Cyber Threat Intelligence · India Edition - 2026

Cyber Threat Intelligence साइबर थ्रेट इंटेलिजेंस

From Reactive
to Proactive

— Vijayant Gaur

Join in · सहभागिता

Scan to join

Scan to join our live Slido Q&A
Powered by Slido · app.sli.do
· सहभागिताSlido

Your responses, live परिणाम

Join and participate.

▶ Open live results

Opens the Slido wall in a new window · or join at slido.com #8590 158

Agenda · रूपरेखाThe journey

Agenda रूपरेखा

First - what is Cyber Threat Intelligence? परिभाषा  then, in three parts:

Part 1

The problemसमस्या

  1. 01 India's threat landscape
  2. 02 The 10-year trend
  3. 03 The reactive problem
Part 2

The solutionसमाधान

  1. 04 The Cyber Threat Intelligence lifecycle
  2. 05 How Cyber Threat Intelligence helps
Part 3

India in focusभारत

  1. 06 Challenges in India
  2. 07 The Indian ecosystem
From reactive defence to proactive intelligence.
What is Cyber Threat Intelligence · परिभाषाThe concept

First, the concept परिभाषा

Evidence-based knowledge about threats,
used to inform defence.

Raw
Data
+ Context
Information
+ Analysis
Intelligence

Four levels of threat intelligence चार स्तर

AStrategicbig-picture riskRisk for leadership & investment decisions.
BTacticalattacker TTPsTactics, techniques & procedures.
COperationallive campaignsDetails of specific incoming attacks.
DTechnicalIoCsIPs, hashes, domains, signatures.
$ ./Cyber Threat Intelligence --load part-01 "the-problem" 01 - 03 Part One · भाग एक

The Problem समस्या

Why India can't keep reacting.

  1. 01 India's threat landscape
  2. 02 The 10-year trend
  3. 03 The reactive problem
01 · India's threat landscapePart 1 - The Problem

Why India परिदृश्य

One of the world's most-targeted nations.

0M
Incidents tracked by CERT-In, 2025
#0
Ransomware target in Asia-Pacific (APAC)*
0cr+
Internet users - a vast attack surface
Prime targets लक्ष्य BFSIHealthcareGovernmentCritical infraIT / BPOTelecomEnergy / PowerDefence
Key threats हमले RansomwarePhishingState-sponsored APTsBanking trojansSupply-chainMalware / virusesWebsite defacementDDoSCredential theft
* Ransomware rank according to vendor reportsWEF Global Risks Report 2026 · CERT-In
02 · The 10-year trendPart 1 - The Problem

A decade of escalation दस वर्ष

0× more incidents in a decade.

~50,000 (2016) → 2.94M (2025)Source: CERT-In
The rising cost · वित्तीय क्षतिPart 1 - The Problem

India's mounting losses आर्थिक क्षति

India's cyber-fraud losses keep climbing.

0%
Jump in losses in one year (2023 → 2024)
0cr
Recovered by rapid reporting - I4C CFCFRMS
Lost to cyber fraud: ₹551 cr (2021) → ₹22,845 cr (2024) · *2025 provisionalSource: I4C · NCRP · MHA
03 · The reactive problemPart 1 - The Problem

Cost of reacting late प्रतिक्रिया

React after the breach, and you've already lost.

0cr
Avg. breach cost, 2025 - highest globally
0days
To identify & contain a breach
Average data-breach cost, ₹ crore (2016 → 2025)Source: IBM
Case study · AIIMS DelhiPart 1 - The Problem

When reacting fails उदाहरण

One breach took down India's top hospital.

0M
Patient records exposed (~4 crore)
0days
Offline - AIIMS ran entirely on paper

Where it went wrong चूक

  • 01No network segmentationRansomware spread freely across all five servers.
  • 02No usable offline backupsRecovery dragged on for nearly two weeks.
  • 03No early detectionPurely reactive - the intrusion was caught only after impact.
Delhi AIIMS ransomware attack, Nov 2022 · ₹200 cr ransom reportedly demandedSource: CERT-In · press reports
$ ./Cyber Threat Intelligence --load part-02 "the-solution" 04 - 05 Part Two · भाग दो

The Solution समाधान

How Cyber Threat Intelligence works - and the payoff.

  1. 04 The Cyber Threat Intelligence lifecycle
  2. 05 How Cyber Threat Intelligence helps
04 · The Cyber Threat Intelligence lifecyclePart 2 - The Solution
  1. 01DirectionWhat do we need to know?
  2. 02CollectionFeeds, OSINT, dark web, logs
  3. 03ProcessingNormalise & structure
  4. 04AnalysisTurn data into intelligence
  5. 05DisseminationDeliver to the right teams
  6. 06FeedbackRefine & repeat the loop
Standards in practice: STIX / TAXII · MITRE ATT&CK
05 · How Cyber Threat Intelligence helpsPart 2 - The Solution
proactive-reactive

Reactive → proactive समाधान

  • Proactive defenceBlock threats before they hit.
  • PrioritisationFocus on threats that target your sector.
  • Faster responseContext speeds detection & containment.
  • Lower costPrevention ≪ recovery.
This is the payoff - the shift from reacting to anticipating.
$ ./Cyber Threat Intelligence --load part-03 "india-in-focus" 06 - 07 Part Three · भाग तीन

India in Focus भारत

The real challenges - and the shield already being built.

  1. 06 Challenges in India
  2. 07 The Indian ecosystem
06 · Challenges in IndiaPart 3 - India in Focus

What's holding us back चुनौतियाँ

  • 01Talent is expensive & scarce Analysts who read TTPs, geopolitics & malware are rare.
  • 02Exploding attack surfaceUPI, mass digitisation, insecure IoT in smart cities.
  • 03Reluctance to share intelReputation, privacy & competitive worries.
  • 04Reactive mindsetSecurity seen as IT cost → underinvestment.
  • 05Data overload, no contextNoise without correlation to adversary TTPs.
smart-city
Cross-border enforcement remains a major hurdle.
07 · The Indian ecosystemPart 3 - India in Focus

Cyber Threat Intelligence in the Indian context भारत

The shield is already being built.

CERT-In

CERT-In

National nodal incident response - runs the automated Cyber Threat Intelligence exchange.

NCIIPC

NCIIPC

Protects critical information infrastructure - power, telecom, banking.

I4C

I4C

Cybercrime coordination under the Ministry of Home Affairs.

CSIRT-Fin

CSIRT-Fin

Sectoral CERT for the BFSI ecosystem.

RBISEBINPCIIRDAI

Regulators

RBI · SEBI · NPCI · IRDAI enforce sector cyber norms.

6-hour breach-reporting mandate (CERT-In, 2022)
Conclusion · निष्कर्षThank you

Conclusion निष्कर्ष

“Reactive security is no longer enough.”

See the threat before it sees you. Cyber Threat Intelligence is the shield that turns India's defence proactive.

Thank you · Questions?Cyber Threat Intelligence · India - 2026