logo
Bridging the gap between ground reality and global standards

Bridging the gap between ground reality and global standards

Hindustan Times3 days ago
India is leading the race of digital transformation and currently stands at the crossroads in its cybersecurity journey. Cybersecurity (Shutterstock (PIC FOR REPRESENTATION))
With over 800 million internet users in the country and a rural penetration of 488 million, it would not be incorrect to say that digital transformation is being driven through the remotest villages and towns of the country. Add to this, the reliance on digital transactions through revolutionary tech of UPI payments system, and the stakes for cybersecurity become astronomically high.
The country has made significant strides in establishing a regulatory framework to counter the threats coming to the fore for digital adoptions by launching key initiatives. But the ground reality of an expanding cyber threat landscape continues to pose formidable challenges when compared to the global cybersecurity standards.
India's ambition of being a leader in the digital realm is clear. But the path is intertwined with a dynamic interplay of vulnerabilities and evolving defences.
India's digital footprint grew ten-fold especially in the years post pandemic. With an expansive digital footprint, the country has inevitably broadened its attack surface and invariably making it a prime target for cyber adversaries.
According to the Cyble's Threat Landscape Report, India ranked as the most targeted country in Asia and second most globally. Another report on defining the ransomware threat landscape, also quoted India as the prime target in the APAC region. Qilin, RansomHub and Cl0P were the most active actors with information technology (IT) and manufacturing being the most targeted sectors.
The financial toll is equally alarming. The country lost an astounding ₹22,845.73 crore to cybercriminals in 2024, marking a sharp 206% surge from the previous year. The main cyber threats include ransomware, phishing campaigns, data breaches, and a rising number of Artificial Intelligence (AI)-driven deepfake attacks.
In the underbelly of these alarming numbers are persistent and systemic vulnerabilities that are out in the open yet often ignored. Some of them are:
Low cybersecurity awareness: A significant portion of the population, like mentioned earlier, is from rural parts where awareness is usually restricted to only checkbox campaigns. But this is not just a rural or urban problem. Many enterprises in tier 1 and 2 cities also lack basic awareness of safer online practices. This makes human error a leading cause of breaches.
A significant portion of the population, like mentioned earlier, is from rural parts where awareness is usually restricted to only checkbox campaigns. But this is not just a rural or urban problem. Many enterprises in tier 1 and 2 cities also lack basic awareness of safer online practices. This makes human error a leading cause of breaches. Skill shortage: There is huge gap in the demand and supply for skilled cybersecurity professionals. Of course, universities and education system, in general, is now taking note of this.
There is huge gap in the demand and supply for skilled cybersecurity professionals. Of course, universities and education system, in general, is now taking note of this. Outdated frameworks and resource constraints: Several organisations, particularly MSMEs, struggle with legacy systems and resource limitations. Some of the core banking functionalities in India also still run on outdated technology which makes the adoption of advanced security solutions difficult.
Several organisations, particularly MSMEs, struggle with legacy systems and resource limitations. Some of the core banking functionalities in India also still run on outdated technology which makes the adoption of advanced security solutions difficult. Under-reporting: Reputational damage is the biggest fear businesses and organisations face when it comes to breaches and security incidents. This is the prime reason why several incidents often go unreported.
Despite the challenges, India has made significant efforts to match the capabilities of its foreign counterparts. The country is moving towards a multi-layered cybersecurity framework designed to safeguard its digital ecosystem.
The Information Technology (IT) Act, 2000, although a couple of decades old, has undergone significant amendments. It serves as baseline legislation and governs cybercrime, data protection, and electronic transactions. The law requires organisations handling sensitive personal data of Indian to follow reasonable security practices and procedures.
To further strengthen its data governance and give the power of owning the data to its uses, the government has also introduced the Digital Personal Data Protection Act of 2023 (DPDP Act). This act not only strengthens individual data privacy rights but also align India more closely with global data protection standard like the European Union's GDPR framework.
With a view to help industry specific incident response, the country also established the Indian Computer Emergency Response Team (CERT-In). It aids organisations in providing first-hand incident response by collecting, analysing and disseminating threat intelligence. Additionally, the government has established the Indian Cyber Crime Coordination Centre (I4C), and the National Critical Information Infrastructure Protection Centre (NCIIPC) which provides added expertise with threats related to frauds and critical infrastructure.
Other government Initiatives like Cyber Swachhta Kendra offer free tools for malware analysis and botnet tracking, while the National Centre of Excellence (NCoE) in collaboration with DSCI focuses on cybersecurity technology development and entrepreneurship among the younger generation.
India believes cyber threats transcend borders and thus also actively forging partnerships through Memoranda of Understanding (MoUs), which will help in sharing of threat intelligence with its allies like the UK, Japan, and the US.
On paper, India's legislative and institutional architecture looks robust and promising, the challenge though lies in its consistent and widespread implementation across a diverse and rapidly digitising economy. Regulatory gaps persist and many businesses are striving to achieve full compliance with evolving laws.
India aspires to build its own capabilities, reduce external dependence, and emerge not just as a leading consumer of digital technologies, but also a trusted global provider of tech products, services, and solutions. The recently drafted National Telecom Policy 2025 (NTP-25) is the proof of India's commitment towards it.
The policy explicitly factors in next-generation technologies like 5G/6G, AI, IoT, and quantum communications, aiming for a 10% global share in 6G-related Intellectual Property Rights (IPR) by 2030. This signals a strategic push towards not just following but setting global standards in critical areas.
The journey from ground reality to global leadership in cybersecurity is complex and continuous. It demands sustained investment in talent development, a proactive approach to emerging threats like AI-powered attacks, the widespread adoption of advanced security paradigms like AI-driven threat intelligence, and a cultural shift towards prioritising cybersecurity at every level. India's digital future and its national security hinges on its ability to effectively bridge this crucial gap.
This article is authored by Ankit Sharma, senior director and head, solutions engineering, Cyble.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

UPI system changes: New NPCI rules kick in from August 1 - All you need to know
UPI system changes: New NPCI rules kick in from August 1 - All you need to know

Time of India

time5 hours ago

  • Time of India

UPI system changes: New NPCI rules kick in from August 1 - All you need to know

Representative image Starting August 1, 2025, UPI will see changes as the National Payments Corporation of India (NPCI) has rolled out new performance-centric guidelines for the UPI ecosystem. The changes are aimed at improving system efficiency, preventing outages, and ensuring better user consent mechanisms. Payment Service Providers (PSPs), UPI apps, and banks must implement the changes by July 31, as per NPCI's compliance notice dated May 21. Cap on balance enquiries to prevent system overload A major change includes a cap on balance enquiry requests, now limited to 50 per app per customer in a rolling 24-hour period, as per ET. These requests must be user-initiated only, with no automatic prompts by apps or systems. UPI apps must also introduce the ability to reduce or halt such requests during peak load hours to minimise system strain. The guidelines also require issuer banks to include the available account balance in every successful UPI transaction message, streamlining user experience and reducing the need for separate balance checks. Limit on bank account access via 'list account' API NPCI has also put in place access limits on the 'list account' API, which lets users view bank accounts linked to their mobile number. This API will now be restricted to 25 requests per customer per app per day, and only after the user selects their bank in the app. by Taboola by Taboola Sponsored Links Sponsored Links Promoted Links Promoted Links You May Like Libas Purple Days Sale Libas Undo Any retries must be made with explicit customer consent, ensuring transparency and avoiding unnecessary API calls. Restrictions on UPI autopay transactions during peak hours To further address system congestion, NPCI has restricted UPI Autopay executions to non-peak hours only. Peak hours are defined as 10:00 to 13:00 and 17:00 to 21:30. Each autopay mandate will be allowed one initial attempt and a maximum of three retries, clearly capped at four total executions per mandate sequence. Industry reaction welcomes move towards efficiency Welcoming the new rules, Tarun Nazare, co-founder and managing director of Neokred was quoted as saying by ET that 'These measures are prudent and forward-thinking, as they prioritise system efficiency and user security. By capping balance requests and optimising API usage—especially with clear restrictions during peak hours—the guidelines will effectively reduce server overloads and potential service outages. ' He also highlighted the value of 'emphasis on customer consent and timely compliance' in enhancing system accountability. Deadline set for compliance; penalties for violations The NPCI has clearly warned that failure to comply with these directives by July 31, 2025, may result in UPI API restrictions, penalties, suspension of new customer onboarding, or any other appropriate action. NPCI has advised all member banks and UPI ecosystem participants to communicate these changes across their systems and partners ahead of the compliance deadline. Stay informed with the latest business news, updates on bank holidays and public holidays . Discover stories of India's leading eco-innovators at Ecopreneur Honours 2025

New UPI rules from August 1: All you need to know
New UPI rules from August 1: All you need to know

Indian Express

time5 hours ago

  • Indian Express

New UPI rules from August 1: All you need to know

UPI Transaction in India: According to a recent note by the International Monetary Fund (IMF) titled 'Growing Retail Digital Payments: The Value of Interoperability,' India has emerged as the global leader in fast payments, largely driven by the success of the Unified Payments Interface (UPI). Launched in 2016 by the National Payments Corporation of India (NPCI), the UPI has changed how people send and receive money in the country. Beginning August 1, 2025, a new set of UPI rules will come into effect. These new rules will further enhance system performance and reduce fraud risks across the country. In a circular issued on May 21, 2025, NPCI said: 'PSP banks and/or acquiring banks shall ensure all the API requests (in terms of velocity and TPS – transactions per second limitations) sent to UPI is monitored and moderated in terms of appropriate usage (customer-initiated and PSP system-initiated).' With the objective of improving the performance of UPI, following changes will be implemented starting August 1: Customers will be allowed to check their account balance through UPI apps up to a maximum of 50 times per app per day. This means each UPI app can be used up to 50 times in 24 hours for balance check. This allows an user to request for the status of the transaction. Under the new rules, the user may initiate the transaction status after 45 to 60 seconds of the initiation/authentication of original transaction. The users can execute UPI Autopay mandates such as electricity bills, water bills, OTT subscriptions, etc., only during non-peak hours. 'Peak hours are defined as the period during the day when UPI financial transactions reach the highest transactions per second, observed from 10:00 hours to 13:00 hours and from 17:00 hours to 21:30 hours. Any other time shall be referred as non-peak hour. During peak hours, UPI members are required to restrict non-customer-initiated APIs,' the NPCI said. It allows users to find the link of accounts linked to their mobile by a particular account provider. Now, the customers can view their bank accounts only 25 times per app in 24 hours.

ICICI Bank to charge payment aggregators for UPI transactions from August 1
ICICI Bank to charge payment aggregators for UPI transactions from August 1

Business Standard

time6 hours ago

  • Business Standard

ICICI Bank to charge payment aggregators for UPI transactions from August 1

ICICI Bank, India's second-largest private sector lender, will begin levying charges on payment aggregators (PAs) for Unified Payments Interface (UPI) transactions routed through their platforms, effective August 1. The move marks a shift in UPI monetisation efforts by banks amid growing transaction volumes and mounting infrastructure costs. The bank has communicated this to payment aggregators via formal letters, sources confirmed. Fee structure linked to escrow relationship According to a source familiar with the development, ICICI Bank will charge 2 basis points (bps) per transaction—capped at Rs 6—to PAs maintaining escrow accounts with the bank. For those without such an arrangement, the charge will be higher at 4 bps per transaction, capped at Rs 10. However, UPI transactions settled directly into an ICICI Bank account held by a merchant will not attract any fees. This exemption allows the bank to benefit from holding the transaction float. Peer banks already charging; margins in spotlight The move is being seen as part of a broader effort by banks to recover investments in UPI infrastructure. 'Banks may have taken a cue from the RBI governor's recent remarks on UPI monetisation,' said an executive at a leading payments firm. With merchant discount rates (MDR) at zero for UPI transactions, banks currently earn little despite bearing the cost of operating the UPI switch and managing backend infrastructure. PAs may pass on costs to merchants Industry experts suggest that payment aggregators—who typically charge merchants a platform or convenience fee—might either absorb the added cost or pass it on to merchants, depending on existing commercial arrangements. 'PAs will either pass on the costs to their merchants to maintain margins or absorb them based on the kind of arrangement they have with merchants,' said a payments executive. He also pointed out that UPI credit card transactions are already being monetised in some form. How UPI settlement works When a UPI transaction is made on a merchant's platform, the PA facilitates the flow between the customer's bank (debit) and the merchant's bank (credit). Typically, funds first land in an escrow account maintained by the PA with its bank of choice, before being settled to the merchant's bank account. Banks are now seeking to monetise this intermediary role played by PAs, especially as peer-to-merchant (P2M) transactions soar, creating high-volume, low-margin stress on digital infrastructure. ICICI Bank's move marks a step toward reshaping the economics of India's fast-growing UPI ecosystem, with implications for payment aggregators, merchants, and the broader digital payments value chain.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store