Sunday, June 15, 2025
India Watch - A Digital Media
  • Home
  • IndiaWatching
    • India Unplugged
    • Maps of India
    • Strategy & Policy
  • Makers for India
    • Gallery & Expo
  • More
    • About Us
    • Contact Us
No Result
View All Result
India Watch - A Digital Media
  • Home
  • IndiaWatching
    • India Unplugged
    • Maps of India
    • Strategy & Policy
  • Makers for India
    • Gallery & Expo
  • More
    • About Us
    • Contact Us
No Result
View All Result
India Watch - A Digital Media
No Result
View All Result
Home India Unplugged

NCIIPC Foundation Day 2017 – (Part 2) Taking stock and looking ahead

Dinesh Bareja by Dinesh Bareja
23/01/2017
in India Unplugged
0

This is the second report on the discussions and talks at the NCIIPC Foundation Day in New Delhi on 16th January 2017. The first part covers the talk given by the Deputy NSA and can be accessed here.

In this report we shall be covering the talks given by Dr Gulshan Rai, National Cyber Security Coordinator (NCSC) and Dr Sanjay Bahl, Director General, CERT-IN but have to say (regretfully) at the outset that the agenda was kept within the boundaries of standard disclosures! However there were a few unknowns which crept into the talks and I these are highlighted.

Dr. Rai opined that by 2020 we will see destructive attacks which will be much more dangerous than the DDOS and Disruptive Attacks which we see today. Quoting a report by Microsoft, he shared that the nature of attacks in India are more spam, RDP, malicious IPs and that NCIIPC is sharing a list daily. He also shared that data was taken away in the credit card hack in October.

IW View: This is something RBI and others have not said. They only told the country that about 681 cards were compromised and Rs 1.3 cr lost after which they went about replacing 3.2 million cards!

He shared 11 important cyber security trends, viz. expanding government roles, growth in cyber offense activity, adaptive tactics of attackers, complexity of cyber attacks, need for deeper analysis, intersection of life safety and cyber security, rise in litigation, reality realization of security costs, . increased expectations, undermining trust and security. Today we face many challenges and the main ones are death of the password, data is omnipresent, identity based access, biometrics, integration of multiple technologies, malware.

Mentioning one area of grave concern – patching – and he called up on the industry to come up with a trusted platform to test and distribute patches. This is a systemic issue and many vulnerabilities are old; an example being the ATM machines which are still running Windows XP.

India is a major source of botnets, and users also demonstrate poor hygiene leading to mobile compromise. He is as scared as any thinking about the impact when BHIM touches core banking systems.

IW View: But the makers and testers of BHIM are not scared of anyone or anything – they are invincible!

A call was made for NCIIPC and the Critical Infrastructure sector to agree upon a threat intelligence sharing system and enable 2-way TTI sharing, training and research. There is also the need to develop a trust system by setting up root level authentication. He shared that at present 250 organizations have been joined in as Critical and are getting the benefit of NCIIPC oversight.

IW View: The last one I don’t understand what he was trying to say and I daresay anyone in the audience understood too!

Besides, there is something wrong here – Dr Rai says 250 and then later in the day, during a panel discussion we were told that only 2 organizations have been notified as Critical (this has to be done through a formal gazette notification)

IW Comment: We are perplexed at the perpetual tryst with the elusive information sharing platform – every senior government and non-government official talks about Information Sharing but nothing is really done about it. You may check some history on Information Sharing initiatives here ARTICLE ON INFORMATION SHARING and it may be noted that this is being talked about very “seriously” since 2006…….. and I have been saying (since then) that nothing is going to happen and this is just hot air (of the smelly type)!

It would have been nice to know hard facts about the progress of the IC4 and NC3 (BTW are they the same organization!) as well as the plans of the various Cyber Security organizations to mesh together in creating a reliable and resilient ecosystem. While agreeing that the conference was about NCIIPC, we do believe that somewhere every cyber event will have a touch point with critical infrastructure.

 

Dr Bahl shared statistics about CERT activity in handling security incidents and providing guidance to stakeholders, plus more. One notable point was that 90% incidents are phishing and others make up the balance 10%. That less cash and digital payments is going to bring risk and that targeted attacks will become more mature. Cyber attacks will expand and the next area will be the supply chain. He also shared that CERT-In has put out full page advertisements (dunno where) asking organizations to report cyber incidents without delay. In keeping with the Swach Bharat Abhiyaan they are starting a “Cyber Swachta Kendra” to bring about a swach cyber system in the country.

IW Comment: Statistics from all government departments are usually at loggerheads with each other so I generally go into a limbo when someone talks numbers. What numbers (incidents) does CERT track, what does NCIIPC track and what does NCRB track … finally what is reported by the concerned Minister to the Parliament, and which number(s) form the basis for the creating policies etc. While the Cyber Swachta Kendra is a good thought, isn’t it the Hindi translation of CERT! Besides, I must also highlight that this bot cleaning stuff was also proposed in 2006… and all that happened is that some people had some free trips, cocktails and dinners.

He did not talk about the empanelment process or the need to bring penalties into the system which is black hole area.

IndiaWatch wishes them well (Dr Rai and Dr Bahl) and hopes that they consider our suggestion of having public meetings with the Information Security professionals across the country. There is a big disconnect in perceptions and expectations at both ends and just getting a clutch of big names and big companies to discuss is really not sufficient.

Tags: Bot CleaningCERT-InCyber SecurityCyber Swachta KendraGulshan RaiindiaNCIIPCNCSCNTROSanjay Bahl
Previous Post

NCIIPC Foundation Day 2017 - (Part 1) Taking stock and looking ahead

Next Post

NCIIPC Foundation Day 2017 – (Part 3) Taking stock and looking ahead

Dinesh Bareja

Dinesh Bareja

Cyber Security practitioner and evangelist working in cyber security in national and enterprise application. Contributor to national policy, awareness and development of capacity / capability. Keeps a critical eye on the past, present and future in the infosec domain, and firm believer in common sense. Uses practical thinking to demolish purveyors of cyber hype and snake-oil.

Next Post

NCIIPC Foundation Day 2017 – (Part 3) Taking stock and looking ahead

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

six − five =

  • Trending
  • Comments
  • Latest

Skeletons in my banks and national system

17/04/2018

Corporate Governance & Cyber Security Responsibility

18/11/2016

Chai pe Charcha – Delhi 11 June 2017

14/06/2017

Govt & Cops twiddle fingers waiting for the nation to burn…

26/08/2017
National Cyber Security Policy 2020 .. in anticipation

National Cyber Security Policy 2020 .. in anticipation

7

Cyber Swatchhta Kendra – A Good Start

6

Demonetisation – Cashless Economy – Urgent Need For Data Localisation

5

Why Are We A Strategically Deficient Nation ?

5
Time to relook at Critical Information Infrastructure

Time to relook at Critical Information Infrastructure

20/09/2020
What the Government does… secure messaging

What the Government does… secure messaging

23/01/2020
They ran, we shot… and u better believe us!

They ran, we shot… and u better believe us!

06/12/2019
National Cyber Security Policy 2020 .. in anticipation

National Cyber Security Policy 2020 .. in anticipation

31/10/2019

Recent News

Time to relook at Critical Information Infrastructure

Time to relook at Critical Information Infrastructure

20/09/2020
What the Government does… secure messaging

What the Government does… secure messaging

23/01/2020
They ran, we shot… and u better believe us!

They ran, we shot… and u better believe us!

06/12/2019
National Cyber Security Policy 2020 .. in anticipation

National Cyber Security Policy 2020 .. in anticipation

31/10/2019
  • Home
  • About
  • Contact
  • Maps of India

© 2018 IndiaWatch - All Rights Reserved. Website Design: Jemistry Info Solutions

  • Home
  • IndiaWatching
    • India Unplugged
    • Maps of India
    • Strategy & Policy
  • Makers for India
    • Gallery & Expo
  • More
    • About Us
    • Contact Us

© 2018 IndiaWatch - All Rights Reserved. Website Design: Jemistry Info Solutions

Login to your account below

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.