Securing India in the Age of Hybrid Threats


Context

  1. Cyber Weapons: The emergence of LONGLEASH malware, alongside earlier cyber weapons such as Stuxnet, underscores cyberspace's transformation into a strategic battlespace where adversaries can pre-position malicious capabilities within Critical Information Infrastructure (CII)

  1. The convergence of cyber espionage, supply-chain compromise and infrastructure sabotage has elevated digital warfare into a core national security concern.
  2. Multi-Domain Security Doctrine: Responding to this evolving threat landscape, India has operationalised PRAHAAR, its comprehensive National Counter-Terrorism Policy and Strategy
  3. The experience of Operation Sindoor has further reinforced a doctrine based on whole-of-government coordination, multi-domain deterrence and the integration of counter-terrorism, cyber security, hybrid warfare, Artificial Intelligence, space security and financial intelligence.


What Are the Evolving Forms of Security Threats for India?


Cross-Border Terrorism
  1. Cross-border terrorism remains India's foremost conventional security challenge through proxy organisations, infiltration and state-sponsored terror infrastructure
  2. The convergence of terrorist groups and state sponsors has blurred the line between proxy warfare and interstate conflict, complicating deterrence and escalation management. 
  3. India must therefore prepare simultaneously for conventional, sub-conventional and hybrid threats.
Internal Security Challenges
  1. With Left-Wing Extremism no longer a major national security challenge, India's internal security focus is shifting towards preventing residual revival while addressing urban radicalisation, identity-based polarisation and digital mobilisation. 
  2. These evolving threats demand intelligence-led, development-oriented and community-centric responses beyond kinetic measures.
Changing Terrorism Landscape
  1. The Global Terrorism Index (GTI) 2026 shows terrorism becoming geographically concentrated yet operationally decentralised, with nearly 70% of deaths in five countries (Pakistan, Burkina Faso, Nigeria, Niger and the Democratic Republic of Congo) and over 60% of attacks within 100 km of international borders
  2. Extremist groups exploit conflicts, fragile governance, porous borders and digital ecosystems to sustain resilient networks. 
  3. Thus, declining fatalities mask terrorism's growing adaptability, technological sophistication and strategic resilience.
Hybrid Warfare
  1. Adversaries increasingly integrate cyberattacks, disinformation, economic coercion, drone incursions, proxy violence, lawfare and psychological operations into grey-zone campaigns
  2. Exploiting the attribution gap, they impose strategic costs while remaining below the threshold of conventional war. 
  3. This complicates deterrence, legal accountability and diplomatic response.
Critical Infrastructure Risks
  1. India's expanding dependence on Critical Information Infrastructure (CII) has enlarged the cyber attack surface across energy, banking, telecommunications, transport, healthcare, digital public infrastructure and defence
  2. Threats such as LONGLEASH show how Advanced Persistent Threats (APTs) can establish covert access before disrupting mission-critical systems. 
  3. Such pre-positioned intrusions heighten the risk of cascading failures and weaken strategic resilience.
Cyber Financial Threats
  1. Cybercrime has evolved into an ecosystem linking financial fraud, cryptocurrencies, mule accounts, money laundering and terror financing
  2. The Enforcement Directorate (ED) has identified cybercrime-linked proceeds exceeding ₹35,925 crore, highlighting the convergence of organised cybercrime and national security. 
  3. Consequently, financial resilience has become a core pillar of internal security.
Artificial Intelligence Warfare
  1. Artificial Intelligence (AI) is transforming warfare through autonomous systems, drone swarms, predictive intelligence and algorithmic targeting
  2. Simultaneously, Generative AI enables deepfakes, adaptive malware, automated phishing and cognitive warfare at unprecedented scale. 
  3. This compresses decision cycles while extending conflict into the digital and cognitive domains.
Space-Based Threats
  1. India's reliance on satellites for communications, navigation, intelligence, disaster management, finance and military operations has made space infrastructure a strategic asset. 
  2. Satellite systems, ground stations and supply chains are increasingly vulnerable to cyber intrusions that can degrade command-and-control and mission assurance
  3. Consequently, space cyber security has become a vital pillar of India's multi-domain security architecture.
Transnational Organised Crime
  1. Transnational organised crime increasingly converges with terrorism through narcotics trafficking, illicit arms trade, cyber fraud, hawala, virtual assets and human trafficking
  2. Exploiting porous borders, global financial networks and digital technologies, these networks operate beyond conventional law-enforcement reach. 
  3. Their convergence with extremist organisations has transformed organised crime into a major national security challenge.
Digital Radicalisation
  1. Extremist groups increasingly exploit encrypted platforms, Generative AI, algorithm-driven recommendation systems and decentralised online communities for recruitment and propaganda. 
  2. Such virtual ecosystems enable self-radicalisation without formal organisational structures or physical training camps. 
  3. Consequently, conventional surveillance and disruption mechanisms face growing limitations.
Supply Chain Insecurity
  1. Dependence on global semiconductors, firmware, cloud infrastructure and third-party software exposes critical systems to hidden compromises beyond domestic oversight. 
  2. Sophisticated supply-chain attacks can remain dormant before simultaneously disrupting multiple critical sectors. 
  3. Such vulnerabilities undermine digital sovereignty and traditional perimeter-based cyber defence.


What Are India's Existing Policies and Institutional Measures?


Strategic Doctrine
  1. India's security architecture has evolved from a reactive approach to a multi-domain deterrence framework through PRAHAAR (National Counter-Terrorism Policy and Strategy) and the doctrine emerging from Operation Sindoor
  2. It institutionalises a whole-of-government approach by integrating intelligence, counter-terrorism, border management, cyber security, financial disruption and international cooperation, while emphasising prevention, preparedness, response, recovery and resilience
  3. Complementing this, Mission Sudarshan Chakra strengthens indigenous technological capabilities and preparedness against emerging multi-domain threats.
Counter-Terrorism Posture
  1. Operation Sindoor has reinforced India's security doctrine through decisive retaliation, deterrence by punishment, no tolerance for nuclear blackmail and no distinction between terrorists and their state sponsors
  2. It integrates calibrated military action with diplomacy, economic statecraft, intelligence-led operations and technological superiority to establish credible deterrence. 
  3. This marks India's shift towards integrated national power beyond purely kinetic responses.
Institutional Architecture
  1. India has established a multi-layered security ecosystem comprising the National Investigation Agency (NIA), Multi Agency Centre (MAC), National Intelligence Grid (NATGRID), National Security Guard (NSG) and specialised intelligence agencies for threat assessment, intelligence fusion and counter-terrorism operations. 
  2. These institutions enable real-time information sharing and coordinated action across the Union and States. 
  3. Their synergy strengthens India's capacity to tackle interconnected multi-domain security threats.
Cyber Security Framework
  1. The Indian Cyber Crime Coordination Centre (I4C) anchors India's cyber security ecosystem through the National Cyber Crime Reporting Portal (NCRP), Citizen Financial Cyber Fraud Reporting and Management System (CFCFRMS), Cyber Fraud Mitigation Centre (CFMC), Suspect Registry, Samanvaya, Pratibimb, Cyber Commando Programme, Inter-operable Criminal Justice System (ICJS) and the National Cyber Threat Intelligence System. Complementing these, the Indian Computer Emergency Response Team (CERT-In) and the National Critical Information Infrastructure Protection Centre (NCIIPC) secure critical infrastructure through incident response, cyber threat intelligence and resilience planning. 
  2. Together, they strengthen preparedness against cyber-enabled crime, hostile cyber operations and attacks on Critical Information Infrastructure (CII).
Technology and Critical Infrastructure
  1. The Defence Research and Development Organisation (DRDO)–Ministry of Home Affairs (MHA) collaboration has accelerated deployment of indigenous technologies, including counter-drone systems, Artificial Intelligence-enabled surveillance, secure communications, thermal imaging, victim-location systems and advanced forensic capabilities for internal security and disaster response. 
  2. Complementing these efforts, CERT-In and SIA-India have issued the Space Cyber Security Guidelines (2026) promoting secure-by-design architecture, defence-in-depth, supply-chain security, mission assurance and adaptive cyber resilience across India's expanding space ecosystem. 
  3. These initiatives recognise that national security increasingly depends on protecting interconnected terrestrial, cyber and space domains through technology-driven resilience.


How Can India Strengthen Its National Security Architecture?


Integrated Threat Fusion
  1. Establish a Multi-Domain Threat Fusion Framework under the National Security Council Secretariat by integrating intelligence, cyber, financial, border and space-security platforms with real-time analytics. 
  2. This will strengthen intelligence fusion, situational awareness and inter-agency coordination.
Cyber Resilience
  1. Institutionalise Cyber Resilience Standards under CERT-In and NCIIPC through resilience audits, recovery benchmarks and continuity planning, aligned with the WEF Global Cybersecurity Outlook 2026
  2. This will ensure continuity of critical services and minimise cascading disruptions.
Trusted Technology Ecosystem
  1. Operationalise a Trusted Digital Supply Chain Framework with secure procurement, firmware validation, software assurance and continuous third-party risk assessment through MeitY, CERT-In and industry. 
  2. This will strengthen digital sovereignty and reduce supply-chain risks.
Adaptive Counter-Terrorism
  1. Periodically review PRAHAAR using evidence-based assessments of hybrid warfare, AI-enabled extremism, border terrorism and transnational organised crime
  2. This will enable a proactive and adaptive counter-terrorism strategy.
Responsible AI Governance
  1. Develop sector-specific AI Security Standards promoting human oversight, algorithmic transparency, adversarial testing and secure deployment through MeitY, DRDO and security agencies. 
  2. This will harness AI responsibly while mitigating autonomous weapons, deepfake and cognitive warfare risks.
Space Cyber Resilience
  1. Operationalise the CERT-In–SIA India Space Cyber Security Guidelines (2026) through secure-by-design architecture, defence-in-depth, cyber exercises, supply-chain assurance and continuous threat monitoring. 
  2. This will enhance mission assurance and resilience of India's space ecosystem.
Integrated Border & Financial Security
  1. Integrate border intelligence, financial intelligence, anti-money laundering investigations and AI-enabled surveillance to simultaneously disrupt infiltration, terror financing and transnational organised crime.
Whole-of-Society Resilience
  1. Institutionalise cyber awareness, counter-disinformation literacy and crisis preparedness through partnerships among government, academia, industry and civil society. 
  2. This will build a digitally resilient society capable of countering hybrid threats.


Conclusion

India's national security paradigm must evolve from territorial defence to multi-domain resilience, where deterrence, preparedness, technological superiority and societal resilience reinforce one another. In an era where "wars begin before the first shot is fired," India's greatest strategic advantage will lie in anticipating threats, integrating capabilities and securing every domain—from borders to cyberspace, and from society to space.


UPSC Prelims Connect  


Q. In India, under cyber insurance for individuals, which of the following benefits are generally covered, in addition to payment for the loss of funds and other benefits? (2020)    

  1. Cost of restoration of the computer system in case of malware disrupting access to one’s computer  
  2. Cost of a new computer if some miscreant wilfully damages it, if proved so  
  3. Cost of hiring a specialised consultant to minimise the loss in case of cyber extortion   
  4. Cost of defence in the Court of Law if any third party files a suit  

Select the correct answer using the code given below:    

(a) 1, 2 and 4 only    

(b) 1, 3 and 4 only    

(c) 2 and 3 only    

(d) 1, 2, 3 and 4    

Ans: (b) 

Q2. In India, it is legally mandatory for which of the following to report on cyber security incidents? (2017)    

  1. Service providers
  2. Data centres
  3. Body corporate

Select the correct answer using the code given below:   

(a) 1 only 

(b) 1 and 2 only 

(c) 3 only 

(d) 1, 2 and 3 

Ans: (d) 


UPSC Mains Connect


Q. What are India’s internal security challenges? Give out the role of Central Intelligence and Investigative Agencies tasked to counter such threats. (2023)

Q. Analyze the multidimensional challenges external state and non-state actors pose to India’s internal security. Also, discuss measures required to be taken to combat the threats. (2021)

Q. What are the sound determinants of left-wing extremism in the Eastern part of India? What strategy should the Government of India, civil administration, and security forces adopt to counter the threat in the affected areas? (2020)


QuestlinkIAS Practice Question


Prelims:

Q1. With reference to emerging dimensions of hybrid warfare, consider the following statements:

  1. Advanced Persistent Threats (APTs) are designed to establish covert, long-term access to critical networks before enabling strategic disruption at a chosen time.
  2. Grey-zone operations deliberately combine cyber intrusions, disinformation and proxy actors to achieve strategic objectives while remaining below the threshold of conventional war.
  3. Deterrence by denial primarily relies on the threat of punitive retaliation after an attack rather than reducing vulnerabilities and strengthening resilience beforehand.

Which of the statements given above is/are correct?

 (a) 1 and 2 only

(b) 2 and 3 only

(c) 1 only

(d) 1, 2 and 3

Answer: (a)

Mains:

Q. Hybrid warfare has rendered the traditional distinction between internal and external security increasingly obsolete. Examine this statement. Discuss why India requires a multi-domain security architecture to counter hybrid threats in the twenty-first century. ( 250 Words)


Source Editorial- Terrorism’s data retreat hides emerging global threats - The Hindu