Cybercrime Governance in the Digital Age: Contemporary Challenges, Legal Responses and the Need for Reform in India
DOI:
https://doi.org/10.29070/na2ygb28Keywords:
Cybercrime Governance, Digital Governance, Cybersecurity, Cyber Law, Information Technology Act, Artificial Intelligence, Data Protection, Intermediary Liability, CERT-In, I4C, Critical Infrastructure, Cyber Resilience, Regulatory ReformAbstract
Cybercrime governance has become an essential component of contemporary public administration, national security, economic regulation and protection of fundamental rights. The digitisation of banking, commerce, government services, communication and critical infrastructure has transformed cybercrime from an isolated law-enforcement concern into a systemic governance issue. Contemporary threats include ransomware, financial cyber fraud, identity theft, digital-arrest scams, phishing, cyberstalking, data breaches, deepfakes, AI-enabled impersonation, malicious synthetic media and attacks upon critical information infrastructure. These offences operate across institutional and territorial boundaries, requiring coordination between government departments, police organisations, banks, telecommunications companies, technology intermediaries, cybersecurity agencies and international partners.
India has created a multi-layered cyber-governance architecture centred around the Information Technology Act, 2000, CERT-In, the National Critical Information Infrastructure Protection Centre, the Indian Cyber Crime Coordination Centre, State cybercrime units, intermediary regulations and sector-specific regulators. The Bharatiya Nyaya Sanhita, 2023, Digital Personal Data Protection Act, 2023 and Bharatiya Sakshya Adhiniyam, 2023 have broadened the legal environment surrounding digital offences and electronic evidence. The Digital Personal Data Protection Rules, 2025 and Information Technology Amendment Rules, 2026 dealing with synthetically generated information further reflect a transition towards regulation of data security and AI-enabled harms.
Despite these developments, India's cyber-governance framework remains institutionally fragmented and continuously challenged by transnational crime, jurisdictional conflicts, rapid technological change, limited investigative capacity, delayed electronic-evidence acquisition and tensions between cybersecurity, privacy and freedom of expression. This article analyses the historical development and contemporary structure of cybercrime governance in India, evaluates regulatory and enforcement challenges and examines international models including the Budapest Convention, United Nations Convention against Cybercrime, NIS2 Directive and NIST Cybersecurity Framework. It argues for an integrated, rights-based and technologically neutral governance model combining prevention, resilience, criminal enforcement, corporate accountability, rapid financial intervention, victim protection and international cooperation.
Downloads
References
1. Government of India. (2000). The Information Technology Act, 2000. Government of India.
2. Council of Europe. (2001). Convention on Cybercrime. Council of Europe.
3. Wall, D. S. (2007). Cybercrime: The transformation of crime in the information age. Polity Press.
4. Government of India. (2008). Information Technology (Amendment) Act, 2008. Government of India.
5. Brenner, S. W. (2010). Cybercrime: Criminal threats from cyberspace. Praeger.
6. Government of India. (2013). National Cyber Security Policy 2013. Department of Electronics and Information Technology.
7. Shreya Singhal v. Union of India, (2015) 5 SCC 1.
8. Clough, J. (2015). Principles of cybercrime (2nd ed.). Cambridge University Press.
9. Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.
10. Holt, T. J., Bossler, A. M., & Seigfried-Spellar, K. C. (2018). Cybercrime and digital forensics: An introduction (2nd ed.). Routledge.
11. Government of India. (2021). Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. Ministry of Electronics and Information Technology.
12. Indian Computer Emergency Response Team. (2022). Directions under sub-section (6) of Section 70B of the Information Technology Act, 2000 relating to information security practices, procedure, prevention, response and reporting of cyber incidents. CERT-In.
13. European Parliament & Council of the European Union. (2022). Directive (EU) 2022/2555 concerning measures for a high common level of cybersecurity across the Union. Official Journal of the European Union.
14. Government of India. (2023). Digital Personal Data Protection Act, 2023. Ministry of Law and Justice.
15. Government of India. (2023). Bharatiya Nyaya Sanhita, 2023. Ministry of Law and Justice.
16. Government of India. (2023). Bharatiya Sakshya Adhiniyam, 2023. Ministry of Law and Justice.
17. National Institute of Standards and Technology. (2024). The NIST Cybersecurity Framework (CSF) 2.0. U.S. Department of Commerce.
18. United Nations General Assembly. (2024). United Nations Convention against Cybercrime: Strengthening international cooperation for combating certain crimes committed by means of information and communications technology systems and for the sharing of evidence in electronic form of serious crimes (A/RES/79/243).
19. Government of India. (2025). Digital Personal Data Protection Rules, 2025. Ministry of Electronics and Information Technology.
20. Government of India. (2026). Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026. Ministry of Electronics and Information Technology.
21. National Crime Records Bureau. (2026). Crime in India 2024. Ministry of Home Affairs, Government of India.
22. Ministry of Home Affairs. (2026). National cybercrime data. Government of India.






