India has no updated national cybersecurity policy since 2013, no accountable cyber regulatory body, no consequences for security auditors who certify poor cybersecurity systems, and companies don’t lose anything if they deny a breach. These are some of the problems in India’s cybersecurity ecosystem that we identified after speaking to several experts.

Here are the ten problems they have highlighted:

  1. CERT-In answers to nobody, so anything it fixes is a favour rather than an accountable duty

Every interviewee, without prompting, raised the accountability concerns of Cert-In as an organisation, which is India’s designated national cybersecurity agency, and there is no mechanism in law that requires it to act on what it receives or answer for what it ignores.

“Just like how no regulator is accountable in India, the cyber regulator is also not accountable in India. So it’s not a problem specific to cybersecurity. Usually, abroad, you will see regulators are held accountable by parliamentary committees and things like that. In India, that structure is only present on paper.” – Srikanth L, Cashless Consumer

“CERT-In does not actually have teeth to say that, ‘you have not acted upon this, so you need to shut down’, or ‘we will basically make this vulnerability public and make the public aware.’ CERT-In basically says that, ‘okay, somebody gave us this thing’, and asks ‘can you fix it if it’s possible?’ But, CERT-In is under no legal obligation to go beyond.” – Srikanth L

Kiran Jonnalagadda, co-founder of HasGeek, draws the same conclusion from his long-standing experience of dealing with CERT-In, and frames it as the difference between a service and a privilege.

“Everything with CERT-In is like it’s a privilege. If they feel like it, they will do something. If you cannot hold them responsible for delivering the service, then it’s not a service. It’s a privilege… Anything that works in CERT-In is a lucky accident because there is no requirement for any of it to work in their setup.” – Kiran Jonnalagadda

Independent security researcher Karan Saini, who has spent years reporting vulnerabilities to government agencies, has arrived at the harshest position of the three.

“I don’t know why CERT-In exists, really…. In a recent piece I wrote,  I was initially going  to suggest  it be closed. I was going to say, let’s shut down CERT-In and have another existing institution assume its responsibilities.” – Karan Saini

What can be done: Jonnalagadda’s prescription is statutory. “Go get an Act of Parliament passed that makes Cert accountable for services… It should be like RTI, that they have to act or there are consequences for not acting on it.” He argues there are only two workable models such as being answerable to Parliament or to public. He cites the US CERT Coordination Center, which comes under the Carnegie Mellon University outside…


Source link

Disclaimer

We strive to uphold the highest ethical standards in all of our reporting and coverage. We blogs.grocliq.com want to be transparent with our readers about any potential conflicts of interest that may arise in our work. It’s possible that some of the investors we feature may have connections to other businesses, including competitors or companies we write about. However, we want to assure our readers that this will not have any impact on the integrity or impartiality of our reporting. We are committed to delivering accurate, unbiased news and information to our audience, and we will continue to uphold our ethics and principles in all of our work. Thank you for your trust and support.

Website Upgradation is going on for any glitch kindly connect at [email protected]

 

 

Categorized in:

Blog,

Last Update: July 17, 2026