Unlocking India’s cyber potential through policy, innovation, and partnerships

Nullcon Goa 2025 · Main Stage

Overview

This Nullcon talk delves into India's strategic vision and ongoing efforts to cultivate a formidable cybersecurity ecosystem. The discussion, presented by a distinguished panel from key government and industry bodies, including the Ministry of Electronics and IT (MeitY), CERT-In, GSTN, and the Data Security Council of India (DSCI), outlines how India is leveraging policy frameworks, fostering innovation, and forging robust public-private partnerships to achieve self-reliance and global leadership in cybersecurity. The core of the presentation emphasizes the burgeoning startup landscape, the critical role of research and development (R&D), and the necessity of indigenous product development to secure the nation's digital infrastructure.

Watch on YouTube

Visual summary for Unlocking India’s cyber potential through policy, innovation, and partnerships
Visual summary for Unlocking India’s cyber potential through policy, innovation, and partnerships

Key moments

  1. 0:00 India's rapid growth as a global cyber product ecosystem
  2. 2:00 Reflecting on past challenges and growth in India's cyber ecosystem
  3. 4:00 Introduction of key government panelists and their roles
  4. 5:15 MeitY's holistic approach to cybersecurity policy and R&D
  5. 6:15 National Center of Excellence (NCoE) incubating 146 cyber startups
  6. 6:30 Announcing the Cyber Security Grand Challenge with significant awards

Unlocking India’s cyber potential through policy, innovation, and partnerships

Speakers: Atul, Data Security Council of India (DSCI); Savita Uttam, Head of Cyber Security and R&D, Ministry of Electronics and IT (MeitY); Dr. Sanjay Bahl, Director General, CERT-In; Anand, GSTN

Conference: Nullcon

YouTube: https://www.youtube.com/watch?v=kYYJVS5IaeI

Overview

This Nullcon talk delves into India's strategic vision and ongoing efforts to cultivate a formidable cybersecurity ecosystem. The discussion, presented by a distinguished panel from key government and industry bodies, including the Ministry of Electronics and IT (MeitY), CERT-In, GSTN, and the Data Security Council of India (DSCI), outlines how India is leveraging policy frameworks, fostering innovation, and forging robust public-private partnerships to achieve self-reliance and global leadership in cybersecurity. The core of the presentation emphasizes the burgeoning startup landscape, the critical role of research and development (R&D), and the necessity of indigenous product development to secure the nation's digital infrastructure.

The panelists illuminate the remarkable growth experienced by India's cybersecurity product sector, which has seen an almost 40-fold increase in product companies over the last decade. They discuss the various government-led initiatives designed to nurture this growth, from substantial grant challenges and R&D funding to preferential public procurement policies. The talk also addresses the inherent challenges in adopting new, unproven technologies within critical national infrastructure and outlines strategies to build trust and facilitate the commercialization of cutting-edge research.

Ultimately, this talk underscores India's ambitious trajectory to position itself as a global powerhouse in cybersecurity, not just as a consumer but as a significant producer of innovative and secure solutions. It provides invaluable insights for policymakers, entrepreneurs, researchers, and security professionals keen on understanding the dynamics of a rapidly evolving national cybersecurity landscape and the opportunities it presents for both domestic and international collaboration.

Background

▶ Watch: India's rapid growth as a global cyber product ecosystem (0:00)

A little over a decade ago, around 2010-2011, India's cybersecurity product ecosystem was in its infancy. The landscape was described as "gloomy," with a mere 10-15 product companies struggling to gain traction. There was a conspicuous absence of initiatives to facilitate product adoption, minimal policy support, and significant hurdles for startups attempting to conduct Proof of Concepts (POCs). Furthermore, the academic sector lacked a robust ecosystem to foster cybersecurity research and innovation, leaving a substantial gap between theoretical knowledge and practical, market-ready solutions. This nascent stage presented a considerable challenge for a rapidly digitizing nation that would soon face an escalating volume and sophistication of cyber threats.

The problem stemmed from a confluence of factors: a lack of dedicated government support for indigenous product development, an underdeveloped venture capital landscape for deep tech, and a general skepticism towards local solutions in favor of established international vendors. The traditional government procurement processes, often characterized by rigid Pre-Qualification (PQ) and Technical Qualification (TQ) criteria, inadvertently created barriers for agile startups that might lack extensive operational history or large-scale deployments. This environment stifled local innovation and made it difficult for Indian companies to compete, let alone scale their products globally.

Recognizing this critical gap, organizations like the Data Security Council of India (DSCI), in collaboration with the Ministry of Electronics and IT (MeitY) and other stakeholders, embarked on a concerted effort to transform this landscape. Their objective was to create a robust ecosystem that would not only support but actively propel the growth of indigenous cybersecurity product companies. This involved developing new strategies, fostering public-private partnerships, and implementing policy interventions designed to address the historical impediments to innovation and adoption. The journey over the past decade has been one of strategic planning, significant investment, and sustained collaboration, aiming to elevate India's standing in the global cybersecurity arena.

Key Findings

▶ Watch: Introduction of key government panelists and their roles (4:00)

The talk highlights several transformative developments and key findings regarding India's cybersecurity ecosystem:

  1. Exponential Growth in Product Companies: India has witnessed an astounding 40x jump in the number of cybersecurity product companies over slightly more than a decade, growing from a mere 10-15 in 2010-2011 to over 400 today. This significant growth positions India as potentially the third-largest product ecosystem globally, trailing only Israel and the US, a fact currently being substantiated through ongoing research by DSCI.
  1. Global Competitiveness: Approximately 50% of the revenue generated by these Indian cybersecurity product companies comes from international markets, demonstrating their global competitiveness and the quality of their offerings. This outward focus is a testament to the ecosystem's maturity and ambition.
  1. Government as a Catalyst for Innovation: MeitY and CERT-In have been instrumental in driving this growth through various strategic initiatives:
  • National Center of Excellence (NCoE): Established in a public-private partnership with DSCI, NCoE has successfully incubated 146 startups, providing them with critical support and resources.
  • Cyber Security Grant Challenge: A flagship initiative launched by MeitY, this challenge offers a substantial prize pool of 6.85 Crore INR (approximately 7 crore INR). It provides market-centric problem statements identified from hundreds of organizations, guiding innovators towards real-world solutions. The challenge features multiple stages with progressive awards: 5 lakhs INR for selected ideas (36 entries across six problem statements), 10 lakhs INR for Minimum Viable Products (MVPs) (18 entries), and 25 lakhs INR for final problem statement winners (6 entries), culminating in Platinum, Gold, and Silver awards of 1.5 Crore INR, 75 lakhs INR, and 25 lakhs INR respectively. This structure incentivizes continuous development and provides financial support at various stages.
  • Public Procurement Order: This policy mandates preference for indigenous cybersecurity products in government procurement, creating a vital domestic market for local innovations.
  • R&D Funding and Collaboration: MeitY actively funds R&D projects in academic institutions, with a crucial recent enablement allowing startups and companies to collaborate directly with these institutions. This ensures that research translates into commercializable products.
  1. CERT-In's Proactive Role: As the national nodal agency for cybersecurity incidents, CERT-In not only manages threats but also actively supports the ecosystem:
  • Mentorship and Adoption: CERT-In provides guidance to startups and innovators, helping them refine their products and ensuring their solutions are adopted, even within critical government infrastructure. They have found indigenous solutions to be "far superior, far more agile, and far more scalable" than many off-the-shelf international products.
  • Cyber Suraksha Kendra: A public-private partnership model where CERT-In provides malware samples to industry partners, enabling them to enhance their products and stay ahead of emerging threats.
  • Regulatory Impact as Opportunity: CERT-In's six directions issued on April 28, 2022, particularly regarding incident reporting (e.g., 6-hour reporting), initially faced industry resistance. However, they ultimately led to improved internal processes, fostered the adoption of new technologies, and created significant opportunities for innovators to develop compliance-driven solutions.
  1. Importance of Testbeds and Co-creation: The panel emphasizes the critical need for national testbeds to evaluate, benchmark, and build trust in new cybersecurity solutions before deployment, especially in sensitive sectors like GSTN. Co-creation with startups, researchers, and even freelancers is identified as a powerful mechanism to augment product development by providing real-world feedback and use cases.
  1. Success Stories: The talk features Aseem, founder of Exploiter, who shared his experience as the first runner-up of a previous Cyber Security Grand Challenge. His testimony highlighted the benefits of the challenge's staged development, rapid feedback from juries, and financial incentives, which significantly aided his company's growth.

These findings collectively paint a picture of a nation strategically investing in its cyber future, transforming challenges into opportunities for innovation, and fostering a collaborative environment to achieve cybersecurity resilience and global leadership.

Technical Deep Dive

▶ Watch: MeitY's holistic approach to cybersecurity policy and R&D (5:15)

While the talk primarily focuses on policy and ecosystem development, several technical aspects and underlying technological needs are discussed, particularly in the context of R&D, threat response, and critical infrastructure security.

1. R&D Focus Areas and Academic Contributions:

MeitY's R&D division actively solicits proposals for solutions addressing contemporary and future cybersecurity challenges. A specific example cited is the call for proposals for VPN detection and deanonymization technologies. This highlights the government's interest in advanced capabilities to monitor and understand encrypted traffic, a critical area for national security and law enforcement. Furthermore, academic institutions like IIT Delhi have contributed significantly, with projects related to Edge Computing solutions being commercialized through industry partnerships. This suggests a focus on securing distributed environments and processing data closer to its source, which is crucial for IoT and future smart infrastructure. The emphasis on industry collaboration from the outset ensures that academic research is not confined to laboratories but translates into tangible, market-ready products.

2. CERT-In's Operational Technology and Guidelines:

CERT-In's role extends beyond incident response to active technology development and guidance.

  • Cyber Suraksha Kendra: This initiative is a public-private partnership model designed to enhance the defensive capabilities of the industry. Technically, it involves CERT-In providing samples of different malwares to industry partners. This direct sharing of threat intelligence, including specific malware binaries and signatures, allows cybersecurity product companies to integrate these into their detection engines, improve their threat intelligence feeds, and develop more robust defenses against emerging threats.
  • Honeypots: CERT-In also deploys honeypots in public-private partnerships. Honeypots are decoy systems designed to attract and trap attackers, allowing defenders to study their tactics, techniques, and procedures (TTPs) without risking real systems. The data collected from these honeypots is invaluable for understanding attacker behavior, identifying new attack vectors, and developing proactive defenses.
  • Cyber Security Drills and Exercise Platform: CERT-In has developed and mentored the creation of a sophisticated platform for conducting cybersecurity drills and exercises. This platform is not merely a simulation environment; it includes mechanisms for evaluation and measurement of participant improvement. It has been successfully used for capacity building, notably for cooperative banks, bringing them from "zero onwards" to a level where they could participate alongside larger banks. The platform's ability to measure individual and team performance during simulated attacks is a significant technical achievement, enabling quantifiable improvements in incident response and defensive skills. This platform was even highlighted at the World Economic Forum in Davos, underscoring its innovative approach to cybersecurity readiness.
  • Technical Guidelines and Advisories: CERT-In also publishes crucial guidelines that drive technological development:
  • Securing Smart Cities: These guidelines outline specific technical requirements and best practices for securing the complex, interconnected infrastructure of smart cities, creating a demand for specialized solutions.
  • Safeguarding Satcom: An advisory providing recommendations for securing satellite communication systems, a critical infrastructure component.
  • Risk-Based Approach for AI: Developed in collaboration with international agencies like ANSSI (National Agency for the Security of Information Systems) of France, this advisory focuses on identifying and mitigating cybersecurity risks associated with Artificial Intelligence systems, a forward-looking technical challenge.

3. GSTN's Rigorous Product Validation:

Anand from GSTN highlighted the extreme sensitivity of the data they manage, where a security breach could have direct implications for the national economy. This necessitates an exceptionally rigorous approach to adopting new security technologies.

  • Malware Ingestion Testing: A classic example of their technical validation involved deploying a security technology and then inducing hundreds of malwares from CERT-In's repositories into the system within a data center. This stress testing measured the tool's capabilities, its learning algorithms, and its effectiveness in real-world, high-volume threat scenarios. The feedback from this exercise was not only used to validate the product's suitability for GSTN but also provided valuable use cases to the OEM for subsequent patch cycles and feature enhancements, demonstrating a co-creation approach to product improvement.
  • Software Development Associates (SDA): GSTN works with SDAs on various initiatives beyond core cybersecurity, particularly in business analytics. These engagements involve developing solutions for compliance, identifying boundary cases (e.g., fraudulent transactions), and minimizing tax leakage possibilities. This demonstrates a technical focus on data analysis, anomaly detection, and fraud prevention within a large-scale financial system.

4. The "Techno-Legal" Imperative:

Dr. Bahl emphasized the "techno-legal" aspect of CERT-In's 2022 directions. Regulations like the 6-hour incident reporting mandate are not merely legal requirements but necessitate technological solutions for compliance. This implies the need for:

  • Automated Incident Response Platforms: To detect, analyze, and report incidents within the stipulated timeframe.
  • Robust Log Management and SIEM Solutions: To collect, store, and correlate security event data for rapid analysis.
  • Threat Intelligence Integration: To quickly identify and classify reported incidents.
  • Secure Virtual Assets Management: Addressing the cybersecurity implications of virtual assets, a complex technical domain requiring specialized solutions.

The overall technical landscape described in the talk emphasizes the need for solutions that are not only effective but also agile, scalable, and adaptable to India's unique challenges and rapidly evolving threat landscape. The focus on indigenous development ensures that these technical solutions are designed with local context and requirements in mind.

Demo / Proof of Concept

▶ Watch: National Center of Excellence (NCoE) incubating 146 cyber startups (6:15)

The talk, being a panel discussion on policy and ecosystem, did not feature a live technical demonstration or a detailed walkthrough of a specific product. However, the concept of Proof of Concept (POC) and rigorous product testing was a recurring and critical theme, particularly in the context of building trust and facilitating the adoption of indigenous innovations in critical infrastructure.

The most prominent example of a real-world "proof of concept" validation discussed was by Anand from GSTN. He described a thorough exercise conducted with CERT-In where they planned to deploy a new security technology. To ascertain its capabilities, they literally sat in the data center and ingested hundreds of malwares from CERT-In's repository into the tool. This was a high-stakes, practical test designed to push the product to its limits under realistic threat conditions. The objective was to observe how the tool performed, learned, and responded to a vast array of malicious software. While the specific name of the product was not disclosed, this rigorous testing served as a critical validation, and the feedback provided to the Original Equipment Manufacturer (OEM) led to innovative use cases and functionality enhancements in subsequent patch cycles. This exemplifies an intensive, real-world POC that directly influenced product development and trust building.

Furthermore, the Cyber Security Grant Challenge implicitly involves multiple stages of "proof of concept" and demonstration. Participants progress from submitting initial ideas to developing Minimum Viable Products (MVPs). These MVPs are then presented and demonstrated to expert juries, who provide feedback. This iterative process of development, demonstration, and feedback is essentially a structured, multi-stage POC, designed to mature innovative concepts into viable products. Aseem, the founder of Exploiter, confirmed that this staged approach with rapid feedback from juries was highly beneficial for their rapid development process.

MeitY's R&D projects also incorporate elements of POC and commercialization. When academic institutions develop solutions, the current policy encourages collaboration with industry partners from the outset. This partnership aims to take the "solution stage" to a "product stage," which inherently involves demonstrating the solution's viability and effectiveness in practical scenarios, akin to a structured POC leading to commercialization.

In summary, while no direct demo was presented, the panel highlighted that robust POCs, particularly those involving real-world stress testing and iterative development, are indispensable for validating new cybersecurity solutions, gaining trust from critical sectors, and bridging the gap between innovation and market adoption.

Defensive Implications

▶ Watch: Announcing the Cyber Security Grand Challenge with significant awards (6:30)

The insights shared during this talk have profound defensive implications for various stakeholders within India's cybersecurity landscape, from government entities and critical infrastructure operators to private enterprises and individual security professionals.

1. Strategic Adoption of Indigenous Solutions:

Defenders should actively consider and prioritize indigenous cybersecurity products and solutions. The panel, particularly Dr. Sanjay Bahl, emphasized that solutions developed within India are often "far superior, far more agile, and far more scalable" for the local context compared to many international off-the-shelf products. The Public Procurement Order further encourages this, making it easier for government and public sector organizations to adopt local innovations. This shift can lead to better support, faster customization, and solutions tailored to India's unique threat landscape.

2. Leveraging Government Initiatives for Enhanced Defense:

Organizations and individual security researchers should actively engage with initiatives like the Cyber Security Grant Challenge and the National Center of Excellence (NCoE).

  • Grant Challenge: The challenge provides market-centric problem statements identified from hundreds of organizations. This is a direct pipeline to understanding current and future defensive needs across various sectors. Participating, even just by studying these problems, can help organizations anticipate threats and identify areas for internal improvement or external procurement.
  • NCoE: Provides incubation and mentorship, fostering the development of new defensive tools and techniques. Defenders can engage with NCoE-incubated startups to explore cutting-edge solutions.

3. Proactive Regulatory Compliance as a Defensive Strategy:

CERT-In's six directions of April 28, 2022, initially perceived as burdensome, are framed as opportunities for enhancing organizational security posture. For example, the 6-hour incident reporting mandate necessitates robust Security Information and Event Management (SIEM), log management, and automated incident response (IR) capabilities. Organizations that invest in these technologies for compliance will inherently improve their ability to detect, analyze, and respond to cyber incidents rapidly, thereby strengthening their overall defense. Viewing regulations as a framework for building stronger defenses rather than just a compliance checklist is crucial.

4. Utilizing CERT-In's Threat Intelligence and Capacity Building:

  • Cyber Suraksha Kendra: Organizations can benefit from this public-private partnership by potentially receiving malware samples and threat intelligence from CERT-In. This direct access to real-world threat data allows defenders to enhance their own threat intelligence platforms, update their security tools, and train their detection systems against the latest attack vectors.
  • Drills and Exercises Platform: CERT-In's platform for conducting cybersecurity drills and exercises is a vital tool for capacity building. Organizations, especially those in critical sectors like cooperative banks, can leverage these exercises to train their security teams, test their incident response plans, and measure their defensive readiness, leading to quantifiable improvements in their security posture.

5. Demand for Testbed Validation and Co-creation:

For critical infrastructure operators, like GSTN, the lesson is clear: demand rigorous testbed validation for any new security product. This involves simulating real-world attack scenarios (e.g., ingesting hundreds of malwares) to thoroughly evaluate a product's effectiveness before deployment. Furthermore, engaging in co-creation or providing detailed feedback to vendors (as GSTN did with their OEM) can lead to the development of more tailored and effective defensive solutions. This collaborative approach helps mature products faster and ensures they meet specific operational security requirements.

6. Investing in R&D and Industry-Academia Collaboration:

Defenders, particularly those in large enterprises, should consider engaging in R&D collaborations with academic institutions and startups, potentially leveraging MeitY's funding frameworks. This allows them to influence the development of future defensive technologies that address their specific pain points and emerging threats, such as VPN detection and deanonymization or Edge Computing security.

In essence, the talk encourages a proactive, collaborative, and innovation-driven approach to cybersecurity defense in India. It emphasizes that by embracing indigenous solutions, leveraging government support, viewing regulations as opportunities, and demanding rigorous validation, organizations can significantly bolster their defensive capabilities against an increasingly complex threat landscape.

Key Takeaways

  • India's cybersecurity product ecosystem is experiencing explosive growth: The number of Indian cybersecurity product companies has increased by approximately 40 times in the last decade, with over 400 companies now operating, positioning India as a significant global player.
  • Government initiatives are crucial catalysts for innovation and adoption: MeitY and CERT-In are driving growth through substantial R&D funding, the Cyber Security Grant Challenge (6.85 Cr INR prize money), the National Center of Excellence (NCoE), and the Public Procurement Order favoring indigenous products.
  • Indigenous solutions offer superior agility and scalability: CERT-In's experience indicates that Indian-developed cybersecurity products are often "far superior, far more agile, and far more scalable" for the country's specific needs compared to many international alternatives.
  • Rigorous testing and testbeds are essential for trust and adoption in critical sectors: Organizations like GSTN mandate intensive "proof of concept" validations, including malware ingestion tests, to ensure the security and reliability of products before deployment, highlighting the need for national testbeds.
  • Regulations can be powerful drivers for technological innovation: CERT-In's 2022 directions (e.g., 6-hour reporting), initially met with pushback, ultimately stimulated the development of new technological solutions for compliance, improving overall security posture across industries.
  • Collaboration across academia, industry, and government is key: MeitY's encouragement of industry-academia R&D partnerships, CERT-In's mentorship, and DSCI's ecosystem building efforts underscore the importance of public-private collaboration for fostering innovation and commercialization.

About the Speaker(s)

  • Atul (Data Security Council of India - DSCI): Served as the moderator and initial speaker, setting the stage for the discussion. He is deeply involved in shaping strategies, fostering public-private partnerships, and building India's cybersecurity ecosystem, a journey he began with DSCI around 2010-2011.
  • Ms. Savita Uttam (Ministry of Electronics and IT - MeitY): Heads the cyber security and R&D division at MeitY. She is instrumental in framing national policies, funding extensive R&D projects in academic institutions, and spearheading major initiatives like the Cyber Security Grant Challenge and the Public Procurement Order to promote indigenous cybersecurity products.
  • Dr. Sanjay Bahl (Director General, CERT-In): Leads CERT-In, India's national nodal agency for cybersecurity incidents. He plays a critical role in managing incidents, facilitating the adoption of new technologies by startups, mentoring innovators, and developing platforms for national cybersecurity drills and exercises.
  • Anand (GSTN): Represents GSTN (Goods and Services Tax Network), where he manages critical national infrastructure handling sensitive data. His work involves designing and implementing security technologies, exploring innovation by startups in business analytics and compliance, and overseeing rigorous testing processes for product adoption.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

A government panel session on India's cybersecurity ecosystem policy — incubation programs, grant challenges, procurement mandates, and ecosystem statistics. Judged as a strategic/policy talk, it's functional institutional promotion with some concrete numbers, but it offers almost nothing that couldn't be extracted from a MeitY press release or DSCI annual report. The speakers have genuine authority over what they're describing, but they use it to recite program summaries rather than say anything substantive about what's actually working, what's failing, or where the real gaps are.

Heather Calloway (CISO) — WEAK

A policy-level panel on India's national cybersecurity ecosystem that reads more like a government press release than a strategic briefing. The findings are real and the growth story is genuinely notable, but the talk never converts its material into decisions, risks, or accountability structures that any CISO or policymaker could act on.

→ Top-rated talks at Nullcon Goa 2025

All talks from Nullcon Goa 2025