New Delhi: The government has introduced new rules to strengthen cybersecurity in India’s telecom sector. Telecom operators must now report any security incidents to the government within six hours and provide detailed updates within 24 hours.
These rules, issued under the Indian Telecommunication Act, aim to protect communication networks from cyber threats. Telecom companies are required to adopt a cybersecurity policy covering areas such as risk assessment, network testing, employee training, and rapid response to security incidents.
A key aspect of the rules allows the government or its authorised agencies to access telecom data, excluding the content of messages, to ensure cybersecurity. Companies must also set up the necessary infrastructure to securely collect and store this data.
Telecom operators will need to appoint a Chief Telecommunication Security Officer to oversee compliance and handle security-related matters. Manufacturers of telecom equipment are also required to register the International Mobile Equipment Identity (IMEI) numbers of devices made in India before they are sold.
The rules prohibit activities that could compromise telecom security, such as using networks or equipment for fraud or transmitting harmful messages. Companies must take proactive steps to identify and fix vulnerabilities in their systems. This includes testing networks for weaknesses, implementing safeguards, and learning from past incidents to prevent future ones.
These measures are part of the government’s broader push to secure India’s digital infrastructure amid rising cyber risks. By holding telecom operators accountable for their cybersecurity practices, the rules aim to protect millions of users and ensure reliable communication networks across the country.





































