Topics: Business News, News, Business
**Snigdha Sharma** (0:01)
When Nisarga Adhikary found critical security flaws in CBSE's Class 12 board exam portal, CBSE publicly denied it. And so, the 19-year-old broke back in, filmed himself doing it, and just to prove his point, left memes and anime videos running on the board's own servers. Since then, he has filed about 30 more vulnerability reports with Certin, which is India's cybersecurity agency. The complaints cover public sector banks, several government bodies, a cafe chain and two dating apps. He told my colleague, Muttasim Khan, that most of those reports are still unpatched or ignored.
He said that the sure incompetence of our authorities baffles him. He claims that this is the kind of stuff that if left to him, he could fix in just a matter of hours.
And turns out, he is not the only one finding these gaps. In May, The Ken reported that Indian enterprises were being left dangerously exposed in a post-LLM world. Within weeks, attackers had leaked classified Apple-Tesla schematics from Tata Electronics, exposed blueprints tied to India's largest nuclear plant and breached hospitals, power grids, telecom firms and even e-rickshaws.
Meanwhile, in June, the RBI asked India's biggest banks what worried them most. And at the top of the list was AI-powered cyberattacks.
This has resulted in the government finally looking for talent in places it has ignored for a long time. In fact, right after the CBSE breach, IIT Kanpur hired Adhikary as a threat intelligence engineer. That same week, the institute launched a first of its kind undergraduate cybersecurity program. One that recruits hackers through hackathons instead of just JEE advanced course and actually sends students to work at government security organizations for two out of the four year program.
But like many of India's best cybersecurity researchers, Adhikary is already weighing offers from California. And his story actually captures India's cybersecurity paradox. The country trains more young ethical hackers than anywhere else in the world, but is still short of nearly a million cybersecurity professionals. The RBI, the Home Ministry Cybercrime Unit, and certain are all hiring to close that gap. But many of these roles are contractual with no path to a permanent job. Which means, against Silicon Valley and global capability centers, India isn't struggling to find talent, it's struggling to give that talent a reason to stay. Welcome to Daybreak, a business podcast from The Ken. I'm your host Rachel Varghese and every day of the week, my co-host Snigdha Sharma and I will bring you one news story that is worth understanding and worth your time. Today is Monday, the 24th of August.
Cyberwarriors of the Future. That's how Manindra Agrawal, the director at IIT Kanpur, described the Institute's new Bachelor of Cybersecurity program at its June launch. He said that future wars will be fought as much online as on the ground.
That language is pretty much the same as the government's. Prime Minister Narendra Modi has long called cyberattacks a bloodless war and has pushed for cyber commandos. And as cyberattacks grow more frequent and more sophisticated, the government is looking beyond the conventional engineering pipelines for talent.
That's the idea that the Bachelor in Cybersecurity program is built around. But the degree is unlike any other IIT undergraduate degree, because no other course mandates work experience as an actual part of its requirements. A former consultant who has worked on government cybersecurity audits told Mutasim that the course might work like a direct pipeline into government institutions. And along with the IIT prestige, it also gives cybersecurity a kind of nationalist identity.
The consultant also believes that it is just a matter of time before other IITs and engineering institutes follow the same path. In fact, IIT Madras is already set to launch the same program from the academic year of 2026 to 2027
The thing is, the talent pool is already there. It's large and untapped. And our research shows that Indians consistently make up the largest share of submissions on global bug bounty platforms, where companies pay independent researchers to find security flaws. For instance, Indians make up roughly a quarter of all researchers on a popular website called HackerOne. But the bounties themselves come almost entirely from foreign companies. Only a handful of Indian firms run them, which leaves India's ethical hackers to earn millions protecting global tech giants while remaining largely ignored at home.
This situation is what is leaving the government in a bind right now.
The consultant said that on one hand, the government runs the most systematically important infrastructure accessed by hundreds of millions. Think about it. Railways, telecom, payments, Aadhar are all digitized and online. On the other hand though, the government has to compete with GCCs or global capability centers for the same talent that keeps these platforms safe.
6 more minutes of transcript below
Thousands of transcripts fetched by people building searchable podcast archives
Try it now — copy, paste, done:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090
Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire. Prices exclude VAT, added at checkout for EU customers. Not what you expected? Email us within 14 days with 20 or fewer credits used and we refund the pack in full.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/YOUR_EPISODE_ID