India’s Computer Emergency Response Team opened National Cyber Security Awareness Month on 1 October with the theme “Cyber Smart India: Secure Today, Resilient Tomorrow,” pairing booklet releases with a MyGov quiz on passwords, multi-factor authentication and phishing that runs through late October.
Awareness stack
The Cyber Swachhta Kendra published English and Hindi AI awareness guides and classroom booklets aimed at schools. DSCI’s parallel “Be Cyber Street Smart” campaign uses puppetry motifs to explain UPI scams and AI-generated fraud, reflecting how digital payments dominate consumer complaints.
The MyGov quiz, hosted with the Information Security Education and Awareness programme, rewards participants who score well on incident-reporting steps and software-update habits. It is education, not enforcement—but it gives CERT-In telemetry on which topics confuse users.
ECINET timing
Separately, a security researcher told Hindustan Times that vulnerabilities in the Election Commission’s ECINET software were reported to the poll body and CERT-In in July, before opposition protests over voter-list revision intensified in October. The commission has denied allegations that the system enables arbitrary deletions; the researcher’s claim focuses on patch cadence and disclosure timelines rather than vote totals.
CERT-In has not published a public incident note on the matter at the time of writing. Readers should treat unpatched-critical claims as allegations until the agency or ECI confirms scope. Still, the overlap with National Cyber Security Awareness Month puts password hygiene and vendor patching back on front pages.
Enterprise parallels
Banks and insurers already run October phishing drills; the government campaign nudges small merchants who rely on single Android phones for billing. IT teams should verify that remote-access tools introduced during pandemic-era work-from-home are removed if unused.
For citizens, the practical step is enabling app-based MFA on email and tax portals, not just banking apps. Report suspicious UPI collect requests through the bank’s in-app dispute flow and the National Cyber Crime Reporting Portal.
What comes next
CERT-In typically closes the month with aggregated phishing statistics. If ECINET fixes land, watch for coordinated advisories naming CVE identifiers. Until then, the awareness quiz is the official visible product—and a reminder that election infrastructure and consumer wallets share the same patch discipline problem.
Sector drills
Banks scheduled tabletop exercises for ransomware during October, overlapping with CERT-In’s theme. UPI fraud hotlines saw elevated call volume after monsoon flooding disrupted courier deliveries—scammers posing as refund agents. The awareness month links those consumer stories to MFA prompts rather than blaming victims.
Election officials maintain ECINET is air-gapped from public internet in critical paths; researchers disputing that architecture will need CVE proof, not anecdote. Until then, CERT-In’s quiz remains the government’s most visible cyber product this week.
Small merchants should separate business UPI handles from personal savings accounts, a step CERT-In emphasises after fraudsters social-engineer shopkeepers into approving malicious collect requests during festival rush hours.
