Cybersecurity 2026

INDIA Law and Practice Contributed by: Anoop Narayanan, Priyanka Gupta and Harshita Sakarya, ANA Law Group

works, requiring co-ordinated incident response, reporting and risk management processes. 1.3 Cybersecurity Regulators Cybersecurity regulation and enforcement in India is administered through a multi-agency framework, comprising central government authorities, sectoral regulators and law enforcement bodies. The CERT-In established under the IT Act and oper - ating under the MeitY, serves as the national nodal agency for cybersecurity incident response affecting non-critical information infrastructure. Its mandate includes: • issuing advisories, guidelines and directions relat - ing to information security practices, procedures, prevention, response and reporting of cyber inci - dents; • collecting, analysing and disseminating information on cyber threats; • co-ordinating incident response; • requiring mandatory reporting of specified cyber incidents within prescribed timelines; • to call for information, conduct audits, seek logs and technical data; • co-ordinate with domestic and international agen - cies; and • such other functions relating to cybersecurity as may be prescribed. The NCIIPC, designated under the IT Act, is respon - sible for protecting CII. It operates under the National Technical Research Organisation (NTRO) and focuses on sectors whose disruption could have a debilitating impact on national security, public health or economic stability, such as power, banking, telecommunica - tions, transport and government services. NCIIPC is authorised to issue sector-specific cyberse - curity guidelines, conduct risk assessments, mandate protective measures, and co-ordinate with sectoral entities on preparedness and incident response. The National Cyber Coordination Centre (NCCC) func - tions as a situational awareness and co-ordination body, which supports real-time monitoring of cyber threats and inter-agency information sharing. It plays

a central role in threat intelligence aggregation and inter-agency co-ordination. Law enforcement oversight is exercised through the Indian Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs (MHA), which supports investigation, co-ordination and capacity-building for cybercrime enforcement across states and union terri - tories. Police authorities derive investigative and pros - ecutorial powers under the IT Act and the Bharatiya Nyaya Sanhita, 2023, enabling search, seizure, arrest and prosecution in cases involving cyber offences. In addition to central authorities, sectoral regula - tors impose cybersecurity obligations and exercise supervisory and enforcement powers within their respective domains. These include the Reserve Bank of India (banking and payments), the Securities and Exchange Board of India (capital markets), the Insur - ance Regulatory and Development Authority of India (insurance), the Central Electricity Authority (CEA) and the Department of Telecommunications (telecoms services). Such regulators issue advisories, binding cybersecurity frameworks, conduct inspections and audits, mandate incident reporting, and may impose penalties or supervisory actions for non-compliance. Cybersecurity enforcement also intersects with data protection oversight. Under the DPDPA, the DPBI has powers to inquire into personal data breaches, direct remedial measures and impose monetary penalties. Further, in case a cybersecurity incident results in per - sonal data compromise, organisations may be subject to parallel scrutiny by CERT-In and the DPBI. Overall, India’s cybersecurity governance relies on centralised technical co-ordination through CERT- In and NCIIPC, supported by law enforcement and sectoral regulators, with national and sectoral cyber incident response teams operating within this frame - work to ensure preparedness, detection, response and enforcement across the digital ecosystem.

195 CHAMBERS.COM

Powered by