Information Technology Act, 2000

IT Act and Cybersecurity: CERT-In, Section 70B and the 2022 Directions

Topic 7 introduced CERT-In, the State's interception and blocking powers, and critical information infrastructure as part of the IT Act's enforcement scheme. This note takes the national view of cybersecurity: the threats India faces, the institutions that respond to them, the layers of law that apply, the specific duties the law places on companies and regulated sectors, and the response to the wave of cyber fraud that led the Supreme Court to order a nationwide CBI investigation in 2025.

1. Locks, Alarms and the Fire Brigade

A safe city needs three things: householders who lock their doors, alarms that go off when someone breaks in, and a fire brigade and police that respond quickly. Cybersecurity law works the same way. Section 43A and sector rules make organisations lock their doors; CERT-In's reporting directions are the alarm system; and CERT-In, NCIIPC, the police and the courts are the responders. A gap in any one of the three leaves the city exposed.

2. The Threat Landscape

Principal cyber threats

Figure 1: Principal cyber threats

  • Scale. As more of the economy and government moves online, the attack surface grows. The ransomware attack on AIIMS, New Delhi in 2022, which disrupted hospital services for days, showed that public institutions are prime targets.
  • Fraud as the mass threat. For ordinary citizens the most common threat is fraud: phishing, fake investment schemes, and 'digital arrest' scams in which callers pose as police or judges to extort money.

3. Institutions

The institutional architecture of cybersecurity

Figure 2: The institutional architecture of cybersecurity

  • National Cyber Security Coordinator. Located in the National Security Council Secretariat, coordinates cybersecurity across government.
  • CERT-In (s.70B). The Indian Computer Emergency Response Team, under MeitY, operating since 2004 and given statutory status in 2008 as the national agency for incident response.
  • NCIIPC (s.70A). The National Critical Information Infrastructure Protection Centre, under the National Technical Research Organisation, designated in 2014 to protect critical information infrastructure.
  • I4C. The Indian Cyber Crime Coordination Centre under the Ministry of Home Affairs coordinates the response to cybercrime, and runs the National Cybercrime Reporting Portal and the 1930 helpline.
  • Sectoral bodies. The RBI, SEBI, IRDAI and the Department of Telecommunications set sector-specific security requirements, supported by sectoral CERTs.
  • Policy. The National Cyber Security Policy, 2013 set the goal of a secure cyberspace ecosystem; a new national strategy has been under preparation.

4. The Legal Layers

Where cybersecurity law is found

Figure 3: Where cybersecurity law is found

  • Definition (s.2(1)(nb)). Cyber security means protecting information, equipment, devices, computers, computer resources, communication devices and stored information from unauthorised access, use, disclosure, disruption, modification or destruction.
  • CERT-In's powers (s.70B). It collects, analyses and disseminates information on cyber incidents, issues forecasts and alerts, takes emergency measures, coordinates response, and issues guidelines and advisories. It may call for information from service providers, intermediaries, data centres, bodies corporate and others, and give directions (s.70B(6)); non-compliance is an offence (s.70B(7))
  • Critical infrastructure (ss.70 and 70A). Protected systems, access only by authorised persons, security practices under the 2018 Rules, and up to ten years' imprisonment for unauthorised access (see Topic 7)
  • Deterrence. Civil liability under Section 43, offences under Section 66, cyber terrorism under Section 66F, and the protected system offence under Section 70(3)

5. The CERT-In Directions of 28 April 2022

  • Who is bound. Service providers, intermediaries, data centres, bodies corporate and government organisations.
  • Six-hour reporting. Listed cyber incidents must be reported to CERT-In within six hours of being noticed. The list includes targeted scanning, compromise of critical systems, unauthorised access, website defacement, malicious code such as ransomware, identity theft, phishing, denial of service attacks, data breaches and leaks, and attacks on payment systems, cloud services and social media accounts.
  • Logs. Logs of all ICT systems must be kept securely for 180 days within India and provided to CERT-In on request.
  • Clock synchronisation. System clocks must be synchronised with the national time servers so that events can be correlated.
  • VPN, cloud and data centre providers. Must register and retain accurate subscriber information, including names, addresses, IP addresses and purpose of use, for five years.
  • Point of contact. Every entity must designate a point of contact to liaise with CERT-In.
  • Criticism. The six-hour window and the VPN data retention requirement were criticised as onerous and privacy-intrusive, and some VPN providers withdrew their servers from India.

6. Duties of Companies and Regulated Sectors

What the law requires of organisations

Figure 4: What the law requires of organisations

  • Reasonable security practices (s.43A). A body corporate handling sensitive personal data must maintain reasonable security practices, such as ISO/IEC 27001, or pay compensation for losses caused by its negligence.
  • DPDP Act (from May 2027). Every Data Fiduciary must take reasonable security safeguards to prevent personal data breaches (s.8(5)) and must notify the Data Protection Board and each affected person of a breach (s.8(6)), with the DPDP Rules, 2025 requiring a detailed report to the Board within 72 hours. Failure to take safeguards attracts a penalty of up to ₹250 crore.
  • Banking. The RBI's Cyber Security Framework for banks (2016) requires a board-approved cyber security policy, a security operations centre and reporting of incidents to the RBI.
  • Securities. SEBI's Cybersecurity and Cyber Resilience Framework (2024) sets graded requirements for regulated entities.
  • Insurance and telecom. IRDAI's information and cyber security guidelines (2023) and the Telecommunications (Telecom Cyber Security) Rules, 2024 under the Telecommunications Act, 2023.
  • Protected systems. Organisations running protected systems must follow the 2018 Rules, including appointing a Chief Information Security Officer.

7. The Response to Cybercrime

📖 In Re: Digital Arrest Scams (Supreme Court, suo motu, 2025)

Background: In October 2025 the Supreme Court took suo motu cognizance after a senior citizen couple lost about ₹1.5 crore to fraudsters who posed as investigators and displayed forged court orders on video calls. Losses across the country were estimated at around ₹3,000 crore.

Directions: On 1 December 2025 the Court directed the CBI to investigate digital arrest scams across India, including the role of bank officials, asked States to consent to CBI jurisdiction, asked the RBI to consider AI and machine learning tools to detect suspicious accounts, asked telecom authorities to prevent misuse of SIM cards, and required intermediaries to cooperate under the IT Rules, 2021.

Significance: Cyber fraud is treated as a national problem requiring coordinated action by police, banks, telecom providers and platforms, not merely scattered local FIRs.

  • Reporting. Victims should report immediately to the 1930 helpline or the National Cybercrime Reporting Portal, which allows funds to be frozen quickly.
  • Investigation. Offences under the IT Act are investigated by an officer not below the rank of Inspector (s.78), with evidence proved under Section 63 BSA.
  • Civil remedy. Compensation against banks or companies whose negligence enabled the loss may be claimed under Sections 43 and 43A before the adjudicating officer.

Milestones in India's cybersecurity framework

Figure 5: Milestones in India's cybersecurity framework

⚠ Exam trap

Keep the agencies distinct: CERT-In (MeitY, s.70B) responds to incidents on any system; NCIIPC (NTRO, s.70A) protects critical information infrastructure; I4C (MHA) coordinates the policing of cybercrime. And remember that the six-hour reporting duty comes from CERT-In's Directions under Section 70B(6), not from the text of the Act itself.

8. Quick Revision and Memory Aids

  • 'Locks, alarms, fire brigade'. Security duties, reporting, response.
  • 'Six hours, 180 days, five years'. CERT-In Directions of 2022.
  • 'CERT-In responds, NCIIPC protects, I4C polices'. The three agencies.
  • '43A now, DPDP 8(5) from 2027'. Corporate security duty.
  • 'RBI 2016, IRDAI 2023, SEBI 2024'. Sector frameworks.
  • '1930 first'. What a fraud victim should do.

9. Frequently Asked Questions

What is the role of CERT-In under the IT Act?

Under Section 70B, CERT-In is the national agency for incident response. It collects and analyses information on cyber incidents, issues alerts and guidelines, takes emergency measures and coordinates response, and may call for information and issue directions, non-compliance with which is an offence.

10. Related Topics

  • Topic 7: Enforcement under the IT Act. CERT-In, CII and state powers in outline.
  • Topic 20: IT Act and Artificial Intelligence. New technology, new risks.