardholders: Cardholders have the flexibility to tokenise their cards at any time and select specific merchants for maintaining tokens.
    • Token Issuance: The tokens can be issued either by the card network, the issuer, or both, providing multiple layers of security.

    Impact and Adotion of CoFT

    • Enhancing Safety and Convenience: CoFT aims to secure card data without compromising the convenience of card transactions.
    • Implementation Timeline: The RBI introduced CoFT in 2021, with full rollout from October 1, 2022.
    • Usage Statistics: Since its implementation, over 56 crore tokens have been created, facilitating transactions worth over ₹5 lakh crore.
  • What is Zero Trust Authentication (ZTA)?

    zero trust

    Central Idea

    • In response to rising cyberattacks, the Centre has established a secure e-mail system for 10,000 users across critical ministries and departments.
    • The National Informatics Centre (NIC) has designed this system, incorporating Zero Trust Authentication (ZTA).

    What is Zero Trust Authentication (ZTA)?

    • ZTA is a security concept and framework that operates on the principle of “never trust, always verify.”
    • This approach to cybersecurity is a significant shift from traditional security models that operated under the assumption that everything inside an organization’s network should be trusted.
    • In contrast, Zero Trust assumes that trust is never granted implicitly but must be continually evaluated and authenticated, regardless of the user’s location or the network’s perimeter.

    Key Principles of ZTA

    • Least Privilege Access: Users are granted only the minimum level of access needed to perform their job functions. This limits the potential damage in case of a security breach.
    • Strict User Verification: Every user, whether inside or outside the organization’s network, must be authenticated, authorized, and continuously validated for security configuration and posture before being granted access to applications and data.
    • Micro-segmentation: The network is divided into small zones to maintain separate access for separate parts of the network. If one segment is breached, the others remain secure.
    • Multi-Factor Authentication (MFA): ZTA often requires multiple pieces of evidence to authenticate a user’s identity. This could include something the user knows (password), something the user has (security token), and something the user is (biometric verification).
    • Continuous Monitoring and Validation: The system continuously monitors and validates that the traffic and data are secure and that the user’s behaviour aligns with the expected patterns.

    Implementation of Zero Trust Authentication

    • Technology: Implementation of Zero Trust requires technologies like identity and access management (IAM), data encryption, endpoint security, and network segmentation tools.
    • Policy and Governance: Organizations need to establish comprehensive security policies that enforce Zero Trust principles, including how data is accessed and protected.
    • User Education and Awareness: Training users on the importance of cybersecurity and the role they play in maintaining it is crucial.

    Benefits of Zero Trust Authentication

    • Enhanced Security Posture: By verifying every user and device, Zero Trust reduces the attack surface and mitigates the risk of internal threats.
    • Data Protection: Sensitive data is better protected through stringent access controls and encryption.
    • Compliance: Helps in meeting regulatory requirements by providing detailed logs and reports on user activities and data access.
    • Adaptability: Zero Trust is adaptable to a variety of IT environments, including cloud and hybrid systems.
  • In cyber attacks, terror has a found a new face

    Recent Cyber Attacks In India 2020

    Central idea

    The article underscores the transformation of terrorism into cyberspace, emphasizing the significance of robust cybersecurity measures in the face of escalating state-sponsored cyberattacks.

    Key Highlights:

    • Mumbai holds the unfortunate title of the most terror-attacked city globally.
    • The November 26, 2008 (26/11) attacks were the most audacious, lasting three days.
    • Intelligence was available before 26/11 attacks, but preventive measures failed.
    • Post-attack, significant changes were made in the police department and security apparatus.

    Key Challenges:

    • Despite reforms, the landscape of terror warfare has shifted to cyberspace.
    • The Russia–Ukraine and Israel–Hamas conflicts demonstrate the growing threat of cyber warfare.
    • State-sponsored cyberattacks against India increased by 278% between March 2021-September 2023.

    Key Terms and Phrases:

    • 26/11 terror attacks, cyberspace, cyber warfare, state-sponsored cyberattacks.

    Key Examples and References:

    • November 26, 2008, terror attacks in Mumbai.
    • Israel-Hamas conflict and the failure of the Iron Dome against cyber threats.
    • 2023 India Threat Landscape Report by Cyfirma.

    Key Facts and Data:

    • State-sponsored cyberattacks on India increased by 278% from March 2021-September 2023.
    • India faced 13.7% of all global cyberattacks.
    • 13.91 lakh cybersecurity incidents in India in 2022.

    Critical Analysis:

    • Cybersecurity is of paramount importance in a highly digitized world.
    • Recent incidents, including Apple’s warning, highlight the urgency for robust cybersecurity measures.
    • The need for nationwide education and training on cyber threats is crucial.

    Way Forward:

    • Urgent investment in robust cybersecurity measures across government, private sector, and individual citizens.
    • Comprehensive education programs, starting in schools, to raise awareness about cyber threats.
    • Adequate training and financial support for government agencies to strengthen cybersecurity.

    In conclusion, the evolving landscape of terrorism emphasizes the shift to cyberspace, demanding urgent and comprehensive cybersecurity measures, education, and training to safeguard against potential online threats like a “cyber 26/11.”