Abstract
India's rapid digitalisation has transformed the manner in which individuals, businesses, and public institutions communicate, transact, and store information, while also creating new opportunities for cybercrime and digital security threats. This paper examines the legal framework governing cyber security in India, with particular emphasis on the Information Technology Act, 2000 and the regulatory mechanisms developed around it. It analyses emerging challenges including financial cyber fraud, cyberstalking, identity-based offences, intermediary liability, cross-border cybercrime, and institutional limitations in investigation and enforcement. The paper further examines the practical difficulties arising from the increasing sophistication and speed of cyber attacks, using the Cosmos Bank cyberattack as an illustrative case study. It argues that although India's existing legal framework provides a substantial foundation for addressing cyber offences, significant gaps remain in institutional capacity, cross-border enforcement, digital forensics, and regulatory coordination. The paper concludes by suggesting measures to strengthen enforcement, improve institutional coordination, enhance international cooperation, and develop a more effective and responsive cyber security framework.
Keywords: Cyber Security, Information Technology Act, 2000, Cybercrime, Financial Cyber Fraud, Intermediary Liability, Data Protection, Cyber Law, India