Ramashankar Dasharath Singh
CYBER TERRORISM AND LAW
-Ramashankar Dasharath Singh
Abstract
Cyber terrorism refers to the use of technology to commit acts of terror and violence against individuals, organizations, or governments. With the rise of the internet and digital technology, cyberterrorism has become a growing concern for law enforcement and security agencies. The purpose of this article is to examine the issue of cyberterrorism and the laws surrounding it. The internet has created a new arena for terrorists to operate, allowing them to remain anonymousand evade detection. Cyberterrorists use various tactics such as website defacement, denial of service attacks, and malware to spread fear and cause harm. These attacks can cause significant damage to critical infrastructure, steal sensitive information, or even disrupt entire economies. In response to the threat of cyberterrorism, governments around the world have introduced laws andregulations aimed at preventing and combating these crimes. The United States has enacted the Computer Fraud and Abuse Act (CFAA) to criminalize unauthorized access to protected computer systems and the theft of confidential information. Additionally, the Electronic Communications Privacy Act (ECPA) provides for the interception of electronic communicationsfor law enforcement purposes. Similarly, the European Union has enacted the Network and Information Systems Directive (NISD) to ensure the security of critical infrastructure, including the protection of networks and systems against cyberattacks. The NISD also requires organizations to report incidents of cybercrime to the relevant authorities. International law has also played a role in addressing cyberterrorism. The Council of Europe Convention on Cybercrime aims to provide a harmonized approach to addressing cybercrime and cyberterrorism, including the suppression of illegal activities and the protection of privacy and personal data. The United Nations also has a number of initiatives aimed at promoting the peaceful use of information and communication technologies and preventing their abuse for malicious purposes. The need for effective laws to address cyberterrorism is becoming increasingly pressing as the number of incidents continues to rise, and it is important forgovernments and international organizations to work together to develop a comprehensive approach to this threat.
Keywords: cybercrime, criminalize, cyberterrorism, malicious, government.
Introduction:
Cyberterrorism is a relatively new phenomenon that has emerged with the advancement of technology and the increasing reliance on digital systems and networks. It refers to the use of the internet and other forms of technology for the purpose of promoting and perpetrating acts of terrorism. The use of technology in this way presents a unique set of challenges and concerns, both in terms of the potential impact on society and the difficulties in preventing and responding to cyberattacks. Cyberterrorism can take many forms, including the spread of propaganda and recruitment efforts, the theft of sensitive information and the use of malware to disrupt critical infrastructure and essential services. The consequences of cyberterrorism can be far-reaching, with the potential to cause widespread disruption, loss of life, and economic damage.
In response to the threat of cyberterrorism, national governments and international organizations have developed a range of laws and regulations to address the issue. The development of these laws and regulations has been a slow and evolving process, as the law has struggled to keep pacewith the rapid advancements in technology. However, there have been significant developments in recent years, and many countries now have specific legislation in place to address cybercrime, including cyberterrorism. One of the key challenges in developing laws and regulations to address cyberterrorism is the nature of the internet itself. The internet is a global network, which means that cyberattacks can originate from anywhere in the world and target anyone, anywhere. This makes it difficult for national governments to respond effectively to cyberattacks, and raisesquestions about jurisdiction and the extent to which different countries should be responsible for regulating the internet.
Another challenge in addressing cyberterrorism is the need to balance security and privacy. While it is important to have measures in place to prevent and respond to cyberattacks, it is also important to ensure that these measures do not infringe on the rights and freedoms of individuals.This requires a careful balancing of interests, and the development of laws and regulations that are both effective and respect the rights of citizens
The laws and regulations that have been developed to address cyberterrorism can be grouped into several categories, including:
]Laws and regulations that deal with the actual commission of cyberattacks, including the theftof sensitive information, the spread of malware and the disruption of critical infrastructure.
Laws and regulations that deal with the dissemination of propaganda and recruitment efforts by terrorists, including the use of the internet and social media for these purposes.
Laws and regulations that deal with the activities of individuals and organizations that support cyberterrorism, including the provision of funding, the development of malware, and the hosting of websites and other resources used by terrorists.
Laws and regulations that deal with the role of service providers and technology companies in preventing and responding to cyberattacks.
International agreements and treaties that set standards for the exchange of information and cooperation between countries in the fight against cyberterrorism.
The threat of cyberterrorism is a significant concern for national governments and international organizations. The development of laws and regulations to address this threat is an ongoing process, and requires a careful balancing of security and privacy.
Meaning:
Cyber terrorism is defined as unlawful attacks and threats against computers, networks, and information stored on them in order to intimidate or coerce a government or its people in furtherance of some political or social goals.
Merriam Webster defines Cyberterrorism as “terrorist activities intended to damage or disrupt vital computer systems”.1
1 Cyberterrorism Definition & Meaning – Merriam-Webster,
https://www.merriam-webster.com/dictionary/cyberterrorism (last visited Feb 13, 2023).
While the Cambridge Dictionary defines it as “the use of the internet to damage or destroy computer systems for political or other reasons”.2
Cyberterrorism is a global threat that requires a coordinated international response. The lack of clear international legal frameworks and the cross-border nature of digital attacks make itdifficult for governments to effectively combat cyberterrorism. In many cases, the perpetrators ofcyberattacks are difficult to identify, and the complexity of digital networks and the speed at which they can spread malware make it challenging to respond in a timely manner. To address the challenges posed by cyberterrorism, many countries have enacted laws to protect against digital attacks. These laws typically focus on protecting critical infrastructure, providing law enforcement with the necessary powers to combat cybercrime, and establishing legal frameworks for the prosecution of cybercriminals.
Research Objectives:
The objective of writing this paper is to elaborately research on the field of cybercrime and cyberterrorism. Get insights on cyberterrorism in India and its legal ramifications. Highlight upon the initiatives taken by the international community and our country to combat cyberterrorism.
Hypothesis
Cyber terrorism is on the rise as a result of the government’s policies and laws, so we must tighten our security systems, policies, initiatives, and punishments to combat it.
Methodology:
The research design adopted for this study is qualitative research design. Qualitative research is appropriate for this study as it enables an in-depth exploration of the complex and multifaceted nature of cyberterrorism.
Scope of Cyberterrorism
Cyberterrorism refers to the use of digital technology and the internet for the purpose of perpetrating terror or inciting fear in a population. In recent years, cyberterrorism has become a growing threat to the global community, and India is no exception. India has a rapidly growing economy that is highly dependent on digital technology, and as such, the country is particularly vulnerable to cyberattacks that could impact its economy, social stability, and national security.
The scope of cyberterrorism in India has become increasingly broad in recent years, with the country experiencing a range of cyberattacks that have caused widespread disruption and damage. One of the most notable forms of cyberterrorism in India has been the use of ransomware attacks. Ransomware attacks are a type of cyberattack that encrypts a victim’s dataand demands payment in exchange for the decryption key. These types of attacks have become increasingly common in India and have targeted a range of organizations, including government agencies, businesses, and educational institutions.
Another form of cyberterrorism that has become prevalent in India is phishing attacks. Phishing attacks are designed to trick victims into disclosing sensitive information, such as passwords and bank account details, by sending emails or messages that appear to be from a trustworthy source. These attacks are often used to steal sensitive information or to spread malware. In India, phishing attacks have become increasingly common and have targeted a range of organizations and individuals, including government employees and private sector employees.
The scope of cyberterrorism in India also extends to the use of social media platforms for the spread of false or misleading information. The use of social media has become a powerful tool for extremists and terrorists to spread propaganda, incite fear, and mobilize support for their causes. In India, the use of social media to spread false or misleading information has become a major concern, particularly during periods of social unrest or political turmoil.
In addition to the above-mentioned forms of cyberterrorism, India has also faced a range of other cyberattacks, including denial of service (DDoS) attacks, malware attacks, and data breaches. These attacks have impacted a range of organizations and individuals and have caused widespread disruption, damage, and loss of sensitive information. In response to these threats,the Indian government has taken a number of steps to enhance the country’s cybersecurity, including the establishment of a National Cybersecurity Coordination Centre (NCCC) and the development of a National Cybersecurity Policy.
Check Point Research (CPR)3 released new data on 2022 cyber attack trends showing that global cyber attacks increased by 38% in 2022, compared to 2021. These cyber attack numbers were driven by smaller, more agile hacker and ransomware gangs, who focused on exploiting collaboration tools used in work-from-home environments, targeting education institutions that shifted to e-learning post COVID-19.
This increase in global cyber attacks also stems from hacker interest in healthcare organisations, which saw the largest increase in cyber attacks in 2022, when compared to all other industries. CPR warns that the maturity of AI technology, such as CHATGPT, can accelerate the number of cyber attacks in 2023.
Threats posed by cyber terrorism:
Data Breaches: Cyber terrorists can break into computer systems, steal sensitive information and cause massive data breaches that put individuals, organizations, and evennations at risk.
Infrastructure Disruptions: Cyber terrorism can also result in the disruption of critical infrastructure systems such as power grids, transportation systems, and financial systems, potentially causing widespread harm.
Financial Losses: Cyberattacks carried out by terrorists can cause significant financial losses for individuals and organizations, particularly small businesses that may not have the resources to recover.
Intellectual Property Theft: Terrorists can also use cyberattacks to steal sensitive intellectual property, putting companies at a disadvantage in the global market.
Reputation Damage: Cyber terrorism can also cause significant damage to a company’s reputation, as news of a breach can spread rapidly and affect public perception.
Political Instability: Cyberterrorism can also have political implications, as it can be used to disrupt elections or destabilize governments by leaking sensitive information or launching cyberattacks on government websites.
Psychological Trauma: The fear and uncertainty caused by cyber terrorism can have a profound psychological impact on individuals and communities, leading to stress, anxiety, and even post-traumatic stress disorder (PTSD).
Public Safety Threats: In some cases, cyber terrorism can also pose a direct threat to public safety, as terrorists could potentially use cyberattacks to target emergency responsesystems or disrupt transportation systems.
Global Interconnectivity: With the increasing interconnectivity of global systems, cyber terrorism has the potential to cause widespread harm across national borders, making it a global threat.
Cyber terrorists’ potential targets include:
Cyber terrorism refers to the use of digital technology to carry out acts of terrorism, including cyberattacks on critical infrastructure, websites, and communication networks. As our world becomes increasingly dependent on digital technology, the threat of cyber terrorism continues to grow. One potential target is critical infrastructure, such as power grids, water treatment plants, and transportation systems. A cyberattack on these systems could cause widespread disruption and chaos, potentially leading to widespread power outages, water shortages, or transportation disruptions. For example, a cyberattack on a power grid could result in blackouts and widespreaddisruption of essential services, while a cyberattack on a water treatment plant could contaminatethe water supply, leading to widespread health concerns. Another potential target of cyberterrorism is financial institutions, such as banks and stock exchanges.
This organization hold vast amounts of sensitive financial information and control significant portions of the global economy.
Websites and communication networks are also potential targets of cyber terrorism. A cyberattack on these networks could result in the shutdown of websites, the compromise of sensitive information, or the disruption of communications. For example, a cyberattack on a major social media network could result in the dissemination of false information, causing panic and confusion among the general public.
Finally, government and military organizations are also potential targets of cyber terrorism. A cyberattack on these organizations could compromise sensitive information, disrupt operations,or cause widespread panic and confusion. For example, a cyberattack on a military networkcould compromise sensitive information and disrupt operations, while a cyberattack on a government website could result in the dissemination of false information, causing widespread panic and confusion. As our world becomes increasingly dependent on digital technology, it is crucial that we take steps to mitigate the threat of cyber terrorism, including implementing robustcybersecurity measures, improving our ability to respond to cyberattacks, and developing international norms and agreements to govern state behavior in cyberspace.

(Source: Statista Technology Market Outlook, National Cyber Security Organisations, IMF)
Cyberspace exploitation
Cyberspace exploitation refers to the illegal use of computer networks, information technology systems, and the internet to carry out malicious activities such as theft, fraud, and cyber attacks. These activities often result in significant financial losses, damage to reputation and identity, and threat to national security.
One of the most common forms of cyberspace exploitation is hacking, where individuals or groups gain unauthorized access to computer systems, networks, and personal information.Hackers use various techniques to bypass security systems and gain access to sensitive information, such as passwords, financial data, and personal identification. They then use this information for malicious purposes, such as identity theft, financial fraud, and data manipulation.
Another form of cyberspace exploitation is phishing, where individuals or groups send emails or messages that appear to be from legitimate sources, such as banks, retailers, or government agencies, to trick individuals into revealing their personal information or downloading malware onto their computer.
Cyberspace exploitation also includes the use of malware, such as viruses, Trojans, and spyware, which can infect computers and cause significant harm to individuals, organizations, and entire networks. Malware can be used to steal personal information, carry out cyber attacks, and damage computer systems.
Cyberspace exploitation is a significant threat to national security, as malicious actors can use the internet to carry out cyber attacks on critical infrastructure, such as power grids, water treatment plants, and financial systems. These attacks can cause widespread harm, disrupt essential services, and pose a threat to national security. It is crucial for individuals and organizations to take steps to secure their computer systems and networks, and for governments to take steps to protect critical infrastructure. Only through education, awareness, and proactive security measures can we prevent the harm caused by cyberspace exploitation.
Infamous incidents of cyber terrorism
Over a two-week period in 1998, ethnic Tamil guerrillas bombarded Sri Lankanembassies with 800 e-mails per day. “We are the Internet Black Tigers, and we’re doing
This to disrupt your communications,4” the messages said. It was the first known terrorist attack on a country’s computer systems, according to intelligence officials.
During the Kosovo conflict in 19995 hacktivists protesting NATO bombings targeted NATO computers with e-mail bombs and denial-of-service attacks. According to reports, businesses, public organisations, and academic institutions received highly politicised virus-laden e-riis from a variety of Eastern European countries. Web defacement was also prevalent.
The Electronic Disturbance Theater (EDT) has been conducting Web sit-ins againstvarious sites in support of the Mexican Zapatistas since December 19976. Thousands of protestors point their browsers to a target site at a predetermined time, using software thatfloods the target with rapid and repeated download requests. Animal rights organisations have also used EDT’s software against organisations accused of animal cruelty. Another group of hacktivists, the electro hippies, staged Web sit-ins against the WTO when they met in Seattle in late 1999.
One of the most heinous cases of cyber terrorists at work occurred when crackers in Romania illegally gained access to the computers controlling the life support systems at an Antarctic research station, putting the 58 scientists on the line.
In May 2007, Estonia was subjected to a mass cyber attack by hackers inside the Russian Federation, which some evidence suggests was coordinated by the Russian government, though Russian officials deny any knowledge of this. This attack appears to have been in retaliation for the removal of a Russian World War II war memorial from downtown Estonia.
In January 2021, Hackers with ties to the Chinese government deployed ransomware attacks against five major gaming companies. They demanded over $100 million in ransom.
4 By BA Athulasiri Kumara Samarakoon, The 3 rd International Conference on Humanities and Social SciencesEthnic Wars on Cyberspace: Case of Tamil Tigers and the Majoritarian Sinhalese State in Sri Lanka Proceedings-Culture and Defining of Meaning (2011), www.tamilnet.com, (last visited Feb 13, 2023).
5 NATO – Topic: Kosovo Air Campaign (March-June 1999), https://www.nato.int/cps/en/natohq/topics_49602.htm (last visited Feb 13, 2023).
6 The Zapatista Movement: The Fight for Indigenous Rights in Mexico – Australian Institute of International Affairs
– Australian Institute of International Affairs,
/ (last visited Feb 13, 2023).
In February 2021, Hackers tried to contaminate the water supply of Oldsmar, Fla., byexploiting a remote access system to increase the amount of sodium hydroxide present.
The Polish government said it suspected Russian hackers had taken control of Poland’s National Atomic Energy Agency and Health Ministry websites for a short time in March 2021. They tried to spread alarms about a radioactive threat that didn’t exist.
North Korea carried out a cyber attack against South Korea’s state-run Korea Atomic Energy Research Institute by taking advantage of a virtual private network vulnerability in May 2021.
On May 30th 2021, cyber criminals breached the JBS network with ransomware, disrupting plants in the USA, Canada and Australia.
Iran used Facebook to target U.S. military personnel, posing as recruiters, journalists and nongovernmental organization personnel in July 2021. The hackers sent files with malwareand used phishing sites to trick victims into providing sensitive credentials.
In September 2021, Hackers stole 15 terabytes of data from 8,000 organizations working with Voicenter, an Israeli company. The hackers offered the data online for $1.5 million.
Brazilian hackers attacked a website belonging to Indonesia’s State Cyber and Password Agency in October 2021.
Robinhood is a USA-based stock trading app. On November 3rd 2021, data of 7 million userswas stolen and held to ransom by cyber criminals.
A Russian group claimed responsibility for a ransomware attack on CS Energy, an Australian utility company in December 2021.
On 23rd February, Nvidia, a major microchip producer suffered a data breach which saw sourcecode fall into the hands of cyber criminals. The hacking group Lapsu$ claimed responsibilityfor the attack, claiming it had stolen around 1TB of data.
One of the most widespread cyber breaches in history, WannaCry was a global ransomware attack that affected more than 200,000 computers in over 150 countries. WannaCry exploited a vulnerability in unpatched versions of the Windows operating system. This vulnerability was known as ‘EternalBlue’, and had allegedly been developed in the US bythe National Security Agency.
A national emergency was declared in Costa Rica in 2022 in the face of a series of ransomwareattacks against critical institutions. An estimated 800 servers and several terabytes of information in the finance ministry were also impacted by the attacks.
Cyberterrorism v/s conventional attacks in cyberspace
Cyberterrorism and conventional attacks in cyberspace are two distinct forms of malicious cyber activities that pose serious threats to organizations, businesses, governments, and individuals. Both forms of attack have significant impacts on their targets, but they have some differences in terms of their objectives, methods, and consequences.
Cyberterrorism is a form of terrorism that uses the internet, computer networks, and information technology to achieve political or ideological objectives. Cyberterrorists aim to cause fear, panic,and disruption through online attacks that can compromise sensitive information, disrupt critical infrastructure, or cause widespread panic. Cyberterrorists often use social engineering tactics to trick people into giving away their passwords, install malware on their devices, or compromise their personal information.
On the other hand, conventional attacks in cyberspace are malicious activities that target organizations and individuals with the primary goal of theft, destruction, or manipulation of data. These attacks are usually motivated by financial gain, competitive advantage, or personal grudges. Hackers, cybercriminals, and nation-state actors are among the most common perpetrators ofconventional attacks in cyberspace. They use a variety of techniques such as phishing, malware, or advanced persistent threats (APTs) to compromise their targets.
Mitigation Initiatives for Cyberterrorism:
Convention on Cybercrime
The Convention on Cybercrime, also known as the Budapest Convention, is the first international treaty aimed at addressing cybercrime and cyber security. It was adopted by the Council of Europe in 2001 and is the only binding international instrument that provides a comprehensive framework for the fight against cybercrime.
The Convention on Cybercrime establishes common standards for the investigation and prosecution of cybercrime and provides for international cooperation between states to address these crimes. It covers a wide range of offenses including computer-related fraud, child pornography, cyber terrorism, and unauthorized access to computer systems. The Convention also provides for the protection of personal data and electronic privacy, as well as the criminalization of activities such as hacking, phishing, and other forms of cyber attacks.
Global Counter-Terrorism Strategy of the United Nations (UN):
The United Nations (UN) has a crucial role in the global counter terrorism strategy, and it is committed to addressing the threat of terrorism through a comprehensive and coordinated approachwith important pillars countering terrorism:
Measures to address the conditions conducive to the spread of terrorism, includingpoverty, conflict, and human rights violations.
Efforts to prevent and combat terrorism through the strengthening of national capacitiesandthe development of international cooperation.
The protection of human rights and the rule of law, including the promotion of respect forhuman dignity, freedom, and equality.
UN Office for the Prevention of Terrorism (UNOPT):
The United Nations Office for the Prevention of Terrorism (UNOCT) was established in 2017 as a dedicated office within the United Nations Secretariat to prevent and combat terrorism. The UNOCT is responsible for providing a comprehensive approach to preventing terrorism and its underlying drivers, including poverty, inequality, marginalization, and conflict.
The main objective of the UNOCT is to enhance the capacities of Member States to prevent terrorism and to promote cooperation and coordination among UN entities, Member States, and other stakeholders to prevent terrorism. This includes providing technical assistance and capacity-building support to Member States, supporting the implementation of relevant UN counterterrorism measures, and promoting international cooperation to prevent terrorism.
United Nations Security Council (UNSC):
The United Nations Security Council (UNSC) is one of the six main organs of the United Nations and is responsible for maintaining international peace and security. The UNSC has a significant role in addressing the threat of cyberterrorism, as it is the body responsible for the development and implementation of international security measures.
The purpose of the UNSC in addressing cyberterrorism is to ensure that cyberattacks do not escalate into a threat to international peace and security. The UNSC has adopted several resolutions on cyber security and cybercrime, including resolution 1373, which addresses terrorism in general, and resolution 1540, which focuses on the proliferation of weapons of mass destruction. The UNSC has also established a working group on cyber security and cybercrime to discuss and coordinate efforts to address these issues.
Counter-Terrorism Strategy of Brazil, Russia, India, China, and South Africa (BRICS):
The Brazil, Russia, India, China, and South Africa (BRICS) group of countries have emerged as major players in global affairs, and their counter terrorism strategies play an important role in maintaining regional and international security.
In Brazil, the government has adopted a multi-faceted approach to countering terrorism that involves the development of strong laws and regulations, the strengthening of the country’s intelligence and security services, and the promotion of international cooperation.
Shanghai Cooperation Organisation (SCO):
The Shanghai Cooperation Organization (SCO) is a multinational political and economic organization founded in 2001. Its members include China, Russia, Kazakhstan, Kyrgyzstan, Uzbekistan, Tajikistan and India, with several observer states and dialogue partners.
The SCO has taken steps to address the threat of cyberterrorism and increase regional cooperation in the field of cybersecurity. The organization has recognized the increasing importance of the Internet and digital technologies in the modern world, and the potential for these technologies to beused for malicious purposes, such as cyberattacks and cybercrime.
The SCO has established a number of mechanisms to address cyber threats, including thecreation of a Regional Anti-Terrorist Structure (RATS) to coordinate the fight against terrorism, extremism and separatism. Within RATS, there is a working group on information security that aims to enhance cooperation among member states in preventing and combating cybercrime and cyberterrorism
United State of America
Cybersecurity and Infrastructure Security Agency (CISA
Cybersecurity refers to the practice of protecting computer systems, networks, and data from unauthorized access, theft, or damage. It involves implementing various technical, organizational, and physical measures to prevent, detect, and respond to cyber threats.
An estimated 53.35 million US citizens have been affected by cyber crime in the first half of 2022. Between July 2020 and June 2021, the US was the most targeted country for cyber attacks,accounting for 46% of attacks globally. US citizens lost $6.9 billion in 2021 to cyber-related crimes, including romance scams ($956 million), investment scams ($1.4 billion) and business email compromise ($2.39 billion).7
An Infrastructure Security Agency (ISA) is a government agency responsible for overseeing and managing the security of a country’s critical infrastructure, such as its power grid, telecommunications networks, financial systems, and transportation networks. The ISA is responsible for implementing policies, standards, and guidelines to ensure the security of these critical infrastructure assets and to minimize the risk of cyber attacks, natural disasters, and other potential threats.
ISRAEL
Israel is known for its advanced technology and innovative approach to cybersecurity, and its national cybersecurity strategy reflects this reputation. The 2017 National Cybersecurity StrategyofIsrael is a comprehensive plan that outlines the country’s approach to cybersecurity and the measuresit will take to protect its critical infrastructure and citizens from cyber threats.
The strategy focuses on several key areas, including:
Protecting Critical Infrastructure: The strategy places a high priority on protecting Israel’s critical infrastructure, including its energy, financial, and transportation networks, from cyber threats. This includes implementing stronger security measures and increasingthe level of resilience and redundancy in these systems.
Cyber Defense: The strategy calls for the development of advanced cyber defensecapabilities to detect and respond to cyber attacks, including the establishment of a national Cyber Defense Authority to coordinate the country’s cybersecurity efforts.
Cyber Intelligence: Israel recognizes the importance of intelligence in the fight against cyber threats and calls for the development of a comprehensive national cyber intelligence capability.
Cyber Education and Awareness: The strategy also places a strong emphasis on cybersecurity education and awareness, both for the general public and for businesses, to help them better understand and address the risks posed by cyber threats.
International Cooperation: The strategy recognizes the importance of international cooperation in addressing global cyber threats and calls for increased cooperation with other countries and international organizations to enhance cybersecurity efforts.
United Kingdom (UK)
The United Kingdom has a comprehensive national cybersecurity program that aims to protectits citizens, businesses, and critical national infrastructure from cyber threats. The program, which was established in 2009, is managed by the National Cyber Security Centre (NCSC), apart of the intelligence agency GCHQ. In 2022, 39% of UK businesses have experienced a cyber attack, the same as in 2021. However, this has dropped since 2020 (46%)
As of December 2022, 54% of UK businesses have acted to identify cyber security risks, up from 52% in 2021. However, the 2022 figures have dropped compared to 64% in 2020.8
The main objectives of the UK’s cybersecurity national program are:
Protecting Critical National Infrastructure: The program places a high priority on the protection of critical national infrastructure, such as the energy, transportation, and financial sectors, from cyber attacks.
Cyber Defense: The NCSC leads the UK’s efforts to detect and respond to cyber threats, working closely with government agencies, the private sector, and international partners to develop and implement robust cyber defense strategies
Cyber Threat Intelligence: The UK has a comprehensive cyber threat intelligencecapability that provides real-time information on cyber threats to the government and private sector, allowing them to respond more effectively to these threats.
Cybersecurity Awareness and Education: The program also places a strong emphasis on cybersecurity awareness and education, providing guidance and training to individuals, businesses, and other organizations on how to better protect themselves from cyber threats. International Cooperation: The UK recognizes the importance of international cooperationin addressing global cyber threats and works closely with other countries andinternational
organizations to enhance its cybersecurity efforts.
India
Like many countries, India is suffering increasingly from cyber crime. The number of cyber-related crimes reported in 2018 was 208,456. In the first 2 months of 2022 alone, there were 212,485 cyber crimes, more than the entirety of 2018.
The figures rose more sharply through the pandemic, with reported crime jumping from 394,499 cases in 2019 to 1,158,208 in 2020 and 1,402,809 in 2021. Between Q1 and Q2 2022, cyber crime across India increased by 15.3%.
Additionally, there have been an increasing number of Indian websites hacked in recent years.In 2018, some 17,560 sites were hacked. In 2020, an additional 26,121 sites were hacked. 78% of Indian organisations experienced a ransomware attack in 2021, with 80% of thoseattacks resulting in the encryption of data. In comparison, the average percentage of attacks
was 66%, with the average encryption rate at 65%.
Information Technology Act: Cyber Terror Law
The Information Technology Act of India,9 enacted in 2000 and amended in 2008, is a legal framework that governs the use of information technology in India. The act is designed to provide a legal framework for e-commerce and to regulate the use of electronic records anddigital signatures.
9 The Information Technology Act, 2000, Acts of Parliament, 2000 (India).
The Information Technology Act of India contains provisions that relate to cyberterrorism andthe use of information technology for illegal activities. For example, the act criminalizes unauthorized access to computer systems, the unauthorized interception of electronic communications, and the publication of false electronic information that causes harm to individuals or organizations. In addition to these provisions, the act also establishes the Office of the Cyber Appellate Tribunal, which has jurisdiction to hear appeals and disputes arising under the act.
National Cybersecurity Policy:
The National Cybersecurity Policy of India is a comprehensive policy framework that outlinesthe country’s approach to cybersecurity and the measures it will take to protect its critical infrastructure and citizens from cyber threats. The policy was first issued in 2013 and has since been updated to reflect the evolving threat landscape and advancements in technology.
The policy focuses on several key areas, including:
Critical Information Infrastructure Protection: The policy places a high priority on the protection of critical information infrastructure, such as the energy, financial, and transportation networks, from cyber attacks. This includes implementing stronger security measures and increasing the level of resilience and redundancy in these systems.
Cyber Defense: The policy calls for the development of advanced cyber defense capabilities to detect and respond to cyber attacks, including the establishment of a National Cyber Coordination Centre to coordinate the country’s cybersecurity efforts.
Cybercrime Investigation and Prosecution: The policy calls for the development of a comprehensive framework for investigating and prosecuting cybercrime, including the establishment of specialized cybercrime units within law enforcement agencies.
Cybersecurity Awareness and Education: The policy also places a strong emphasis on cybersecurity awareness and education, both for the general public and for businesses, to help them better understand and address the risks posed by cyber threats.
International Cooperation: The policy recognizes the importance of international cooperation in addressing global cyber threats and calls for increased cooperation with other countries and international organizations to enhance cybersecurity efforts.
Legislative reforms in india:
India has made several legislative reforms aimed at improving cybersecurity and addressing the threat of cyberterrorism. Some of the major ones include:
Information Technology Act, 2000: This act provides a legal framework for electronictransactions and regulation of certifying authorities. It also lays down penalties for hacking,cyberstalking, and other cybercrimes.
The Information Technology (Amendment) Act, 2008: This amendment act expanded the definition of cybercrimes and increased the penalties for offenses such as cyber terrorism,identity theft, and cyberstalking.
The Personal Data Protection Bill, 2019: This bill aims to protect the privacy of individuals by regulating the collection, storage, and processing of personal data by companies. It also establishes a Data Protection Authority to enforce the provisions of theact.
The Intermediary Guidelines and Digital Media Ethics Code, 2021: This code lays down guidelines for online intermediaries, such as social media platforms and search engines,toregulate the publication of online content and to address issues such as cyberbullying, fakenews, and disinformation.
The Cryptocurrency and Regulation of Official Digital Currency Bill, 2021: This billaimsto regulate cryptocurrencies in India and provide a framework for the issuance of anofficialdigital currency.
Recommendations:
In view of the expanding dimensions of computer-related crimes, there is a need for adopting appropriate regulatory legal measures and gearing up the law enforcement mechanism to tackle the problem of cybercrime with stern hands. A multi-pronged approach and concerted efforts of all the law enforcement functionaries is much more needed for effective handling of cybercrime cases. A common cybercrime regulatory law universally acceptable to all the countries would perhaps provide a viable solution to prevent and control cyber criminality.
Technological aspects:
Intrusion Management: Process which primarily aims at precluding intrusions in the computer system therefore furnishing effective-security control medium.
Self- regulation by computer and net druggies: It’s a process of developing a healthy law ofconduct by espousing a policy of restraint by both the computer druggies as well as the service providers.
Use of voice-recognizer, sludge software and collar-ID for Protection: Computers as a means for carrying out routine life conditioning, should be equipped with some safety andsecurity bias to cover against authorised operation of computer systems.
Use of diligent Anti-Virus Softwares: Antivirus software is a computer program which detects, prevents and takes action to protect the system and remove all malicious softwareprograms like viruses etc.
Legal Aspect:
Use of encryption technology: To appoint well trained Information Security Officers who should be responsible for overall protection of computer coffers and for any lapse in computer security.
Use of international treaties & agreements to present a combined front: Ensures that all applicable local legislations are in harmony with international laws and conventions.
Establish progressive capacity building programmers for national law enforcementagencies.
Research Aspect:
Improving awareness and competence in information security;
Develop foster and maintain national culture of cyber security;
To standardize and coordinate cybersecurity awareness and education programmes.
Conclusion:
In conclusion, cybersecurity and cyberterrorism are two important and interconnected issues that have significant impacts on the digital world. Cybersecurity focuses on protecting digital systems, data, and networks from unauthorized access, theft, and attacks, while cyberterrorism involves the use of technology to cause harm to individuals, organizations, or even governments.As technology continues to advance, the threat of cyberattacks and cyberterrorism will only continue to grow, making it crucial for individuals, organizations, and governments to take proactive measures to protect themselves from these risks. This can be achieved by staying informed about the latest cybersecurity threats, implementing strong security measures, and investing in the training and education of personnel. It’s time for the Indian legal system to match its pace with the growing cyber crimes and the developing transnational justice around it as in the information age, openings to grow life for those who are stylish and suitable to use both technology and information. With the outpour of information to the cyber sphere with the arrival of COVID-19 epidemic the need for this change has become more imminent andnecessary. Statutory laws, government programs, specialised probing agencies will go a long way in securing India’s cyber spaces. The people ought to be equipped with enough knowledgeto be suitable to defend themselves against the pitfalls of cyber crimes through legal mindfulnessprogrammes. The unborn India’s digital world lies on a fulcrum and the time to shift the fulcrumtowards safety and security vis a vis cyber crimesis now.