Cyber Disruptions & Protection
What this session covered
This session, the third in the institute's interactive series, took the form of a single presentation by an invited speaker introduced as a practising advocate and specialist in cyber law, followed by questions from the moderator, two participants and the institute's president. The speaker framed cyber disruption as the temporary or permanent loss of access to digital services, and argued that disruption — rather than theft alone — is now the common aim of both state and non-state actors. Illustrations drawn from the presentation included ransomware against a corporate services firm, a university hospital in March 2020 whose IT network collapsed and forced the suspension of operations and surgeries, a ransomware payment made by a United States pipeline operator, and the October 2020 power outage in Mumbai, which the speaker attributed to a cyber attack originating in China. The speaker also observed that Indian cyber law contains no provision addressed specifically to cyber disruption, so such conduct must be brought within existing offences under the Information Technology Act, 2000.
Much of the presentation concerned obstacles to regulation. The speaker argued that identifying the source of an attack is the first difficulty, given routine use of VPNs, anonymisers and the darknet, and that internet jurisdiction compounds the problem because national law stops at national borders. He described a policy vacuum at the international level, suggesting that states are disinclined to negotiate a common framework because they conduct both covert and overt operations themselves, and that the response has instead been a patchwork of national cyber security legislation. On the technology side, the speaker identified artificial intelligence, cloud services, blockchain and crypto-asset exchanges, the internet of things, facial recognition data and, prospectively, quantum computing as areas where disruptors are active or where basic security parameters are absent. He said he had seen a 300 per cent increase in attacks on devices used for working from home, and described video conferencing as a fertile target.
In the discussion that followed, the speaker said the military concept of hot pursuit has no counterpart in cyberspace jurisprudence, and that mutual legal assistance treaties, though the available mechanism, operate too slowly to be effective. Asked how a company might limit its exposure, he set out the statutory exemption from liability available to intermediaries under section 79 of the Information Technology Act, subject to four conditions — compliance with the Act and rules, due diligence in discharging intermediary obligations, not committing or abetting an offence, and expeditious removal of data on government direction without vitiating the original electronic evidence — and cautioned that cyber insurance policies require close reading of their exclusions. On attribution, he said identification of perpetrators usually fails and that extradition is a further obstacle, so effort is better directed at protection and rapid return to normalcy. Asked what small groups, as distinct from state-sponsored and financially motivated attackers, are aiming at, he said the element of fun had long gone and that such activity is now professional and directed at data, and stated that a company somewhere in the world falls victim to a ransomware attack every 11 seconds. Asked about families, he urged sensitisation of household members and children, stripping metadata from photographs before uploading them, and caution about online contacts. Responding to the president's questions on the state of Indian law, the speaker said India has no dedicated statute on privacy despite the Supreme Court's recognition of privacy within the fundamental right to life, no dedicated cyber security law, and no dedicated data protection law, and that the National Cyber Security Policy of 2013 was never implemented. He described the Information Technology Rules, 2021, effective from 25 February 2021, as substantially expanding governmental powers and compliance obligations. In closing remarks the president asked that future analysis address who defines the security and sovereignty exceptions in such laws, expressing concern that they could be used to curb individual privacy.
Key points raised
- The speaker characterised cyber disruption — denial of access to systems and data rather than data theft alone — as the shared objective of state and non-state actors, and noted that Indian law contains no provision addressed specifically to it.
- Attribution was described as the central practical obstacle, given the use of VPNs, anonymisers and the darknet, with extradition presenting a further barrier even where an actor is identified.
- The speaker argued there is no international cyber law or cyber security law in place, and that states have little incentive to create one, leaving a patchwork of national legislation.
- The statutory exemption from liability for intermediaries under section 79 of the Information Technology Act was set out as available only on satisfaction of four conditions, including due diligence and expeditious compliance with government directions.
- Cyber insurance was recommended with the caveat that exclusions in the fine print may materially narrow the cover offered.
- On domestic law, the speaker said India lacks dedicated statutes on privacy, cyber security and data protection, and that the 2013 national cyber security policy was never implemented.



