Most departments have no operational process to report a breach within 6 hours
02
Citizen data protection
Aadhaar, PAN, voter ID handling under DPDP and pre-existing acts
03
Critical infrastructure
NCIIPC-designated assets need additional controls
04
Insider threat
Privileged user audit, segregation of duties, log retention for forensic review
05
Vendor lock-in risk
Dependence on single-vendor SaaS without exit strategy or data portability
06
Procurement security
Cybersecurity clauses in tenders, supply chain risk assessment
Who this is for
Central and state government departments, public sector undertakings, defence-adjacent organisations, government-owned health and financial institutions, and any agency processing citizen data.