Key Points
- Cyber security incidents in India rose 85% from 15.9 lakh in 2023 to 29.4 lakh in 2025
- 237 security auditing organisations empanelled by CERT-In to audit government systems
- Over 11 lakh participants trained through 6,650 cyber awareness workshops nationwide
India recorded 29.44 lakh cyber security incidents in 2025, an 85 per cent increase from the 15.92 lakh incidents logged in 2023, the government told Parliament on Wednesday (12 August).
Jitin Prasada, minister of state for electronics and information technology, disclosed the figures in a written reply to a question from Congress MP Rajmohan Unnithan in the Lok Sabha.
The data, tracked by the Indian Computer Emergency Response Team (CERT-In), the national agency designated under Section 70B of the Information Technology Act 2000 to respond to cyber security incidents, shows incidents rising steadily from 15.92 lakh in 2023 to 20.41 lakh in 2024 before reaching 29.44 lakh last year.
The disclosure comes as government digital platforms and citizen service portals face mounting threats. When incidents affecting government-managed platforms are detected, CERT-In advises remedial measures to the concerned organisations and coordinates response with service providers, sector regulators and law enforcement agencies.
The sharp rise in reported incidents shows both an expanding attack surface as more government services move online and improved detection capabilities. However, the numbers also underscore the scale of the challenge facing the Centre as it seeks to secure critical infrastructure serving hundreds of millions of citizens.
National coordination
The government said it has established a multi-layered defence architecture. The National Cyber Security Coordinator under the National Security Council Secretariat ensures coordination across agencies. The National Cyber Coordination Centre, operated by CERT-In, monitors cyberspace for threats and shares intelligence with state governments and sectoral bodies.
For critical infrastructure, meaning systems whose disruption could affect national security, the economy or public health, the National Critical Information Infrastructure Protection Centre (NCIIPC) provides near real-time threat intelligence and situational awareness. NCIIPC issues regular alerts to protected system entities and conducts periodic vulnerability assessments.
The Cyber Swachhta Kendra, a citizen-focused service extending the Swachh Bharat vision to cyberspace, operates as a botnet cleaning and malware analysis centre. It detects malicious programs on citizen devices and provides free removal tools alongside security tips for individuals and organisations.
Sectoral response teams
Two sector-specific Computer Security Incident Response Teams (CSIRTs), which are specialised units that handle cyber incidents within particular industries, are now operational. CSIRT-Fin, covering banking and financial services, has been functioning since May 2022. CSIRT-Power, an extended arm of CERT-In for the power sector, became operational in September 2024.
CERT-In operates an automated threat intelligence exchange platform that shares tailored alerts with organisations across sectors for proactive threat mitigation. The agency has also formulated a Cyber Crisis Management Plan for all ministries, departments and state governments to counter cyber attacks and cyber terrorism.
Regular cyber security mock drills test the preparedness of government and critical sector organisations. To ensure baseline security standards, 237 information security auditing organisations have been empanelled by CERT-In to conduct vulnerability assessments and penetration testing. All government websites and applications must be audited for cyber security before hosting and undergo regular audits thereafter.
Awareness and training
The Ministry of Electronics and Information Technology (MeitY) is implementing the Information Security Education and Awareness (ISEA) project to build human resources in information security and promote cyber hygiene among the public. The project has conducted 6,650 awareness workshops across the country, reaching over 11.37 lakh participants including students, teachers, law enforcement personnel, government officials and citizens.
Kerala received specific attention with 70 awareness workshops covering 9,481 participants. Training materials including handbooks, short videos, posters, brochures and cartoon stories for children have been published in multiple languages and disseminated through print, electronic and social media channels as well as dedicated government portals.
CERT-In also runs training programmes in collaboration with industry partners to upskill the cyber security workforce across government, public and private organisations. In 2025, 32 programmes trained 20,799 participants, with 786 from Kerala. In 2026 up to June, 13 programmes have trained 12,109 participants including 411 from Kerala.
By the numbers
- 29.44 lakh
- cyber incidents recorded in India in 2025
- 85%
- increase in incidents from 2023 to 2025
- 237
- security auditing firms empanelled by CERT-In
The government organises regular awareness events including National Cyber Security Awareness Month in October, Safer Internet Day on the second Tuesday of February, Swachhta Pakhwada from 1 to 15 February, and Cyber Jagrookta Diwas on the first Wednesday of every month. CERT-In shares safety tips and awareness content through its official website and social media handles on Facebook, X, Instagram, YouTube and LinkedIn.
The government also stressed that the statutory framework has been strengthened with the Digital Personal Data Protection Act, 2023. Rules framed under the Act ensure that sharing and processing of citizens’ digital personal data for law enforcement purposes is undertaken in a lawful, secure and accountable manner.
Your Questions, Answered
How many cyber security incidents did India report in 2025?
India recorded 29.44 lakh cyber security incidents in 2025, according to data tracked by CERT-In and disclosed in Parliament on 12 August.
What is CERT-In and what does it do?
CERT-In is the Indian Computer Emergency Response Team, the national agency designated under the IT Act 2000 to respond to cyber security incidents. It advises remedial measures and coordinates incident response across organisations.
How does the government protect critical infrastructure from cyber attacks?
The National Critical Information Infrastructure Protection Centre provides real-time threat intelligence, issues alerts and conducts vulnerability assessments for critical systems whose disruption could affect national security or public health.
What training programmes exist for cyber security awareness in India?
The ISEA project has conducted 6,650 workshops reaching over 11.37 lakh participants. CERT-In runs additional training programmes that trained 20,799 participants in 2025 and 12,109 in 2026 up to June.


