![]()
What is CERT-In?
The Indian Computer Emergency Response Team (CERT-In) is India's national cybersecurity Incident Response Agency. It operates under the authority of the Ministry of Electronics and Information Technology (MeitY), Government of India.
It plays an important role in collecting and analyzing cyber incident information, issuing cybersecurity advisories, coordinating incident response, and enhancing the country's overall cyber resilience.
Roles of CERT-In
CERT-In has two major roles: Reactive and Proactive. Reactive actions occur after a cyber attack happens, and proactive actions work to prevent cyber attacks from happening.
In simple terms,
Reactive Role :
Responds after a cyber incident occurs.
Focuses on response, recovery, and investigation.
Proactive Role:
Prevents cyber incidents before they happen.
Focuses on prevention, protection, and preparedness.
| Reactive | Proactive |
| Serve as the primary contact point for reporting cybersecurity incidents. | Publish security advisories, alerts, and best practice guidelines. |
| Support organisations and users in responding to and managing security incidents. | Identify vulnerabilities through continuous analysis and recommend preventive measures. |
| Exchange threat information and incident learnings with CERTs, response teams, and other stakeholders. | Assess cyber risks to help organisations strengthen their security posture. |
| Coordinate incident handling and response efforts during cyberattacks. | Work closely with technology providers and industry partners to improve cyber resilience. |
| Provide round-the-clock (24×7) incident response assistance. | Maintain a national knowledge base and referral system for cyber intrusion cases. |
| Assist organisations in recovering from cybersecurity incidents. | Monitor attacker tactics and analyse emerging cyber threat trends. |
| Analyse malware and examine digital evidence | Organise cybersecurity awareness initiatives, workshops, and training programmes. |
| Investigate, trace, and analyse cyber incidents to determine their source and impact. | Collaborate with vendors and stakeholders to identify risks and implement preventive security solutions. |
Functions of CERT-In
The CERT-In functions are divided into 3 vital tasks.
1) Report
2) Analyze
3) Response
What does CERT-In do?
1) Coordinates responses to cybersecurity incidents such as malware, phishing, ransomware, and data breaches.
2) Issues security advisories, publishes alerts on newly discovered vulnerabilities and zero-day exploits, and provides security guidelines, technical documents, and best practices.
3) Monitors emerging cyber threats and shares threat intelligence, Indicators of Compromise (IOCs), malware analysis, and mitigation guidance.
4) Coordinates incident response with government agencies, private organisations, Internet Service Providers (ISPs), law enforcement agencies, and international CERTs during major cyber incidents.
5) Conducts cybersecurity training, workshops, and awareness programmes to help organisations and professionals improve information security and reduce cyber risks.
Importances of CERT-In
1) Reduces the impact of cyberattacks
2) Enables quick responses to cybersecurity incidents.
3) Improves cyber resilience through advisories, training, and security guidelines
4) Protects critical information from cyber threats.
Final Thoughts
The Indian Computer Emergency Response Team (CERT-In) plays a vital role in strengthening India's cybersecurity by monitoring cyber threats, responding to security incidents, and issuing timely advisories. Through these proactive and reactive efforts, CERT-In helps organisations build stronger cyber resilience and enhance the overall security of India's digital ecosystem.
Need help with this topic?
Our security experts can assess your specific situation and provide actionable recommendations.
Talk to an Expert