UPSC MainsGeneral Studies Paper IInternal SecurityPractice question

Dual Role of AI in Cybersecurity and Critical Infrastructure

With India witnessing a record surge in the economic costs of data breaches and sophisticated cyber threats, examine the dual role of artificial intelligence as both a tool for executing cyberattacks and a mechanism for cyber defence. Suggest measures to enhance the cyber-resilience of India's critical infrastructure.

ExamineSuggest~250 words3 min readmedium
Attempt it first, timed · optional

Write the answer on paper, as in the exam. Start the timer, keep to the word target.

00:00/ 11 min · 250 words

Done writing? Photograph the sheet and see how it scores against this model answer, with feedback on what to fix.

Upload your answer sheet

How to approach

Introduce the context using recent data breach trends and the expanding digital attack surface. In the body, examine AI as an offensive weapon versus a defensive shield, then suggest structural, technical, and regulatory measures to strengthen India's Critical Information Infrastructure (CII). Conclude by emphasizing the shift from reactive mitigation to predictive resilience.

Model answer

418 words

Introduction

According to IBM's Cost of a Data Breach Report 2024, the global average cost of a data breach has reached an all-time high of $4.88 million. As India's attack surface expands rapidly through Digital Public Infrastructure (DPI) and smart technologies, Artificial Intelligence (AI) has emerged as a double-edged sword, revolutionizing both offensive cyber warfare and proactive defense mechanisms.

The Dual Role of Artificial Intelligence in Cyberspace

Artificial intelligence functions as an asymmetric multiplier, empowering both malicious actors and defensive systems.

1. AI as an Offensive Tool (Executing Cyberattacks)

  • Polymorphic Malware: Threat actors use generative AI algorithms to dynamically modify malicious source code and payloads, effectively bypassing conventional signature-based antivirus solutions.
  • Automated Reconnaissance: AI scrapers rapidly identify exposed attack surfaces and map unpatched vulnerabilities across critical networks and web-facing servers.
  • Hyper-Personalized Phishing: Threat actors deploy Large Language Models (LLMs) and deepfakes to craft high-context spear-phishing emails and voice clones targeting senior administrators.

2. AI as a Defensive Mechanism (Cyber Defence)

  • Predictive Threat Hunting: Machine learning models analyze massive volumes of telemetry and anomalous network traffic to preemptively detect zero-day exploits.
  • Automated Breach Containment: Integrated AI Security Orchestration, Automation, and Response (SOAR) frameworks isolate compromised endpoints in seconds, drastically cutting breach dwell time.
  • User and Entity Behavior Analytics (UEBA): AI benchmarks baseline activity across institutional networks, flagging lateral movements and unauthorized credential use in real time.

Measures to Enhance Cyber-Resilience of Critical Infrastructure

Safeguarding Critical Information Infrastructure (CII) requires a multi-layered defense-in-depth framework spanning governance, architecture, and workforce capabilities.

  • Sector-Specific Hardening: Mandate strict compliance with National Critical Information Infrastructure Protection Centre (NCIIPC) guidelines across India's designated CII sectors: Energy, Transport, Telecom, Banking, Strategic Enterprises, and Government.
  • Zero-Trust Architecture (ZTA): Transition away from legacy perimeter security toward strict, continuous identity and access verification ("never trust, always verify") using micro-segmentation.
  • Supply Chain Risk Management (SCRM): Mandate comprehensive hardware trust audits and firmware validation for Operational Technology (OT) and SCADA systems to mitigate embedded backdoors from untrusted foreign vendors.
  • Institutional and Legal Enforcement: Strictly enforce data minimization principles under the Digital Personal Data Protection (DPDP) Act, 2023, and strengthen the operational coordination between CERT-In and sector-specific Computer Emergency Response Teams.
  • Capacity Building and Specialised Commands: Scale the civilian cyber workforce via initiatives like FutureSkills Prime, while bolstering the Defence Cyber Agency (DCyA) to counter state-sponsored Advanced Persistent Threats (APTs).

Conclusion

India's cybersecurity posture must transition from reactive incident mitigation to predictive, continuous resilience. Harmonizing AI-powered automated defense with rigorous hardware supply chain audits will safeguard the nation's critical infrastructure against increasingly sophisticated asymmetric threats.

Key facts to remember

statistic

The average cost of a data breach globally reached $4.88 million in 2024, representing a 10% annual increase and a record high.

IBM Cost of a Data Breach Report 2024
definition
Critical Information Infrastructure (CII)

As defined under Section 70 of the Information Technology Act 2000, CII refers to any computer resource whose incapacitation or destruction would have a debilitating impact on national security, economy, public health, or safety.

scheme
Digital Personal Data Protection (DPDP) Act 2023

An Act of Parliament that governs digital personal data processing, mandating reasonable security safeguards and obligations on data fiduciaries to prevent breaches.

Frequently asked questions

What is Zero-Trust Architecture (ZTA)?

Zero-Trust Architecture is a cybersecurity paradigm requiring strict, continuous authentication, authorization, and validation for every user and device attempting to access network resources, regardless of whether they are located inside or outside the corporate perimeter.