Whatsapp 88106-52225 For Details
Get Free IAS Booklet
Get Free IAS Booklet
CYBER SECURITY
• The digital revolution has speed up the emergence of a global digital space. This Digital Space, the “Cyberspace”, is the communication space made of network infrastructure (such as servers and cables), devices (like computers and smartphones), software (both human-machine and machine-to-machine interfaces) and data carried over the network.
• Further, the convergence of various forms of media— television, social, and online networks have doubled the impact of the revolution and acted as instruments of information that replicate the threat to law and order as well as security.
• It has forced people, governments and organizations, both public and private, to rethink strategies on how they manage their information engage in an increasingly interconnected world, and produce an entirely new ecosystem of information exchange.
• Media of the current world system, particularly Press, Electronic and TV Media use cyberspace and digital technology plays an important role in nation building and public engagement.
• Likewise, Social networking sites such as Facebook, Twitter and Instagram are examples of cyberspace where people can connect and communicate with each other regardless of their physical location.
Key Terms related to Cyber Security
• Internet is the abbreviation of internetwork system.
• Internet may be defined as a network of networks that are interconnected physically, capable of communicating and sharing data with each other and able to act together as single networks.
• Cyberspace refers to the virtual computer world, and more specifically, an electronic medium that is used to facilitate online communication.
• Cyberspace provides major opportunities for innovation, economic progress, cultural development and access to information. While its quick development has proved hugely useful for many human activities, it also brings new threats.
Cyber Security is the practice of defending computers, servers, mobile devices, electronic systems, networks, and data from malicious attacks.
Cyber security means securing the cyberspace from attack, damage, and misuse. It pertains to protecting Internet-connected systems and networks from digital attacks:
To access, alter, or sabotage sensitive information.
To extort money
To interrupt normal business processes.
Internet Security is a central aspect of cybersecurity, and it includes managing cyber threats and risks associated with the Internet, web browsers, web apps, websites and networks.
Cyber Warfare: Cyberwarfare is the use of cyber attacks against an enemy state, causing comparable harm to actual warfare and/or disrupting vital computer systems. Some intended outcomes could be espionage, sabotage, propaganda, manipulation or economic warfare.
Network Security refers to the strategies, protocols, and measures implemented to safeguard a computer network and its resources from unauthorized access, misuse, alteration, or disruption. It involves prevention, detection, and continuous monitoring to ensure protection.
Firewall: In computing, a firewall is a security mechanism that regulates incoming and outgoing network traffic based on predefined security rules. It serves as a protective barrier between a trusted network and an untrusted one, such as the Internet, to prevent potential threats.
Encryption is the process of encoding information into an alternative form to ensure that only authorized parties can decipher and access the original information, a cryptographic key.
Cyber Security
Computer Security, Cyber Security, Digital Security or Information Technology (IT) Security is the protection of computer systems and networks from attacks by malicious actors that may result in unauthorized information disclosure, theft of, or damage to hardware, software, or data, as well as from the disruption or misdirection of the services they provide.
Digital Security is a broader term encompassing protection of online identity data assets through tools like software, Web Services, biometrics, firewalls, proxies, vulnerability scanner, instant message or telephone encryption tools etc. against cyber-attacks, unauthorised access, online malicious activities etc.
• The 3 Key Pillars of Digital Security are:
• Confidentiality
• Integrity
• Availability
Cybercrime
• Cybercrime is a criminal activity that either targets or uses a computer, a computer network or a networked device to commit an offense.
Cybercrimes fall under State List as per the Seventh Schedule of the Constitution of India.
• Increasing vulnerability: Interpol’s ‘Global Trend Summary Report’ 2022 indicated that some of the cybercrime trends such as ransomware, phishing, online scams, online child sexual abuse, and hacking are posing serious threats across the globe.
• New and dangerous practices are developing in cyberspace: cybercrime, information manipulation, political or economic espionage, attacks on critical infrastructure or individuals, theft of personal information or confidential data, compromise of information and communications systems used by citizens, companies and agencies. These attacks can come from State or non- State groups that respect no borders.
CYBERCRIMES ARE OF 4 TYPES
• Crime Against Individuals: Cybercrimes committed against individual persons include such types of crimes like transmission of Child Pornography, Harassment of any one with the use of a computer such as e-mail, Cyber Defamation, Hacking, Indecent exposure,
E-mail spoofing, IRC Crime (Internet Relay Chat), Net Extortion, Malicious code, Trafficking, Distribution, Posting, Phishing, Credit Card Fraud and Dissemination
of obscene material including Software Piracy.
• Crime Against Property: These crimes include computer vandalism (obliteration of others’ property), Intellectual Property Crimes, Threatening, Salami Attacks, Data Breach, hacking of data of institutions.
• Crime Against Organisation/State: Cyberterrorism against government entities to jeopardise security and safety of cyber entities.
• Other Types of Cybercrimes: There are several other types of cyber crime which includes, crime in metaverse (metaverse gangrape case), and cases like bulli bai and
sulli deals.
Security Threats and Communication Networks
Natural threats like floods, earthquakes, tsunami, volcanic activities etc. can disrupt the communication networks and all utility services dependent on such a network like power, water supply etc.
Terrorist activities (Non-State Actors):
• Recruitment and Radicalization: Extremist groups have used social media platforms to recruit and radicalize individuals, leading to acts of terrorism and violence. For example, Al-Qaeda utilized the internet to communicate with supporters and even to recruit new members.
• Disinformation Campaigns: Non-state actors have spread false information and propaganda online to manipulate public opinion, sow discord, and undermine democratic processes such as fake videos going viral during the ongoing 2023 Israel-Hamas conflict.
• Cyberattacks: Some non-state actors have carried out cyberattacks on critical infrastructure, businesses, and governments, causing disruptions and financial losses. For example, Pakistani Cyber Army is a group of hackers who regularly deface websites of, particularly Indian, Chinese, and Israeli companies and governmental organizations.
• Online Fundraising: Terrorist organisations have exploited online platforms to solicit funds for their activities, making it challenging to track and block their financing such as by al-Qassam Brigades, Hamas’s military wing, al-Qaeda, and Islamic State
of Iraq and the Levant (“ISIS”).
• Data Exploitation: Non-state actors have stolen and exploited personal data for various malicious purposes, including identity theft and harassment.
• For instance, the Islamic State of Iraq and Syria (ISIS) and Lashkar-e-Taiba are known to have developed their own secure communication applications for smartphones.
State actors: Utilise cybercrimes to destabilise a nation state.
• Potential targets include critical infrastructure such as financial services, governments and utilities.
• In September 2023, Russian hacktivists launched DDoS attacks against Czech banks to cut online banking access to the banks’ clients and demanded that the institutions stop supporting Ukraine.
• In August 2023, Chinese hackers targeted a U.S. military
procurement system for reconnaissance.
• In April 2023, Iranian state-linked hackers targeted critical infrastructure in the U.S. and other countries in a series of attacks using a previously unseen customized dropper malware.
Figure: Ransomware Attacks by Industry
Terms Related to Cyber Attacks
• In today’s digital world, cybersecurity is no longer a luxury - it’s a necessity. India has quickly become one of the fastest-growing technology hubs in the world, but with that comes an increased risk of cyber threats.
Phishing: Phishing is the act of attempting to acquire information, such as usernames, passwords and credit card details (and sometimes, indirectly, money) by masquerading as a trustworthy entity in an electronic communication. Phishing is typically carried out by email spoofing or instant messaging.
Vishing (Voice Phishing): When phishing is done with the help of telephonic system, it is called vishing.
Tab nabbing: It takes advantage of tabbed browsing (which uses multiple open tabs) that a user uses and silently redirects the user to the affected site.
Whaling: Phishing attacks directed specifically at senior executives and other high profile targets within businesses.
Between 2013 and 2015, Evaldas Rimasauskas impersonated a Taiwanese hardware supplier, Quanta computer, whose services were used by two tech giants, Google and Facebook. He sent out fake invoices worth $122 million for almost three years.
Ransomware: All the information/data of the computer is hacked and the hacker demands certain amount of money in exchange for access to your own data.
If ransom is not paid, then the data is deleted forever. e.g., Petya virus, WannaCry virus.
Spoofing: One person or program successfully masquerades as another by falsifying data and thereby gaining an illegitimate advantage. The purpose of this is usually to fool programmes, systems or users into revealing confidential information, such as user names and passwords, to the attacker.
•
Zombies: A zombie is a computer connected to the internet that has been compromised by a hacker, computer virus or trojan horse. It can be used to perform malicious tasks under remote direction. Most owners of zombie computers are unaware that their system is being used in this way.
• Botnets: Botnets sometimes compromise computers whose security defences have been breached and control conceded to a third party. Each such compromised device, known as a ‘bot’, is created when a computer is penetrated by software from a malware (malicious software) distribution.
• Pharming: It is an attack to redirect a website’s traffic to a different, fake website, where the individual’s information is then compromised.
• Drive-by: Opportunistic attacks against specific
weaknesses within a system.
• Man in the Middle Attack: It is an attack where a middleman impersonates each endpoint and is thus able to manipulate both victims.
• Bluebugging: Hacking of Bluetooth enabled devices.
• Zero Day Vulnerability: Any flaw or loophole existing in the cyber network or software which the developer is still unaware of and can be exploited by the cyber criminals.
• Critical Infrastructure (CI): Section 70 of the IT Act, 2000 defines Critical Information Infrastructure (CII) as computer resources whose disruption or incapacitation would severely impact national security, the economy, public health, or safety.
CII is declared by the Central Government under Section 70- recently Census and National Population Register databased, ICICI & HDFC Banks, NPCI’s IT resources were declared as critical infrastructure by the government.
Types of Security Threats
• An internal threat occurs when individuals with access to an organization’s systems, facilities, or sensitive information exploit vulnerabilities to compromise security, services, products, or operations with the intent to cause harm. Insider betrayals cause losses due to IT sabotage, fraud and theft of confidential or proprietary information. This may be intentional or due to ignorance.
• External threat arises from outside of the organisation, by individuals, hackers, organisations, terrorists, foreign government agents, non-state actors, and pose risk, like crippling CII, espionage, cyber/electronic warfare, cyber terrorism, etc.
• Natural threats: like earthquake, tsunami etc.
• Accidental or Technical Threats: transportation accidents, grid failure.
India and Cyber security
• India being placed 17 out of 20 by MIT Review CyberDefence Index 2022-23. India continues to be on the top of the agenda of nation-state actors when it comes to cyber-attacks.
•
India has been positioned as the 7th most breached country in the world during the second quarter of 2023 according to cybersecurity firm Surfshark.
• India has ranked 10th in Global Cybersecurity Index (GCI) 2020 by ITU (International Telecommunication Union) by moving up 37 places.
Figure: State of Indian Cybersecurity
• It is measured along five pillars - (i) Organizational Measures, (ii) Legal Measures, (iii) Technical Measures,
(iv) Cooperation, and (v) Capacity Development.
• According to the latest report by Microsoft, India accounts for 13 percent of cyber-attacks in the Asia- Pacific (APAC) region, making it one of the top-three most attacked countries by nation-state actors.
• Ransomware Report 2022 by CERT-In reported that ransomware incidents have gone up 53% in 2022 over 2021.
•
Lockbit was the most prevalent ransomware variant in India, followed by Makop and DJVU/Stop ransomware. New variants such as Vice Society and BlueSky were noticed in 2022.
• Makop and Phobos Ransomware families mainly targeted medium and small organisations, while Djvu/Stop variants used for attacks on individuals.
• The IBM Security Data Breach Report of 2022 states that,
for the fiscal year of 2022, the average data breach costs in India have reached a record high of 17.5 crores ($175 million) rupees, or around $2.2 million, which is an increase of 6.6% from 2021, and a staggering 25% rise from 2020.
• India witnessed highest number of cyber-attacks after Japan in Asia-Pacific region (2020) as per a report by IBM X-Force Intelligence Index.
• As per the NPCI, UPI payment crossed more than 20 billion transactions worth over 24.85 Lakh Crore by August 2025Examples of Cybercrime Incidents
• Recently, AIIMS & Safdarjung Hospitals in New Delhi have been victims of Ransomware attack as a result of which millions of medical records have been compromised.
• In India, cyber-attacks have been occurring with increasing frequency. For example, leak of personal information of 3.2 million debit cards in 2016 and the Data Theft At Zomato (2017), WannaCry Ransomware
(2017), PETYA Ransomware (2017) etc.
• In May 2021, the national airline Air India reported a cyber-attack in which the data of 4.5 million of its customers across the world, was compromised.
• In October 2019, there was an attempted cyber-attack on the Kudankulam Nuclear power plant.
• In 2020, the cyber security attack on Australia’s communication system has brought the governance to a standstill.
• The rate at which cybercrimes are rising, $8 trillion will be lost to cyber-crimes by the end of 2023, which is almost a third of the GDP of the United States in 2022 and twice as much as India’s projected GDP this year.
• GPS spoofing of flights reported at major airports including Delhi, Mumbai, Chennai in December 2025
Challenges of Cybersecurity
Figure: Challenges in the Cyberspace
•
Distinction between military and civilian targets is increasingly blurred and civilians are becoming increasingly vulnerable targets.
• Lack of Awareness and Training: Many organisations and individuals in India are not aware and most of the cyber-attacks are not reported. This lack of awareness can lead to poor cyber security practices, which makes organisations and individuals more vulnerable to cyber- attacks.
• Shortage of Skilled Cyber Security Professionals: It is difficult for organisations to find the skilled staff. India has a negligible base of cyber-security specialists, when compared to internet user base (second largest).
• Lack of Coordination: The government and private sector need to work together to implement the National Cyber Security Policy 2013 effectively.
• Constantly Evolving Threats: Cyber security threats are constantly evolving, which makes it difficult to keep up with the latest trends and developments. This makes it challenging to implement effective cyber security measures.
• Limited Budget: Many organisations have limited budgets for cyber security. This can make it difficult for them to implement the necessary cyber security measures.
• Global Frameworks: India is not a signatory to Convention of Cybercrime of the Council of Europe (Budapest Convention).
Measures Taken by the Government
• India’s digital landscape has witnessed tremendous growth, with over 80 crore Indians (Digital Nagriks) actively utilizing the Internet and cyberspace, making it one of the largest connected nations in the world. Citizens are increasingly relying on the Internet to cater to their daily requirements, including aspects such as business, education, finance, and availing digital government services.
• Initiatives for ‘digital delivery of services’ have transformed India into a ‘Digital Nation’ within a decade. India has been at the forefront of adopting emerging technologies at the grassroots level.
• Today 840 million Indians have an online presence, and by 2025 another 400 million Indians will enter the digital world.
• India leads in global digital payments with 90 million transactions in 2022.
• 46% of global digital payments are done in India.
• Pradhan Mantri Jan-Dhan Yojana has led to 500 million new bank accounts being opened.
• Direct Benefit Transfer (DBT) from ‘Jan Dhan- Aadhaar-Mobile’ (JAM).
• .38 billion Aadhaar - digital identities have been generated.
• DigiLocker stores around 6 billion documents.
• Under BharatNet, 600,000 kilometers of Optical Fiber Cable (OFC) has been laid.
• UMANG App - Unified Mobile Application for
New Age Governance with 53 million Registrations.
• Central government has issued an advisory that certain medical devices such as Oximeter, Pacemaker, Hearing Aids, etc. may act as path for ransomware attacks.
Policy Measures for Cybersecurity
• Recognising the significance of a secure and trustworthy digital environment, the Government of India has formulated policies aimed at ensuring safe & trusted and secure cyber space for its users.
• Policy Framework
Figure: PM Vision for Digital India
• The National Cyber Security Policy of 2013 emphasizes the development of strong Public-Private Partnerships and collaborative efforts through technical and operational cooperation to strengthen cybersecurity.
• It outlines a vision and mission focused on creating a secure and resilient cyberspace for individuals, businesses, and the government.
• Enabling goals aimed at reducing national vulnerability to cyber-attacks, preventing cyber- attacks & cyber-crimes, minimising response & recover time and effective cyber-crime investigation and prosecution.
• Focused actions at the level of government, public- private partnership arrangements, cyber security related technology actions, protection of critical information infrastructure and national alerts and advice mechanism, awareness & capacity building and promoting information sharing and cooperation.
• Enhancing cooperation and coordination between all the stakeholder entities within the country.
•
Framework and initiatives that can be pursued at the Govt. level, sectoral levels as well as in public private partnership mode.
• Facilitating monitoring key trends at the national level such as trends in cyber security compliance, cyber-attacks, cyber-crime and cyber infrastructure growth.
• Draft National Cyber Security Strategy 2021 (NCSS2021). The main components of this strategy cover:
• Large Scale digitization of public services
• Supply Chain security
• Critical Information Infrastructure Protection
• Digital Payments
• State Level Cyber Security
• Security of Small and Medium Businesses
• National Cyber Security Reference Framework (NCRF) 2023:
• This framework policy has been formulated for selected seven sectors as critical sectors namely telecom, power and energy, banking and financial services, transportation, strategic enterprises, government enterprises and healthcare, to provide a “strategic guidance” to address cyber security concerns, amid growing incidents of malware attacks.
• For example, recent malware attacks on Oil India, a group in Nagpur, and an attack on a Tata Power plant.
• Cyber Crisis Management Plan for Countering Cyber Attacks and Cyber Terrorism:
• A cyber crisis management plan is a comprehensive approach to identifying, responding to and recovering from cybersecurity incidents, which outlines the steps taken to minimise the damage while preventing further incidents and restoring normal operations.
• Guidelines on Information Security Practices for Government Entities by CERT-In for a Safe & Trusted Internet.
• They also include all government institutions, public sector enterprises, and other government agencies under their administrative purview.
• These guidelines are a roadmap for the Government
entities and industry to reduce cyber risk, protect
citizen data and continue to improve the cyber security ecosystem in the country.
• They will serve as a fundamental document for audit teams, including internal, external, and third-party auditors, to assess an organisation’s security posture against the specified cybersecurity requirements.
• The guidelines include various security domains such
as network security, identity and access management, application security, data security, third-party outsourcing, hardening procedures, security monitoring, incident management, and security auditing.
Legislative Framework for Cybersecurity in India
• In 2021, the Supreme Court of India ruled that cyber- attacks and data thefts are a crime under the Information Technology Act (IT Act) of 200 and the Indian Penal Code (IPC).
Figure: Provisions under IT Act, 2000
• Transparent Use of personal data;
• The principle of Purpose Limitation (use of personal data only for the purpose specified at the time of obtaining consent of the Data Principal);
The principle of Data Minimisation (coll
• Information Technology Act 2000 (Amended in 2008)
• While India does not have an exclusive, unitary cybersecurity law, it uses the IT Act and multiple other sector-specific regulations to promote cybersecurity standards. It also provides a legal framework for critical information infrastructure in India. Some of its important provisions are:
• Section 43: Applicable to people who damage computer systems without permission from the owner.
• Section 43A: Indian businesses and organisations must have “reasonable security practices and procedures” to protect sensitive information from being compromised, damaged, exposed, or misused.
• Section 66: Applicable in case a person is found to dishonestly or fraudulently committing any act referred to in section 43.
• Section 66B: Incorporate the punishments for fraudulently receiving stolen communication devices
or computers.
• Section 66C: Scrutinizes the identity thefts related to imposter digital signatures, hacking passwords or other distinctive identification features.
• Section 66D: Punishes cheaters doing impersonation using computer resources.
• Section 66E: punishes capturing, transmitting or publishing private parts of any human being without consent.
• Section 66F: punishes cyberterrorism with life imprisonment.
• Section 69: authorizes the Indian government to expeditiously intercept, monitor, decrypt, block, and remove data and content at its discretion
• Section 72A: any intermediaries or persons that disclose personal data without the owner’s consent (with ill intention and causing damages) are punishable by imprisonment of up to three years, a fine of up to Rs500,000, or both.
• The Information Technology (Information Security Practices and Procedures for Protected System) Rules, 2018
• It spells out the institutional requirements for organisations, particularly the government, to establish an Information Security Steering Committee (ISSC) as well as appointment of Chief Information Security Officer (CISO).
• It entails the organisations to plan and improve the Information Security Management System (ISMS) as well as to establish a Cyber Crisis Management Plan.
• Further, liaison role of NCIIPC between itself and the government agencies like CERT-In for sharing threat information.
• Information Technology (Guidelines for Intermediaries and Digital Media Ethics Code) Rules, 2021
• Require intermediaries to implement reasonable security practices and procedures to secure their computer resources and information, maintaining safe harbour protections. Intermediaries are also mandated to report cybersecurity incidents to the CERT-In.
• Indian Penal Code 1860/Bharatiya Nyaya Sanhita (BNS)-2023: The sections of the IPC that covers cyber frauds are:
• Forgery (IPC Section 464 (BNS 335))
• Forgery pre-planned for cheating (IPC Section 468 (BNS 336 (3))
• False documentation (IPC Section 465 (BNS 336))
• Presenting a forged document as genuine (IPC Section 471 (BNS 340))
• Reputation damage (IPC Section 469 (BNS 336))
Companies Act, 2013
• Under this Act, the regulatory compliances are covered, including cyber forensics, e-discovery, and cybersecurity diligence.
• The Companies (Management and Administration) Rules, 2014 prescribes strict guidelines confirming the cybersecurity obligations and responsibilities upon the company directors and leaders.
Digital Personal Data Protection Act, 2023
• Act provides for the processing of digital personal data in a manner that recognizes both the rights of the individuals to protect their personal data and the need to process such personal data for lawful purposes and for matters connected therewith or incidental thereto.
The Act is based on the following seven principles:
• The principle of Consented, Lawful a ection of only as much personal data as is necessary to serve the specified purpose);
• The principle of Data Accuracy (ensuring data is correct and updated);
• The principle of Storage Limitation (storing data only till it is needed for the specified purpose);
• The principle of Reasonable Security Safeguards; and
• The principle of Accountability (through adjudication of data breaches and breaches of the provisions of the Bill and imposition of penalties for the breaches).
The Act provides for following Rights to the Individuals:
• The Right to Access information about personal data processed;
• The Right to Correction and Erasure of data;
• The Right to Grievance Redressal; and
• The Right to Nominate a person to exercise rights in case of death or incapacity.
The Act provides the following obligations for Data Fiduciary:
• To have security safeguards to prevent personal data breach;
•
To intimate personal data breaches to the affected Data Principal and the Data Protection Board;
• To erase personal data when it is no longer needed for the specified purpose;
• To erase personal data upon withdrawal of consent;
• To have in place grievance redressal system and an officer to respond to queries from Data Principals; and
• To fulfill certain additional obligations in respect of Data Fiduciaries notified as Significant Data Fiduciaries, such as appointing a data auditor and conducting periodic Data Protection Impact Assessment to ensure higher degree of data protection.
• Proposed Digital India Act, 2023
• The DIA, poised to replace the two-decade-old Information Technology Act of 2000 (IT Act), is designed to address the challenges and opportunities presented by the dramatic growth of the internet and emerging technologies.
• The new law should evolve through rules that can be updated, and address the tenets of Digital India
• Open Internet
• Online Safety and Trust
• Accountability and Quality of Service
• Adjudicatory mechanism
• New Technologies
• Urgent need for a specialized and dedicated adjudicatory mechanism for online civil and criminal offences. The adjudicatory mechanism should
• Be easily accessible.
• Deliver timely remedies to citizens.
• Resolve cyber disputes.
• Develop a unified cyber jurisprudence.
• Enforce the rule of law online.
Figure: Aspects of Digital India Act, 2023
• Objectives:
• to bring India’s regulatory landscape in sync with the digital revolution of the 21st century.
• Tackle emergence of various intermediaries and the proliferation of new forms of user harm, such as cyberstalking, trolling, and doxing.
• Key provisions
• Whole-of-Government Response for a unified, coordinated, efficient and responsive governance architecture including an effective appropriate government structure, a dedicated inquiry agency and a specialised Dispute resolution/ adjudication framework.
• It upholds the concept of an ‘Open Internet’, striking a balance between accessibility and necessary regulations to maintain order and protect users. An Open Internet should have
• Choice;
• Competition;
• Online diversity
• Fair market access, and
• Ease of Doing Business and Ease of Compliance for Startups
• Age-gating by regulating addictive tech and protect minors’ data, safety and privacy of children on social media platforms, gaming and betting apps; Mandatory ‘do not track’ requirement to avoid children as data subjects for ad targeting, etc.
• Stringent Know Your Customer (KYC) requirements for wearable devices, accompanied by criminal law sanctions.
•
Guidelines for Responsible Utilization of new technologies like AI, to not only encourage the adoption but also to ensure their ethical deployment along with striking a balance between fostering innovation and safeguarding against potential harms.
Definition and Regulation of hi-risk AI systems through legal, institutional quality testing framework to examine regulatory models, algorithmic accountability, Zero-Day (i.e., previously unknown vulnerability) Threat & Vulnerability Assessment, examine AI based ad-targeting, content moderation etc.
• May need to update provisions in the Competition Act, 2002.
• Review of “Safe Harbour” Principle, which presently shields online platforms from liability related to user-generated content, indicating a potential shift in online accountability standards. These provisions underscore the proposed DIA’s commitment in addressing the complexities of the digital age.
• Protecting Digital User Rights including Right to be forgotten,Right to secured electronic means,Right to redressal,Right to digital inheritance, Right against discrimination, Rights against automated decision making, etc.
• Discretionary moderation of Fake News by social media platforms should be critically examined and regulated under the Constitutional Rights Of Freedom Of Speech & Expression.
Figure: Types of Intermediaries
• Promotion of Digital Governance, ease access to government & other public utility services, delivery of public services through online and mobile platforms in a simple, accessible, interoperable and citizen friendly manner.
• Fair Trade Practices, prevention of concentration of market power and gatekeeping, distortions through regulation of dominant Ad-tech platforms, App stores etc., promoting start-up India via non-discriminatory access to digital services and interoperable platforms.
• Safeguard innovation to enable emerging technologies like AI/ML, Web 3.0, Autonomous systems/ Robotics, IoT/ Distributed Ledger/ Blockchain, Quantum Computing, Virtual Reality/ Augmented Reality, Real-time language translators, Natural-language processing, etc.
• Adjudicating User Harm against revenge porn, Cyber-Flashing (i.e. sending obscene pictures to strangers online, often done through Bluetooth or AirDrop transfers between devices), dark web, women and children, defamation, cyber-bullying, Doxing (i.e. online harassment by publicly exposing someone’s real name, address, job, or other identifying info without a victim’s consent), Salami Slicing (i.e. the crime of stealing a large amount of money, by taking it over a period of time in small amounts that are less likely to be noticed), etc.
• Content Monetisation Rules for platform-generated and user-generated content.
• DisclosureNorms fordata collected byData Intermediaries, collecting data above a certain threshold.
• Standards for ownership of anonymized personal data collected by Data Intermediaries.
• Concerns about the Act
• Potential impact on innovation and the ease of doing business.
• Stricter regulations, particularly in emerging technologies, could inadvertently stifle entrepreneurial initiatives and deter foreign investments.
• Additionally, the review of the “safe harbour” principle, which shields online platforms from liability for user- generated content, could lead to a more cautious approach among these platforms, possibly impinging on freedom of expression.
CONCLUSION
• DIA’s success hinges on effective enforcement, which will require substantial resources, expertise, and infrastructure.
•
Balancing the interests of various stakeholders, including tech giants, while ensuring the protection of citizen rights, poses a significant challenge.
• Therefore, while the DIA is a progressive move, its implementation and potential repercussions warrant vigilant monitoring and adaptability to avoid unintended consequences.
Institutional Framework for Cyber Security
• “Indian Computer Emergency Response Team (CERT- In)” has been established and appointed as national agency under Ministry of Electronics and Information Technology (MeITY) in respect of cyber incidents and cyber security incidents in terms of the provisions of section 70B of Information Technology (IT) Act, 2000 (IT Act, 2000) to perform the following functions in the area of cyber security: -
• Collection, analysis and dissemination of information on cyber incidents;
• Forecast and alerts of cyber security incidents;
• Emergency measures for handling cyber security incidents;
• Coordination of cyber incidents response activities;
• Issue guidelines, advisories, vulnerability notes and whitepapers relating to information security practices, procedures, prevention, response and reporting of cyber incidents;
• Such other functions relating to cyber security as may be prescribed.
• Indian Cyber Crime Coordination Centre (I4C) under Home Ministry of Home Affairs (MHA). It is designated as the nodal point in the fight against cybercrime.
• ‘Joint Cyber Coordination Teams’ have been constituted for seven regions at Mewat, Jamtara, Ahmedabad, Hyderabad, Chandigarh, Vishakhapatnam and Guwahati under the I4C to address the issue of jurisdictional complexity, based upon cyber-crime hotspots/ areas, by on-boarding all the States/UTs to provide a robust coordination framework to the LEAs.
• National Cyber Coordination Centre (NCCC):
• It was set up in 2013 under Ministry of Electronic and Information Technology (MeITY) to generate necessary situational awareness of existing and potential cyber security threats.
• National Cybersecurity Coordinator (NCSC):
• It is another office under the National Security Council Secretariat (NSCS).
• NCSC formulates the National Cyber Security Strategy.
• Security Monitoring Centre (SMC) at the National Informatics Centre (NIC)
• For detecting and responding to security incidents related to NIC infrastructure and data centres.
• Periodic security audits and vulnerability assessment
of resources are performed for enhancing data security.
• National Cyber Crime (NCC) reporting portal . cybercrime.gov.in)
• To enable public to report incidents pertaining to all types of cybercrimes.
• It has a special focus on crimes against women and children.
•
National Critical Information Infrastructure Protection Center (NCIIPC) 2014
• It has been established under National Technical Research Organisation (NTRO) under the Prime Minister’s Office (PMO).
• It provides near real time threat intelligence and situation awareness.
• Based on which regular alerts and advisories are sent to Critical Information Infrastructure (CII) or Protected System Entities (PSE) to avert cyber- attacks.
Figure: Actions for Cyber Security
ReBIT, founded in 2016 by Reserve Bank of India to conduct deep audits which have increased the baseline capacity of the banking sector.
International Dimensions on Cyber Security
PM Narendra Modi has said that “Cyber security is no longer confined to the digital world only. It has become a subject of national security – global security”.
• G-20 conference on “Crime and Security in the Age of the Non–Fungible Token (NFT), Artificial Intelligence (AI) and Metaverse”.
• A global initiative towards coordinated action to make the digital world safer for all. Minister of Home Affairs,
stated that “The transformation of our security challenges from ‘Dynamite to Metaverse’ and ‘Hawala to Crypto currency’ is a matter of concern for the countries of the world. And all of us, together, have to devise a common strategy against it.” The conference concluded with the following key takeaways:
• Countering ICT Threats: Emphasized the importance of preventing the use of ICTs by state and non-state actors for terrorist purposes.
• Need for open, secure, and peaceful ICT environment, protecting individuals, especially women and children, from online exploitation.
• The importance of countering advanced persistent threats and establishing comprehensive international conventions on ICT crimes was also emphasized.
• International Cooperation on Cybercrimes: Need for international cooperation, sharing of information, and mutual legal assistance to combat cybercrime effectively.
• AI Governance: Transparent and accountable governance frameworks for AI were also discussed
• Role of Private Sector: Identifying partnerships between industry and organisations as an essential tool for ensuring secure technology development and deployment, the participating experts recommended capacity building, public-private partnerships, awareness, and education as crucial in addressing the gaps in cyber resilience and security.
• Budapest Convention on Cybercrime, 2001
• Budapest Convention on Cybercrime was the first international treaty addressing computer related criminal activities, wanted to harmonize the national laws, to improve the investigation techniques and to promote the cooperation between different nations. Japan, South Africa etc. also joined it, except India.
• Adopted by the Council of Europe. It aims to pursue a common criminal policy. It provides for the:
• Criminalisation of conduct, ranging from illegal access, data and systems interference to computer- related fraud and child pornography
• Procedural law tools to make investigation of cybercrime and securing of e-evidence in relation to any crime more effective.
• International police and judicial cooperation on cybercrime and e-evidence.
• Global Centre for Cybersecurity
• It is an autonomous organisation under the World Economic Forum (WEF).
• The Centre for Cybersecurity provides an independent and impartial platform to reinforce the importance of cybersecurity as a strategic priority and drive global public-private action to address systemic cybersecurity challenges.
• It aims is to establish a global platform for governments, businesses, experts and law enforcement agencies to collaborate on cybersecurity challenges and work towards an appropriate and agile regulatory framework on cybersecurity.
• Global Conference on CyberSpace | The London Process
• The London Process is a series of multistakeholder meetings held biennially since 2011 under the name Global Conference on Cyberspace or GCCS.
• It is an international event focusing on the issue of cyber space with an emphasis on the nature of threats and challenges faced by the larger cyber environment.
• India hosted the Global Conference on Cyberspace in 2017.
•
‘Commonwealth Cyber Declaration’ at the Commonwealth Summit 2018
• The Commonwealth countries at the end of Commonwealth Heads of Government Meeting (CHOGM) in London have adopted Commonwealth Cyber Declaration to take action on cybersecurity by 2020.
• It recognised the potential for a free, open, inclusive and secure cyberspace to promote economic growth for all communities and help to achieve the Sustainable Development Goals across the Commonwealth.
• Paris Call for Trust and Security in Cyberspace
• The Paris Call was sent in 2018 by the President of the French Republic, Emmanuel Macron, during the Internet Governance Forum held at UNESCO and the Paris Peace Forum.
• It is based around nine common principles to secure cyberspace, which act as as many areas for discussion and action.
• Protect individuals and infrastructure.
• Protect the Internet.
• Defend electoral processes.
• Defend intellectual property.
• Non-proliferation: on malicious software.
• Lifecycle security: Strengthen the security of digital processes, products and services, throughout their lifecycle and supply chain.
• Cyber hygiene.
• No private hack back: prevent non-State from hacking-back, for their own purposes or those of other non-State actors.
• International norms: confidence-building measures in cyberspace.
Recent Initiatives
• 2nd Edition of the National Cyber Security Exercise 2023 ‘Bharat NCX 2023’ will be conducted as a hybrid exercise to train senior management and technical personnel of Government/Critical Sector organizations and Public and Private agencies on contemporary cyber threats and handling cyber incidents and response. The program is being conducted by the National Security Council Secretariat (NSCS), Govt. of India in strategic partnership with Rashtriya Raksha University (RRU).
• A toll-free number 1930 has been operationalized to get assistance in lodging online cyber complaints.
• The Citizen Financial Cyber Fraud Reporting and Management System module has also been launched for immediate reporting of financial frauds and to stop siphoning off fund by the fraudsters.
• ‘Cyber Swachhta Kendra’ (Botnet Cleaning and Malware Analysis Centre) is being operated by the government. It helps in detection of malicious programs and provides free tools to remove the same.
• Cyber Crime Prevention against Women & Children (CCPWC) scheme: Ministry of Home Affairs has provided financial assistance to all the States & UTs to support their efforts for setting up of cyber forensic- cum-training laboratories, training, and hiring of junior cyber consultants.
• Computer Security Incident Response Team- Finance Sector (CSIRT-Fin) operations under its umbrella to respond to, contain and mitigate cyber security incidents reported from the financial sector.
• Cyber forensic-cum-training laboratories have been commissioned in 28 States.
• CyberDome Project: It is a public-private partnership initiative that aims to combat cybercrime and protect Kerala’s critical infrastructure. It includes capacity building of law enforcement agencies, cyber forensics labs, dedicated team for incident reporting, collaborations with national and international cybersecurity agencies. It will help tackle cybercrime through a proactive model of policing as well as spreading awareness.
• CERT-In, Reserve Bank of India (RBI) and Digital India jointly carry out a Cyber Security Awareness Campaign on ‘beware and be aware of financial frauds’ through Digital India Platform.
• Operation Chakra by CBI against cyber enabled crime networks.
• KAVACH-2023- is a national hackathon to identify innovative ideas.
• Exercise Synergy by CERT-in.
• Cyber Surakshit Bharat (CSB) by MeitY to spread awareness about cyber-crime.
• The CISO council will be a beacon of cyber security in Telangana. It is the best example of Public-Private Partnership (PPP) model that we often talk about. Cyber security breaches are multiplying and will grow by leaps and bounds when the next billion internet users start going digital. The enterprises are also going to be at risk.
Justice B.N. Srikrishna Committee Recommendations
• The Justice B. N. Srikrishna Committee Report on ‘A Free and Fair Digital Economy’ (2018) outlined key principles for regulating personal data and the digital economy.
• Fiduciary relationship: requires that service providers handling personal data must act fairly and use the data only for authorized purposes.
• Fiduciaries have certain obligations, including processing data in a fair and reasonable manner and informing individuals at the time of data collection and at various stages thereafter.
• The report defined personal data as any information that can directly or indirectly identify an individual. It
also differentiated between personal data and sensitive personal data, the latter involving intimate aspects where a higher expectation of privacy exists, such as caste, religion, or sexual orientation.
• The Committee emphasized that consent must be a fundamental requirement for processing personal data.
• Exceptions: The Committee outlined four scenarios where personal data can be processed without consent:
When necessary for the state to fulfill its welfare responsibilities.
To adhere to legal requirements or comply with court orders in India.
In urgent situations requiring immediate action, such as saving a life.
Under specific conditions in employment contracts, particularly when obtaining consent would place an unreasonable burden on the employer.
• Participation Rights: The rights of the individual are based on the principles of autonomy, self-determination, transparency and accountability to give individuals control over their data.
• The right to access, confirmation and correction of data.
• The right to object to data processing, automated decision-making, direct marketing and the right to data portability.
• The right to be forgotten.
• Enforcement models: The Committee also recommended setting up a regulator to enforce the regulatory framework.
• Consolidated Framework: various allied laws are relevant in the context of data protection because they either require or authorise the processing of personal data e.g., Information Technology Act, 2000, the Census Act, 1948, Aadhaar Act, 2016 etc.
Way Forward
• User Education: Promote digital literacy and critical thinking skills among internet users to help them identify and resist online manipulation and radicalization.
• Cybersecurity Measures: Strengthen cybersecurity infrastructure to protect critical systems and data from cyberattacks. This includes regular security audits, updates, and employee training.
• Regulation and Oversight: Regular audits of platforms’ content moderation practices.
• Financial Monitoring: Enhance monitoring of online financial transactions to detect and prevent the financing of subversive activities.
• Transparency and Accountability: Social media platforms should be transparent about their algorithms and content moderation policies.
• Introducing Effective Reporting Mechanisms, such as hotlines for internal security threats.
• Whistleblower Protections: Establish mechanisms to protect whistleblowers who provide information about subversive activities online. Encourage individuals to report suspicious online content.
• Counter-Narratives: Promote counter-narratives that challenge extremist ideologies and propaganda. Engage community leaders, civil society organisations, and religious institutions in countering radicalization efforts.
• Research & Development: Encourage technology companies to develop tools and algorithms that can automatically detect and remove harmful content while respecting privacy and free speech rights.
• Capacity building and skill development:
• India needs upskilling and cross skilling in the emerging technologies like cybersecurity stack across adaptive security, Cloud Security Posture
Management (CSPM), Zero Trust Architecture (ZTA) (i.e. continuous verification of every digital interaction stage via real-time information from multiple sources), quantum cryptography, Network Virtualisation Functions (NVF), network and Data Sandboxes (i.e. a tool that allows you to test your network and data in a safe environment without affecting the actual network and data), leverage of Security-On-A-Chip like Intel SGX extensions.
• International Cooperation Agreements: Advocate for international agreements that address the global nature of online threats, setting norms and rules for responsible behavior in cyberspace.
• India-Israel Cybersecurity Agreement 2020
• India-Japan Cybersecurity Agreement 2020
• India-AustraliaCybersecurity and Critical Technology Partnership 2020
• India-Russia Cybersecurity Agreement 2016
• India-US Cybersecurity Agreement 2011
• Adapting International Best Practices:
• Tallinn Manual of US, which identifies international law principles applicable to cyber warfare and enumerates ninety-five “black-letter rules” governing such conflicts.
• The General Data Protection Regulation (GDPR) is a European Union regulation on information privacy in the European Union and the European Economic Area. The GDPR is an important component of EU privacy law and human rights law, in particular Article 8 of the Charter of Fundamental Rights of the European Union.
CONCLUSION
Amid regular reports of government and large private sector systems falling prey to serious cyberattacks and data breaches, the DIA must be accompanied by a strong triad of laws safeguarding privacy, data protection and cybersecurity.
• The last must lead to data sharing frameworks between institutions, voluntary reporting of vulnerabilities, bigger budgets, and a large cadre of cybersecurity professionals.
• Amidst ongoing Industrial Revolution 4.0, India requires a strong cybersecurity framework based on the 4D principles i.e., Deter, Detect, Destroy and Document so that it can subverse all attempts towards any cyber challenges.
Media
• “The media is sometimes referred to as the fourth estate,” according to Ikram Sehgal, “as the fourth pillar in support of the vital tripod of the government, the executive, the legislative, and the judiciary.
• Media of today has successfully pushed further the process of increased globalization and has summarised foreign policy and international relations to a compact world structure that has become dependent on information as a major resource for building a secure global environment.
• As Malcolm X, an African American Human Rights Activist, has said-The media been the most powerful entity on earth. They have the power to make the innocent guilty and to make the guilty innocent, and that’s power, because they control the minds of the masses.
Role of Media
• Media of today plays multiple roles in its capacity through public and private means through individual and organisational efforts to impact the individual citizen, family, community, state and the nation at large and the globe on the whole.
• Various roles Media can be as below:
• Important role in Nation building and public engagement.
• Key Source of Information to the State and the global system and encompasses the potential to influence and change the global structure, both positively and negatively. For instance, it was misused during the 26/11 attacks, when terrorists used the ground news reporting for carrying out the attack.
• Even for a country’s national security, the media plays a vital role in securing and promoting the interests that help safeguard the people and the institutions.
Role in informing the people and validating the acts of the government on issues of national security, which further elucidates the relationship between media and its function in preserving national security.
However, recent growth of the “New Media Phenomenon” is a concern where conventional media (mainly television) is increasingly relying on social media to feed its 24-hour news cycles and picking content and coverage led by social media trends.
For example, recent 2023 Hamas attack on Israel led to unverified reporting by the media news channels about the targeted killing of children by Hamas. This created a warlike explosive situation and global condemnation. It later came out to be unconfirmed and bogus.
Building Public Opinion:
For instance, Indian Air Force shot down a Pakistan Navy Breguet Atlantique patrol plane in August 1999 after which Pakistan took India to
the International Court of Justice.
Support that the Indian media showed for its nation and the timely information that it disseminated to local and foreign audiences helped not only the Indian population but also the foreign media understand the reality on the ground, which in turn affected the ICJ’s ruling.
Figure: Role of Media in Internal Security
• Help in Tackling Non-Traditional threats: Tackling such threats require the cooperation and collaboration of security forces with organisations that are State or Non-State like media, for support and expertise to diminish and eradicate the threat either completely or to a minimum level.
Challenges In Internal Security Due to Media
• Sensationalizing Coverage: Unfortunately, our present Indian Journalism is plagued by sensationalism and wrong reporting.
Rather than making people aware of the on goings around the world, it focuses on presenting an
exaggerated, distorted and perverted version of the most absurd, non-issues and insignificant events, sidelining real issues. This is what is known as “Yellow Journalism”.
• In 2017, sensationalisation of the death of the student of National Law University, Jodhpur. They created a whole issue out of it calling it a “selfie death” whereas in reality, it was a mere accident and an unfortunate event. Such irresponsible news reporting not only disgusts the viewers, but also aggrieves the already in- grief family.
• This is a clear example of how the media has crossed its boundaries to the extent of victimizing and being judgmental of the youth today.
• Indian TV anchors discussing national security issues do not have the political and strategic maturity to discuss national security issues.
• The other major defect of the media is twisting of facts. Media often twists facts to make it look more controversial and interesting.
• Fake News:
• The cut throat competition, especially in case of electronic media, has resulted in priority to exclusivity of coverage over authenticity of the news itself. This manifests in a lack of culture of fact-checking, resulting in dissemination of fake news, often having internal security implications.
• FIR was registered against anchor Sudhir Chaudhary for “conspiring to disrupt communal harmony” in a TV News show where he talked about the state government’s commercial vehicle subsidy scheme, allegedly claiming that subsidies were being provided only for minorities in Karnataka and not for Hindus claiming that the scheme meted injustice to poor Hindus in the state.
• Media and Politics:
• Media is often driven by politics and often targets issues which serves as an agenda for political parties in a meticulously well planned manner in the garb of so called “News”.
• For instance, Republic News was co-founded and owned by Mr. Rajiv Chandrashekhar, who is currently an independent member of Rajya Sabha but has links with the Bharatiya Janata Party (BJP). The channel has been accused of being biased towards BJP and violating the code of ethics of journalism.
• Media Trials:
• Media trials influence the outcome of a case jeopardising justice delivery. For example, 2008 Aarushi Talwar- Hemraj double murder case gained extensive media coverage shaped public opinion and influenced the investigation and subsequent court proceedings.
• Media trials can also violate the rights of the accused. For instance, the media coverage of the Nirbhaya
case 2012 was criticized for portraying the accused in a negative light and for influencing public opinion before the trial.
The media coverage of the Sushant Singh Rajput case 2020 led to several conspiracy theories being propagated, which diverted attention from the actual investigation.
• Revealing Sensitive Information:
• Supreme Court, after 26/11, slammed the TV channels for live coverage of the 26/11 Mumbai terror attack which put nation’s security in jeopardy.
• Recently concerns over striking a balance between the right to information and the right to privacy have been raised, especially, by controversies like the Radia-tapes or revealing name of rape victim in Hathras Case.
• The Puttaswamy Judgment of 2017 established the Right to Privacy as a Fundamental Right under Article 21 of the Constitution. In the case of Rajgopal
v. State of Tamil Nadu, the Supreme Court stated that every citizen has the fundamental right to protect their privacy, including matters related to personal life, family, marriage, procreation, motherhood, childbirth, and education. No one is permitted to publish information regarding these aspects without the individual’s consent. However, media outlets often do not adhere to this principle.
• Flaming Communal Tensions:
• SC had to intervene to impose a pre-telecast ban on a programme “UPSCJihad”, partially aired on a news channel.
• News Broadcasters and Digital Association (NBDSA) had earlier imposed a fine on TV18 news anchor Aman Chopra for two of his programmes.
• Paid News:
• In 2003, many companies, such as Videocon India, Kinetic Motors, and Pantaloons bought space in Times of India in exchange for shares in their companies.
• Erode Public Trust:
• When the media reports on national security issues in a sensationalized or biased way, it can erode public trust in the government’s ability to protect the country.
Regulations and Restrictions on Media Reporting in India
• In the case of Romesh Thapar v. State of Madras, the Supreme Court of India held that the right to freedom of speech and expression under Article 19(1) (a) of the Constitution encompasses the right to disseminate information. However, this freedom is not absolute and is subject to reasonable restrictions under Article 19(2) based on considerations such as the sovereignty and integrity of the nation, state security, public order, morality or decency, contempt of court, defamation, and incitement to commit an offense.
• Civil Defence Act, 1968 – It allows the Government to make rules for the prohibition of printing and
publication of any book, newspaper or other document damaging to the civil defence of the country and its people. It defines civil defence as any measure, not amounting to actual combat, that protects persons, property and places in India from hostile attack or during disasters.
• Press Council of India Act, 1978: It is a statutory body, responsible for preserving the freedom of the press, maintaining and improving the standards of newspapers and news agencies, etc. Its powers include conducting inquiries into complaints, inter alia, against newspapers or news agencies for offending the standards of journalistic ethics or professional misconduct by editors or journalists.
• National Security Act of 1980 provides power to the Central Government to make rules on the following-
• The publication of any newspaper, book, or document containing content that could be detrimental to India's defense, civil defense, public safety, maintenance of public order, efficient execution of military operations, or the continuity of essential supplies and services necessary for the community's well-being may be prohibited.
• Additionally, authorities may require security deposits from any press found violating these regulations and may even order the closure of such establishments if necessary.
• The Prasar Bharati (Broadcasting Corporation of India) Act, 1990 setups up Prasar Bharti to be the Broadcasting Regulator in India to stablish a system for news, radio and television in India.
• The Act directs that Prasar Bharti should uphold the integrity and unity of India and boost national integration by disseminating programmes in regional languages.
• Pursuant to this, a Broadcast Code was adopted to govern All India Radio, which has also been normatively followed by broadcast organisations. This code prohibits
• Criticism of friendly countries.
• Attack on religions or communities.
• Anything obscene or defamatory.
• Incitementto violence or anythingagainst maintenance of law and o rder.
• Anything amounting to contempt of court.
• Hostile criticism of any state or the centre.
• Anything showing disrespect to the Constitution or advocating change in the Constitution by violence.
• News Broadcasters & Digital Association (NBDA): It is the collective voice of the news, current affairs and digital broadcasters in India. NBDSA administers the Codes of Ethics & Broadcasting Standards, which has been voluntarily drawn up to demonstrate their commitment to responsible broadcasting.
• The Indian Broadcasting Foundation has also released
‘Self-Regulatory Content Guidelines for Non-News and
Current Affairs Television Channels’, after the critical broadcasting of the Mumbai terror attacks in 2008 that brought in media experts and journalists to review the coverage and revise the content of the Indian media.
• Central Media Accreditation Guidelines 2022 (the CMA Guidelines) stipulate the eligibility conditions for accreditation of working journalists. They also provide for withdrawal of accreditation on broad grounds, such as if a journalist acts in a manner prejudicial to the country’s security, sovereignty and integrity, friendly relations with foreign states, or public order, or if he or she is charged with a serious cognisable offence.
Way Forward
• Law Commission 200th Report 2006 Recommendations
• To prohibit the publication of anything that is prejudicial to the reputation if accused- a restriction which shall from the mine of the arrest.
• The starting point of a criminal case should not be from the filing of the charge sheet but from the time of arrest of an accused. The perception behind such an amendment is that it would prevent prejudicing or prejudging the case.
• To address the damaging effect on the administration of justice of the sensationalised news reports.
• The High Court is empowered to direct the postponement of the telecast or the publication in criminal cases and to prevent the media from restoring to such a telecast or publication.
• Striking a Balance between National Security and Freedom of Speech: This challenge has been acknowledged across the world as well when the Johannesburg Principles on national security, freedom of expression and access to information were adopted by a group of international legal experts in 1995.
• State must set out clear laws that are understandable,
accessible, and specific to ensure media is compliant with national security concerns. There must be safeguards in place against abuse of the law, such as judicial scrutiny.
• Restrictions must genuinely be for the purpose of protecting national security, and must have the demonstrable effect of protecting that aim.
• Restrictions must be necessary, meaning the restricted expression is a serious threat to national security and limiting the expression is the least restrictive way of addressing this threat.
• Madrid Principles on the Relationship Between the Media and Judicial Independence: It is the job of the media to “convey information to the public and to comment on the administration of justice, including cases before, during and after trial, without violating the presumption of innocence.”
Way Forward
Role of Social Media
Utility of Social Media
• Communication: Social media allows people to connect and communicate with friends, family, and others from all over the world.
• Information sharing: Social media is a valuable source of information on a wide range of topics, including news, current events, and research.
• Transparency: Social media can be used to promote transparency and accountability in government.
• Service delivery: Social media can be used to deliver services to citizens, such as scheduling appointments, paying bills, and reporting problems.
• Crisis communication: Social media can be used to communicate with citizens during emergencies and crises.
• Education: Social media can be used to learn new things and connect with experts in different fields.
Figure: Resposible Media to protect National Security
• Business: Social media can be used to promote businesses, connect with customers, and generate sales.
• Social activism: Social media can be used to raise awareness about important issues and organize social movements.
Figure: Types of Social Media
• Digital India programme has now become a movement which is empowering common Indians with the power of technology. The extensive spread of mobile phones, Internet etc. has also enabled many social media platforms to expand their footprints in India.
• The enormous amount of data provided and shared on these social networks may include the following data about a user: personal details, current address, hometown, email addresses, messenger usernames, activities, interests, favourite sports, groups, favorite athletes, favorite music, television shows, games, languages, his religious views, political views, inspirations, favorite quotations, service users history, education history, relationship status, family members, and software applications.
• The users likewise give update as status information or Tweets, which could include: an idea, a demonstration, a link they need to contribute a video. This d This data admits a considerable information about the user, which will hold interest to many different groups.
Challenges from Social Media
• There are widespread concerns around social media:
• Misuse of Social Media like trolling and abuse on Twitter.
• Lack of transparency and accountability from digital platforms.
• Violation of Rights of Users of digital media platforms like breach of privacy on social media.
• Inducement for recruitment of terrorists, spread of disharmony, financial frauds, incitement of violence, public order etc.
• Criminals, Anti-National Elements have brought new challenges for law enforcement agencies.
• Threat to Dignity of Women: to share morphed images of women and contents related to revenge porn have often threatened the dignity of women.
Of abusive language, defamatory and obscene contents and blatant disrespect to religious sentiments through platforms are growing.
•
Content regulation in case of online publishers including Over The Top (OTT) platforms like Netflix and news portals.
• Organised use of Social Media and other online content generation platforms is engineering the opinion and perspective of the masses.
Social Media and Threat to Internal Security
• Spread Of Misinformation and Disinformation: Social media platforms have been used to spread fake news and disinformation on a wide range of topics, including politics, public health, and climate change. This can have a negative impact on democracy, social cohesion, and public safety. For instance, Fake News on WhatsApp, Facebook etc. Few examples:
• In April 2023, a mob attack on a Muslim man in Uttar Pradesh was allegedly triggered by fake news and disinformation spread on social media.
• During the 2023 Manipur violence, fake news regarding assault of a Metei woman triggered massive violence.
• Radicalization Of Individuals: Extremist groups use social media to recruit and radicalize individuals, both online and offline. This can lead to violence and terrorism.
• Exploitation of Children: Social media platforms have been used to exploit and abuse children. This includes online grooming, sextortion, and child sexual abuse material.
Prevalence of child pornography and content depicting sexual violence such as on Twitter, Tiktok, etc.
• Cybercrime: Social media platforms can be used to commit a variety of cybercrimes, such as phishing, identity theft, and fraud.
It has a potential for disrupting public order, either involuntarily through the unchecked spread of rumors, or deliberately through the propagation of misinformation with the intent of creating enmity between groups.
Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021
Figure: Evolution of IT Rules
• The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, were established under Section 87(2) of the Information Technology Act, 2000, replacing the previous 2011 guidelines.
• The objective is to implement a balanced and minimal intervention framework for overseeing social media platforms, digital media, and OTT services while ensuring transparency, accountability, and the protection of user rights.
• The Ministry of Electronics and Information Technology is responsible for administering Part II of these rules, while the Ministry of Information and Broadcasting oversees Part III, which pertains to the Code of Ethics and procedural safeguards for digital media.
KEY FEATURES
Figure: Key Features of IT Act, 2000
• Self-Regulation: Fine blend of liberal touch with gentle self-regulatory framework.
• Levels the Field: It works on the existing laws and statues of the country which are applicable to content whether online or offline.
• Due Diligence To Be Followed By Intermediaries: The Rules prescribe due diligence that must be followed by intermediaries, including social media intermediaries. In
case, due diligence is not followed by the intermediary, safe harbour provisions will not apply to them. These include-
• Service agreements must outline the types of content
that users are prohibited from uploading or sharing.
• Content must be removed within 36 hours upon receiving a directive from the court or government authorities.
• Intermediaries are required to assist law enforcement
agencies as needed.
• A monthly compliance report must be published, detailing the number of complaints received and the actions taken in response.
• Two Categories of Social Media Intermediaries: To encourage innovations and enable growth of new social media intermediaries without subjecting smaller platforms to significant compliance requirement, the Rules make a distinction between Social Media Intermediaries and Significant Social Media Intermediaries.
• Intermediaries with registered users above a notified threshold will be classified as significant social media intermediaries (SSMIs). The additional due diligence to be observed by these SSMIs include:
Personnel: An SSMI must appoint:
Achief compliance officer for ensuring compliance with the Rules and the Act.
A nodal person for coordination with law enforcement agencies.
A grievance officer, all of whom should reside in India.
• Identifying the first originator of information:
An SSMI, which primarily provides messaging services, must enable the identification of the first originator of information within India on its platform
• Technology-based measures: SSMIs will endeavour to deploy technology-based measures to identify content depicting child sexual abuse and rape and block it.
• User-centric requirements: SSMIs must provide users with:
A voluntary identity verification mechanism,
A mechanism to check the status of grievances,
An explanation if no action is taken on a complaint, and
A notice where the SSMI blocks the user’s content on its own accord, with a dispute resolution mechanism.
• Three Tier Regulation Mechanism:
• The Rules institute a three-tier structure for regulating digital media publishers:
• Self-Regulation by Publishers: Any person aggrieved by the content of a publisher may file a complaint with the publisher, who must address it within 15 days.
• Self-Regulation by Associations of Publishers: If a person is not satisfied with the resolution or if the complaint is not addressed within the stipulated time, they may escalate it to the association of publishers, which must resolve the issue within 15 days.
• Central Government Oversight: The Ministry of Information and Broadcasting may refer the complaint to an inter-departmental committee if:
The complainant or the publishers' association escalates the matter under specific conditions.
The Ministry itself decides to take it up.
• Code of Ethics:
• For publishers of news and current affairs, the following existing codes will apply:
Norms of journalistic conduct formulated by the
Press Council of India.
Programme code under the Cable Television Networks Regulation Act, 1995.
For online publishers of curated content code requires the publishers to:
Age restrictions: classify content in specified age-appropriate categories, restrict access of age- inappropriate content by children, and implement an age verification mechanism.
National Security: exercise due discretion in featuring content affecting the sovereignty and integrity of India, national security, and likely to disturb public order.
Harmony: consider India’s multiple races and religions before featuring their beliefs and practices.
Accessibility: make content more accessible to disabled persons.
• Oversight by Ministry:
The Ministry of Information and Broadcasting will:
publish a charter for self-regulating bodies, including Codes of Practices,
issue appropriate advisories and orders to publishers;
have powers to block content on an emergency basis (subject to review by the inter-departmental committee).
Any directions for blocking content will be reviewed by a committee headed by the Cabinet Secretary.
Figure: Evolution of IT Rules
Way Forward
• Identifying and monitoring threats: Social media platforms can be used to identify and monitor threats to internal security, such as terrorist groups, hate groups, and criminal organisations.
• The Mumbai police in 2023 inaugurated the country’s first ‘Social Media Lab’ to monitor the happenings on Facebook, Twitter and YouTube.
• Social media analysis generated intelligence (SOCMINT) to generate predictive tools for countering illegal activities.
• Educating the public:
• Indian Police social media handles are using memes and humor to inform citizens about hyperlocal challenges.
• Assam Police made sure to ask parents to not become a ‘Sharent’ (sharing parent) and share too much information about their children.
• Mumbai Police’s road safety initiatives make use of Bollywood and involve celebrities to caution people.
• Delhi Police used a popular driving game to raise awareness on staying in our lane on roads.
• Strengthening Regulation: as this is a developing field, it is necessary to evolve regulations.
Internet Restrictions in India
Internet censorship allows blocking certain websites/ data on the internet which could be for various reasons.
Restrict Copyrighted data, misleading materials.
Website used to radicalize youth for terrorism.
Information threatening security- fake news, misinformation and rumours can lead to deterioration in law and order in an area.
Harmful content like pornography, sexual abuse, harassment, hate speech, defamation etc.
Sensitive content violating privacy of individuals.
Internet Ban means the power of government to shut down internet services in any location in the territory of India in case of an emergency situation such as any dissent with the government, any new law related dissent, or election.
• Procedure for Internet Restrictions
• The internet suspension is primarily imposed under the Temporary Suspension of Telecom Services (Public Emergency or Public Safety) Rules, 2017, and Section 144 of the Code of Criminal Procedure, 1973 (CrPC).
• Section 69A of the Information Technology Act, 2000: empowers the central government to block access to any information on the internet that it considers to be prejudicial to the sovereignty, integrity, defence, security or friendly relations of India, or to public order or decency, or to incitement of any offence. However, this section
only applies to blocking specific websites or content, not the entire internet.
• In India, the central and state government is not compelled to seek permission or advice from any court of India to impose a ban on the internet, the government can directly impose a ban on or can ask All licensed ISPs (Internet Service Providers) to filter that content or to remove or to impose a complete net ban.
Telecommunications Act 2023
In the event of a public emergency or in the interest of public safety, the government may halt the transmission of any message under Section 20(2) of the Act.
Internet Shutdowns
• In January 2020, the Supreme Court in Anuradha Bhasin
v. Union of India held that access to information via the internet is a fundamental right under Article 19(1) of the Indian Constitution. The three-judge bench order further observed that internet shutdowns are a ‘drastic measure’, which may be imposed only if it is lawful, necessary, and proportionate and only after publishing internet suspension orders.
• Parliamentary Standing Committee on Communications and Information Technology in its 2021 Report on ‘Suspension of Telecom Services/Internet and its impact’ observed the following-
• Data Collection: There are no records of total internet shutdown orders being tracked by either authority.
• Broad Based Review Committee: Review Committees are intended to act as an important instrument to ensure checks and balances, the Committee recommend that the composition of the Review Committee should be expanded so as to include non-official Members, such as retired Judges, eminent citizens, heads of Pubic organisations.
• Review Committee in all States: it was noted that some states like Delhi did not have a Review Committee, which should be remedied.
• Standard Operating Procedure: for uniformity within a State for issuance of suspension orders should be established.
• Efficacy Study: a thorough study should be commissioned by the Government of India so as to assess the impact of internet shutdown on the economy and also find out its effectiveness in dealing with Public Emergency and Public Safety.
• Need for consultation with stakeholders including non-Governmental Organisations working in the field of internet freedom, Telecom Service Providers, commercial bodies, public organisations, etc.
• Principle of Proportionality: Recourse to internet shutdown should ideally be avoided and be taken sparingly only when it is absolutely necessary and expedient and that too only for a limited period of time which need to be clearly defined.
• Procedure for Lifting of Internet Shutdown should be provided, which is missing in several states.
• Impact of Internet Shutdowns
• Parliamentary Committee Report on Internet Shutdowns observed that some reports state India lost
2.8 billion US dollars in 2020 to internet shutdowns.
• It noted that internet shutdowns have massive implications for national economy, constitutional rights of the citizens to freedom of speech and expression, right to carry on any trade or business, etc.
• Shut downs affected and disrupted healthcare services, freedom of press and education etc. Further, suspension of telecom services/ internet greatly affects the local economy, healthcare services, freedom of press and education, etc.
• There is no conclusive evidence that internet shutdowns lead to the preservation or restoration of public order.
• Shutting the internet results in a lack of information and transparency that can also cause panic and hysteria.
• According to the Software Freedom Law Center (SFLC), a legal services organisation working in this field in India, since 2012 there have been 665 Internet shutdowns in India till 2022.
• Internet speed was reduced to 2G for 18 months in Kashmir after abrogation of the special status of the erstwhile state.
• In late January 2021, the government imposed a localised internet blackout in Delhi in response to the farmers’ protest.
Rajasthan has had the most shutdowns — with 88 such instances in almost 10 years. The reasons have ranged from protests by the Gujjar community for reservation, to preventing cheating.
Internet Shutdowns in India (Year-wise)
Figure: Frequency of Internet Shutdown and its Cost
WAY FORWARD:
• The government should consider other less intrusive measures to deal with law-and-order disturbances, communal violence, terrorist attacks, examinations, and political instability, such as blocking specific websites or content, issuing warnings or advisories, engaging with civil society and media, or deploying more security forces