India’s rapid digital expansion has created enormous economic and social opportunities, but it has also made telecommunications, cloud platforms, smartphones, connected vehicles, artificial intelligence and digital public infrastructure strategic assets.
The challenge now is to build stronger cyber defences without creating systems that enable unnecessary or indiscriminate surveillance.
A policy proposal by cybersecurity professional Dr. Smith Gonsalves argues that India should move towards what he describes as “Sovereign Cyber Immunity” — a federated, privacy-preserving security architecture that connects citizen protection, advanced malware analysis, digital forensics, exploit defence, supply-chain assurance, AI security and independent oversight.
The proposal uses Sanchar Saathi as its starting point, while emphasising that the existing platform should not itself become a national cyber-defence or surveillance system.
Sanchar Saathi Shows What Citizen-Centric Cybersecurity Can Do
Sanchar Saathi is a citizen-focused initiative of the Department of Telecommunications offering services such as Chakshu for reporting suspected fraudulent communications, facilities to identify mobile connections registered in a citizen’s name, mechanisms to block and trace lost or stolen devices, and tools to check handset genuineness.
Government figures reported in July 2026 showed that 11.18 lakh citizen reports of suspected fraudulent communications submitted through Sanchar Saathi had contributed to the disconnection of 50.90 lakh mobile connections.
The government also reported that ASTR, an AI and big-data analytics system used to identify suspicious mobile connections, had contributed to more than 88 lakh disconnections following failed reverification.
In August 2026, Sanchar Saathi crossed another milestone, with more than 75,000 lost or stolen mobile handsets recovered in a single month.
These developments demonstrate how citizen-participatory cybersecurity mechanisms can operate at national scale. However, the platform’s existing functions are fundamentally different from advanced endpoint detection, exploit analysis, firmware attestation, malware research and digital forensics.
The proposal therefore calls for Sanchar Saathi to remain primarily a citizen-security gateway, while advanced forensic, malware and threat-intelligence capabilities operate through separate and independently governed technical layers.
The Pre-Installation Controversy Highlighted the Need for Trust
Sanchar Saathi’s proposed pre-installation on mobile devices in 2025 generated debate over consent, privacy, user control and the role of government software on personal devices.
The Government subsequently removed the mandatory pre-installation requirement, citing increasing voluntary adoption.
The episode highlighted a broader issue for digital infrastructure: security systems require public trust as well as technical capability.
Users need clarity about what information is collected, why it is collected, where it is processed, how long it is retained, who can access it and what remedies are available when a system makes an error.
The central policy challenge is therefore not choosing between security and privacy, but designing systems in which both are built into the architecture.
A Proposed Model of “Sovereign Cyber Immunity”
The proposed Sovereign Cyber Immunity model takes inspiration from the biological immune system.
Rather than continuously monitoring ordinary private behaviour, a national cyber-defence architecture could focus on detecting malicious technical activity, learning from attacks, isolating threats and helping affected systems recover.
The core design principle is straightforward: detect the threat, understand the attack, protect the citizen, preserve relevant evidence, remediate the compromise and collect no more personal information than necessary.
Under this approach, sensitive technical capabilities would be distributed across specialised institutions instead of being concentrated inside a single consumer-facing platform.
India Needs Advanced Malware and Threat Analysis Capability
India already has cybersecurity expertise across CERT-In, government organisations, defence institutions, academia, private companies and independent researchers.
The proposed next step is to connect this expertise through a national advanced malware analysis and digital threat capability.
Such a capability could focus on:
- Malware reverse engineering and exploit-chain reconstruction
- Memory, mobile and operating-system forensics
- Firmware integrity and persistence analysis
- Privilege-escalation and malicious configuration analysis
- Threat-intelligence correlation
- Vulnerability disclosure and vendor escalation
- Rapid support for high-risk individuals and critical organisations
- National repositories of sanitised defensive indicators
The proposal specifically separates these functions from Sanchar Saathi.
A citizen could use the platform to report a suspected compromise, while the technical investigation could be handled by accredited forensic and cybersecurity institutions operating under separate governance controls.
Digital Evidence Must Address the Era of Remote Compromise
Cybersecurity is increasingly becoming an evidentiary issue.
Modern attacks can potentially create or modify files, execute commands, alter application states or operate accounts without the informed participation of the device owner.
This raises a fundamental forensic question: the presence of a file or digital artefact does not necessarily explain how it came to exist on a device.
The proposed framework calls for greater emphasis on:
- File and filesystem provenance
- Timestamps and metadata
- Process execution and authentication artefacts
- Network connections and remote-access indicators
- Memory artefacts and persistence mechanisms
- Cloud synchronisation and account activity
- Integrity hashes
- Acquisition methodology
- Chain of custody and reproducibility
The broader argument is that digital investigations should increasingly examine how an artefact got there, rather than relying solely on whether it was present.
Reducing Domestic Exposure to Zero-Day Threats
Zero-day vulnerabilities can provide attackers with access to devices, networks and strategically important infrastructure.
Their ecosystem includes independent researchers, commercial vulnerability markets, surveillance vendors, leaked tools, criminal groups and state programmes.
The proposal calls for a National Exploit Defence Programme focused primarily on reducing India’s domestic exposure.
Potential areas include advanced vulnerability research, exploit detection, responsible disclosure, emergency remediation, exploit-mitigation research and protection for high-risk individuals and critical systems.
The broader measure of cyber capability, according to the proposal, should therefore include how effectively a country can defend its own population and infrastructure from sophisticated exploitation.
Digital Sovereignty Begins With the Supply Chain
India’s digital vulnerability does not begin when malware executes. It can begin much earlier, within technology supply chains.
Modern systems rely on processors, firmware, operating systems, open-source packages, proprietary libraries, cloud services, identity providers, cryptographic components, telecom equipment and software-update mechanisms.
Manufacturing a device domestically does not automatically eliminate strategic dependencies if critical components, firmware, operating systems, cloud infrastructure or update channels remain externally controlled.
The proposal therefore advocates broader supply-chain assurance covering:
- Software, AI and hardware bills of materials
- Firmware provenance
- Secure-boot mechanisms
- Code-signing controls
- Open-source dependencies
- Cloud jurisdiction
- Privileged remote administration
- Vendor incident-notification commitments
- End-of-life security commitments
- Vendor substitution and resilience planning
The objective is not complete rejection of foreign technology. Instead, it is to maintain strategic optionality so that India is not excessively dependent on a single vendor, country, cloud provider, hardware architecture or technology stack.
AI Is Becoming a New Layer of Technology Dependency
Artificial intelligence is increasingly being incorporated into governance, healthcare, education, finance, defence, cybersecurity and enterprise systems.
This creates a new set of security and sovereignty questions.
Who controls an AI model? Where are inference requests processed? What data influences its behaviour? Are prompts retained? What permissions do AI agents have? Can external tools influence autonomous systems? Can model updates materially alter system behaviour?
India’s AI policy framework already includes work on Foundation Models and Safe & Trusted AI under the IndiaAI Mission.
The proposed framework suggests that future AI-security services could help organisations identify sensitive-data leakage, assess model dependencies, evaluate agent permissions, detect prompt injection and malicious tool instructions, and provide greater provenance and risk information for AI-generated outputs.
A Wider “Saathi” Ecosystem
The proposal also expands the Sanchar Saathi concept beyond smartphones and telecommunications.
A broader ecosystem could potentially include:
Sanchar Saathi: Telecom fraud, SIM misuse, device genuineness, stolen-device protection and citizen telecom security.
Vahan Saathi: Connected-vehicle cybersecurity, automotive vulnerability coordination and malicious firmware reporting.
IoT Saathi: Security information for routers, smart cameras, appliances, wearables and other connected devices.
AI Saathi: AI-system transparency, model-risk guidance, agent-security assessments and responsible-use information.
Cloud Saathi: Security assurance and resilience information for nationally important cloud and digital-service providers.
The proposal does not necessarily call for these to become separate government applications. Instead, the underlying idea is to provide citizens and organisations with actionable information about the security of the technologies they depend upon.
Privacy Must Be Built Into the Architecture
India’s Digital Personal Data Protection framework provides an important legal backdrop for any future cyber-security infrastructure.
The proposal argues that privacy should be treated as an engineering requirement rather than simply a policy statement.
Key safeguards include:
Data minimisation: Collect only the information necessary for a specific security function.
Purpose limitation: Cybersecurity information should not silently become available for unrelated profiling, advertising, political analysis or routine activities.
Local analysis: Where technically possible, security detection should occur on-device or in trusted environments, with only necessary indicators transmitted externally.
Defined retention: Sensitive security information should not be stored indefinitely without a defined purpose.
Access controls: Least-privilege access, separation of duties and administrative audit logs should be incorporated into sensitive systems.
Independent oversight: Technical and privacy assessments should verify whether systems behave as publicly described.
Defining a Surveillance-Free Cyber Defence System
The proposal argues that the term “surveillance-free” needs a technically meaningful definition.
A privacy-preserving cyber-defence system could process information related to malicious technical activity without continuously profiling or analysing lawful private activities beyond what is necessary for a defined security purpose.
For example, a malware hash, known command-and-control domain or firmware-integrity failure could constitute security telemetry.
A person’s political views, ordinary private conversations, relationships or lawful movements would not inherently constitute cybersecurity telemetry.
The distinction must be supported by architecture, law and independent auditing.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
Oversight Should Be Treated as a Security Control
The proposal also frames democratic oversight as part of cybersecurity itself.
Highly privileged systems can become targets for external attackers, malicious insiders, compromised administrators or attempts to expand a system beyond its original purpose.
Potential safeguards include:
- Parliamentary visibility into high-level capabilities
- Independent technical and privacy oversight
- Judicial authorisation for highly intrusive investigations where required
- Immutable administrative logs
- Separation of duties
- Periodic red-team exercises
- Privacy-impact assessments
- Whistle-blower mechanisms
- Citizen grievance channels
- Public transparency metrics that do not expose sensitive operations
The proposed approach treats cybersecurity as an area requiring institutional accountability rather than simply technical deployment.
Protecting High-Risk Individuals
Certain individuals may face more sophisticated cyber threats because of the nature of their work.
The proposal identifies journalists, judges, senior officials, military personnel, law-enforcement officers, diplomats, scientists, critical-infrastructure operators, political leaders, corporate executives and high-value researchers as potential candidates for specialised protection.
A High-Risk Digital Protection Programme could provide:
- Periodic device and account-security assessments
- Rapid escalation for suspected targeted compromise
- Secure-device and travel-security procedures
- Advanced threat notifications
- Forensic triage
- Secure backup and recovery guidance
- Evidence-preservation support
Protecting such individuals can also protect the institutions and national missions associated with their work.
Cyber Sovereignty Does Not Have to Mean Isolation
The proposal distinguishes digital sovereignty from technological isolationism.
It argues that India should develop domestic capability in strategically important areas while continuing to work with global technology and security partners.
Three principles are central:
Build indigenous capability in strategically important technologies.
Diversify suppliers, cloud providers, hardware architectures, models and other critical dependencies.
Interoperate globally so Indian technologies can participate in international markets and security ecosystems.
The underlying argument is that technological sovereignty without interoperability can create isolation, while global dependence without domestic capability can create vulnerability.
A National Digital Resilience Grid
Instead of creating an “India Wall” that could be interpreted as internet isolation, the proposal introduces the concept of a National Digital Resilience Grid (NDRG).
The proposed framework would connect relevant capabilities across organisations such as DoT, CERT-In, NCIIPC, I4C, C-DOT, sectoral regulators, telecom operators, technology vendors, accredited cybersecurity laboratories, universities, law enforcement and critical infrastructure.
Sensitive intelligence would remain compartmentalised, while sanitised defensive indicators could be shared more rapidly.
For example, if a researcher identifies a previously unknown malicious implant, validated and sanitised indicators could potentially be distributed to organisations that need them without unnecessarily exposing the victim’s private information.
The objective would therefore be interoperability rather than centralisation of every digital-security system.
Cybersecurity as a National Scientific Mission
The proposal argues that India’s cybersecurity talent needs stronger institutional infrastructure to translate individual expertise into national capability.
Potential measures include:
- National cyber-research laboratories and test ranges
- Funding for exploit mitigation and digital forensics
- Legal protections for good-faith security research
- University-industry-government research programmes
- Startup procurement pathways
- International research partnerships with appropriate safeguards
The comparison is drawn with India’s scientific programmes, where institutional structures have enabled individual expertise to contribute to large national missions.
India’s Role in International Cyber Norms
Traditional arms-control models cannot simply be transferred to cyberspace.
Vulnerabilities are information, exploit research can have legitimate defensive purposes, governments have law-enforcement and intelligence requirements, and researchers need space to investigate insecure products.
At the same time, the uncontrolled proliferation of highly intrusive spyware and exploit capabilities has raised international concerns.
The proposal suggests that India could contribute to discussions around commercial spyware accountability, responsible vulnerability disclosure, export controls for highly intrusive technologies, researcher protections, cross-border incident cooperation and safeguards for civilian critical infrastructure.
India’s position as a large digital democracy, technology consumer, technology producer and growing cyber power gives it a potential role in shaping these international discussions.
A Roadmap to 2030
The proposed framework is designed as a staged process rather than a single technology deployment.
Phase I — Citizen Protection: Strengthen telecom fraud reporting, stolen-device recovery, SIM misuse detection, trusted contacts, public awareness and telecom intelligence sharing.
Phase II — National Cyber Immunity: Develop advanced malware laboratories, zero-click investigation capabilities, firmware forensics, exploit analysis and rapid support for high-risk users.
Phase III — Digital Evidence Modernisation: Standardise forensic acquisition, mobile and memory forensics, chain-of-custody controls, provenance analysis and specialist judicial training.
Phase IV — Supply-Chain Sovereignty: Expand bills of materials, firmware assurance, secure development, indigenous security products, semiconductor-security research and diversified cloud infrastructure.
Phase V — AI and Autonomous-System Security: Develop AI-agent security, foundation-model assurance, prompt-injection defence, model supply-chain controls, AI red teaming and safeguards for autonomous response.
Phase VI — Democratic Cyber Governance: Institutionalise privacy engineering, independent oversight, citizen redress, transparency metrics and international cyber-norm building.
What India Could Ultimately Build
The proposal does not call for an Indian copy of a foreign operating system, mandatory government software on every device or a firewall separating India from the rest of the internet.
Instead, it envisions a democratic cyber-security ecosystem capable of developing indigenous technology while maintaining global interoperability.
Such a system would seek to detect sophisticated spyware without routinely accessing ordinary private communications, assist investigators without treating every digital artefact as conclusive, protect critical infrastructure without creating unlimited state access, and adopt AI while maintaining control over critical technology dependencies.
The proposal describes this distinction as the difference between digital nationalism and digital sovereignty.
Digital nationalism focuses largely on where technology comes from. Digital sovereignty, in this formulation, concerns whether a country can independently understand, secure, audit, replace and govern the technology on which its society depends.
The Strategic Question for India
India’s growing digital economy and infrastructure will continue to attract cyber threats from increasingly capable actors.
The central strategic questions are therefore whether India can independently detect and investigate sophisticated attacks, determine how compromises occurred, preserve evidence that can withstand legal scrutiny, coordinate with affected technology providers and restore compromised systems — while maintaining meaningful privacy safeguards.
Sanchar Saathi does not currently perform all of these functions, and the proposal does not suggest that it should.
Instead, Sanchar Saathi is presented as evidence that citizen-facing digital-security infrastructure can operate at national scale.
The larger policy question is what India builds next.
The proposed model seeks to combine cybersecurity, technological sovereignty, privacy, scientific capability and democratic oversight into a broader national digital-resilience framework.
Three Questions India Must Answer
- Can India independently detect, investigate and remediate advanced cyberattacks against the technologies on which citizens and institutions depend?
- Can India build those capabilities while technically and legally preventing them from becoming infrastructure for indiscriminate surveillance?
- Can India develop a sustainable balance between sovereignty, security, innovation and civil liberties that can inform wider democratic technology policy?
About the Author – Dr. Smith Gonsalves is the Founder, Director and Principal Consultant of CyberSmithSECURE. His work covers cybersecurity, digital forensics, cyber resilience, governance, penetration testing and AI security. He holds a Ph.D. in Computer Science and professional certifications including OSCP, CISA, CCSK, CHFI and CEH.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics