India’s cybersecurity system faces significant accountability challenges, with no updated national cybersecurity policy since 2013 and the absence of a legally accountable cyber regulatory body, according to experts interviewed by medianama.com. The designated national cybersecurity agency, CERT-In, lacks legal obligations to enforce fixes or penalize poor cybersecurity practices, raising concerns about the effectiveness of India’s cybersecurity framework.
Experts pointed out that CERT-In operates without accountability mechanisms common in other countries, such as oversight by parliamentary committees. Srikanth L from Cashless Consumer noted that CERT-In cannot compel organizations to act on vulnerabilities or publicly disclose them, functioning more as an advisory body than a regulator with enforcement powers. This lack of teeth means companies face no consequences for denying breaches or failing to improve security after audits.
The absence of consequences for security auditors who certify inadequate cybersecurity systems and the fact that companies do not suffer penalties for breach denial further weaken the ecosystem. This situation contrasts with international practices where regulators have clear mandates and enforcement authority. The cybersecurity gaps in India’s system could expose critical infrastructure and businesses to increased risks, underscoring the need for reforms in regulatory accountability and legal frameworks.
The last national cybersecurity policy update was in 2013, and no new policy has been introduced since, leaving the regulatory environment outdated. Experts emphasize that without legal accountability for CERT-In and clear consequences for companies and auditors, India’s cybersecurity posture remains vulnerable, as detailed in the medianama.com report.