Concept Page

National Cyber Security Coordinator

The National Cyber Security Coordinator is a high-ranking official responsible for overseeing and coordinating the country's cyber security efforts. This position plays a crucial role in protecting the nation's digital infrastructure from cyber threats and ensuring the security of sensitive information. In India, the National Cyber Security Coordinator is headed by a senior official, currently Rajesh Pant.

The National Cyber Security Coordinator (NCSC) is the senior official charged with synchronising India’s cyber‑defence architecture across ministries, state agencies, the private sector and the armed forces. Situated within the National Security Council Secretariat (NSCS) under the Prime Minister’s Office, the role was institutionalised to give a single point of strategic oversight for protecting the nation’s digital infrastructure, a task that has grown in urgency as India’s internet user base crossed 800 million in 2023 and cyber‑threats have multiplied in scale and sophistication. ## Historical Background The NCSC post emerged from the National Cyber Security Policy (NCSP) of 28 July 2013, which recognised that fragmented responsibilities hampered an effective response to cyber incidents. The policy called for a “National Cyber Security Coordinator” to sit at the apex of a newly created cyber‑coordination framework, reporting directly to the Prime Minister. The first appointment, made in early 2014, went to a senior Indian Administrative Service officer who was tasked with drafting the operational guidelines for the nascent National Critical Information Infrastructure Protection Centre (NCIIPC). In 2016, the Information Technology (Amendment) Act 2008 was supplemented by the Personal Data Protection Bill (still pending as of 2024), reinforcing the legal scaffolding within which the NCSC operates. The 2022 revision of the NCSP expanded the coordinator’s remit to include oversight of the National Cyber Coordination Centre (NCCC) and the Cyber Swachhta Kendra, reflecting the shift from reactive incident handling to proactive threat hunting. ## Mandate and Mechanism The NCSC’s core mandate is threefold: strategic policy formulation, inter‑agency coordination, and crisis management. Under Section 70 of the Information Technology Act, the coordinator can issue binding directions to any “relevant agency” for the protection of critical information infrastructure (CII). Operationally, the NCSC chairs the Cyber Security Advisory Group (CSAG), a standing committee that meets fortnightly and includes heads of MeitY, the Ministry of Defence, the Ministry of Home Affairs, and the Indian Computer Emergency Response Team (CERT‑In). When a cyber incident is reported—whether a ransomware strike on a state electricity board or a data breach in a banking consortium—the NCSC activates the National Cyber Incident Response Framework (NCIRF). This framework mandates a 24‑hour initial assessment, a 72‑hour containment plan, and a 14‑day remediation timeline, with the coordinator authorising resource mobilisation from the National Disaster Management Authority (NDMA) if needed. The NCSC also maintains a real‑time threat intelligence dashboard that aggregates feeds from CERT‑In, NCIIPC, and private sector ISPs. ## Key Provisions of the 2013 Policy The 2013 NCSP enumerates six strategic objectives, three of which are directly overseen by the NCSC: (1) creation of a robust legal and regulatory regime, (2) development of a skilled cyber‑security workforce, and (3) establishment of a national cyber‑security ecosystem. Provision 3.2 of the policy mandates the NCSC to “ensure the seamless flow of cyber‑threat intelligence among all stakeholders.” Another pivotal clause, 4.1(b), requires the coordinator to “formulate and periodically update a National Cyber Security Strategy,” a task that culminated in the 2022 draft strategy outlining a 5‑year roadmap with a budget allocation of ₹1,200 crore for capacity building and research. The policy also stipulates that the NCSC must submit an annual “Cyber‑Readiness Report” to the Prime Minister, a document that has become a benchmark for measuring progress across ministries. ## India’s Evolving Cyber Governance Since Rajesh Pant’s appointment in August 2022, the NCSC has overseen several high‑profile operations. In March 2023, Pant led the joint response to a ransomware attack that crippled the Indian Railways’ ticketing platform, coordinating rapid decryption efforts and issuing a public advisory that limited passenger inconvenience to under 12 hours. The same year, the NCSC championed the rollout of the “Cyber Swachhta Kendra” across 30 state cyber‑security cells, extending the reach of threat‑intel sharing to regional law‑enforcement agencies. The coordinator’s office has also been instrumental in drafting the 2024 amendment to the IT Act, which introduced mandatory breach‑notification timelines of 72 hours for entities handling CII. Moreover, under Pant’s guidance, India signed a bilateral cyber‑security cooperation pact with Singapore in September 2024, facilitating joint exercises and the exchange of best practices on supply‑chain risk management. ## International Comparison While the United States houses a Cybersecurity Coordinator within the White House National Security Council, and the United Kingdom

    National Cyber Security Coordinator — UPSC Concept | TheKnowledgeOrbits