New Delhi: Cybersecurity in Indian Public Sector Undertakings (PSUs) is a critical concern involving regulatory compliance, data protection, risk assessment, incident response, and network and endpoint security.
PSUs must secure sensitive data, implement strict access controls, and train employees in security best practices. At APAC’s 2nd PSU Tech Conclave held in New Delhi, Sanjay Kumar Das, the then Joint Secretary, Department of Information Technology & Electronics, and State Information Security Officer, Government of West Bengal and present Managing Director of WEBEL, talked about the importance of enhancing cybersecurity efforts across Indian PSUs, which often manage critical infrastructure and public services.
Das said, “India is at the threshold of witnessing relentless ransomware attack.” Collaboration and participation in government initiatives, such as the National Cyber Security Policy and National Critical Information Infrastructure Protection Centre, play a crucial role in ensuring protection from such attacks.
WEBEL
The West Bengal Electronics Industry Corporation Limited (WEBEL) functions under the jurisdiction of the Department of Information Technology and Electronics (DITE). It promotes and develops the electronics and information technology industry within the state. WEBEL engages in various activities, including industrial infrastructure development, investment facilitation, skill development, software and IT services, and research and development, to support the growth of these sectors in West Bengal.
WEBEL has taken serveal initiatives, like the Webel Education and Training initiative, Webel Learning Services, and the Cyber Security Centre of Excellence (CS-CoE), to impart cyber security and cyber hygeine training. Das says, “Electricity is the blood of information technology. You stop electricity, there is no information technology.”
Critical Information Infrastructure
Critical Information Infrastructure (CII) refers to the systems, networks, and assets that, if compromised, could have a severe and far-reaching impact on a nation’s security, economy, public health, or safety. These encompass telecommunications, energy grids, financial systems, transportation, healthcare, government databases, and more. Protecting CII from physical and cyber threats is a top priority, with governments and organisations implementing strict security measures to ensure the continuous operation of essential services and to guard against potential vulnerabilities and disruptions that could have catastrophic consequences.
Cyber Crisis Management Plan
A Cyber Crisis Management Plan is a comprehensive strategy that organisations or government entities use to respond to significant cybersecurity incidents effectively. It details how to identify and report incidents, establish response teams with defined roles, set up communication protocols, analyse the incident’s nature, contain and eradicate threats, and ultimately restore normal operations. It also addresses legal and regulatory compliance, public relations, and post-incident analysis for continuous improvement. This plan is essential for mitigating damage during cyber crises, maintaining trust, and demonstrating a commitment to cybersecurity best practices.
Pain points of security in Public Sector
High value data: The public sector deals with sensitive and personal data (like credit card numbers, financial records, healthcare data, government and defence information, employee records, payment data, data related to critical infrastructure, and more), and safeguarding this information from breaches and unauthorised access is a significant concern.
- Large attack surface: Public sector organisations often have a wide range of systems, networks, and IT infrastructure, which can include legacy systems, newer technologies, and third-party services. Each of these components can introduce potential vulnerabilities.
- Decentralised IT Environment: Public sector units may be spread across various departments or agencies, each with its own IT systems and networks. This decentralised structure can lead to inconsistencies in security measures and gaps that attackers can exploit.
- Limited Cybersecurity Policies: Limited cybersecurity policies in the public sector can result in undefined responsibilities, inadequate access controls, poor password management, inadequate training, incomplete data protection, non-compliance, and other vulnerabilities, risking data breaches and security incidents.
- Regulatory compliance challenges: Public sector organisations are often subject to a multitude of regulations and compliance requirements. Ensuring compliance across various systems and services can be challenging, and non-compliance can lead to security risks.
- Limited funding: Public sector organisations often face limited budgets, making it challenging to invest in advanced security technologies and personnel.
- Insider Threats: Public sector units may have a large and diverse workforce, making it difficult to monitor and prevent insider threats. Disgruntled or negligent employees can pose significant risks.
- Versatile compliances: In the public sector, versatile compliances refer to the challenge of navigating diverse and often overlapping regulatory and compliance requirements, which can lead to complexity, resource allocation issues, and potential conflicts in meeting the necessary security standards across various jurisdictions and sectors within the public sector.
Cyber Hygiene Practices
To counter these pain points Das suggests cyber hygiene practices, which, in PSUs, involve a range of measures to maintain strong cybersecurity, like promoting strong password management, keeping systems updated with security patches, providing ongoing employee training in cybersecurity awareness, enforcing access controls, and encrypting sensitive data.
PSUs should also develop and test incident response plans, conduct regular security audits, and establish secure backup and recovery procedures. They should also focus on securing Wi-Fi networks, mobile devices, and third-party vendor relationships, while also implementing robust email and web security solutions and ensuring compliance with cybersecurity policies, regulations, and standards.
By following these practices, PSUs can keep their data and systems safe, lower the risk of security issues, and ensure they can provide vital public services without interruptions.










































