💥Join UPSC 2027,2028 Mentorship (July Batch) + XFactor Notes & Microthemes PDF

Subject: Internal Security

  • Social media and encrypting messaging services pose a serious security challenge. What measures have been adopted at various levels to address the security implications of social media? Also suggest any other remedies to address the problem.

    India has second-largest social media market with 491 million active users. However, in 2025, these platforms are central to “Grey Zone Warfare” as their architecture creates a “security paradox”

    Challenges Posed by Social Media & Encrypted Messaging

    Social Media Challenges

    Algorithmic Echo Chambers creating polarized “digital silos”. (India Hate Lab report)

    Cognitive Warfare- Eg- “Bot-farms” to build anti-India narratives

    Cyber Stalking and Harassment – Eg- Women targeted through doxxing and revenge porn.

    Online Radicalisation – Eg- ISIS recruitment through social media.

    Encrypted Messaging Challenges

    Traceability Paradox- End-to-end encryption prevents law enforcement from identifying the “first originator”

    Operational Backbone for Terror- Eg- ISIS and LeT using Telegram or Signal

    Serve as the front-end for darknet markets dealing in narcotics and illegal firearms.

    Shadow Financial Hubs- Eg- use of “self-destructing” messages for “Digital Arrest” extortions

    Measures Adopted at Various Levels

    Legal and Regulatory Framework

    IT Rules, 2021 – mandate Traceability, requiring significant social media intermediaries to identify the “first originator” on court orders.

    DPDP Act- Requires data breach notifications to the Data Protection Board within 72 hours.

    Bharatiya Nyaya Sanhita Section 353 penalizes the spread of misinformation causing public fear.

    Institutional and Operational Measures

    I4C acts as the national nodal point for identifying and removing unlawful content.

    CyberDome Project (Kerala) to monitor the Darknet and social media for criminal patterns.

    “Operation Blackface” of Maharashtra Police Cyber Department for crack down on Child Sexual Abuse Material (CSAM)

    Global and Social Initiatives

    India actively participates in the UN Convention against Cybercrime (2024) and the Christchurch Call to eliminate extremist content.

    Initiatives like Cyber Swachhta Kendra and the 1930 Helpline promote “Digital Hygiene.”

    Suggested Remedies to Address the Problem

    Metadata Analysis over Decryption- By analyzing “who talks to whom, when, and from where” (metadata), to identify criminal clusters.

    Mandating social media platforms to undergo independent audits of their “Recommendation Engines.”

    Implementing mandatory Digital Watermarking for all AI-generated content (deepfakes).

    Establishing an independent, statutory Digital Ombudsman to provide a “Single-Window” grievance redressal mechanism for citizens

    Mandatory SIM-Binding for messaging apps to prevent the use of international virtual numbers in local scams like “Digital Arrests.”

    Integrating “Cognitive Defense” and digital civics into school and college curricula.

    Formalizing a real-time data-sharing bridge between the I4C and tech giants to instantly “freeze” fraudulent financial flows during the Golden Hour.

    Community Fact-Checking Models- Empowering certified organizations with “Priority Reporting” status on platforms to flag virally dangerous misinformationce.

    Push for a Global Cyber-Extradition Framework to ensure that criminals operating from “Safe Haven” countries can be prosecuted.

    Sovereign Messaging Alternatives- Eg- apps like Sandes for government communication.

    Adopting global best practices

    “Duty of Care” Principle (UK)- Shifting burden of safety from the user to the platform.

    EU’s Digital Services Act for Algorithmic Transparency

    Estonia’s e-residency program using Blockchain

    For “Safe and Trusted Cyberspace” there is need for a “Whole-of-Nation” approach

    Border Management and Security Forces

  • Describe the context and salient features of the Digital Personal Data Protection Act, 2023

    The DPDP Act, 2023 aims to transform India from a “privacy-neutral” state to a “privacy-centric” digital democracy. It provides the legal backbone for India’s $1 trillion digital economy aspirations.

    Context of the Act

    Committee Recommendations (Justice B.N. Srikrishna Committee) emphasizing “Data Sovereignty” and the “Fiduciary” relationship.

    Digital economy- With over 900 million internet users, the rapid expansion of digital payments (UPI) and digital public infrastructure (Aadhar, CoWIN) required robust safeguards.

    Inadequacy of IT Act, 2000- The previous framework (Section 43A) was narrow, outdated, and lacked the “teeth” to penalize global tech giants for data breaches.

    To remain a global outsourcing hub, India needed a law compatible with Global Norms. Eg- EU’s GDPR.

    Data Breaches highlighted the vulnerability of citizens’ personal data. Eg- CoWIN data leak

    The rise of AI-driven behavioral profiling and “dark patterns” in e-commerce necessitated “Purpose Limitation.”

    Data has become the “new oil” in modern warfare, with data localization as a vital component of national security.

    Salient Features of the Act

    The Act is built on the philosophy of “Rightful Processing”

    Tripartite Stakeholder Model- Identifies the Data Principal (individual), Data Fiduciary (entity deciding data use), and Data Processor (entity handling data).

    Consent-First Approach- Processing is only lawful with “free, specific, informed, unconditional, and unambiguous” consent via a clear notice.

    Rights of Data Principals- Grants the right to Access (summary of data), Correction, Erasure, and Nomination (bequeathing digital data after death).

    Significant Data Fiduciaries (SDFs)- Entities handling high-volume or sensitive data (e.g., Social Media) must appoint a Data Protection Officer (DPO) and conduct annual audits.

    Protection of Minors- Mandates verifiable parental consent for children (under 18) and strictly prohibits tracking or targeted advertising directed at them.

    Data Protection Board of India (DPBI)- A digital-first regulatory body empowered to investigate breaches and impose fines.

    Negative List for Cross-Border Flow- Permits data transfer to most countries unless specifically restricted by a government “Blocklist.”

    Stringent Financial Penalties- Forgoes criminal jail terms in favor of massive civil penalties-up to for failure to prevent a data breach.

    Challenges That Remain

    Surveillance concerns- Section 17 allows the state to bypass most provisions for “security of the state” and “public order”.

    Diligence vs. Innovation- high cost of implementing “Privacy by Design” and maintaining audit trails for MSMEs and startups.

    One-size-fits-all approach- Unlike GDPR, the Indian law does not distinguish between general data and “Sensitive” data.

    The Act is a right step toward Digital Sovereignty. It must move beyond mere legal text to create a “Privacy Culture” for meaningful exercise of digital autonomy.

  • Explain how narco-terrorism has emerged as a serious threat across the country. Suggest suitable measures to counter narco-terrorism.

    Narco-terrorism refers to the use of drug trafficking and narcotics trade to finance terrorist and insurgent activities. In India, it has emerged as a serious challenge due to porous borders, regional instability and rising drug demand.

    Narco-Terrorism as a Serious Threat in India

    India lies between the Golden Crescent and Golden Triangle, making it vulnerable as a transit and destination country.

    Nexus between Terror Groups and Organised Crime to move drugs and launder money.

    Destabilisation of Border States– Eg- Rising drug addiction and arms recovery in Punjab.

    Use of Advanced Technology– Eg- Drone-based drug and arms drops across the Punjab border.

    Threat to Youth and Social Fabric – Eg- as per AIIMS report, 15.4% of Punjab’s population was engaged in some form of substance use (over 3 million people)

    .

    Maritime security concerns

    Measures to Counter Narco-Terrorism

    Strengthening Border Management – Enhance surveillance, fencing, anti-drone systems and coastal security.

    Integrated Intelligence – Seamless coordination among NIA, NCIB, ED, DRI, state police and intelligence agencies.

    Targeting Financial Networks – Crackdown on money laundering, hawala and benami assets linked to drug trade.

    International Cooperation – Cooperation under FATF framework and bilateral mechanisms.

    Legal and Institutional Strengthening – Swift prosecution under Narcotic Drugs and Psychotropic Substances (NDPS) Act, 1985

    Technological Solutions – Use of AI, data analytics and drone monitoring to track trafficking routes.

    Fast track implementation of National Action Plan for Drug Demand Reduction (NAPDDR) and Nasha Mukt Bharat Abhiyaan (NMBA)

    Community Policing – Involve border communities in intelligence gathering.

    A multi-pronged strategy under zero tolerance for narcotics is essential to dismantle the narco-terror ecosystem and ‘Nasha Mukt Bharat’.

  • What are the major challenges to internal security and peace process in the North-Eastern States? Map the various peace accords and agreements initiated by the government in the past decade.

    The N-E region comprising eight states and connected to the Indian mainland by a small Silghuri Corridor (Chicken Neck – 23 km width) has been facing the problems of insurgency for over 5 decades.

    Major challenges to internal security and peace process in North-Eastern states

    Cross-Border Dynamics– Porous Indo-Myanmar borders enable arms, insurgent movement, and illegal trade.

    “Tyranny of distance” – Policy attention from New Delhi remains inadequate due to geographic remoteness and low political representation of the region.

    Ethnic divisions – Eg- deepening Meitei-Kuki-Zo divide post-2023 riots in Manipur

    Weak peace processes – Talks with 30+ insurgent groups in Manipur and Nagaland continue without breakthroughs

    Protracted insurgencies and splintering of groups reduce prospects for a single comprehensive settlement. Eg- NSCN splits (IM/NK/R).

    Poor governance and developmental deficit sustain grievance and provide recruitment ground.

    Drug trafficking, illegal timber/mineral extraction and extortion fund insurgents and fuel local conflict. Eg- proximity to Golden Traingle

    Demographic stress – Large-scale illegal Bangladesh-origin immigration create social tensions and political mistrust. Eg- in Assam

    High Violence– In 2024, NE India experienced 266 insurgency-related incidents, causing 258 deaths and displacing 60,000 people.

    External factors

    China – Territorial claims in Arunachal Pradesh and support to insurgent groups

    Bangladesh – Anti-India shift post coup and growing Pakistan-China influence

    Myanmar – destabilised border post ‘Spring Revolution’

    Map of major peace accords

    2015 – Naga Framework Agreement for an “inclusive political solution” within the Indian Union (framework terms still being negotiated).

    2019 – Tripura NLFT (SD) Memorandum of Settlement – surrender of cadres and rehabilitation package to end insurgency.

    2020 – Bru-Reang Agreement (Tripura-Mizoram) – Repatriation and rehabilitation of Bru refugees with security and development assurances.

    2020 – Bodo Peace Accord (Phase-II) – Expansion of Bodoland Territorial Region (BTR) powers, and development funds.

    2021 – Karbi Anglong Agreement (Assam)

    2022 – Assam-Meghalaya Boundary Agreement – land demarcation to resolve long-standing boundary disputes.

    2022 – Adivasi (Assam) Peace Accord (2022) – Settlement package including rehabilitation and development measures.

    2023 – Dimasa accords – Ceasefire, surrender/rehab and local development commitments.

    2023 – ULFA Accord – bringing a major faction of ULFA into a political process in Assam

    2024 – NLFT and ATTF Agreements (Tripura) – Memoranda of Settlement leading to cadre surrender and integration

    Other supporting measures (2015-2024)

    Extension of ceasefires with various Naga factions, multiple SoO (Suspension of Operations) agreements, and targeted MoUs with smaller groups

    AFSPA withdrawal from Tripura and MEghalaya

    Peace in the North-East requires a multipronged approach involving negotiated settlements backed by credible security, sustained development, rights protection and wide stakeholder inclusion

    Terrorism

  • Terrorism is a global scourge. How has it manifested in India? Elaborate with contemporary examples. What are the counter measures adopted by the State? Explain.

    As per Bruce Hoffman, “Terrorism is the deliberate creation and exploitation of fear through violence or the threat of violence in the pursuit of political change.”

    Terrosim as a global scourge (Global Terrorism Index 2025)

    over 8,000 terrorism-related deaths globally (2024)

    Islamic State (IS) expanded its operations to 22 countries

    Terrorist attacks jumped by 63% in the West

    India witnessed Pahalgam terrorist attack in 2025

    Manifestations of Terrorism in India

    State-Sponsored Terrorism – Pakistan-backed groups like Lashkar-e-Taiba (LeT), Jaish-e-Mohammed (JeM), and Hizbul Mujahideen.

    Insurgency in Jammu & Kashmir – Radicalisation, infiltration, and hybrid terrorism

    Left-Wing Extremism (LWE) – Naxalite-Maoist insurgency in ‘Red Corridor’

    Ethno-Nationalist Militancy in the N-E – Insurgent groups like ULFA (Assam), NSCN (Nagaland).

    Urban & “Lone-Wolf” Terrorism – Eg- Recent Delhi Blast

    Narco-Terrorism along Golden Traingle and Golden Crescent

    Financing of Terrorism – Use of Hawala, Fake Currency, NGOs, and Cryptocurrency

    Digital and Cyber-Terrorism – Online recruitment, fundraising and encrypted communications.

    Counter-Measures Adopted by the State

    Legislative Measures

    UAPA, 1967 – empowers State to designate individuals as terrorists.

    NIA Act, 2008 – established National Investigation Agency with nationwide jurisdiction.

    PMLA, 2002 – to curb money laundering and terror financing.

    Institutional Mechanisms

    National Security Council Secretariat headed by the NSA for inter-agency coordination

    NATGRID and Multi-Agency Centre for real-time intelligence sharing and coordination

    Operational Measures

    Operation Sindoor, Surgical Strikes (2016) and Balakot airstrikes (2019) as deterrence.

    Operation All-Out in J&K to neutralize militants.

    Border & Internal Security Measures

    Fencing and electronic surveillance along the Indo-Pak and Indo-Bangladesh borders.

    Use of drones, radars, and thermal imaging to detect infiltration.

    Community Engagement

    De-radicalisation programmes in J&K.

    Heart and mind strategy – Eg- Operation Sadbhavana (Goodwill) of Indian Army

    Employment and Skill Development to mainstream youth. Eg- Udaan Scheme

    International Cooperation

    Active role in FATF to blacklist terror-financing states.

    UN sanctions listing of terrorists like Masood Azhar and Hafiz Saeed.

    The zero tolerance against terrorism strategy needs 4-pronged approach

    Strengthening HUMINT (Human Intelligence) and TECHINT (Technological Intelligence).

    SMART Borders (Madhukar Gupta Committee)

    Raising cost of terrorism for Pakistan. Eg- Operation Sindoor

    Human-centric Counterinsurgency

  • The Government of India recently stated that Left Wing Extremism (LWE) will be eliminated by 2026. What do you understand by LWE and how are the people affected by it? What measures have been taken by the government to eliminate LWE?

    LWE refers to violent insurgency driven by Maoist or Naxalite ideologies, with an objective of overthrowing the government and establishing a communist society.

    Determinants of Left-Wing Extremism in Eastern India

    Maoist ideology of armed class struggle

    Land Displacement due to Mining

    Poor implementation of FRA, 2006, and PESA.

    Historical Socio-Economic Deprivation

    Unemployment & Lack of Livelihood Options

    Governance Deficit

    Geographical challenges

    Impact on people

    Over 14,000 lives were lost to Naxal violence in the last 20 years

    Infrastructure Destruction– targeting road networks, railways, and telecom towers in the “Red Corridor”.

    Extortion and “Levy”

    Human Rights Violations – Eg- abduction and killing of local leaders

    Low-growth trap increases inequality and poverty. Eg- The HDI for Malkangiri district (Odisha) – a LWE stronghold – is only 0.37, compared to the state’s average of 0.579.

    Socio-economic impact – Eg- As per MHA report, 70% population of naxal affected areas lives under BPL.

    Recruitment of Minors and Vulnerable Youth – Eg- Reports of child soldiers in southern Bastar.

    Measures taken by government

    Security Measures

    Specialised Forces- Eg- Greyhounds in Andhra Pradesh and the Bastariya Battalion in Chhattisgarh

    Naxal’s Financial chocking

    Security Related Expenditure and Special Infrastructure Scheme for strengthening State Special Forces and Special Intelligence Branches

    Developmental measures

    Building Critical Infrastructure in LWE Areas – Eg- Road Requirement Plan (RRP-I) constructing 14000 km of roads

    Socio-economic development

    Financial Inclusion- over 1,00 bank branches have been opened in LWE affected districts since April 2015.

    Aspirational districts program

    ROSHNI Scheme for skill development and employment-linked training for youth

    Surrender and rehabilitation policy – attractive incentives and assured livelihood. Eg- stipend for professional training

    Panchayat Extension To Scheduled Areas Act (PESA) and Forest Rights Act 2006 for strengthening tribal self-governance

    Progress anchored in justice and inclusion is the best antidote to extremism.

  • Why is maritime security vital to protect India’s sea trade? Discuss maritime and coastal security challenges and the way forward.

    Maritime security is the “silent guardian” of India’s economic prosperity. The safety of Sea Lanes of Communication (SLOCs) is not just a military concern but a vital economic imperative.

    Importance of maritime security for India’s sea trade

    Economic Lifeline- Approximately 95% of India’s trade by volume and 70% by value is conducted via the sea.

    Energy Security- India imports over 88% of its crude oil and 51% of its natural gas from chokepoints like the Strait of Hormuz and Malacca Strait.

    Global Hub Aspirations- Secure seas are essential for India to emerge as a global transshipment hub

    Protection of “Blue Economy”- to protect fisheries, offshore oil/gas (Mumbai High), and seabed minerals in India’s 2.3 million sq. km. Exclusive Economic Zone (EEZ)

    Strategic Connectivity- Initiatives like Sagarmala and IMEC rely on secure seas.

    Submarine Cable Safety- Almost 99% of India’s internet data travels through undersea fiber-optic cables.

    Regional Leadership under SAGAR Vision – Eg- India as a “First Responder”.

    Climate Resilience- Security agencies like the Indian Coast Guard play a critical role in responding to oil spills and natural disasters.

    The Indian ocean region is ‘New Hotbed’ of security threats – Fareed Zakaria

    Maritime Terrorism- Eg- the 26/11 Mumbai attacks

    Geopolitical Competition from China challenging India’s role as a “Net Security Provider.”

    “dual-use” ports like Hambantota (Sri Lanka) and Gwadar (Pakistan)

    Chinese spy ships in Indian Ocean (Tianwen I)

    Piracy and Armed Robbery-

    Somali piracy in the Gulf of Aden and Arabian Sea

    Houthi disruptions in the Red Sea

    Transnational Organized Crime- The “Golden Crescent” and “Golden Triangle” routes converge in the IOR. (MHA)

    Human Trafficking- Illegal migration routes across the Bay of Bengal and Andaman Sea.

    Illegal, Unreported, and Unregulated (IUU) Fishing- Eg- Large foreign deep-sea trawlers encroaching on India’s.

    Offshore Asset Vulnerability- Eg- Mumbai High oil rigs and the Great Nicobar Project from state and non-state sabotage.

    Nuclearization of IOR due to AUKUS

    IOR emerging as theater of great-power rivalry – Eg- US-UK base in Diego Garcia

    Way Forward

    Maritime Domain Awareness (MDA)- Strengthening the NC3I Network and Information Fusion Centre (IFC-IOR)

    Fishermen as “Eyes & Ears”- Speeding up the issuance of Biometric ID cards and distress alert transmitters.

    Apex committee to coordinate all maritime operations (Kargil Review Committee)

    Technological Modernization

    Deploying AI-powered systems for 24/7 surveillance.

    Utilizing ISRO’s RISAT and UAVs like the Heron for all-weather, day-and-night imaging.

    Accelerate the induction of P-8I long-range maritime patrol aircraft and Sea Guardian drones.

    Global collaboration under UNCLOS to ensure Rules based Order in IOR

    Strengthening Marine Police with specialized training, equipments and proper legal powers.

    Regular joint exercises like Sagar Kavach and Sea Vigil to build synergy among various agencies

    Strengthening regional cooperation through Indian Ocean Naval Symposium

    Environmental Resilience- Integrating climate risk management into maritime strategy

    Maritime security is the backbone of India’s strategic autonomy, leadership (“Net security provider”) and Navy’s ambition of Blue Water Navy

    Science and Technology

    IT, Defence and Space

  • BSF Border Security Infrastructure in Gujarat

    Why in the news?

    Amit Shah inaugurated the G-7 and G-13 Border Out Posts (BOPs) in Bhuj, Gujarat, and highlighted plans to strengthen border security through advanced technology and CISF-style security grids.

    Key Highlights

    • New BOPs inaugurated along the India-Pakistan border in Gujarat
    • Focus on:
      • Technological fencing
      • Smart border security
      • Territorial security concept
      • Leak-proof security grid

    About BSF (Border Security Force):

    • India’s “First Line of Defence”
    • Comes under the Ministry of Home Affairs
    • Guards borders with Pakistan and Bangladesh
    • Operates in extreme conditions from:
      • Desert regions
      • Marshlands
      • Forests
      • High-altitude areas

    Strategic Areas

    Sir Creek

    • The marshy disputed region between India and Pakistan
    • Security-sensitive coastal area

    Harami Nala

    • Creek area near Sir Creek
    • Vulnerable to infiltration and smuggling

    [2023] Which one of the following is the best example of repeated falls in sea level, giving rise to present-day extensive marshland?

    [A] Bhitarkanika Mangroves

    [B] Marakkanam Salt Pans

    [C] Naupada Swamp

    [D] Rann of Kutch

  • CISF Oversight for Fishing Harbours

    Why in News?

    The Ministry of Home Affairs plans to bring fishing harbours and landing centres under the security oversight of the Central Industrial Security Force (CISF) to strengthen coastal security.

    Key Highlights

    • Around 1,200 fishing harbours and landing sites to come under CISF supervision.
    • India has:
      • 1,547 notified fish landing centres and fishing harbours
      • Spread across 13 coastal States and Union Territories
    • CISF will:
      • Design security protocols
      • Guide local administration
      • Develop uniform security architecture

    Why is this Important?

    Because of large India’s coastline:

    • Extends about 7,516 km
    • Involves multiple agencies:
      • Local police
      • Indian Coast Guard
      • Indian Navy

    Lessons from 26/11 Mumbai Attacks

    • Terrorists entered Mumbai through the sea route after hijacking a fishing vessel, exposing vulnerabilities in coastal surveillance.

    About the Central Industrial Security Force

    • The Central Industrial Security Force (CISF) is a premier paramilitary organization under India’s Ministry of Home Affairs.
    • Established in 1969, it safeguards the nation’s critical industrial and infrastructure assets—including airports, seaports, power plants, and major public sector undertakings—playing a central role in India’s internal security architecture.

    [2025] With reference to the Government of India, consider the following information:
    Organization Some of its functions It works under
    I.Directorate of EnforcementEnforcement of the Fugitive Economic Offenders Act, 2018Internal Security Division- I, Ministry of Home Affairs
    II.Directorate of Revenue IntelligenceEnforces the Provisions of the Customs Act, 1962Department of Revenue, Ministry of Finance
    III.Directorate General of Systems and Data ManagementCarrying out big data analytics to assist tax officers for better policy and nabbing tax evadersDepartment of Revenue, Ministry of Finance
    In how many of the above rows is the information correctly matched?

    [A] Only one

    [B] Only two

    [C] All the three

    [D] None

  • How safe is India’s critical national infrastructure

    Why in the News?

    India’s critical infrastructure security has come into focus amid rising concerns over cyber threats targeting IoT-enabled systems used in energy, transport, communications and industrial networks. Recently, there were warnings from India’s National Cyber Security Coordinator that highlight that traditional cyber defences are no longer adequate against increasingly sophisticated attacks on critical systems.

    What Constitutes Critical Infrastructure in India?

    Critical Information Infrastructure (CII): Systems whose incapacitation can severely impact national security, economy, public health or safety.

    Major Sectors

    1. Energy: Power grids, oil and gas networks.
    2. Transport: Railways, airports, ports and highways.
    3. Telecommunications: Internet backbone and communication networks.
    4. Banking & Finance: Payment systems and financial infrastructure.
    5. Healthcare: Hospital networks and medical databases.
    6. Strategic Systems: Defence, satellites and emergency services

    Why has digital transformation increased vulnerabilities in critical infrastructure?

    1. Digital Integration: Connects traditionally isolated infrastructure systems with internet-enabled networks, increasing exposure to cyber risks. Earlier, local control systems operated independently; today they function through networked environments.
    2. Automation Expansion: Enables predictive maintenance, remote monitoring and optimisation across power plants, chemical industries, transport systems and refineries. Greater connectivity, however, increases the possibility of remote compromise.
    3. IoT Proliferation: Expands attack surfaces through connected devices such as cameras, GPS systems, industrial controllers, water-level sensors and smart monitors that continuously exchange data.
    4. Systemic Dependence: Creates cascading risks because disruption in one sector may trigger failures across supply chains, communication networks and essential services.
    5. National Security Exposure: Converts technical vulnerabilities into strategic risks as attacks on infrastructure can disrupt economic stability and public order.

    How has the convergence of IT, OT and IoT transformed security risks?

    1. Information Technology (IT): Processes and stores digital data through servers, cloud systems and computational networks.
    2. Operational Technology (OT): Controls physical systems such as industrial machinery, transport systems and manufacturing plants.
    3. IoT Connectivity: Integrates physical infrastructure with digital control systems using sensors, controllers and automated devices.
    4. Control Vulnerability: Allows compromised IoT systems to manipulate physical operations. Breached devices may alter industrial controls or operational parameters.
    5. Invisible Threats: Creates hidden security risks through malicious firmware, embedded control pathways or hardware-level vulnerabilities.
    6. Trojan Risks: Enables insertion of concealed vulnerabilities that remain dormant but can later disrupt systems or facilitate surveillance.

    Why are conventional cybersecurity measures insufficient for critical infrastructure?

    1. Limited Scope: Cybersecurity measures such as server protection, anti-virus systems and breach prevention primarily secure digital layers but may not protect embedded physical systems.
    2. Physical-Digital Interdependence: Requires security frameworks that protect not only software but also hardware, sensors and communication pathways.
    3. Critical Infrastructure Sensitivity: Demands higher scrutiny because disruption may directly affect public safety and strategic operations.
    4. Procurement Gaps: Weak tender conditions often fail to prioritise trusted products or deep security evaluation.
    5. Compliance Weakness: Eligibility assessments frequently focus on paperwork rather than hardware authenticity, origin verification and operational vulnerability.
    6. Institutional Enforcement Deficit: Existing IT and IoT guidelines remain inadequately enforced for national-level infrastructure.

    Examples 

    1. SCADA Systems: Earlier local process control systems managed industrial operations through Supervisory Control and Data Acquisition systems; today many are internet-connected.
    2. CERT-In: Strengthens cyber response capacity through incident monitoring and emergency response protocols but does not fully secure infrastructure hardware.

    How do procurement and certification weaknesses create national security risks?

    1. Trusted Procurement Deficit: Allows deployment of imported systems without rigorous security verification.
    2. Security Evaluation Gaps: Weak scrutiny of design origin, manufacturing authenticity and operational vulnerabilities increases risk of embedded backdoors.
    3. Certification Challenges: Existing testing procedures remain lengthy and unevenly enforced across infrastructure sectors.
    4. Imported Device Risk: Raises concern over GPS-enabled electronic locks and communication systems manufactured abroad but deployed in sensitive supply chains.
    5. False Certification Concerns: Creates risks when imported products receive domestic certification despite unresolved security questions.

    Example 

    1. STQC Certification: Recent certification of cameras by Standardisation Testing and Quality Certification (STQC) ensures devices do not perform unintended control or data-sharing functions. However, certification remains time-consuming and inconsistently applied across IoT devices.

    Why is fuel transportation emerging as a major infrastructure vulnerability?

    1. Fuel Supply Digitisation: Integrates tankers with GPS tracking, digital monitoring and IoT-enabled electronic locking systems.
    2. Operational Dependence: Makes petroleum logistics increasingly dependent on remote communication technologies.
    3. Remote Disruption Risk: Creates vulnerability if vehicle tracking systems or e-locks are imported, compromised or improperly certified.
    4. Supply Chain Exposure: Enables interference with fuel distribution systems, affecting energy security and economic continuity.

    Example 

    1. Petroleum Tankers: Earlier protected through seals, locks and keys; now increasingly dependent on IoT-based keyless systems and GPS-enabled monitoring.
    2. Recent U.S. Case: A cyberattack on fuel storage systems reported by CNN demonstrates how attacks on energy systems can disrupt supply chains.

    How can India strengthen critical infrastructure resilience?

    1. Trusted Technology Ecosystem: Prioritises secure and trusted domestic technologies for sensitive sectors.
    2. Certification Enforcement: Ensures rigorous security testing for IoT devices deployed in national infrastructure.
    3. Supply Chain Security: Strengthens scrutiny of hardware origin, firmware integrity and manufacturing authenticity.
    4. Cyber-Physical Security Framework: Integrates IT, OT and IoT protection rather than treating cybersecurity as a software issue alone.
    5. Awareness Generation: Encourages industrial users, utilities and government agencies to recognise cyber risks in connected systems.
    6. Continuous Vigilance: Supports real-time monitoring and regular security audits of infrastructure networks.

    Conclusion

    India’s critical infrastructure is undergoing rapid digital transformation through automation, IoT and AI, improving efficiency and service delivery across sectors. However, increasing interconnection between digital and physical systems has also expanded vulnerabilities to cyberattacks, supply-chain risks and remote disruptions. In an era of connected systems, infrastructure resilience has become inseparable from national security and economic stability.

    PYQ Relevance

    [UPSC 2022] What are the different elements of cyber security? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy.

    Linkage: The PYQ tests understanding of cyber security architecture, vulnerabilities and institutional preparedness in India’s digital ecosystem. The article expands the cyber security debate beyond data protection to critical infrastructure protection.