Govt's cybersecurity rules risk creating 'environment of fear': Tech firms

Indian cybersecurity rules due to come into force later this month will create an "environment of fear rather than trust", a body representing top tech companies has warned the government

hacking, cyberfraud, cyber threat, security, privacy, phone tapping, surveillance
Reuters New Delhi
2 min read Last Updated : Jun 03 2022 | 9:08 PM IST

Indian cybersecurity rules due to come into force later this month will create an "environment of fear rather than trust", a body representing top tech companies has warned the government, calling for a one-year delay before the rules take effect.

The Internet and Mobile Association of India (IAMAI), which represents firms including Facebook, Google and Reliance, wrote this week to India's IT ministry criticising a directive on cybersecurity set out in April.

Among other changes the directive from the Indian Computer Emergency Response Team (CERT) requires tech companies to report data breaches within six hours of noticing such incidents and to maintain IT and communications logs for six months.

In the letter seen by Reuters, IAMAI proposed to extend the six-hour window, noting the global standard for reporting cyber-security incidents is generally 72 hours.

CERT, which comes under the IT ministry, has also asked cloud service providers such as Amazon and virtual private network (VPN) companies to retain names of their customers and IP addresses for at least five years, even after they stop using the company's services.

The cost of complying with such directives could be "massive", and proposed penalties for violation including prison would lead to "entities ceasing operations in India for fear of running afoul," the IAMAI letter said.

On Thursday, VPN service provider ExpressVPN removed its servers from India, saying it "refuses to participate in the Indian government's attempts to limit internet freedom".

IAMAI's letter follows one from 11 significant tech-aligned industry associations earlier this week, which said the new requirements made it difficult to do business in India.

India has tightened regulation of big tech firms in recent years, prompting pushback from the industry and in some cases even straining trade ties between New Delhi and Washington.

New Delhi has said the new rules were needed as cybersecurity incidents were reported regularly but the requisite information needed to investigate them was not always readily available from service providers.

(Reporting by Munsif Vengattil in New Delhi; Editing by David Holmes)

(Only the headline and picture of this report may have been reworked by the Business Standard staff; the rest of the content is auto-generated from a syndicated feed.)

Subscribe to Business Standard digital and get complimentary access to The New York Times

Quarterly Starter

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

Save 46%

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Access to Exclusive Premium Stories Online

  • Over 30 behind the paywall stories daily, handpicked by our editors for subscribers

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

Topics :cybersecuritycyber securityindian government

First Published: Jun 03 2022 | 2:53 PM IST

Next Story