Skip to content
India

Building India’s National Cyber Reserve Force: Feasibility, Models, and Strategic Value

A National Cyber Reserve Force provides strategic utility by enabling rapid mobilisation during crises, such as the May 2025 standoff, and fostering a culture of indigenous innovation essential for long-term sovereignty. However, the NCRF's effectiveness depends on the…

WhatsApp Facebook X LinkedIn Email
Building India’s National Cyber Reserve Force: Feasibility, Models, and Strategic Value



A National Cyber Reserve Force provides strategic utility by enabling rapid mobilisation during crises, such as the May 2025 standoff, and fostering a culture of indigenous innovation essential for long-term sovereignty. However, the NCRF’s effectiveness depends on the state’s capacity to balance military secrecy with civilian collaboration and manage the tension between offensive requirements and the risk of escalation. In an era characterised by grey-zone warfare, leveraging India’s civilian cyber capabilities forms the foundation for comprehensive national defence in the 21st century.


Executive Summary


Traditionally, the Indian Government and its defence establishments have largely relied on standing military units and centralised civilian agencies to address national security concerns. The conceptualisation of a National Cyber Reserve Force in India likely represents a fundamental pivot in the nation’s strategic approach to the cyberspace domain. Traditional hierarchical structures are proving inadequate given cyberspace’s unique characteristics, including its geographical indeterminacy, the blurred boundaries between civilian and military infrastructure, and the rapid technological advancement and the shifts in the threat landscape.


The rationale for establishing this National Cyber Reserve Force rests on creating a structured, legally sanctioned, and professionally vetted body of civilian cybersecurity experts, specialists, academics and researchers. This force could be mobilised to safeguard the state, and, under clearly defined mandates, undertake offensive measures during a high-intensity conflict or national emergencies to enhance cyber deterrence.


The rapid expansion of India’s digital footprint underscores the strategic imperative to establish such a force. By early 2025, internet connections in India surpassed 100 crores and average monthly internet usage per subscriber surpassed 24 GB, reflecting the deep integration of digital infrastructure in the economy and society[3]. The Carnegie Endowment for International Peace projects that by 2030, India’s digital economy will account for one-fifth of its gross domestic product (GDP), significantly increasing the nation’s cyber attack surface[4]. This transformation is taking place amid a deteriorating regional security environment, in which state-sponsored actors, advanced persistent threats, and grey-zone warfare strategies have become the new normal [5].


The current institutional architecture, which includes the Ministry of Defence (MoD), Ministry of Home Affairs (MHA), Ministry of Electronics and Information Technology (MeitY), and the National Security Council Secretariat (NCSC), is marked by fragmented responsibilities for civil-military cyber coordination. Although the establishment of the Defence Cyber Agency (DCyA) in 2019 advanced tri-service collaboration, the agency is still constrained by the conventional military recruitment processes and faces challenges in attracting and retaining top technical talent from India’s private sector and global capability centres[8]. This report evaluates how India can establish a dedicated National Cyber Reserve Force by examining its feasibility, potential models, and strategic value.


Contemporary Threat Landscape


Understanding the need for establishing a reserve cyber force requires examining the unique challenges that India as a country has faced and is continuing to face in the evolving cyber threat landscape. Threat actors have advanced from conducting simple website defacements to executing complex attacks on Critical Information Infrastructure (CII).


A significant escalation occurred during the military standoff between India and Pakistan in May 2005, demonstrating how cyber operations can create strategic ambiguity and misinterpretation, undermining regional deterrence. In addition to influence operations conducted through automated social media accounts, offensive cyber operations now target unmanned combat aerial vehicles and nuclear command-and-control communications, potentially causing operational failures of essential digital assets.

Table: Threat actor categories and their strategic intent and impact


Threat actor categories, strategic intent, and documented examples


A persistent structural challenge is posed by China’s cyber statecraft. Chinese activity groups such as RedEcho have escalated network breaches targeting India’s power industry since the 2020 Galwan Valley conflict. According to Maharashtra Cyber, over 1.5 million attacks on critical infrastructure websites were executed by seven advanced persistent threat (APT) groups in 2025 following terror incidents. This demonstrates the scale of coordinated cyberattacks that exceed the response capacity of standing armies alone. By leveraging plausible deniability to avoid reprisal and sustain strategic disruption, these operations are designed to remain below the threshold of open conflict.


Existing Institutional Architecture and its Limitations


India’s current cybersecurity architecture is a complex web of institutions, each with distinct but overlapping mandates and missions. The 2024 amendment to the Allocation of Business Rules (AoBR), which designated the National Security Council Secretariat (NSCS) as the nodal agency for overall coordination and strategic direction, sought to bring much-needed clarity to this landscape[4].


  • The Military Component: Defence Cyber Agency (DCyA)


The operational arm of the Indian Armed Forces in cyberspace is the Defence Cyber Agency (DCyA), headquartered in New Delhi, and reports directly to the Chief of Defence Staff (CDS) [8]. Its personnel is drawn from all three services – the Army, Navy, and Air Force – reflecting the tri-service character. Despite notable progress, including the release of the “Joint Doctrine for Cyberspace Operations” in August 2025 and the successful establishment of Cyber Emergency Response Teams (CERTs) for each service, the agency continues to grapple with persistent scalability challenges [8]. Calls to upgrade the DCyA into a full-fledged cyber command, staffed with up to 5,000 security experts, have been made repeatedly; yet the military’s ongoing “teeth-to-tail” ratio reforms, alongside the Agnipath scheme’s emphasis on leaner force structures, complicates the prospects for such large-scale expansion [18].

Ex-CDS General Anil Chauhan at Exercise Cyber Suraksha – 2024


Ex-CDS General Anil Chauhan at Exercise Cyber Suraksha – 2024 | PIB


  • Civilian Nodal Agencies: CERT-IN and NCIIPC


Under Section 70B of the Indian Information Technology Act 2000, the Computer Emergency Response Team (CERT-IN) serves as the national nodal agency responsible for responding to cybersecurity incidents [20]. The scale of this task is considerable: CERT-In processed roughly 29 lakh incidents in 2025 alone, underscoring the sheer volume of cyber activity affecting even the residential and domestic sphere [3].


Complementing CERT-In is the National Critical Information Infrastructure Protection Centre (NCIIPC), which focuses on sectors such as banking, transportation, and power [21]. Yet, despite the depth and regularity of their operations, both agencies remain fundamentally defensive and reactive in orientation. Neither currently possesses the institutional authority or trained manpower to undertake “hunt forward” operations or “offensive cyber operations”—capabilities that are becoming increasingly vital to deterring state-sponsored actors and other adversaries [2].


  • Internal Security and Crime: I4C and CyMAC


On the domestic front, the Indian Cybercrime Coordination Centre (I4C), under the Ministry of Home Affairs, plays an active role in investigating organised fraud and disinformation campaigns [20]. To this end, several important tools have been developed, such as “Pratibimb,” which enables real-time the geospatial mapping of cybercriminals’ locations [6]. Furthermore, the “Cyber Multi Agency Centre” (CyMAC) functions as a unified platform bringing together agencies such as the DCyA, CERT-In, the Intelligence Bureau (IB), and the Research and Analysis Wing (R&AW). However, even this level of coordination is often restricted to government personnel, leaving the considerable expertise residing in the private sector largely untapped


The Talent Gap: Human Capital as a Strategic Vulnerability


The strongest argument in favour of a National Cyber Reserve Force (NCRF) is the shortage of advanced cybersecurity talent within government. Indian organisations continue to experience a significant skills deficit. In 2024, 92 per cent of Indian organisations reported security breaches, primarily attributed to inadequate training and competence [16]. Although India is recognised as a global IT leader, specialised skills essential for cyber warfare—such as vulnerability research, malware reverse engineering, and AI-driven threat hunting—are predominantly found in private-sector firms and global capability centres, where compensation and career advancement opportunities exceed those in the military or civil services [9].


The existing recruitment model for the Territorial Army (TA) presents a potential pathway for cyber specialists but is constrained by outdated regulations from 1976 and stringent eligibility criteria, including requirements for prior military experience or employment in specific government departments such as Railways [28]. Opportunities for TA cyber warfare specialists remain limited, with only six positions available in 2023 and four in 2024, which is inadequate given the strategic demand for a substantially larger force [19]. Moreover, the rigid hierarchy of the armed forces may hinder the innovative “hacker mindset” needed to advance in this domain.


Comparative International Models: Evaluating transferability


To assess the feasibility of an Indian NCRF, it is important to examine relevant international models and consider their applicability to India’s socio-political and legal context.


  • The Volunteer Militia Model: Estonia’s Cyber Defence Unit (CDU)


The Estonian model rests on national pride and professional networking. The Estonian Defence League’s Cyber Defence Unit (EDL CDU) is staffed by volunteers drawn from the civilian ICT community, who retain their regular employment but remain available for training and activation in times of crisis [29]. This approach works particularly well for a small, highly digitised nation, where the civilian population has a direct and tangible stake in the state’s digital resilience [31].


Transferability to India: The “national pride” motivation translates well, but scaling this model across India’s vast geography would be difficult without a decentralised, state-level chapter system.


  • The Incubator Model: Israel’s Unit 8200 and Reserves


Israel identifies exceptional technical talent at the age of 18 through compulsory military service, with some recruits going to serve in Unit 8200 — Israel’s elite cyber warfare and signals intelligence (SIGINT) unit, and remaining committed to the reserves for life [32]. This creates a seamless talent pipeline between the military and the cybersecurity industry, with reservists bringing private-sector innovation back into the Israel Defense Forces (IDF) [32].


Transferability to India: Once again, the applicability of this model is low, given that India does not practise conscription. Adopting an “elite conscription” model would require a fundamental transformation of national education and recruitment practices. What is far more relevant to the Indian context, however, is the underlying principle of lateral entry — drawing industry specialists into reservist roles.

US Cyber Command


US Cyber Command | USNI News


  • The Public-Private Mobilisation Model: United States National Guard


The United States relies on its Guard and Reserve components to provide surge capacity for US Cyber Command (USCYBERCOM). These units are increasingly viewed as a means of retaining “preeminent military cyber personnel” who move fluidly between private-sector careers and military duty. Discussions are currently underway to establish a dedicated “Cyber Force” to better manage this hybrid workforce [35].


Transferability to India: Moderate to High. The TA already possesses a framework comparable to the US National Guard, though its terms of service and specialised trades would require significant modernisation.

Table: Comparing the Estonian, Israeli, US, and proposed Indian cyber reserve models


Comparing global cyber reserve models against the proposed Indian NCRF


Legal, Institutional, and Operational Feasibility


Establishing a National Cyber Reserve Force in India is feasible, but it necessitates overcoming substantial structural constraints.


  • Legal Feasibility and Authorities


India’s existing legal regime, anchored by the IT Act, 2000, remains predominantly civilian in orientation and lacks explicit provisions authorising civilian participation in military-executed cyber operations [37]. The “civilian-military” coordination essential to a reserve force is complicated by the Official Secrets Act (OSA), under which the classification of threat intelligence and offensive cyber tools is a tightly guarded domain within the Ministry of Defence (MoD) [39]. Compounding this is the ambiguity surrounding the legal status of civilian volunteers in armed conflict, who risk being classified as “unprivileged belligerents” under International Humanitarian Law (IHL) – a designation that could expose them to both prosecution and kinetic targeting [41].


  • Institutional and Command-and-Control (C2)


An NCRF would need to operate within the “Joint Doctrine for Cyberspace Operations” released in 2025, which emphasises synchronised operations across the three services [17]. However, its command structure must be flexible enough to allow for “distributed authorship” and rank-agnostic courses that involve academia and industry [44]. A central question, then, is whether the force should sit under the DCyA (military) or the NSCS (civilian). A hybrid model, in which a civilian-military board raises and trains the force but DCyA retains operational control during a declared emergency, appears the most viable path forward.


  • Operational and Economic Feasibility


A compelling economic case underpins the argument for a reserve force. High personnel turnover and the recurring cost of maintaining specialised skills make standing cyber units prohibitively expensive to sustain. A reserve force allows the state to “rent” competence, significantly improving the armed forces’ “teeth-to-tail” ratio [19]. While INR 782 crore was earmarked for cybersecurity in 2025, this remains insufficient to create a standing force of 5,000 professionals [3]. The TA’s adoption of a lateral entry of “domain specialists” from mid-2025 marks a step in the right direction, but it will need to be scaled up considerably to meet the strategic requirement [45].


Strategic Value: Resilience, Surge Capacity, and Deterrence


The strategic value of an NCRF extends beyond technical support, serving as a force multiplier that enhances the state’s overall capabilities in the digital domain:


  • Deterrence and Signalling


A strong reserve force helps to “deter by denial” by showing that India has a “whole-of-society” approach to cyber resilience. If an enemy understands that a cyberattack on a power grid will be confronted with thousands of mobilised defenders who created those very systems in the private sector, then the perceived utility of such an attack goes down [23]. In addition, the NCRF offers a credible way of “signalling” in a crisis. Mass mobilisation of cyber reservists can be a non-kinetic signal of determination, perhaps de-escalating a situation before it crosses the kinetic threshold [23].


  • Surge Capacity and Crisis Response


In a national emergency like the 2025 India-Pakistan impasse, the sheer volume of cyber incidents, ranging from disinformation to infrastructure probing, can rapidly overwhelm standing authorities [11].


An NCRF gives the “mass” the ability to monitor networks, conduct quick forensics, and restore services simultaneously across several sectors [48]. The surge capacity is critical to prevent the “cascading effects” of a cyberattack on public order and economic stability [6].


  • Resilience and Indigenous Innovation


Technical reservists can support military operations, providing access to advanced technical and AI capabilities that regular forces cannot afford to maintain full-time [19]. They can be incorporated in research institutions such as Signals Technology Evaluation and Adaptation Group (STEAG) to innovate in next-generation communications and “Secure by Design” protocols [6]. This would ensure real “Atmanirbharta” (self-reliance) by ensuring Indian cyber defence is based on indigenous systems and intellectual property [6].


Risks and Mitigation: Managing the Downsides of a Reserve Force


Creating a hybrid force is not without significant risks, particularly in the sensitive domain of national security. Some of the challenges are highlighted below:


  • Militarisation of Civilians and Attribution Challenges


Deploying semi-civilian personnel in offensive operations further complicates the “attribution” dilemma. If a reserve unit goes on the counter-offensive, the enemy may have a hard time distinguishing a state act from a non-state “patriotic hacker” act, raising the potential of inadvertent escalation [49]. This is especially problematic in the South Asian context, where the misattribution of a cyberattack on NC3 systems could lead to a nuclear strike. To counter this, well-defined “Rules of Engagement” (RoE) need to be put in place, and offensive actions should be the sole prerogative of the regular military, with the reservists restricted to support and defensive missions [11].


  • Insider Threats and Governance Failures


Bringing private-sector personnel into the national security system increases “insider threat” dangers. Reservists can have their allegiance divided between the state and their business employers, or be targeted by foreign intelligence organisations for recruitment[40]. An in-depth, Multi-Stage Vetting Process requires “Pratibimb-style” geospatial monitoring and continuous background checks [6]. There are also concerns that agencies such as the NCCC and NTRO are not subject to parliamentary supervision, raising questions about widespread monitoring and infringement of civil liberties [53].


What if the reservist, while defending a private network under a government mandate, causes collateral damage to a third party? The current legal framework provides no “safe-harbour” or liability protection for such situations. A defined responsibility framework and state-backed indemnity insurance for mobilised reservists are prerequisites for private-sector engagement [54].


Actionable Policy Recommendations


To effectively build a National Cyber Reserve Force that advances India’s strategic interests, the following recommendations are provided:


1. Enact a Cyber Reserve Act (CRA)


India requires a specific statutory framework to govern the NCRF. The CRA should:


  • Define the legal status of reservists during “active” and “inactive” periods.

  • Provide liability protection for reservists and their primary employers during authorised operations.

  • Establish a “Cyber Reserve Board” with representatives from the NSCS, MoD, MHA, and the private sector to oversee recruitment and vetting.

  • Strategic Rationale: This mitigates the legal ambiguities of the IT Act and ensures the force is “institutionalised in law” rather than operating on an ad-hoc basis.[37]


2. Implement a “Specialised Technical Trade” in the Territorial Army


The MoD should move beyond the current 1976-era TA regulations and create a specific “Cyber and Emerging Tech” cadre.


  • Relax age limits (e.g., up to 55 or 60 for niche technical roles) and physical standards for these specialists.[19]

  • Allow for “lateral entry” at higher ranks (Major or Lt. Colonel) for industry veterans to match their civilian expertise.[28]

  • Strategic Rationale: This leverages the existing TA framework while addressing the human capital mismatch that prevents elite talent from joining the military.[28]


3. Establish Regional Cyber Training Ranges (RCTR)


To keep the reserve force technically current, India should establish RCTRs in major technology hubs like Bengaluru, Hyderabad, and Pune.


  • These ranges should facilitate “joint cyber drills” between regular forces, reservists, and CII operators.[6]

  • Training should be “rank-agnostic” and focus on “future warfare courses” open to academia and industry.[44]

  • Strategic Rationale: Continuous transmission of know-how is critical for a “work in progress” domain like cybersecurity.[27]


4. Create a “Cyber National Guard” for CII Protection


The NCIIPC should be empowered to raise its own “Reserve Wing” comprising employees from designated critical sectors (Power, Banking, Telecom).


  • These “In-situ Reservists” would be trained in NCIIPC-approved incident response protocols and would be the first responders for their own organisations during a national-level threat.

  • Strategic Rationale: This ensures that the people who know the systems best are also the ones defending them, enhancing the “recovery” aspect of national resilience.


5. Develop an “AIBOM” and “Trusted Source” Vetting Protocol


Given the rise of AI-driven threats, the NCRF must be part of a “Trusted Telecom Portal” framework that audits not just hardware but the human elements of the supply chain.[3]


  • Implement AI-driven “Technical Guidelines on SBOM/AIBOM” to ensure that the tools used by the reserve force are free from foreign “kill switches” or surveillance backdoors.[3]

  • Strategic Rationale: This manages the “insider threat” and supply chain risks associated with leveraging private-sector capabilities.


Conclusion: Toward a “Whole-of-Nation” Cyber Posture


The primary challenge is not the feasibility of establishing a National Cyber Reserve Force, but whether sufficient institutional and legal commitment exists to implement it. The 2025 Joint Theory for Cyberspace Operations has laid the groundwork for a unified military approach; however, essential human resources remain concentrated in the private sector. A legally robust, tiered, and professionally managed reserve force can address the skills gap, strengthen strategic deterrence, and ensure that digital transformation does not become a security vulnerability.


A National Cyber Reserve Force provides strategic utility by enabling rapid mobilisation during crises, such as the May 2025 standoff, and fostering a culture of indigenous innovation essential for long-term sovereignty. However, the NCRF’s effectiveness depends on the state’s capacity to balance military secrecy with civilian collaboration and manage the tension between offensive requirements and the risk of escalation. In an era characterised by grey-zone warfare, leveraging India’s civilian cyber capabilities forms the foundation for comprehensive national defence in the 21st century.


[The article is exclusive to NatStrat. The views expressed by the author(s) are personal and do not necessarily reflect the views of the organisation.]


References


  1. Babu, Keisiya Glory, and Gayathri N. M. “An Analysis of Cybercrimes Laws in Comparison with the United States of America and the European Union.” Aut Aut Research Journal 14, no. 3 (2024). Accessed January 29, 2026. https://autrj.com/wp-content/uploads/2024/03/6-AUT-MARCH-2024-4695.pdf

  2. Basu, Arindrajit. India’s International Cyber Operations: Tracing National Doctrine and Capabilities. Geneva: United Nations Institute for Disarmament Research (UNIDIR), December 16, 2022. Accessed January 29, 2026. https://unidir.org/files/2022-12/UNIDIR_India_International_Cyber_Operations.pdf

  3. Press Information Bureau, Government of India. “CERT-In: India’s Frontline Defender against Cyber Threats.” January 23, 2025. Accessed January 29, 2026. https://www.pib.gov.in/PressReleasePage.aspx?PRID=2217537®=3&lang=1

  4. Carnegie India. “Mapping India’s Cybersecurity Administration in 2025.” September 2025. Accessed January 29, 2026. https://carnegieendowment.org/research/2025/09/mapping-indias-cybersecurity-administration-in-2025

  5. Observer Research Foundation. “Pakistan and China’s Collusive Grey-Zone Warfare.” August 2025. Accessed January 29, 2026. https://www.orfonline.org/public/uploads/posts/pdf/20250801103519.pdf

  6. The Cybercrime and the Crisis of Global Governance.” The Hindu, January 27, 2026. Cybercrime and the crisis of global governance – The Hindu

  7. Ministry of Electronics and Information Technology, Government of India. “Rajya Sabha Unstarred Question No. 1342.” Accessed January 29, 2026. https://sansad.in/getFile/annex/266/AU1342_Wrgj1b.pdf?source=pqars

  8. Business Standard. “Govt Approves Setting Up of Defence Cyber Agency.” Business Standard. November 27, 2019. Accessed January 29, 2026. https://www.business-standard.com/article/pti-stories/govt-approves-setting-up-of-defence-cyber-agency-119112701445_1.html

  9. “Demand Drives Up Cybersecurity Talent Gap to 50%.” The Economic Times. Accessed January 29, 2026.https://medial.app/news/demand-drives-up-cybersecurity-talent-gap-to-50percent-the-economic-times-fb533ce27168a

  10. Pant Harsh V., and Kartik Bommakanti. “Emerging Technologies and India’s National Security.” Daksh, Chapter 10. Accessed January 29, 2026. https://www.dakshindia.org/Technology-and-Analytics-for-Law-and-Justice/part11.xhtml

  11. Saadia, Halima. “Cyber Quicksand? Uncharted Risks and Escalatory Dynamics in a Future India-Pakistan Crisis.” Stimson Center, 2025. Accessed January 29, 2026. https://www.stimson.org/2025/cyber-risks-and-escalatory-dynamics-future-india-pakistan-crisis/

  12. Imran-ul-Hassan, SYed. “The Limits of Limited War and the Dangers of Escalation Dominance in the Aftermath of the Pakistan–India 2025 Crisis.” BASIC, November 27, 2025. Accessed January 29, 2026. https://basicint.org/the-limits-of-limited-war-and-the-dangers-of-escalation-dominance-in-the-aftermath-of-the-pakistan-india-2025-crisis/

  13. South Asian Voices. “Cyber Quicksand? Uncharted Risks and Escalatory Dynamics in a Future India-Pakistan Crisis.” September 3, 2025. Accessed January 29, 2026. https://southasianvoices.org/sec-f-pk-r-cyber-india-pakistan-crisis-09-03-2025/

  14. Manhas, Neeraj Singh. “From the Border to Cyberspace: Investigating the Post-Galwan Escalation of Chinese Cyber Attacks against India.” China-India Brief, no. 230. Centre on Asia and Globalisation, Lee Kuan Yew School of Public Policy, August 11, 2023. Accessed January 29, 2026. .https://lkyspp.nus.edu.sg/cag/publications/center-publications/publication-article/detail/from-the-border-to-cyberspace-investigating-the-post-galwan-escalation-of-chinese-cyber-attacks-against-india

  15. Data Security Council of India. Cyber Security Outlook 2025. 2025. Accessed January 29, 2026. https://www.dsci.in/files/content/documents/2025/Cyber-Security-Outlook-2025_0.pdf

  16. Express Computer. “Fortinet Report: AI Skillsets Critical to Address Cybersecurity Skills Gap Solution in India.” Accessed January 29, 2026. https://www.expresscomputer.in/news/fortinet-report-ai-skillsets-critical-to-address-cybersecurity-skills-gap-solution-in-india/130115/

  17. The Economic Times. “CDS General Chauhan Formally Releases Joint Doctrines for Cyberspace, Amphibious Operations.” Accessed January 29, 2026. https://m.economictimes.com/news/defence/cds-general-chauhan-formally-releases-joint-doctrines-for-cyberspace-amphibious-operations/articleshow/123172121.cms

  18. Panwar, R. S. “Enhancing Offensive Cyber Capability within the Indian Armed Forces: An Imperative for Synergized Multi-Domain Operations.” Future Wars, June 3, 2025. Accessed January 29, 2026. https://futurewars.rspanwar.net/enhancing-offensive-cyber-capability-within-the-indian-armed-forces/

  19. Bommakanti, Kartik. “The Imperative for Technical Reservists in the Indian Army.” ORF Occasional Paper, no. 466. Observer Research Foundation, March 2025. Accessed January 29, 2026. https://www.orfonline.org/research/the-imperative-for-technical-reservists-in-the-indian-army

  20. Ministry of Electronics and Information Technology, Government of India. “Lok Sabha Starred Question No. 232.” Accessed January 29, 2026. https://sansad.in/getFile/loksabhaquestions/annex/182/AS232_pojRcq.pdf?source=pqals

  21. UpGuard. “NCIIPC Explained: Safeguarding India’s Critical Infrastructure.” Accessed January 29, 2026. https://www.upguard.com/blog/nciipc-explained

  22. Cybersecurity Intelligence. “National Critical Information Infrastructure Protection Centre (NCIIPC), India.” Cybersecurity Intelligence. Accessed January 29, 2026. National Critical Information Infrastructure Protection Centre (NCIIPC) – India

  23. U.S. Department of Defense. 2023 DOD Cyber Strategy Summary. September 2023. Accessed January 29, 2026. https://media.defense.gov/2023/Sep/12/2003299076/-1/-1/1/2023_DOD_Cyber_Strategy_Summary.pdf

  24. The Statesman. “Govt Institutionalized Nationwide Integrated & Coordinated System to Tackle Cyber Threats.” Accessed January 29, 2026. https://www.thestatesman.com/business/govt-institutionalized-nationwide-integrated-coordinated-system-to-tackle-cyber-threats-1503520560.html

  25. Manufacturing Today India. “Fortinet Report Highlights Urgent Cybersecurity Talent Shortage.” Accessed January 29, 2026. https://www.manufacturingtodayindia.com/fortinet-cybersecurity-shortage

  26. Data Security Council of India. India Cybersecurity Domestic Market 2023 Report. 2023. Accessed January 29, 2026. https://www.dsci.in/files/content/knowledge-centre/2023/India%20Cybersecurity%20Domestic%20Market%202023%20Report.pdf

  27. Baezner, Marie. Study on the Use of Reserve Forces in Military Cybersecurity: A Comparative Study of Selected Countries. Center for Security Studies, ETH Zürich, April 2020. Accessed January 29, 2026. https://css.ethz.ch/content/dam/ethz/special-interest/gess/cis/center-for-securities-studies/pdfs/Cyber-Reports-2020-03-military-cybersecurity.pdf

  28. Singh, Vikram. “The Imperative for Technical Reservists in the Indian Army.” Accessed January 29, 2026. https://www.researchgate.net/publication/389561607_The_Imperative_for_Technical_Reservists_in_the_Indian_Army

  29. Defense Visual Information Distribution Service (DVIDS). “E-Warriors: The Estonian Cyber Defence Unit.” Video. Accessed January 29, 2026. https://www.dvidshub.net/video/579705/e-warriors-estonian-cyber-defence-unit-square

  30. Ottis, Rain. “Estonia’s Cyber Defence League: A Model for the United States?” Accessed January 29, 2026. https://www.researchgate.net/publication/263405936_Estonia’s_Cyber_Defence_League_A_Model_for_the_United_States

  31. Grzegorzewski, Jan. “Civil Cyber Defense: A New Model for Cyber Civic Engagement.” Cyber Defense Review 8, no. 3 (Fall 2023). Accessed January 29, 2026. https://cyberdefensereview.army.mil/Portals/6/Documents/2023_Fall/CDR_V8N3_Fall-2023_04-Grzegorzewski.pdf?ver=jq4tDehBVgnuexDMZmxXug%3D%3D

  32. Cordey, Sean. Trend Analysis: The Israeli Unit 8200: An OSINT-Based Study. Center for Security Studies (CSS), ETH Zürich, December 2019. Accessed January 29, 2026. .https://css.ethz.ch/content/dam/ethz/special-interest/gess/cis/center-for-securities-studies/pdfs/Cyber-Reports-2019-12-Unit-8200.pdf

  33. Press Information Bureau, Government of India. “Government Strengthens India’s Cyber Security Ecosystem.” March 26, 2025. Accessed January 29, 2026. https://www.pib.gov.in/PressReleaseIframePage.aspx?PRID=1742322&utm®=48&lang=2

  34. Cyber 8200. “Unit 8200: Expanded OSINT Handbook to Israel’s Cyber-Intelligence Powerhouse.” Accessed January 29, 2026. , https://www.cyber8200.com/en/blog/israeli-cyber-unity-8200

  35. Foundation for Defense of Democracies (FDD). “Building the Future U.S. Cyber Force.” September 9, 2025. Accessed January 29, 2026. https://www.fdd.org/analysis/2025/09/09/building-the-future-us-cyber-force/

  36. Couillard, Michael. “Beyond USCYBERCOM: The Need to Establish a Dedicated U.S. Cyber Military Force.” Cyber Defense Review 9, no. 1 (Spring 2024). Accessed January 29, 2026. https://cyberdefensereview.army.mil/Portals/6/Documents/2024_Spring/Couillard_CDRV9N1-Spring-2024.pdf

  37. Chawla, Gunjan. “India’s New Defence Cyber Agency—II: Balancing Constitutional Constraints and Covert Ops?” The CCG Blog, October 1, 2019. Accessed January 29, 2026. https://ccgnludelhi.wordpress.com/2019/10/01/indias-new-defence-cyber-agency-ii-balancing-constitutional-constraints-and-covert-ops/

  38. “Cyber Security Laws of India, United States and United Arab Emirates: A Comparative Analysis.” African Journal of Biomedical Research. Accessed January 29, 2026. https://africanjournalofbiomedicalresearch.com/index.php/AJBR/article/download/3014/2321/5307

  39. Watkin, Ken. “Intelligence Wars, Their Warriors, and Legal Ambiguity – Part I: Wars and Warriors.” Articles of War, Lieber Institute West Point, July 16, 2025. Accessed January 29, 2026. https://lieber.westpoint.edu/intelligence-wars-their-warriors-legal-ambiguity-part-i-wars-warriors/

  40. Dewar, Robert S., ed. National Cybersecurity and Cyberdefense Policy Snapshots: Collection 1. Center for Security Studies (CSS), ETH Zürich, 2018. Accessed January 29, 2026. https://css.ethz.ch/content/dam/ethz/special-interest/gess/cis/center-for-securities-studies/pdfs/Cyber-Reports_National_Cybersecurity_and_Cyberdefense_Policy_Snapshots_Collection_1.pdf

  41. Wilmshurst, Elizabeth, Harriet Moynihan, and Tsvetelina van Benthem. Securing Justice for Cyber-Enabled International Crimes: Legal Foundations and Practical Routes to Prosecution. Chatham House, January 26, 2026. Accessed January 29, 2026. .https://www.chathamhouse.org/2026/01/securing-justice-cyber-enabled-international-crimes/02-applying-international-criminal-law

  42. Ruhr-Universität Bochum, Institute for International Law of Peace and Armed Conflict. Modern Technologies and Targeting under International Humanitarian Law. Working Paper No. 3.3. Accessed January 29, 2026. , https://www.ruhr-uni-bochum.de/ifhv/documents/workingpapers/wp3_3.pdf

  43. Watts, Sean. “Combatant Status and Computer Network Attack.” UC Berkeley School of Law. Accessed January 29, 2026. https://www.law.berkeley.edu/files/watts–combatant_status_and_computer_network_attack.pdf

  44. ANI News. “CDS Gen Anil Chauhan Highlights India’s Military Transformation.” August 9, 2025. Accessed January 29, 2026. https://www.aninews.in/news/national/general-news/cds-gen-anil-chauhan-highlights-indias-military-transformation20250809023754/

  45. Raksha Anirveda. “Digitised Battlefields: Indian Army Steps Up High-Tech Infusion to Be Future-Ready Force.” Accessed January 29, 2026. https://raksha-anirveda.com/digitised-battlefields-indian-army-steps-up-high-tech-infusion-to-be-future-ready-force/

  46. Brock, Julia V., and James A. Lewis. Mutual Defense in Cyberspace: Joint Action on Attribution. Center for Strategic and International Studies (CSIS), September 17, 2025. Accessed January 29, 2026. https://www.csis.org/analysis/mutual-defense-cyberspace-joint-action-attribution

  47. Schulze, Matthias. “Cyber in War: Assessing the Strategic, Tactical, and Operational Utility of Military Cyber Operations.” In 2020 12th International Conference on Cyber Conflict (CyCon). NATO Cooperative Cyber Defence Centre of Excellence, 2020. Accessed January 29, 2026. https://ccdcoe.org/uploads/2020/05/CyCon_2020_10_Schulze.pdf

  48. Healey, Jason, and Erik B. Koran. “Defense Support to the Private Sector.” Cyber Defense Review. Special Edition, 2019. Accessed January 29, 2026. https://cyberdefensereview.army.mil/Portals/6/Session%205%20Number%201%20CDR-Special%20Edition-2019.pdf

  49. Hill, Robert. “The Ultimate Challenge: Attribution for Cyber Operations.” Air University Press. Accessed January 29, 2026. https://www.airuniversity.af.edu/Portals/10/AUPress/Papers/WF_70_HILL_THE_ULTIMATE_CHALLENGE_ATTRIBUTION_FOR_CYBER_OPERATIONS.PDF

  50. Singh, Virpratap Vikram. “The Six Degrees of Cyber Attribution.” International Institute for Strategic Studies (IISS), November 20, 2024. Accessed January 29, 2026. https://www.iiss.org/online-analysis/cyber-power-matrix/2024/11/the-six-degrees-of-cyber-attribution/

  51. Hasan, Naveed Ul. “Pakistan-India Conflict Escalation and the Risk of Nuclear Exchange.” World Geostrategic Insights, May 17, 2025. Accessed January 29, 2026. https://www.wgi.world/pakistan-india-conflict-escalation-and-the-risk-of-nuclear-exchange/

  52. Patil, Sameer. “Interpreting India’s Cyber Statecraft.” Carnegie Endowment for International Peace, March 2025. Accessed January 29, 2026. https://carnegieendowment.org/research/2025/03/interpreting-indias-cyber-statecraft

  53. Tulsian, Vrinda. “Increase Parliamentary Oversight on Indian Intelligence Agencies: Congress MP.” Hindustan Times, October 19, 2024. Accessed January 29, 2026. .https://www.hindustantimes.com/india-news/increase-parliamentary-oversight-on-indian-intelligence-agencies-congress-mp-101729276049178.html#google_vignette n

  54. Butler, John. “When Cyberweapons End Up on Private Networks: Third Amendment Implications for Cybersecurity Policy.” American University Law Review. Accessed January 29, 2026. https://digitalcommons.wcl.american.edu/context/aulr/article/1886/viewcontent/Butler.off_to_website.pdf

  55. Yannakogeorgos, Panayptis A. Strategies for Resolving the Cyber Attribution Challenge. U.S. Government Publishing Office. Accessed January 29, 2026. https://www.govinfo.gov/content/pkg/GOVPUB-D301-PURL-gpo71641/pdf/GOVPUB-D301-PURL-gpo71641.pdf

  56. “Cyber Security Legal Framework in India: Overlaps, Problems and Challenges.” QTanalytics Journal. Accessed January 29, 2026. https://qtanalytics.in/journals/index.php/JBMIS/article/download/4934/2469/15486

  57. CertCube Labs. “NCIIPC Critical Information Infrastructure (CII) Audit.” Accessed January 29, 2026. https://blog.certcube.com/nciipc-critical-information-infrastructure-cii-audit/



Source link

WhatsApp Facebook X LinkedIn Email

Author

admin

Writing for 2020Bharat on the stories that are moving now.