Why in the News
India has unveiled PRAHAAR, its first comprehensive National Counter Terrorism Policy and Strategy, which sets a national framework for preventing and responding to terrorist activity and radicalisation through coordinated “whole of government” and “whole of society” approaches. The policy follows Operation Sindoor, the strikes of 6 and 7 May on the Pakistan based terror network launched after the Pahalgam attack of 22 April 2025, and follows the three declarations India issued immediately after that operation. The first of those declarations ended the stated era of restraint, the second classified any future act of cross border terrorism emanating from Pakistan as an “act of war”, and the third removed Pakistani nuclear blackmail as a restraining factor. The tension is that the doctrine India has hardened is built for a state sponsor with a return address, while the threat itself has fragmented into lone wolf attackers, autonomous cells and drone, cyber and artificial intelligence enabled methods that a retaliatory strike does not reach.
What is PRAHAAR?
- PRAHAAR as a national policy: PRAHAAR is India’s first comprehensive National Counter Terrorism Policy and Strategy, unveiled on 23 February 2026.
- Scope of the framework: It sets out a national counter terrorism framework for preventing and responding to terrorist activities and to radicalisation.
- Whole of government and whole of society approach: It works through coordinated “whole of government” and “whole of society” approaches, so prevention is not left to security agencies alone.
How has the form of terrorism changed in 25 years?
- The organisational form has fragmented: Large terror groups run by single leaders, such as al-Qaeda under Osama bin Laden or the Islamic State under Abu Bakr al-Baghdadi with its call for an Islamic Caliphate, have given way to smaller and more autonomous entities.
- The attacker is now often solitary: Lone wolf attacks are becoming the norm, which removes the network that intelligence collection is designed to detect.
- Drones, cyber capability and artificial intelligence: Drones, cyber capabilities and artificial intelligence are now used to perpetrate terror.
- Counter terrorism use of the same technologies: Those technologies are used by the nations combating terrorism as well, so capability advantage is contested rather than assured.
What is a lone wolf attack?
- The definition: A lone wolf attack is an attack planned and executed by a single individual, or by a pair acting alone, who belongs to no organisation and takes no operational direction from one.
- How the attacker is produced: Radicalisation runs through online propaganda rather than through recruitment by a handler, so the individual adopts a group’s cause without ever joining its structure. Eg. Self radicalised modules assembled around professionals, rather than around infiltrators, in recent hinterland cases.
- Why detection fails: Intelligence collection works by intercepting communication between conspirators and by penetrating networks, and an attacker who communicates with nobody generates neither signal.
- Why a retaliation doctrine does not reach it: A cross border response needs attribution to a sponsoring state, and an individual acting alone offers no camp, handler or command node to strike.
Why did the early Indian response stay passive, and which attacks fell inside that period?
- Assassination of a former Prime Minister, 1991: The assassination of former Prime Minister Rajiv Gandhi by the Liberation Tigers of Tamil Eelam on 21 May 1991 at Sriperumbudur in Tamil Nadu came while cross border terror was only beginning in Kashmir.
- Internal detection failed repeatedly: The March 1993 Mumbai serial blasts killed over 250 people in 13 coordinated blasts, and the synchronised blasts across Coimbatore in February 1998 exposed the inadequacy of internal security mechanisms.
- Pakistan’s direct role was first exposed by a hijack: The hijack of Indian Airlines flight IC-814 on 24 December 1999 forced India to release the Pakistan based terrorists Ahmed Omar Sheikh and Masood Azhar in exchange for more than 160 civilian hostages.
- Operation Parakram and its outcome: The Jaish-e-Mohammed (JeM) attack on Parliament on 13 December 2001 triggered a large scale military mobilisation under Operation Parakram, and after almost two years of standoff the disengagement took place with no direct punishment on Pakistan.
- Nuclear parity was the restraint: With both countries holding nuclear weapons, the threat of escalation drew the international community in to cool tempers each time.
- The 26/11 Mumbai attacks and the absence of retaliation: The 26/11 Mumbai attacks of November 2008, which brought the world’s solidarity with India’s fight against cross border terrorism, produced no military action against Pakistan.
- The Red Fort attack of 2000: An Army garrison within the Red Fort was targeted on 22 December 2000 by Lashkar-e-Taiba (LeT) terrorists, killing three soldiers.
- Delhi market blasts of 2005: Over 60 people were killed in serial blasts across Delhi markets including Sarojini Nagar and Paharganj in October 2005.
- Delhi commercial district blasts of 2008: Multiple blasts hit Connaught Place, Greater Kailash and Karol Bagh in September 2008, months before the Mumbai attacks.
- The Delhi High Court blast of 2011: A briefcase bomb outside the Delhi High Court on 7 September 2011 killed 15 people, claimed by Harkat-ul-Jihad Islami (HUJI), an al-Qaeda affiliated group largely based in Pakistan.
- Akshardham, Varanasi and Pune attacks: The 2002 Akshardham Temple attack, the 2006 Varanasi serial blasts and the 2010 German Bakery blast in Pune are part of the same record.
- Proof did not produce a response: In each of these cases India chose not to respond directly and decisively, even after conclusive proof of Pakistan’s support.
What changed when the fight moved across the border?
- The Uri attack and the 2016 surgical strikes: The JeM attack on an Army camp at Uri in Kashmir on 18 September 2016 led to the first cross border surgical strikes on 28 and 29 September.
- Message conveyed by the surgical strikes: They sent a message and served as a statement of intent that terror would not go unpunished.
- The Balakot air strike of 2019: After the attack on a Central Reserve Police Force convoy at Pulwama on 14 February 2019, the Indian Air Force struck a JeM terror camp at Balakot, the first time it had crossed into Pakistani airspace to hit a terror target.
- Operation Sindoor, 2025: Operation Sindoor was launched on 6 and 7 May after the Pahalgam attack, and in 96 hours the leaders and headquarters of the LeT and JeM networks were destroyed and Pakistani military assets were hit.
What is the four fold strategy proposed from here?
- Elimination of the residual network: Continue to hunt down and eliminate the remnants of the terror network inside the country, particularly in Kashmir.
- Pre emptive action across the Line of Control: Take pre emptive military action against any potential terror threat building across the Line of Control (LoC), including at terrorist launch pads, which years of experience and an embedded intelligence network make possible.
- The de radicalisation programme: Run an exhaustive de radicalisation programme that motivates young people towards the mainstream and makes joining or supporting a terror outfit unattractive and prohibitively costly.
- Terror financing: Take all necessary steps to cut off terror financing, in close coordination with friendly countries.
What is India pressing for at the multilateral level?
- The charge of double standards: At the Shanghai Cooperation Organisation Summit in Bishkek on 1 September the Prime Minister said, “We must send a strong message to countries that use terrorism as an instrument of policy and provide safe haven and support to terrorists that terrorism can never be a strategic asset for anyone.”
- A named attack entered a group declaration: The 18th BRICS Summit in New Delhi included an exclusive paragraph on the Pahalgam attack in the Delhi Declaration.
- Effect of a grievance carried in multilateral text: A specific Indian grievance is now carried in the text of a multi country declaration rather than only in national statements.
Challenges to India’s counter terrorism strategy
- A retaliation doctrine has no target in a lone wolf attack: An “act of war” classification presumes an attributable state sponsor, and a self radicalised individual acting alone gives no address to strike. Eg. Self radicalised modules assembled around professionals, rather than infiltrators, in recent hinterland cases.
The Fix: Pair the declaratory doctrine with a published attribution standard, so the threshold of evidence that triggers a cross border response is fixed in advance rather than argued after each attack. - Police and public order are State subjects: A national policy has to be executed through State police forces that the Union does not control, which is where coordination breaks down. Eg. The delay in National Security Guard deployment during the 26/11 Mumbai attacks.
The Fix: Route PRAHAAR’s obligations through a standing Centre State counter terrorism council with State specific implementation timelines, rather than through advisories. - Intelligence remains fragmented across agencies: Multiple collection agencies without seamless real time sharing means a warning held by one is not actionable by another. Eg. Intelligence fusion is attempted through the Multi Agency Centre and the National Intelligence Grid, which depend on voluntary feeds from database holding agencies.
The Fix: Give a single fusion centre statutory authority to task and receive feeds, on the model of a national counter terrorism centre, so sharing is an obligation rather than a courtesy. - De radicalisation has no measurable output: A programme aimed at intent rather than at incidents cannot be judged by attack counts, and India runs no published evaluation of one. Eg. Online influence of the kind that drove youth radicalisation in Kashmir operates outside any programme’s reach.
The Fix: Fix published indicators for the programme, such as recruitment attempts intercepted and cases of disengagement sustained over a stated period, and report them annually. - Terror financing has moved to channels outside the banking system: Hawala, counterfeit currency and cryptocurrency route funds without touching a reportable transaction. Eg. Informal channel financing was traced in the ISIS linked Padgha module.
The Fix: Bring virtual digital asset service providers fully under reporting obligations to the Financial Intelligence Unit India, so the fastest growing channel is monitored on the same terms as banks. - There is no agreed international definition of terrorism: The absence of one lets states label selectively and refuse cooperation on legal grounds. Eg. Repeated holds placed on listings under the United Nations Security Council 1267 sanctions committee.
The Fix: Press the Comprehensive Convention on International Terrorism, which India first proposed in 1996, to a vote rather than leaving it in open ended negotiation.
Conclusion
The doctrine India adopted after Operation Sindoor answers one form of the threat well and leaves the other untouched. A declared willingness to retaliate raises the cost of sponsoring an attack from across the border; it does nothing about an attacker who was recruited online and never crossed anything. PRAHAAR is the first instrument that addresses the second half, which is why its prevention and radicalisation components, rather than its enforcement components, are the part worth watching. The marker is whether the policy produces named nodal responsibilities and reported outcomes, or remains a framework document that the next attack is measured against.
Terrorism in India
- Definition of terrorism: Terrorism is the deliberate use of violence, or the threat of violence, to instil fear and achieve political, ideological or religious goals.
- The statutory definition: Under Section 15 of the Unlawful Activities (Prevention) Act, 1967, a terrorist act is any act intended to threaten India’s sovereignty, security or unity, or to create terror through violence, explosives or disruption of essential services.
- The four recognised strands in the Indian context: Cross border terrorism driven by Pakistan based groups in Jammu and Kashmir and by Khalistani networks, North East insurgencies run by ethno nationalist groups such as NSCN and ULFA, Left Wing Extremism across the Red Corridor, and hinterland terrorism by modules operating outside traditional conflict zones.
- The direction of change: The terror and organised crime nexus supplies funding, arms and logistics, and technology acts as a force multiplier through drones, encrypted platforms and 3D printing. Eg. The Houthi drone attack on Saudi Aramco in 2019.
Institutional Architecture and Initiatives Against Terrorism
- Multi Agency Centre and Cyber Multi Agency Centre: Fuse intelligence inputs across central and State agencies.
- National Intelligence Grid: Networks databases held by different departments to give agencies real time access.
- Indian Cyber Crime Coordination Centre: Acts as the nodal point against cybercrime with a citizen reporting route. Eg. The 1930 helpline.
- Border management systems: Smart fencing under the Comprehensive Integrated Border Management System plugs infiltration gaps, backed by a layered coastal security grid.
- Surrender and rehabilitation policies: Pull cadres out of insurgency through reintegration rather than through prosecution alone.
Matching Previous Year Question
“[2025, GS3, 10 marks] Terrorism is a global scourge. How has it manifested in India? Elaborate with contemporary examples. What are the counter measures adopted by the State? Explain.”

