Mains Ready By December. Smash Mains & Smash PYQ Admissions Open

GS Paper: GS3-21.Role of External State and Non-state Actors in creating challenges to Internal Security.

  • What does it take to obtain justice for cybercrime?

    Why in the News

    For many cybercrime victims, getting the police to act takes a bribe or a personal contact rather than procedure, and these informal channels are used most by women, poor and rural victims. The Status of Policing in India Report (SPIR) 2026, by Lokniti-Centre for the Study of Developing Societies (Lokniti-CSDS) and Common Cause, finds that both channels also work best for them, so recovering lost money depends on influence.

    What does the survey measure, and how many victims go to the police?

    1. What it is: The SPIR 2026 surveyed 8,306 citizens across 16 States on their experience of policing. It asks what makes police act on a cybercrime complaint.
    2. Why it matters: As digital payments and online services enter daily life, cybercrime has become a serious security threat to citizens.
    3. Burden beyond delay: Besides procedural delays and repeated station visits, how police personnel treat a victim decides whether the case moves.
    4. Who complains: Nearly half of victims (49 per cent) complained to the police, and 39 per cent never complained.
    5. The takeaway: Filing a complaint is only the first hurdle, and what follows often turns on money or connections.

    How does bribery decide whose case moves?

    1. Paying to be heard: More than a quarter (27 per cent) of complainants paid the police at some point to get their case handled.
    2. Unequal burden: Payment rates differ sharply, most of all by class:
      • women 35 per cent, against 22 per cent of men;
      • rural victims 36 per cent, against 24 per cent of urban victims;
      • poor victims 51 per cent, against 12 per cent of affluent victims.
    3. Bribes linked to recovery: Of those who paid, 41 per cent recovered the full amount lost, against 12 per cent of those who did not pay.

    How do personal networks stand in for procedure?

    1. Network of influence: More than a third (37 per cent) of victims asked a personal contact, such as a senior police officer, official or local politician, to press the police.
    2. Who uses contacts: Reliance on contacts is higher among the disadvantaged:
      • women 41 per cent, against 35 per cent of men;
      • rural victims 44 per cent, against 35 per cent of urban victims;
      • poor victims 55 per cent, against 30 per cent of the rich.
    3. Contacts and recovery: Of victims who used a contact, 32 per cent recovered their full loss, against 13 per cent of those who did not, roughly tripling the odds.

    Why do the most vulnerable depend most on informal channels?

    1. Fewer formal options: Women, poor and rural victims use these channels not because they have more money or contacts, but because they have fewer other ways to make the system work.
    2. Parallel unofficial system: Bribery and personal influence work as unofficial channels to secure police action, so formal procedure alone fails a large share of victims.
    3. Enforceable procedure: Victims cannot enforce First Information Report (FIR) registration or joint bank and police action on cyber fraud, so a bribe or a call stays their only reliable route.

    Challenges

    1. Discretionary FIRs: Police often delay cyber fraud FIRs. Lalita Kumari v. Government of Uttar Pradesh (2013) made registration mandatory for cognisable offences, crimes police can act on without a court order.
    2. Slow fund freezes: Stolen money passes within hours through mule accounts, bank accounts used to route stolen funds, faster than police and banks can coordinate a freeze.
    3. Corruption rewarded: When bribes raise recovery rates, victims gain a reason to pay, which entrenches police corruption.

    Way Forward

    1. Time-bound FIRs: State police should register cyber fraud FIRs within a fixed time, with supervisory review of every refusal.
    2. Binding freeze timelines: The Reserve Bank of India (RBI) should set mandatory timelines for banks to freeze and return defrauded funds on police request.
    3. Single reporting channel: Victims should be routed through the 1930 helpline and the National Cyber Crime Reporting Portal, which send complaints directly to banks.

    Conclusion

    Recovering cyber fraud losses in India now rests on informal leverage, and the weakest victims pay the most for it. The test is whether State police and banks accept time-bound duties that victims can enforce without paying or calling anyone.

    Key numbers

    1. Complaints abandoned: 9 per cent of victims went to the police but did not pursue the case.
    2. No recovery: 35 per cent of bribe payers recovered nothing, against 68 per cent of those who did not pay.
    3. Contacts by class: 31 per cent of middle-class victims used a personal contact.

    Matching Previous Year Question

    “[2022, GS3, 10 marks] What are the different elements of cyber security? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy.”

  • Six high-tech Army labs to weed out foreign bugs from drones, cameras

    Why in the News

    The Indian Army will operate six AASHVAST laboratories, at which all its drones will undergo mandatory inspection for firmware level vulnerabilities before use. One laboratory is already running in Delhi, with at least five more planned in the coming months. Drones procured by the Army until now were never checked at the firmware level, and their origin was established from the purchase invoice alone. The tension is that an invoice records where a component was bought, not what is embedded inside the silicon. A component sourced from China can be presented as made in India with no test contradicting the claim.

    What is AASHVAST?

    1. The name: AASHVAST stands for Assessment and Analysis of Electronic Systems Hardware for Vulnerabilities and Security Threats.
    2. What it is: It is a firmware analysis and validation suite, built by a private developer for the Directorate General of Electronics and Mechanical Engineering (DG EME).
    3. What it inspects: It examines the software that operates an unmanned aerial vehicle (UAV), rather than physically inspecting the airframe alone.
    4. Procurement route: The Army issued a Request for Proposal in April 2026 for customised licensed software to validate firmware and embedded systems in electronic components, including UAV components.

    What vulnerabilities can the laboratories detect?

    1. Scale of the screen: About fourteen types of vulnerability can be detected by the suite.
    2. Geospatial faults: A malfunction triggered when the aircraft flies over a particular location, or a fault that stops it reaching a preset destination.
    3. Hidden and unused code: Code left in the firmware that can make a drone terminate its flight before reaching its target.
    4. Time and location bugs: Instructions that let a drone operate normally except at specific times or in specific places.
    5. Access and identity artefacts: Hidden passwords, embedded keys, remote access tools and location based security controls.
    6. Foreign origin components: Chinese or other foreign origin active components sitting inside the airframe’s electronics.
    7. How a vulnerability enters: It can be introduced during the manufacturing stage of a component or during a later upgrade process.

    Why does the invoice not establish origin?

    1. What the invoice shows: A purchase invoice records the point at which a component was bought, not the origin of what is inside it.
    2. No test at the silicon level: No mechanism in the procurement chain determines what is embedded within the silicon itself.
    3. The misrepresentation risk: Active components sourced from China can be presented as made in India or in a third country on the strength of that invoice.
    4. The existing prohibition: Domestic military drone manufacturers have already been barred from using parts made in China.
    5. The framework in progress: The Army Design Bureau submitted a detailed framework to the Ministry of Defence in 2025 aimed at eliminating Chinese origin components from UAVs.

    Why does the screen matter now?

    1. Procurement volume: The Army is acquiring drones at scale through the emergency procurement route, which compresses the time available for technical scrutiny.
    2. Where the drones fly: Many of these drones are used in operations along the eastern borders, where the supplier concern and the adversary are the same state.
    3. The gap being closed: Firmware level checks were absent from Army drone procurement until now, so the suite covers a stage that no other test reached.
    4. Operational purpose: The stated aim is to neutralise enemy interference that would stop a drone performing its designated task in a contested area.
    5. Cameras next: CCTV cameras procured by the Army in future will also be inspected, for Chinese proprietary protocols or their equivalent.
    6. The declared frame: The Army has placed the facility under the Atmanirbhar Bharat vision, presenting it as raising cyber resilience and growing the domestic defence electronics ecosystem.

    Challenges to firmware screening of military drones

    1. Screening capacity against procurement volume: Six laboratories testing every drone and later every camera create a throughput bottleneck at the point of induction. Eg. Emergency procurement contracts run on delivery timelines measured in months rather than years.
      The Fix: Set a risk tier so that only new firmware builds and new component sources take full analysis, with repeat builds cleared on a cryptographic hash comparison.
    2. Firmware changes after clearance: A drone cleared at induction can be altered through a later update pushed by the supplier. Eg. Commercial drone platforms routinely push updates that change flight envelope and geofencing behaviour.
      The Fix: Require signed firmware with a key held by the Army, and revalidate any build before it is loaded onto a fielded aircraft.
    3. Hardware implants escape a software test: A malicious function fabricated into the chip itself is not visible to firmware analysis. Eg. Counterfeit and re-marked integrated circuits are a recurring finding in defence supply chain audits worldwide.
      The Fix: Pair the firmware suite with hardware level testing, such as X ray and die level inspection, on a sampled share of every batch.
    4. Supply chain depth beyond the first tier: A vendor can certify an Indian assembly while its own sub suppliers buy from the restricted origin. Eg. Restrictions on direct imports have historically shifted sourcing to intermediaries in third countries rather than changing the component.
      The Fix: Require a component level bill of materials with origin declarations down to the sub tier, verified against the laboratory’s own findings.
    5. Substitutes must exist before a ban works: Removing a restricted component only helps where a qualified domestic or allied alternative exists at the same performance and price. Eg. Motors, flight controllers and imaging sensors for small drones are concentrated in a few overseas suppliers.
      The Fix: Fund qualification of domestic alternatives for the specific component classes the laboratories flag most often, rather than relying on a blanket origin ban.

    Conclusion

    Procurement has until now verified where a component was bought. The laboratories move verification to what the component actually does, which is the only level at which a concealed function can be found. The gap that remains sits between a one time clearance at induction and a fleet that keeps receiving software through its service life. The marker to watch is whether the screen is applied to the drone and camera stock already in service, or only to what is bought next.

    Back2Basics: Directorate General of Electronics and Mechanical Engineering (DG EME)

    1. What it heads: DG EME heads the Corps of Electronics and Mechanical Engineers, the Indian Army’s technical corps, from Army Headquarters.
    2. Mandate: The Corps maintains, repairs and upgrades the Army’s equipment, covering vehicles, weapon systems, electronics and instrumentation.
    3. Origin: The Corps was raised in 1943 and took its present form after Independence.
    4. Indigenisation role: DG EME sponsors development and validation projects with Indian industry for equipment support, testing and life extension.

    Matching Previous Year Question

    “Keeping in view India’s internal security, analyse the impact of cross-border cyber attacks. Also, discuss defensive measures against these sophisticated attacks.”

  • Meta to share child safety reports with govt. directly

    Why in the News

    Meta Platforms Inc., the parent company of Facebook and Instagram, will report child sexual abuse material (CSAM) cases directly to the cybercrime portal run by the Indian Cyber Crime Coordination Centre (I4C) under the Union Ministry of Home Affairs. Indian agencies have had access to such reports for years through a 2019 memorandum of understanding between the National Crime Records Bureau (NCRB) and the United States based National Center for Missing and Exploited Children (NCMEC), which received them first. The change follows scrutiny of the company by the Union government and the National Commission for Protection of Child Rights (NCPCR) over reports of such material being served in advertisements on its platforms. The NCPCR has opened an investigation after an initial exchange of correspondence with the company. The question the arrangement raises is whether a voluntary reporting channel can substitute for a duty the company can be held to.

    What is the Indian Cyber Crime Coordination Centre?

    1. I4C: It is the Union Ministry of Home Affairs body that coordinates the response of law enforcement agencies across States to cybercrime.
    2. The reporting portal: It runs the National Cyber Crime Reporting Portal, through which a complaint filed by a citizen or an agency is routed to the police jurisdiction concerned.
    3. Why a national portal exists: Policing is a State subject, so a central entry point is needed to move a report to the State that can act on it.
    4. Founding: It was established in 2018 as a centralised mechanism against cybercrime, and it also runs the national cybercrime helpline.

    How did the reporting route work until now?

    1. The American obligation: A technology company based in the United States is required by its own law to report apparent child sexual exploitation on its services to NCMEC, which operates the CyberTipline.
    2. The 2019 memorandum: NCRB signed a memorandum of understanding with NCMEC that year, giving Indian agencies access to tipline reports concerning India.
    3. The volume involved: More than 69.05 lakh CyberTipline reports had been shared with the States and Union Territories concerned as on 31 March 2024, per the Union government’s reply in the Rajya Sabha that year.
    4. The extra step: Every report reached an Indian agency only after passing through a body in another jurisdiction, so the Indian system received reports rather than generated them.

    What prompted the change?

    1. Advertising as the vector: News reports described child sexual abuse material being served in advertisements on Facebook and Instagram, which placed the material inside the paid inventory the company itself sells.
    2. The company’s account: Meta stated that it screens all advertisements posted by third parties, and that some bad actors were able to get such content posted anyway.
    3. The regulatory response: The Union government and the NCPCR examined the company over those reports in recent weeks.
    4. The commission’s step: NCPCR has initiated an investigation on the basis of its correspondence with the company.
    5. The company’s commitment: Meta has said that protecting children on its platforms is a priority and that it will work with the government to hold the perpetrators of these crimes responsible.

    What does direct reporting change in practice?

    1. One less jurisdiction in the chain: A report moves from the company to the Indian portal without first being filed with a body governed by another country’s law and disclosure rules.
    2. Speed against evidence decay: Subscriber records, device logs and uploaded content are retained for limited periods, so the interval between detection and a police request decides whether the evidence still exists.
    3. Routing to the police station: A report arriving at the portal can be sent directly to the district and the State in which the account holder sits.
    4. The existing channel continues: Reporting to NCMEC runs alongside, so the direct route is an addition rather than a replacement.
    5. A first among intermediaries: No other major intermediary currently reports child safety matters directly to the Indian portal, so this arrangement becomes the reference point for what others may be asked to do.

    Challenges to intermediary reporting of child sexual abuse material

    1. The channel is a commitment, not a duty: An undertaking offered by a company can be narrowed or withdrawn without breaching anything. Eg. Section 19 of the Protection of Children from Sexual Offences Act, 2012 places a reporting duty on any person with knowledge of an offence, and it was not drafted for automated detection at platform scale.
      The Fix: Notify a platform level reporting standard under the Information Technology Act, 2000 specifying the format, the timeline and the designated recipient for every significant social media intermediary.
    2. Detection is limited to what a platform can scan: Hash matching finds material already known to investigators, and end to end encrypted messaging carries content no server side scan can read. Eg. Meta completed the rollout of default end to end encryption on its messaging services, which removes the message body from inspection.
      The Fix: Require reporting of behavioural and metadata signals, such as bulk contact of minor accounts from a single adult account, where the content itself cannot be inspected.
    3. Reports outrun the capacity to act on them: Millions of tipline reports have reached Indian agencies while forensic examination capacity sits in a small number of units. Eg. The Cyber Crime Prevention against Women and Children scheme funds State cyber forensic laboratories and training precisely because examination capacity lags complaint volume.
      The Fix: Publish the disposal rate of tipline reports alongside the number shared, so capacity is measured against the load rather than assumed.
    4. Paid distribution fails differently from user posts: An advertisement that clears review is then delivered to a selected audience by the platform’s own targeting machinery, so a single screening failure is amplified rather than contained.
      The Fix: Require human review before first delivery for any advertisement flagged by an automated child safety classifier, with the reviewer’s decision recorded.
    5. Takedown is not victim identification: Removing a file closes the platform’s obligation and leaves the child in it unidentified. Eg. NCMEC runs a dedicated child victim identification programme precisely because a removed image still points to an offence that is continuing.
      The Fix: Route every report to a designated child protection unit alongside the police, so identification and rehabilitation begin with the investigation rather than after it.
    6. Cross border evidence still needs the treaty route: Content and subscriber data held on servers abroad are obtained through mutual legal assistance, which a reporting channel does not shorten. Eg. Mutual legal assistance requests to the United States routinely take many months to return data.
      The Fix: Issue a data preservation request at the moment the report is received, so the material is held while the formal request is processed.

    Conclusion

    Reporting is the point at which a platform’s private detection becomes a matter for the state, and that point has now moved from a body in another country to one in India. What has not changed is the basis of the arrangement, which is an undertaking the company has offered rather than an obligation it owes. The unresolved tension is between voluntary cooperation from the largest intermediaries and a statutory duty that would bind all of them equally. The marker to watch is what the NCPCR investigation concludes about advertisement screening, since that finding will decide whether reporting alone is accepted as a sufficient answer.

    Back2Basics: National Center for Missing and Exploited Children

    1. Nature: It is a private non profit organisation in the United States, not a law enforcement agency.
    2. Founding: It was established in 1984 and operates under a mandate from the United States Congress.
    3. The CyberTipline: It runs the centralised reporting line to which technology companies based in the United States are legally required to report apparent child sexual exploitation.
    4. What it does with a report: It reviews each report and forwards it to the law enforcement agency with jurisdiction, whether in the United States or abroad.

    Matching Previous Year Question

    “Discuss different types of cyber crimes and measures required to be taken to fight the menace”

  • Terror’s changing face, India’s counter-terror strategy

    Terror’s changing face, India’s counter-terror strategy

    Why in the News

    India has unveiled PRAHAAR, its first comprehensive National Counter Terrorism Policy and Strategy, which sets a national framework for preventing and responding to terrorist activity and radicalisation through coordinated “whole of government” and “whole of society” approaches. The policy follows Operation Sindoor, the strikes of 6 and 7 May on the Pakistan based terror network launched after the Pahalgam attack of 22 April 2025, and follows the three declarations India issued immediately after that operation. The first of those declarations ended the stated era of restraint, the second classified any future act of cross border terrorism emanating from Pakistan as an “act of war”, and the third removed Pakistani nuclear blackmail as a restraining factor. The tension is that the doctrine India has hardened is built for a state sponsor with a return address, while the threat itself has fragmented into lone wolf attackers, autonomous cells and drone, cyber and artificial intelligence enabled methods that a retaliatory strike does not reach.

    What is PRAHAAR?

    1. PRAHAAR as a national policy: PRAHAAR is India’s first comprehensive National Counter Terrorism Policy and Strategy, unveiled on 23 February 2026.
    2. Scope of the framework: It sets out a national counter terrorism framework for preventing and responding to terrorist activities and to radicalisation.
    3. Whole of government and whole of society approach: It works through coordinated “whole of government” and “whole of society” approaches, so prevention is not left to security agencies alone.

    How has the form of terrorism changed in 25 years?

    1. The organisational form has fragmented: Large terror groups run by single leaders, such as al-Qaeda under Osama bin Laden or the Islamic State under Abu Bakr al-Baghdadi with its call for an Islamic Caliphate, have given way to smaller and more autonomous entities.
    2. The attacker is now often solitary: Lone wolf attacks are becoming the norm, which removes the network that intelligence collection is designed to detect.
    3. Drones, cyber capability and artificial intelligence: Drones, cyber capabilities and artificial intelligence are now used to perpetrate terror.
    4. Counter terrorism use of the same technologies: Those technologies are used by the nations combating terrorism as well, so capability advantage is contested rather than assured.

    What is a lone wolf attack?

    1. The definition: A lone wolf attack is an attack planned and executed by a single individual, or by a pair acting alone, who belongs to no organisation and takes no operational direction from one.
    2. How the attacker is produced: Radicalisation runs through online propaganda rather than through recruitment by a handler, so the individual adopts a group’s cause without ever joining its structure. Eg. Self radicalised modules assembled around professionals, rather than around infiltrators, in recent hinterland cases.
    3. Why detection fails: Intelligence collection works by intercepting communication between conspirators and by penetrating networks, and an attacker who communicates with nobody generates neither signal.
    4. Why a retaliation doctrine does not reach it: A cross border response needs attribution to a sponsoring state, and an individual acting alone offers no camp, handler or command node to strike.

    Why did the early Indian response stay passive, and which attacks fell inside that period?

    1. Assassination of a former Prime Minister, 1991: The assassination of former Prime Minister Rajiv Gandhi by the Liberation Tigers of Tamil Eelam on 21 May 1991 at Sriperumbudur in Tamil Nadu came while cross border terror was only beginning in Kashmir.
    2. Internal detection failed repeatedly: The March 1993 Mumbai serial blasts killed over 250 people in 13 coordinated blasts, and the synchronised blasts across Coimbatore in February 1998 exposed the inadequacy of internal security mechanisms.
    3. Pakistan’s direct role was first exposed by a hijack: The hijack of Indian Airlines flight IC-814 on 24 December 1999 forced India to release the Pakistan based terrorists Ahmed Omar Sheikh and Masood Azhar in exchange for more than 160 civilian hostages.
    4. Operation Parakram and its outcome: The Jaish-e-Mohammed (JeM) attack on Parliament on 13 December 2001 triggered a large scale military mobilisation under Operation Parakram, and after almost two years of standoff the disengagement took place with no direct punishment on Pakistan.
    5. Nuclear parity was the restraint: With both countries holding nuclear weapons, the threat of escalation drew the international community in to cool tempers each time.
    6. The 26/11 Mumbai attacks and the absence of retaliation: The 26/11 Mumbai attacks of November 2008, which brought the world’s solidarity with India’s fight against cross border terrorism, produced no military action against Pakistan.
    7. The Red Fort attack of 2000: An Army garrison within the Red Fort was targeted on 22 December 2000 by Lashkar-e-Taiba (LeT) terrorists, killing three soldiers.
    8. Delhi market blasts of 2005: Over 60 people were killed in serial blasts across Delhi markets including Sarojini Nagar and Paharganj in October 2005.
    9. Delhi commercial district blasts of 2008: Multiple blasts hit Connaught Place, Greater Kailash and Karol Bagh in September 2008, months before the Mumbai attacks.
    10. The Delhi High Court blast of 2011: A briefcase bomb outside the Delhi High Court on 7 September 2011 killed 15 people, claimed by Harkat-ul-Jihad Islami (HUJI), an al-Qaeda affiliated group largely based in Pakistan.
    11. Akshardham, Varanasi and Pune attacks: The 2002 Akshardham Temple attack, the 2006 Varanasi serial blasts and the 2010 German Bakery blast in Pune are part of the same record.
    12. Proof did not produce a response: In each of these cases India chose not to respond directly and decisively, even after conclusive proof of Pakistan’s support.

    What changed when the fight moved across the border?

    1. The Uri attack and the 2016 surgical strikes: The JeM attack on an Army camp at Uri in Kashmir on 18 September 2016 led to the first cross border surgical strikes on 28 and 29 September.
    2. Message conveyed by the surgical strikes: They sent a message and served as a statement of intent that terror would not go unpunished.
    3. The Balakot air strike of 2019: After the attack on a Central Reserve Police Force convoy at Pulwama on 14 February 2019, the Indian Air Force struck a JeM terror camp at Balakot, the first time it had crossed into Pakistani airspace to hit a terror target.
    4. Operation Sindoor, 2025: Operation Sindoor was launched on 6 and 7 May after the Pahalgam attack, and in 96 hours the leaders and headquarters of the LeT and JeM networks were destroyed and Pakistani military assets were hit.

    What is the four fold strategy proposed from here?

    1. Elimination of the residual network: Continue to hunt down and eliminate the remnants of the terror network inside the country, particularly in Kashmir.
    2. Pre emptive action across the Line of Control: Take pre emptive military action against any potential terror threat building across the Line of Control (LoC), including at terrorist launch pads, which years of experience and an embedded intelligence network make possible.
    3. The de radicalisation programme: Run an exhaustive de radicalisation programme that motivates young people towards the mainstream and makes joining or supporting a terror outfit unattractive and prohibitively costly.
    4. Terror financing: Take all necessary steps to cut off terror financing, in close coordination with friendly countries.

    What is India pressing for at the multilateral level?

    1. The charge of double standards: At the Shanghai Cooperation Organisation Summit in Bishkek on 1 September the Prime Minister said, “We must send a strong message to countries that use terrorism as an instrument of policy and provide safe haven and support to terrorists that terrorism can never be a strategic asset for anyone.”
    2. A named attack entered a group declaration: The 18th BRICS Summit in New Delhi included an exclusive paragraph on the Pahalgam attack in the Delhi Declaration.
    3. Effect of a grievance carried in multilateral text: A specific Indian grievance is now carried in the text of a multi country declaration rather than only in national statements.

    Challenges to India’s counter terrorism strategy

    1. A retaliation doctrine has no target in a lone wolf attack: An “act of war” classification presumes an attributable state sponsor, and a self radicalised individual acting alone gives no address to strike. Eg. Self radicalised modules assembled around professionals, rather than infiltrators, in recent hinterland cases.
      The Fix: Pair the declaratory doctrine with a published attribution standard, so the threshold of evidence that triggers a cross border response is fixed in advance rather than argued after each attack.
    2. Police and public order are State subjects: A national policy has to be executed through State police forces that the Union does not control, which is where coordination breaks down. Eg. The delay in National Security Guard deployment during the 26/11 Mumbai attacks.
      The Fix: Route PRAHAAR’s obligations through a standing Centre State counter terrorism council with State specific implementation timelines, rather than through advisories.
    3. Intelligence remains fragmented across agencies: Multiple collection agencies without seamless real time sharing means a warning held by one is not actionable by another. Eg. Intelligence fusion is attempted through the Multi Agency Centre and the National Intelligence Grid, which depend on voluntary feeds from database holding agencies.
      The Fix: Give a single fusion centre statutory authority to task and receive feeds, on the model of a national counter terrorism centre, so sharing is an obligation rather than a courtesy.
    4. De radicalisation has no measurable output: A programme aimed at intent rather than at incidents cannot be judged by attack counts, and India runs no published evaluation of one. Eg. Online influence of the kind that drove youth radicalisation in Kashmir operates outside any programme’s reach.
      The Fix: Fix published indicators for the programme, such as recruitment attempts intercepted and cases of disengagement sustained over a stated period, and report them annually.
    5. Terror financing has moved to channels outside the banking system: Hawala, counterfeit currency and cryptocurrency route funds without touching a reportable transaction. Eg. Informal channel financing was traced in the ISIS linked Padgha module.
      The Fix: Bring virtual digital asset service providers fully under reporting obligations to the Financial Intelligence Unit India, so the fastest growing channel is monitored on the same terms as banks.
    6. There is no agreed international definition of terrorism: The absence of one lets states label selectively and refuse cooperation on legal grounds. Eg. Repeated holds placed on listings under the United Nations Security Council 1267 sanctions committee.
      The Fix: Press the Comprehensive Convention on International Terrorism, which India first proposed in 1996, to a vote rather than leaving it in open ended negotiation.

    Conclusion

    The doctrine India adopted after Operation Sindoor answers one form of the threat well and leaves the other untouched. A declared willingness to retaliate raises the cost of sponsoring an attack from across the border; it does nothing about an attacker who was recruited online and never crossed anything. PRAHAAR is the first instrument that addresses the second half, which is why its prevention and radicalisation components, rather than its enforcement components, are the part worth watching. The marker is whether the policy produces named nodal responsibilities and reported outcomes, or remains a framework document that the next attack is measured against.

    Terrorism in India

    1. Definition of terrorism: Terrorism is the deliberate use of violence, or the threat of violence, to instil fear and achieve political, ideological or religious goals.
    2. The statutory definition: Under Section 15 of the Unlawful Activities (Prevention) Act, 1967, a terrorist act is any act intended to threaten India’s sovereignty, security or unity, or to create terror through violence, explosives or disruption of essential services.
    3. The four recognised strands in the Indian context: Cross border terrorism driven by Pakistan based groups in Jammu and Kashmir and by Khalistani networks, North East insurgencies run by ethno nationalist groups such as NSCN and ULFA, Left Wing Extremism across the Red Corridor, and hinterland terrorism by modules operating outside traditional conflict zones.
    4. The direction of change: The terror and organised crime nexus supplies funding, arms and logistics, and technology acts as a force multiplier through drones, encrypted platforms and 3D printing. Eg. The Houthi drone attack on Saudi Aramco in 2019.

    Institutional Architecture and Initiatives Against Terrorism

    1. Multi Agency Centre and Cyber Multi Agency Centre: Fuse intelligence inputs across central and State agencies.
    2. National Intelligence Grid: Networks databases held by different departments to give agencies real time access.
    3. Indian Cyber Crime Coordination Centre: Acts as the nodal point against cybercrime with a citizen reporting route. Eg. The 1930 helpline.
    4. Border management systems: Smart fencing under the Comprehensive Integrated Border Management System plugs infiltration gaps, backed by a layered coastal security grid.
    5. Surrender and rehabilitation policies: Pull cadres out of insurgency through reintegration rather than through prosecution alone.

    Matching Previous Year Question

    “[2025, GS3, 10 marks] Terrorism is a global scourge. How has it manifested in India? Elaborate with contemporary examples. What are the counter measures adopted by the State? Explain.”

  • Financial Fraud Risk Indicator crosses ₹5,000 crore in prevented fraud

    Why in News

    1. Milestone crossed: The Financial Fraud Risk Indicator (FRI) has prevented suspected cyber fraud transactions of over ₹5,000 crore.

    Core facts

    1. What FRI is: The Financial Fraud Risk Indicator is a real time risk assessment framework. It flags whether a mobile number may be linked to cyber crime or fraud.
    2. Administering body: The Department of Telecommunications (DoT) developed and operates it. It launched on 22 May 2025.
    3. Risk classes: FRI classifies mobile numbers into three categories. These are Medium, High and Very High risk.
    4. Data sources: It draws on citizen reports through Sanchar Saathi, the National Cybercrime Reporting Portal, telecom operators and financial institutions.
    5. Use by institutions: Banks, payment providers, insurers and pension entities use the risk signal for transaction monitoring.
    6. Amount protected: FRI prevented ₹5,043.73 crore in suspected fraud as of August 2026.
    7. Recent record: Over ₹2,000 crore was prevented between April and August 2026. More than 1,600 organisations are on the platform.

    Static Context

    1. The Digital Intelligence Platform was launched by the Department of Telecommunications in 2024. FRI operates within it.
    2. Sanchar Saathi is a citizen portal to report suspected fraud communication and to block lost or stolen mobile handsets.
    3. The National Cybercrime Reporting Portal is run by the Indian Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs.

    Prelims angle

    1. FRI custodian: Department of Telecommunications, within the Digital Intelligence Platform.
    2. Related platforms: Sanchar Saathi, National Cybercrime Reporting Portal and I4C are frequently tested.

    Mains angle

    1. GS3, internal security: A question can assess how real time data sharing between telecom and banking systems strengthens India’s response to cyber financial fraud.

    Matching Previous Year Question

    “No direct Prelims PYQ on financial fraud prevention was traced in the provided files. Closest Microtheme: Cyber Security (Internal Security).”

    “[2022, GS3, 10 marks] What are the different elements of cyber security? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy.”

  • Focus on the children, not the platform

    Focus on the children, not the platform

    Why in the News

    Meta has settled a $171 billion case with several United States States over allegations about the effect of its apps on children’s mental health. The settlement requires daily usage limits and “nighttime blocks” for teenagers. It requires “enhanced age assurance measures” (checks intended to establish a user’s age before access is granted) to keep children off the apps. It also requires the depersonalisation of feeds, so a child is served random content rather than content matched to that child’s interests. The outcome is being read as a step towards holding platforms accountable. That framing places the platform at the centre of the problem rather than the child, and the two framings do not produce the same policy.

    Why does a platform centric approach to child safety misfire?

    1. The measures are difficult to enforce: An age gate assumes a child will not defeat it, while children are sophisticated and motivated users of technology who find ways around such checks.
    2. It ignores what children need to be safe online: Poorly designed recommendation systems expose children to harmful content, and stripping personalisation replaces that risk with irrelevant or inappropriate material. It also makes it harder for educational and support services to reach the children who need them.
    3. Online spaces are the only support some children have: Children experiencing neglect or abuse, LGBTQIA+ children and socially isolated children use platforms to find information, companionship or help. A child’s participation is not confined to one service, so a platform that becomes too restrictive simply loses them to platforms with weaker protections.
    4. The offline environment is what pushes children online: In India screens fill a vacuum rather than displacing abundant offline opportunities, because many children have no access to safe public spaces or affordable recreational facilities.

    What would a child centred approach ask for instead?

    1. Equip the child, as is done in the physical world: Children are taught what not to share, how to respond to unsolicited contact, how to recognise manipulation, when to block or report someone, and when to seek help.
    2. Treat digital literacy as the instrument, not the afterthought: Digital literacy and sensitisation are what change a child’s behaviour at the moment a technical control fails, and they receive far less policy attention than platform obligations.
    3. Address the whole ecology of childhood: Responsibility sits across platforms, parents, schools, communities, public spaces and children themselves, so a measure aimed at one of the six leaves the other five untouched.

    Why does the harder answer receive less policy attention?

    1. A platform obligation is visible and countable: A regulator can order a control, verify that it shipped, and record compliance, none of which a curriculum or a public playground delivers on the same timescale.
    2. India’s move so far is a recommendation, not a mandate: The 2026 Economic Survey called for a digital wellness curriculum in schools, and whether it is implemented widely and appropriately is untested.
    3. The effective lever sits outside the regulator’s reach: Digital literacy runs through school systems and recreational space runs through municipalities, while enforcement powers sit with technology and data protection regulators.
    4. The argument does not absolve platforms: Platform responsibility survives intact, and the contest is over which lever produces a safer child rather than over whether platforms owe anything at all.

    Conclusion

    Child online safety is presently measured by the number of controls a service ships. The better measure is what a child is able to do when a control fails, and the settlement model produces no information about that at all. The capability side of the problem belongs to schools, parents and municipalities. The enforcement side belongs to a technology regulator, and nobody owns the gap between the two.

    Child Online Safety in India

    1. What the field covers: The rules governing children’s access to online services, the data those services may collect about a child, and the content they may direct at one.
    2. How India regulates it: Through due diligence obligations on intermediaries under technology law and consent rules under data protection law, rather than through a single children’s online safety statute.
    3. Who counts as a child: Indian data protection law treats every person below 18 as a child, a higher threshold than the 13 year line used in United States children’s privacy law.

    Laws and Rules Governing Child Online Safety

    1. Information Technology Act, 2000, amended in 2008: The parent statute for offences committed through a computer resource, carrying Section 66D on cheating by impersonation and Section 69 on interception.
    2. Section 67B separately punishes publishing or transmitting material depicting children in sexually explicit acts.
    3. Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, amended in 2023: Impose due diligence, grievance redressal and content takedown obligations on intermediaries.
    4. Digital Personal Data Protection Act, 2023, with the Digital Personal Data Protection Rules, 2025: Govern consent, data fiduciary duties, breach notification and the Data Protection Board of India.
    5. Section 9 requires verifiable parental consent before a child’s personal data is processed, and bars tracking, behavioural monitoring and advertising targeted at children.
    6. Protection of Children from Sexual Offences Act, 2012: Defines and punishes sexual offences against persons below 18, covers offences committed using electronic material, and makes reporting mandatory.

    [2024, GS3, 10 marks] Describe the context and salient features of the Digital Personal Data Protection Act, 2023.

  • Need to break Manipur’s cycle of reprisal (Editorial)

    Need to break Manipur’s cycle of reprisal (Editorial)

    Why in the News

    More than three years after the Meitei-Kuki clashes began, Manipur now faces a deepening Kuki-Naga fault line. Four Naga civilians were killed this week in Kuki-dominated Kangpokpi district, an episode that follows the killing of Kuki-Thadou church pastors in May, retaliatory abductions on both sides, and the recovery a month later of the bodies of six Naga men.

    How has the conflict widened beyond the original Meitei-Kuki fault line?

    1. A second, distinct fault line has opened: What began as Meitei-Kuki violence in 2023 has produced a separate Kuki-Naga confrontation, evident in this week’s killing of four Naga civilians in Kangpokpi, a district that sits between Naga-dominated Senapati to the north and Meitei-dominated valley districts to the south.
    2. A traceable chain of retaliation: The killing of Kuki-Thadou pastors in May was followed by retaliatory abductions from both communities, and the subsequent recovery of six Naga men’s bodies a month later, establishing a pattern of reprisal rather than an isolated incident.
    3. Blockades have turned roads into contested territory: Meitei, Kuki and Naga groups have separately imposed blockades that disrupt supplies, raise the cost of food and fuel, and restrict access to healthcare, with Kangpokpi the worst affected due to its position between rival-dominated districts.

    Why has the return of an elected government failed to restore order?

    1. A power-sharing arrangement has not translated into reconciliation: The state government led by Yumnam Khemchand Singh, a Meitei chief minister with deputy chief ministers from the Kuki and Naga communities, returned in February after almost a year of President’s Rule, but has found little success pulling the state back from the brink.
    2. Social segregation has outpaced political representation: The communities remain socially segregated, so political representation across the three groups in government has not by itself addressed the everyday separation that sustains distrust and enables further violence.
    3. Displacement has produced a significant, undercounted toll: Right to Information data has revealed that more than 700 internally displaced people have died in relief camps, a toll separate from and additional to deaths from direct violence.

    Challenges to a political settlement in Manipur

    1. Security forces have struggled to secure supply routes: Security forces have had very little success ensuring the safe movement of convoys carrying essential supplies through blockaded areas. Eg. Blockades imposed by Meitei, Kuki and Naga groups have repeatedly disrupted the movement of food, fuel and medical supplies into Kangpokpi and surrounding districts. Fix. Establish dedicated, jointly monitored humanitarian corridors for essential supplies, with monitoring involving representatives from all three communities rather than security forces alone.
    2. Armed groups remain undisbanded: Militant groups from multiple communities continue to operate, and a crackdown on extremist elements has not kept pace with the scale of continuing violence. Eg. The killing of four Naga civilians in Kangpokpi this week, alongside the earlier killing of Kuki-Thadou pastors, shows armed actors from more than one community remain capable of carrying out attacks. Fix. Pursue simultaneous, verifiable disarmament commitments from armed groups across all three communities rather than sequencing disarmament by community.
    3. No agreed framework exists for resolving land and identity claims: Every claim over land and identity cannot be resolved overnight, and the absence of an interim framework leaves communities without a safe basis for movement, trade or daily coexistence. Eg. The overlapping blockades by all three communities show there is currently no shared understanding of which areas each community can safely access. Fix. Prioritise an interim framework guaranteeing safe movement, trade and access to essential services, deferring final land and identity settlements to a later, dedicated political process.

    Conclusion

    The editorial’s position is that political representation alone, through a Meitei chief minister and Kuki and Naga deputy chief ministers, cannot resolve a conflict sustained by social segregation and repeated cycles of reprisal. It calls for sustained dialogue empowering civil society leaders, an interim framework for safe movement and trade, and simultaneous disarmament and action against extremist elements, alongside the immediate arrest of those responsible for this week’s killings.

    Back2Basics: What is President’s Rule?

    Central takeover of state governance: President’s Rule, imposed under Article 356 of the Constitution, allows the Union government to assume direct control of a state’s administration when its constitutional machinery is deemed to have broken down, as occurred in Manipur for nearly a year before the elected government returned in February.

    1. AI is transforming cyber attacks as well as defences: What this means for India

      AI is transforming cyber attacks as well as defences: What this means for India

      Why in the News

      Artificial Intelligence (AI) is now amplifying cyber threats across the cyber kill chain at speed, scale and sophistication, and is developing the ability to act as an autonomous agent that identifies, plans, adapts and carries out offensive cyber operations. The shift follows the fastest technology adoption on record: the Internet took 15 years to reach a billion users, and ChatGPT did so in three. The tension is that AI capability is concentrated in very few countries, so the same technology that raises the threat also determines who can defend against it. India’s indigenous AI ecosystem lags the United States and China across the entire AI stack, leaving it exposed on both sides of that equation.

      What is the cyber kill chain?

      1. Definition: The cyber kill chain is the sequence of stages an attacker must complete to succeed, running from reconnaissance on a target, through weaponisation of malicious code, to command and control of the compromised system.
      2. Why the framework matters: Defence has traditionally worked by breaking any one link in that chain, since an attack that fails at one stage cannot proceed to the next.
      3. What AI changes: AI is now compressing or automating several stages at once, so breaking a single link no longer stops the sequence.

      How is AI amplifying offensive cyber operations?

      1. Reconnaissance is automated: Gathering information about a target once depended on humans, and research shows ChatGPT models being used to mine social media for precise details to craft AI generated phishing emails.
      2. Deepfakes are now real time: AI is generating real time deepfakes, deepening confusion about what is authentic online.
      3. Social engineering scales: AI enabled social engineering, the use of AI to trick or persuade people into taking harmful actions, no longer requires a human operator per target.
      4. Malware no longer holds a fixed shape: Large language models (LLMs) can autonomously generate, modify and restructure polymorphic malware to suit the situation, unlike traditional malware, which relies on fixed signatures and predictable patterns.
      5. An AI has already run an attack chain: In September 2025 Anthropic claimed a Chinese state sponsored group, GTG-1002, had used Claude Code as an autonomous cyber agent across multiple stages of an attack, in what the company called the first reported case of an AI orchestrated cyber espionage campaign.

      Why does autonomous vulnerability discovery change the risk?

      1. Zero-days are being found at scale: Anthropic’s latest frontier model, Claude Mythos Preview, has identified thousands of zero-day vulnerabilities, meaning flaws previously unknown to developers, across major operating systems and browsers, many of them critical.
      2. It builds the exploits too: The model developed related exploits largely without human intervention, collapsing the gap between finding a flaw and being able to use it.
      3. Hardened systems are not exempt: It found a 27 year old vulnerability in OpenBSD, an operating system reputed to be highly security hardened and widely used to run firewalls and critical infrastructure.
      4. Industrial systems are the exposed surface: Such vulnerabilities are especially dangerous for Operational Technology (OT) and Industrial Control Systems (ICS), the computing that governs nuclear facilities, energy grids, pharmaceutical manufacturing, chemical processing, oil refineries and communication networks.
      5. Exposure grows with integration: That infrastructure becomes more exposed as it integrates further with AI, so the adoption that improves efficiency also widens the attack surface.

      Why do old cyber defences no longer hold?

      1. Signature matching fails against shape shifting code: Traditional antivirus looks for known malware fingerprints, which malware that constantly changes and adapts no longer presents.
      2. Static patching is too slow: Security patches written for known vulnerabilities are far less effective when new flaws are discovered and weaponised faster than patch cycles run.
      3. AI defence works differently: AI in cybersecurity enables real time threat detection, automated response and large scale data analysis, mitigating risks faster than human led triage.
      4. The divide has shifted: The real AI divide is not about who uses AI but about who builds it and who controls its development, which is why cybersecurity capability now tracks AI capability.

      How exposed is India?

      1. A nuclear plant’s data was posted: The ransomware group World Leaks claimed to have stolen and posted data related to India’s largest nuclear plant, Kudankulam, including blueprints of facility parts and supplier details.
      2. The ranking moved sharply: Cyber intelligence firm CloudSEK’s 2024 report placed India as the second most cyber attacked nation after the United States, and its 2025 report placed India sixth.
      3. State backed actors targeted defence during a conflict: During Operation Sindoor, Pakistan backed threat actors such as APT36 targeted India’s critical sectors, including the Ministry of Defence, the Army, the Navy and the Defence Research and Development Organisation (DRDO).
      4. A new target class appeared: The same campaign targeted Bharat Operating System Solutions (BOSS) Linux for the first time, extending the attack surface to India’s indigenous operating system.

      Can India defend a cyberspace built on an AI stack it does not own?

      1. The ecosystem is incremental: India’s indigenous AI ecosystem remains incremental and lags well behind the United States and China across the AI stack.
      2. The gap is at every layer: The shortfall runs across foundational models, graphics processing units, chip design and large scale data centre infrastructure, so no single procurement closes it.
      3. Dependence is the security problem: The lag leaves India heavily dependent on the United States and other technologically advanced countries for the very tools its defence now requires.
      4. Capability determines both roles: Countries with leading AI ecosystems gain a greater ability both to conduct sophisticated cyber campaigns and to defend against them, so dependence caps India’s ceiling on defence as well as deterrence.

      What has India done so far?

      1. CERT-In has shifted its methods: The Indian Computer Emergency Response Team (CERT-In), the national agency for responding to cyber security incidents, has since 2025 adopted AI driven threat detection, cyber resilience measures, trusted AI frameworks and citizen centric malware mitigation.
      2. A specific advisory was issued: In April 2026 it issued an advisory for organisations on defending against AI driven cyber risks.
      3. The advisory’s operative instructions: Recommendations included “removing unnecessary internet-facing services” and treating every newly discovered vulnerability as something that “could be exploited within hours, not weeks”.
      4. Governance work is at the framework stage: The Ministry of Electronics and Information Technology (MeitY) is exploring a consent based framework for synthetically generated content, alongside curbs on agentic AI autonomy and clearer liability frameworks for AI models.

      Challenges to India’s AI-enabled cyber defence

      1. Defence rests on advisories rather than obligations: CERT-In’s guidance to organisations is recommendatory, so a private operator of critical infrastructure faces no penalty for ignoring it. Eg. The April 2026 advisory asked organisations to remove unnecessary internet facing services, with no compliance audit attached. Fix. Convert the advisory content into mandatory, audited security baselines for power, banking, telecom and healthcare operators under the Information Technology Act, 2000.
      2. Compute dependence caps defensive AI: Running real time detection models at national scale needs domestic graphics processing unit capacity that India does not have. Eg. India’s shortfall spans foundational models, chip design and large scale data centre infrastructure alike. Fix. Prioritise sovereign compute for security workloads specifically, reserving a share of publicly funded AI infrastructure for CERT-In and sector CSIRTs.
      3. Attribution is harder when the attacker is an agent: An AI orchestrated campaign leaves a machine’s traces rather than an operator’s, which weakens the evidentiary basis for a state response. Eg. The GTG-1002 campaign was identified by the model provider, not by a victim’s own forensics. Fix. Mandate model providers serving Indian users to report detected misuse of their systems for offensive operations, on the six hour breach reporting model already in force.
      4. Legacy industrial systems cannot be patched quickly: Control systems in refineries and grids run on decade old software where a patch requires a plant shutdown. Eg. A 27 year old OpenBSD flaw survived in software widely used to run firewalls and critical infrastructure. Fix. Require network segmentation and one way data diodes between industrial control networks and corporate networks, so an unpatched system is not internet reachable.
      5. The skills base is thin at the state level: Cyber investigation and forensics capacity is concentrated in central agencies, while most first response happens at state police stations. Eg. Citizen fraud complaints route through the national helpline before reaching local police with the capacity to act. Fix. Establish State Computer Emergency Response Teams and cyber forensic laboratories with dedicated cyber police training academies in every State.

      Conclusion

      AI has moved cyber conflict from a contest between attackers and defenders to a contest between countries that build AI and countries that buy it. India sits on the wrong side of that line while carrying one of the world’s largest attack volumes, from a ransomware posting of Kudankulam plant data to state backed targeting of its defence establishment. India cannot build the AI stack quickly, so the immediate requirement is that AI and cybersecurity stop being treated in silos and are handled as interconnected strands of policymaking: AI for cyber defence, and cybersecurity for AI.

      “[2022, GS3, 10 marks] What are the different elements of cyber security? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy.”

    2. Remembering Niketu Iralu: Peace activist, bridge between Nagas, mainland India

      Remembering Niketu Iralu: Peace activist, bridge between Nagas, mainland India

      Why in the News

      Niketu Iralu, a Naga peace activist, died in a Delhi hospital on 18 August 2026 at the age of 91. He spent six decades on reconciliation between Naga factions and between the Naga people and the rest of India, outside every formal negotiating channel. His maternal uncle, Angami Zapu Phizo, led the Naga National Council (NNC), which declared Naga independence on 14 August 1947. The Centre constituted a new ministerial panel last week to carry forward the stalled talks on a final Naga settlement. The conflict has found no solution in the nearly eight decades since that declaration. One position holds that a final text can now be signed. The competing position is that the reconciliation work behind six decades of talks has no institutional successor.

      What is the Naga peace process?

      1. A ceasefire came before any accord: A peace camp at Chedema, on a hilltop near Kohima, negotiated a ceasefire in 1964 between the rebel Naga Federal Government and the Government of India. It was the first suspension of hostilities after more than a decade of armed insurgency.
      2. The Shillong Accord split the movement: NNC representatives signed the Shillong Accord in 1975, accepting the Constitution of India. A faction rejected it and formed the National Socialist Council of Nagaland (NSCN) in 1980.
      3. The current track opened with the 1997 ceasefire: The Centre signed a ceasefire with the NSCN (Isak-Muivah) faction in 1997. Talks under it have run for close to three decades without a final agreement.
      4. The Framework Agreement fixed the terms in 2015: The Centre and the NSCN (Isak-Muivah) signed a Framework Agreement on 3 August 2015 recognising the “unique history” of the Nagas. Its contents have never been published.

      Why did a family at the centre of the sovereignty claim produce its leading peace advocate?

      1. The lineage ran through the sovereignty movement: His father, Sevilie Iralu, was among the first Naga doctors. His maternal uncle led the council that made the 1947 declaration.
      2. He chose a different method: He committed himself to non-violence, dialogue and reconciliation rather than armed struggle. He became known across the Northeast as a peace activist rather than a political negotiator.
      3. Initiatives of Change shaped that method: He worked in Initiatives of Change, an organisation that pursues social transformation through “personal change”. Its premise is that a political conflict is resolved by first changing the people inside it.
      4. Mainland India was a discovery, not an inheritance: He left for Madras Christian College in the 1950s, his first encounter with mainland India. He described the crowds boarding trains at Kolkata as a scale of population that felt unsurvivable.
      5. His house was named for the method: His home at Sechu Zubza in Kohima district was called Kerunyu Ki, “The House of Listening”. People travelled to it for counsel rather than to a party office or a negotiating table.
      6. Recognition came as a bridge builder: He received the Bhupen Hazarika Integration Award among other honours. Hundreds gathered at Dimapur airport when his body arrived from Delhi.

      How does the Second World War figure in Naga political memory?

      1. The war reached Naga villages: The Japanese Army invaded Nagaland in 1944 during the Second World War. His village, Khonoma, was overrun and families fled into the forest.
      2. The battle of Kohima was the turning point: The Japanese retreated after the battle of Kohima. An advance past it would have taken them to the Brahmaputra valley and into mainland India.
      3. The cemetery fixed the memory: The Kohima War Cemetery carries the epitaph, “When you go home, tell them of us and say, for their tomorrow, we gave our today.”
      4. The war left a habit of seeing the enemy as human: His sister slapped a Japanese soldier helping himself to a Naga shawl, and the soldier bowed and left. He read that restraint as evidence that the soldier also had a sister at home.

      What did the 1990 repatriation of Phizo’s body show about informal mediation?

      1. The leader died in exile: Angami Zapu Phizo died in London in April 1990. He had been in exile since 1960, when he left for the United Kingdom to mobilise world opinion for the Naga cause.
      2. The request came from the insurgent side: NNC leaders asked him to help bring the body back to India. No working channel existed between the NNC and the Government of India at that point.
      3. The government feared a funeral would trigger violence: The Janata Dal led government judged that returning the body might set off violence in Nagaland. A Janata Dal member of the Rajya Sabha, who had worked with him in Initiatives of Change for three decades, argued that denying the Nagas the right to grieve was the greater risk.
      4. The ask was procedural, not financial: He told the then Finance Minister at a 5 a.m. meeting that the Nagas had collected the money themselves. He asked only for foreign exchange clearance.
      5. The state supplied the logistics: The remains were received at the technical area of Palam airport. A Home Ministry aircraft then carried the casket to Kohima for the funeral.

      Does reconciliation require a community to confront its own failures?

      1. The demand was turned inward, not outward: A tribute in Ukhrul Times described him as a man who spent decades asking Nagas to confront their failures, resist hatred and recover the courage to listen. The demand was addressed to Naga society, not to the Indian state.
      2. Moral courage was defined as internal criticism: He held that moral courage involves “telling one’s own side what it does not want to hear”. He did not treat reconciliation as a concession or as weakness.
      3. Factional politics penalises exactly that: Naga groups have fought each other as often as they have fought the state, and internal criticism reads as disloyalty inside a faction. Eg. The NSCN split of 1988 into the Isak-Muivah and Khaplang factions produced years of inter-factional killing.
      4. The obstacle is not an administrative clause: The unresolved items are a separate Naga flag and a separate Naga constitution, which are claims about identity rather than about administration. A negotiator can concede an administrative arrangement, and only the community can revise a claim about who it is.

      Challenges to the Naga peace settlement

      1. The flag and constitution demand is unresolved: The NSCN (Isak-Muivah) insists on a separate Naga flag and a separate constitution, the Yehzabo, rejected by the Centre as incompatible with Indian sovereignty. Eg. The talks declared concluded in October 2019 ended without agreement on either demand. Fix. Settle the symbolic claim as a cultural flag protected under Article 371A’s guarantee for Naga customary practice, separated from any constitutional status.
      2. The territorial claim crosses three other States: The “Greater Nagalim” demand would merge Naga inhabited areas of Manipur, Assam and Arunachal Pradesh into one unit. Eg. The Manipur Assembly has repeatedly resolved against any settlement altering the State’s boundaries. Fix. Use non-territorial autonomy, giving Naga councils outside Nagaland cultural and development powers without redrawing State boundaries.
      3. The negotiation has two competing counterparties: The Centre talks in parallel to the NSCN (Isak-Muivah) and to the Naga National Political Groups, and each rejects a settlement signed only with the other. Eg. The Working Committee of the Naga National Political Groups signed a separate Agreed Position in 2017. Fix. Convene one joint negotiating forum so a single signed text binds every group.
      4. Ceasefire ground rules are routinely breached: Cadres under ceasefire run parallel taxation in Nagaland and in Naga areas of Manipur, which keeps an armed economy alive through the negotiation. Eg. Traders and salaried employees in Dimapur pay levies to more than one faction. Fix. Publish the ceasefire monitoring group’s findings with a fixed penalty schedule for each verified breach.
      5. A text kept secret cannot be ratified: The 2015 Framework Agreement has never been published, so no legislature or public body has examined what was agreed. Eg. Nagaland’s own legislators have sought disclosure of the text on the floor of the Assembly. Fix. Table the agreed text in Parliament and in the Nagaland Assembly before signature, so ratification precedes implementation.
      6. Security law feeds the grievance the talks address: The Armed Forces (Special Powers) Act, 1958 remains in force across parts of Nagaland, sustaining the alienation a settlement is meant to end. Eg. The Oting killings of December 2021 in Mon district led the Assembly to demand repeal. Fix. Complete the district by district withdrawal already begun and move residual powers to a civil authority subject to judicial review.

      Conclusion

      The Naga settlement is stalled on claims about identity, not on administrative detail, and identity claims are revised by a community rather than conceded by a negotiator. The reconciliation work that kept six decades of talks survivable was carried by individuals with no official standing, and it has no institutional successor. A ministerial panel can reopen the file. It cannot by itself rebuild the trust that would let a signed text hold.

      “[2025, GS3, 15 marks] What are the major challenges to internal security and peace process in the North-Eastern States? Map the various peace accords and agreements initiated by the government in the past decade.”

    3. In J&K, a facade of normalcy cannot substitute for peace

      Why in the News

      An administrative order circulating in Anantnag directed government employees to take part in a Tiranga Rally, making attendance at a State sponsored event an official obligation. The order brings out the central tension in the governance of Jammu and Kashmir since August 2019, between an official account of restored normalcy and a security regime of raids, dismissals, detentions and attachments that continues without pause. Whether participation of this kind reflects public enthusiasm or administrative compulsion is the question the order leaves unanswered.

      What is Article 370 of the Constitution?

      1. What it provided: A temporary provision under Part XXI that limited Parliament’s legislative power over Jammu and Kashmir to defence, foreign affairs and communications, with other laws requiring the State government’s concurrence.
      2. The linked provision: Article 35A, added by a 1954 Presidential Order, allowed the State to define permanent residents and reserve rights in employment and property for them.
      3. What changed in 2019: Presidential Orders of August 2019 applied the whole Constitution to the State and rendered Article 370 inoperative, and Article 35A ceased to apply.
      4. The statutory change: The Jammu and Kashmir Reorganisation Act, 2019 split the State into two Union Territories, Jammu and Kashmir with a legislature, and Ladakh without one.
      5. The judicial outcome: The Supreme Court upheld the 2019 measures in In re Article 370 of the Constitution (2023) and directed that statehood be restored and elections held.
      6. The contested question: The argument advanced in this piece treats the 2019 change as an abrogation imposed without consent, and reads subsequent governance as its continuation.

      Who is an overground worker?

      1. The term: A person alleged to provide logistical support to militants, such as shelter, transport, money or information, without taking part in armed action.
      2. Why the term matters: It is not defined in statute, so the label carries no fixed evidentiary threshold and can be applied to large numbers after a single incident.

      What is preventive detention?

      1. What it is: Detention ordered by the executive to prevent an anticipated act, without any charge, trial or conviction.
      2. Its basis: Article 22(3) to 22(7) carve preventive detention out of the ordinary protections against arrest, and permit detention up to three months before an Advisory Board must review it.

      What is the United Liberation Council?

      1. What it is: The name attached to a purported threat letter reported on 12 August, described by authorities and sections of the media as an affiliate of Lashkar e Taiba.
      2. What the letter did: It reportedly named several Kashmiri Pandit government employees and carried their telephone numbers.

      Why is the Tiranga Rally order treated as symptomatic rather than isolated?

      1. The object is not the issue: The objection is not to the national flag but to the coercive form of the instruction.
      2. Obligation replaces participation: When attendance at a government event becomes an administrative duty, the resulting turnout cannot be read as evidence of public sentiment.
      3. A pattern of governance: The order fits a style of administration that has defined the region since the Union government took direct control in August 2019.
      4. Display as policy output: A visible ceremony is treated as the deliverable, so the appearance of normalcy substitutes for the conditions that would produce it.
      5. Self defeating measurement: A government that compels attendance loses the only instrument that could have told it whether sentiment had actually changed.

      What measures define administration in the Valley since 2019?

      1. Raids and investigations: Searches and investigations by multiple central and State agencies have become a recurring feature of life in the Valley.
      2. Dismissals from service: Government employees have been dismissed over alleged links with militancy or with militant sympathisers, without the ordinary departmental process.
      3. Mass detention: Thousands have been detained after militant incidents, at times under broad allegations of being overground workers.
      4. Institutional closure: Educational and charitable institutions have faced closure or restriction over alleged links with banned organisations.
      5. Property attachment: Properties worth hundreds of crores of rupees have been attached under various laws.
      6. House demolition: Homes have been demolished where a member of the family stands accused of militancy.
      7. Post incident crackdowns: Thousands were reportedly detained after the killing of a police constable in south Kashmir, and the cycle of raids, detentions and suspicion followed the killing of migrant workers.

      What does the record on the Kashmiri Pandit community show?

      1. The threat letter: Reports on 12 August described a purported threat letter naming several Kashmiri Pandit government employees along with their telephone numbers.
      2. The attributed source: The letter was attributed to the United Liberation Council, described as an affiliate of Lashkar e Taiba.
      3. The casualty count: 25 members of the community have been targeted and killed since 2019.
      4. The named victims: They include Ajay Pandita Bharti, Rakesh Pandita, Makhan Lal Bindroo, Rahul Bhat, Rajni Bala, Puran Krishan Bhat and Sanjay Sharma.
      5. Why the memory matters: For a community displaced in the 1990s, each such threat revives the circumstances of that displacement rather than reading as an isolated crime.
      6. The return condition: Return has to rest on an environment in which the community feels safe, not on participation in official ceremonies designed to demonstrate that everything is normal.

      Why do the claim of normalcy and the continuing security regime contradict each other?

      1. The official account: The government tells the rest of India that Kashmir has entered a new era of peace and normalcy.
      2. The parallel reality: Extraordinary security measures, raids, detentions, dismissals and restrictions continue to shape the everyday lives of ordinary people.
      3. Both cannot be operative: A settled peace does not require a standing apparatus of preventive detention and property attachment to maintain it.
      4. The tourist test fails: Busy markets, full hotels and traffic on the roads are what a visitor sees in a few days. They measure commerce, not security of person.
      5. What each side gains: The government gains a demonstrable output in the display. The population gains nothing it can rely on when the display ends.
      6. The unresolved reminder: The threat letter of 12 August is the demonstration that the underlying problem has not closed, whatever the ceremonies record.

      How should normalcy actually be measured?

      1. Freedom to speak: Whether ordinary people feel secure enough to speak freely without anticipating consequences.
      2. Law as protection: Whether families believe the law will protect them rather than intimidate them.
      3. A visible future: Whether young people see a future for themselves in the region.
      4. Safe return: Whether communities that have suffered displacement and violence feel safe enough to return and rebuild their lives.

      What does the security regime do to a generation born after the conflict?

      1. Who they are: Those in their teens and twenties in Kashmir were born decades after the worst years of the conflict and bear no responsibility for the violence of the 1990s.
      2. What they observe: Many grow up watching fathers, brothers, relatives and neighbours being summoned, detained or questioned.
      3. Collective punishment: Large scale detentions and punitive measures after militant attacks deepen the perception that a whole community is being punished for the acts of individuals.
      4. The asymmetry they learn: One section of society is repeatedly assured that everything is normal while another is continually asked to prove that it is not a threat.
      5. The outcome: This produces bruised memory rather than reconciliation, and bruised memory does not disappear because officials are instructed to display flags.
      6. The time horizon: Brute force can silence a street for a period. It cannot silence a generation’s memory.

      What distinctions must the state draw?

      1. Militant and citizen: The State must distinguish between a militant and an ordinary citizen, which mass categorisation after an incident destroys.
      2. Accused and convicted: It must distinguish between an accused person and a convicted person, which dismissal, attachment and demolition before trial collapse.
      3. Family member and accused: It must distinguish between a family member and the person accused of committing a crime, which punitive action against a household erases.

      Challenges to restoring political normalcy in Jammu and Kashmir

      1. Punitive measures before adjudication: Attachment and demolition operate before a court has decided guilt, so the penalty precedes the finding. e.g. property attachments running to hundreds of crores of rupees under various laws since 2019.
      2. Undefined categories in enforcement: Terms such as overground worker carry no statutory definition, so detention scales with suspicion rather than evidence. e.g. thousands reportedly detained after the killing of a police constable in south Kashmir.
      3. Employment as a security instrument: Dismissal without departmental inquiry converts government service into a lever of security policy. e.g. dismissals of employees over alleged links with militancy since 2019.
      4. Targeted killings of minorities: The safety of returning and resident minority employees remains unsecured. e.g. 25 members of the Kashmiri Pandit community killed since 2019 and a threat letter naming employees on 12 August 2026.
      5. Statehood still pending: Restoration of full statehood remains incomplete, leaving an elected government without control over police and public order. e.g. the Supreme Court’s 2023 direction to restore statehood at the earliest.
      6. Space for civil society: Closure of educational and charitable institutions removes the mediating layer between the State and the population. e.g. restrictions on institutions over alleged links with banned organisations.
      7. Cross border sponsorship: Infiltration and external support keep the security justification alive irrespective of local political settlement. e.g. attacks on migrant workers in the Valley followed by area wide crackdowns.
      8. Economic dependence on tourism: A single security incident removes the region’s main visible income source. e.g. the collapse of bookings in the Valley after major attacks on visitors.

      Conclusion

      The administrative order in Anantnag is a small instrument, and its significance lies in what it substitutes for. Kashmir needs healing built on dignity, justice, security and dialogue, and healing cannot be produced by an order requiring attendance. A facade of normalcy may impress visitors, and it cannot substitute for real peace. The measure of whether the situation has changed is whether the State begins to distinguish the militant from the citizen and the accused from the convict, not whether the flag is displayed on schedule.

      Jammu and Kashmir after 2019

      1. Constitutional status: The former State was reorganised on 31 October 2019 into the Union Territory of Jammu and Kashmir, with a legislature, and the Union Territory of Ladakh, without one.
      2. Political timeline: Assembly elections were held in 2024, the first since 2014, restoring an elected government to the Union Territory.
      3. Statehood question: Full statehood has not been restored. Public order and police remain with the Union government under the Reorganisation Act.
      4. Security geography: The region has a Line of Control of about 740 km with Pakistan and a Line of Actual Control segment with China in Ladakh.
      5. Displacement history: Large scale displacement of the Kashmiri Pandit community occurred from 1990, and return and rehabilitation remains an unfinished policy objective.
      6. Economy: Horticulture, handicrafts and tourism dominate the economy, all of which are directly sensitive to security incidents.

      Constitutional Framework Governing Jammu and Kashmir and Security Measures

      1. Article 1: Declares India a Union of States and makes the territories in the First Schedule part of that Union.
      2. Article 3: Empowers Parliament to form new States and Union Territories and to alter boundaries, the provision used for the 2019 reorganisation.
      3. Article 370: The temporary provision governing the State’s relationship with the Union, rendered inoperative by the Presidential Orders of August 2019.
      4. Article 14: Requires equality before the law, which limits arbitrary classification of persons or communities in security administration.
      5. Article 19: Guarantees freedom of speech, assembly, association and movement, subject to reasonable restrictions on the specified grounds.
      6. Article 21: Protects life and personal liberty, and requires that any deprivation follow a procedure that is fair, just and reasonable.
      7. Article 22: Provides protections on arrest, and separately permits preventive detention with an Advisory Board review after three months.
      8. Article 239A read with the Reorganisation Act: Provides the framework for a legislature in a Union Territory, with police and public order reserved to the Union in the case of Jammu and Kashmir.
      9. Article 355: Places a duty on the Union to protect every State against external aggression and internal disturbance.

      Laws and Rules Governing Security Administration in Jammu and Kashmir

      1. Jammu and Kashmir Reorganisation Act, 2019: Created the two Union Territories and set out the distribution of legislative and executive power between them and the Union.
      2. Unlawful Activities (Prevention) Act, 1967: The principal anti terrorism statute, providing for banning organisations, designating individuals and attaching proceeds of terrorism.
      3. Jammu and Kashmir Public Safety Act, 1978: Permits preventive detention for up to two years on grounds of security of the State or maintenance of public order.
      4. Armed Forces (Jammu and Kashmir) Special Powers Act, 1990: Confers search, arrest and use of force powers on the armed forces in areas declared disturbed, with prior sanction required for prosecution.
      5. National Investigation Agency Act, 2008: Establishes the central counter terrorism investigation agency and defines the scheduled offences it can take over.
      6. Prevention of Money Laundering Act, 2002: Provides for provisional attachment of property representing proceeds of crime, used in terror financing investigations.
      7. Bharatiya Nagarik Suraksha Sanhita, 2023: Replaces the Code of Criminal Procedure, 1973 and carries the powers to issue prohibitory orders and regulate assemblies.

      Back2Basics: In re Article 370 of the Constitution (2023)

      1. What it was: A Constitution Bench judgment of the Supreme Court on the validity of the Presidential Orders of August 2019 and the Jammu and Kashmir Reorganisation Act, 2019.
      2. Holding on sovereignty: The Court held that Jammu and Kashmir retained no element of internal sovereignty after its accession and the adoption of the Constitution.
      3. Holding on Article 370: Article 370 was held to be a temporary provision, and the President’s power to declare it inoperative was held to survive the dissolution of the Constituent Assembly of the State.
      4. Holding on Article 35A: The Court held that the removal of Article 35A did not violate the fundamental rights framework.
      5. Direction on statehood: The Court directed that the statehood of Jammu and Kashmir be restored at the earliest, while upholding the carving out of Ladakh.
      6. Direction on elections: The Election Commission was directed to hold Assembly elections by 30 September 2024.
      7. Additional direction: The Court recommended a truth and reconciliation commission to examine human rights violations in the region since the 1980s.

      Government Initiatives

      1. Prime Minister’s Development Package, 2015: An outlay of about Rs 80,068 crore covering road, power, health, tourism and rehabilitation projects in the region.
      2. Prime Minister’s Package for Kashmiri Migrants: Provides government jobs and transit accommodation to support the return of displaced Kashmiri Pandit families to the Valley.
      3. Udaan and Himayat: Skill development and placement schemes for youth of the region, run through the National Skill Development Corporation and the rural livelihoods mission.
      4. Prime Minister’s Special Scholarship Scheme: Funds higher education outside the region for students from Jammu and Kashmir and Ladakh.
      5. Security Related Expenditure scheme: Reimburses the Union Territory for expenditure on security, relief and rehabilitation of surrendered militants and civilian victims.
      6. Operation Sadbhavana and the Civic Action Programme: Army and central armed police force programmes that fund schools, medical camps and community infrastructure in border and affected areas.
      7. New Central Sector Scheme for Industrial Development, 2021: An outlay of about Rs 28,400 crore of capital and interest incentives to attract manufacturing investment to the Union Territory.

      Key Facts about Jammu and Kashmir

      1. Reorganisation date: The two Union Territories came into existence on 31 October 2019, observed as National Unity Day.
      2. Representation: The Union Territory of Jammu and Kashmir returns five members to the Lok Sabha and Ladakh returns one.
      3. Delimitation: The 2022 delimitation raised Assembly seats to 90, with 43 in the Jammu division and 47 in the Kashmir division, besides seats reserved for Scheduled Castes and Scheduled Tribes for the first time.
      4. Reservation extension: Central laws on reservation, including for Scheduled Tribes such as the Gujjar, Bakarwal, Gaddi and Sippi communities, now apply to the Union Territory.
      5. Boundaries: The region borders Pakistan along the Line of Control and China along the Line of Actual Control in Ladakh.
      6. Geography: The Pir Panjal range separates the Jammu division from the Kashmir Valley, and the Jhelum, Chenab and Indus are the principal rivers.
      7. Treaty link: The Indus Waters Treaty of 1960 governs the use of the western rivers that flow through the region, and India placed it in abeyance in 2025.

      Challenges in Internal Security Management

      1. Balancing force and consent: Security operations that succeed tactically can widen alienation and cost the political objective. e.g. area wide cordon and search operations following a single militant incident.
      2. Preventive detention without adjudication: Detention laws allow long custody without trial, which produces grievance even where the intelligence is sound. e.g. detention up to two years permitted under the Jammu and Kashmir Public Safety Act, 1978.
      3. Radicalisation through digital channels: Recruitment and propaganda have moved online, beyond the reach of physical area domination. e.g. encrypted messaging used for handler communication in recent militancy cases.
      4. Terror financing: Funding routes through hawala, cryptocurrency and front organisations are hard to interdict. e.g. investigations into non governmental organisations and trusts by central agencies since 2017.
      5. Rehabilitation of surrendered cadre: Without livelihood and social acceptance, surrendered militants relapse. e.g. surrender and rehabilitation policies across the Northeast and Left Wing Extremism affected districts.
      6. Centre and State coordination: Multiple agencies operating in the same theatre create gaps in intelligence handover. e.g. the multi agency centre framework created after the 2008 Mumbai attacks.
      7. Human rights accountability: Sanction requirements delay prosecution in cases of alleged excess, which erodes trust in the process. e.g. the prior sanction requirement for prosecuting armed forces personnel.
      8. Border management technology: Infiltration continues where terrain defeats physical fencing. e.g. tunnels detected along the international boundary in the Jammu sector.

      Way Forward

      1. Restore statehood on a stated timeline: Give the elected government responsibility for public order so accountability for security decisions is politically located.
      2. Individualise security action: Confine dismissal, attachment and demolition to persons against whom a case is established, with reasons recorded and an appeal available.
      3. Institutionalise dialogue: Create a standing channel with elected representatives, civil society and displaced communities rather than event driven engagement.
      4. Secure minority employees: Provide verified protection and posting choices to Kashmiri Pandit employees rather than requiring presence at ceremonial events.
      5. Time bound trials: Expand special court capacity so that persons in preventive detention are either charged and tried or released.
      6. Youth employment at scale: Convert skill schemes into placement linked outcomes so that the young have a visible economic route.
      7. Independent grievance mechanism: Set up an accessible body to examine complaints of excess, following the reconciliation mechanism the Supreme Court recommended in 2023.

      “[2023, GS3, 10 marks] Winning of ‘Hearts and Minds’ in terrorism-affected areas is an essential step in restoring the trust of the population. Discuss the measures adopted by the Government in this respect as part of the conflict resolution in Jammu and Kashmir.”