Numbers like this tend to wash over people the first time they read them. Twenty-nine lakh. Almost 30 lakh cyber security incidents, recorded across India in a single year. It's easy to nod at a figure that large and move on to the next headline.
It's worth pausing on this one instead, because the number isn't really about last year. It's about the direction things are moving, and how fast.
India recorded 29.44 lakh cyber security incidents in 2025 — an 85% increase from the 15.92 lakh incidents logged just two years earlier, in 2023. The government shared these figures in a written reply to Parliament on 12 August, tracked by CERT-In, the Indian Computer Emergency Response Team designated under Section 70B of the Information Technology Act, 2000, to respond to cyber incidents nationally.
Laid out year by year, the trajectory is hard to misread:
* 2023: 15.92 lakh incidents
* 2024: 20.41 lakh incidents
* 2025: 29.44 lakh incidents
That's not a spike. That's a steady, accelerating climb — nearly doubling in two years, with each year's increase larger than the one before it.
It would be easy to read an 85% jump as a story about India getting less secure. The more accurate story is a little more layered than that.
Part of this rise reflects a genuinely expanding attack surface — more government services, more citizen platforms, more of daily life moving online, and each new digital touchpoint is one more thing that can be targeted. But part of it also reflects something more encouraging: better detection. An incident that would have gone unnoticed or unreported a few years ago is far more likely to be caught, logged, and acted on today, simply because the infrastructure to catch it has matured.
Both things are true at once. The threat landscape really is growing. And the country's ability to see that landscape clearly is growing too. The second part matters, because you can't defend against what you can't see — and for a long time, a lot of this activity was effectively invisible.
What stands out reading through the government's disclosure isn't just the incident count — it's how much coordinated infrastructure has been quietly assembled around it.
* A layered national defence structure now sits behind the headline number. The National Cyber Security Coordinator, under the National Security Council Secretariat, coordinates across agencies. The National Cyber Coordination Centre, run by CERT-In, monitors cyberspace and shares threat intelligence with state governments and sector regulators. For systems classified as critical infrastructure — the kind whose disruption could genuinely affect national security, the economy, or public health — the National Critical Information Infrastructure Protection Centre (NCIIPC) provides near real-time threat intelligence and runs periodic vulnerability assessments.
* Sector-specific response teams have started coming online. CSIRT-Fin, covering banking and financial services, has been operating since May 2022. CSIRT-Power, extending CERT-In's reach into the power sector, went live in September 2024 — a meaningful signal that critical infrastructure sectors are now being treated as distinct threat environments requiring their own specialized response capability, not a one-size-fits-all national approach.
* Baseline security standards are being enforced structurally, not just recommended. CERT-In has empanelled 237 information security auditing organisations to conduct vulnerability assessments and penetration testing, and every government website and application is now required to be audited before it goes live, with regular audits continuing afterward. That's a real, enforced gate — not a best-practice suggestion sitting in a policy document somewhere.
* Citizen-level protection exists too. The Cyber Swachhta Kendra — a botnet-cleaning and malware-analysis centre extending the Swachh Bharat vision into cyberspace — detects malicious programs on individual devices and offers free removal tools, alongside basic security guidance for people who may never have had a reason to think about any of this before.
The infrastructure story is only half of it. The other half is about people, and it's arguably the more important half.
Through the Information Security Education and Awareness (ISEA) project, run by the Ministry of Electronics and Information Technology, the country has conducted 6,650 awareness workshops, reaching over 11.37 lakh participants — students, teachers, law enforcement personnel, government officials, and ordinary citizens. Kerala alone accounted for 70 of those workshops, reaching 9,481 participants.
Training materials — handbooks, short videos, posters, brochures, even cartoon stories written specifically for children — have been published in multiple languages and pushed out through print, television, social media, and dedicated government portals. On the more specialized end, CERT-In's industry-collaboration training programmes trained 20,799 participants across 32 programmes in 2025 alone, with another 12,109 participants across 13 programmes in the first half of 2026.
There's a version of cyber security awareness that stays confined to security teams and IT departments. This is deliberately not that. This is an attempt to build a baseline of digital literacy across an entire population — because a huge share of real-world incidents don't start with a sophisticated exploit. They start with someone clicking the wrong link, because nobody ever showed them what the wrong link looks like.
It's tempting to read a story about government cyber statistics and file it under "not my problem." That would be a mistake, for a few concrete reasons.
The same growth curve applies to you. The 85% rise in incidents isn't confined to government systems — it reflects the overall threat environment every organization operating in India is sitting inside right now, whether or not it shows up in your own logs yet.
Regulatory expectations are rising in parallel. The government's own disclosure specifically points to the Digital Personal Data Protection Act, 2023, and the rules framed under it, as part of the strengthened statutory framework — a reminder that legal obligations around how personal data is handled and secured are not static, and are tightening rather than loosening.
The empanelment model is a signal, not just a government procurement detail. CERT-In requiring 237 vetted, audited organisations to test government systems reflects a broader principle worth sitting with: security testing conducted by qualified, independent specialists has become the baseline expectation for anything handling sensitive systems or citizen data — not an optional extra layered on afterward.
Twenty-nine lakh incidents in a year is a big number precisely because it's not abstract. It represents almost three million individual moments where something — a system, a device, a piece of data — was targeted, probed, or compromised. Some of those moments were caught quickly because the infrastructure to catch them now exists. Some almost certainly weren't.
The trajectory here matters more than any single year's total. Fifteen lakh, to twenty, to twenty-nine — climbing steadily, not spiking randomly. Whatever the number looks like when it's reported again next year, the organizations that come out ahead of it won't be the ones who read a statistic like this and moved on. They'll be the ones who took it as a reason to actually check where they stand.