
CERT-In expands role in protecting India’s digital ecosystem from emerging Cyber threats
The Computer Emergency Response Team – India (CERT-In), the national nodal agency for cybersecurity, has continued to play a crucial role in safeguarding the country’s digital infrastructure through prompt response, awareness initiatives, and global collaboration. Operating under the Ministry of Electronics and Information Technology (MeitY), CERT-In serves as India’s National Incident Response Centre for addressing major cybersecurity incidents across all states and Union Territories.
Established on January 19, 2004, CERT-In functions under the provisions of Section 70B of the Information Technology (Amendment) Act, 2008, and is headquartered in New Delhi. The agency is mandated to enhance the security of India’s digital ecosystem by issuing advisories, coordinating incident responses, and offering technical assistance to organizations and individuals facing cyber threats.
At the Digital India Pavilion during the India International Trade Fair (IITF) 2025, CERT-In’s initiatives have been showcased to highlight its nationwide efforts in raising cybersecurity awareness and ensuring a safer online environment. The agency’s activities include identifying emerging cyber threats, conducting vulnerability assessments, and collaborating with global partners to prevent large-scale digital attacks.
Whenever a cyber incident such as phishing, hacking, data theft, or ransomware occurs, affected individuals or organizations are required to report the matter directly to CERT-In. Reports can be submitted online through the official website ( www.cert-in.org.in ), by email to incident@cert-in.org.in, or via fax and post to the agency’s New Delhi office. Upon receiving the report, a case ID is generated, and a technical team is assigned to assess and respond to the issue.
The process begins with incident identification and immediate containment, followed by log preservation and forensic analysis. CERT-In’s experts then analyze the attack to identify vulnerabilities, trace its source, and recommend measures for recovery. Depending on the severity of the incident, coordination is undertaken with law enforcement agencies, internet service providers, and sectoral CERTs such as those for power, finance, and defence.
In cases involving state-level systems or local institutions, coordination is carried out through State IT Departments or Cyber Security Cells, which work directly with CERT-In to ensure timely mitigation. For critical or large-scale breaches, collaboration is extended to the National Critical Information Infrastructure Protection Centre (NCIIPC) and, when necessary, with international CERTs to handle cross-border cyber threats.
After the technical investigation, a comprehensive report is shared with the concerned organization or entity. The report details the root cause of the incident, the extent of the compromise, and recommended preventive measures. CERT-In also continues to issue regular advisories and best practice guidelines to help citizens and institutions strengthen their digital defences.
Officials have reiterated that the timely reporting of incidents is mandatory under the April 28, 2022 directive issued by CERT-In. Non-compliance or delayed reporting of certain types of cybersecurity incidents may attract penalties under the Information Technology Act.
Through its awareness campaigns and technical guidance, CERT-In aims to ensure that India’s cyberspace remains secure and resilient against evolving global threats. Citizens and organizations are encouraged to stay informed, adopt strong cybersecurity practices, and cooperate with authorities in maintaining a safe digital environment for all.
Cybersecurity Incidents Reported to CERT-In
According to official government data, the Computer Emergency Response Team – India (CERT-In) has handled more than 61 lakh (6.1 million) cybersecurity incidents between 2018 and 2025. The year-wise figures reported to Parliament show that 2.08 lakh incidents were recorded in 2018, 3.94 lakh in 2019, 11.58 lakh in 2020, 14.02 lakh in 2021, 13.91 lakh in 2022, and 9.44 lakh in 2023. For 2024, approximately 12.5 lakh incidents were registered, while provisional data for 2025 indicates that over seven lakh cases have already been reported by mid-year. These incidents cover a broad range of threats, including phishing, ransomware, website defacement, data breaches, denial-of-service (DoS/DDoS) attacks, and unauthorized access to computer systems. Officials have explained that the growing number of reports reflects not only the increasing frequency and sophistication of cyberattacks but also a rise in public awareness and compliance with CERT-In’s April 2022 directive, which makes it mandatory for service providers, intermediaries, and government organizations to report cybersecurity incidents within six hours of detection under Section 70B of the Information Technology (Amendment) Act, 2008.
