Skip to main content
Government

Government Cybersecurity

CERT-In empanelled cybersecurity services for Government organisations. 6,700+ assessments delivered since 2006.

6,700+
Assessments Delivered
1,000+
Enterprise Clients
150+
Security Professionals
Since 2006
Founded · CERT-In 2008

Challenges

Security challenges in Government

1

CERT-In empanelled audit requirements for all central and state government IT infrastructure

2

Citizen data protection at population scale — Aadhaar, DigiLocker, UMANG, and e-governance platforms

3

Critical infrastructure protection across power, water, transport, and telecom sectors

4

Legacy system modernization with security debt accumulated over decades

5

Supply chain risk from multiple vendors, system integrators, and managed service providers

Trusted by

ICICI Bank
NPCI
HDFC
Mahindra
Aditya Birla
PhonePe
Pernod Ricard
Swiggy
Asian Paints
Yes Bank
Tata Play
Larsen & Toubro
Voltas
DHL Express
Etihad Airways
Amazon Pay
Go Digit
Pharmeasy
BillDesk
Jubilant Foods
UltraTech
Titan
Infosys
Capgemini
Groww
Sephora

The estate

Most of a government estate is run by somebody else

A department is accountable for systems it did not build, does not host and cannot patch without raising a ticket with a vendor.

What it isWho actually operates it, and what that means for testing
The citizen-facing portal Usually built by an empanelled systems integrator on a fixed-price contract that ended years ago. It is the most reachable thing the department owns and the least likely to have anyone assigned to it. Testing it is straightforward; getting a fix deployed is the part that needs planning before the assessment starts.
Departmental applications Internal workflow systems, often a decade old, frequently the only place a given record exists. Authorisation between roles is where the findings are, because roles accumulated as the department reorganised and nothing was ever removed.
The hosting layer A state data centre, a national facility or a cloud tenancy procured centrally. The infrastructure is not yours to test, but the tenancy configuration is — and that boundary needs to be written down before the engagement, not discovered during it.
Integrations with other departments Data moves between departments over interfaces nobody owns end to end. Each side assumes the other validates. This is the single most productive place to look and the hardest to get scoped, because it needs two organisations to agree.
Whatever the last project left behind Pilot environments, migration staging, a vendor demo instance still holding real data. Government estates accumulate these because decommissioning is nobody's deliverable. External discovery finds them faster than an asset register does.

The citizen-facing portal

Who actually operates it, and what that means for testing
Usually built by an empanelled systems integrator on a fixed-price contract that ended years ago. It is the most reachable thing the department owns and the least likely to have anyone assigned to it. Testing it is straightforward; getting a fix deployed is the part that needs planning before the assessment starts.

Departmental applications

Who actually operates it, and what that means for testing
Internal workflow systems, often a decade old, frequently the only place a given record exists. Authorisation between roles is where the findings are, because roles accumulated as the department reorganised and nothing was ever removed.

The hosting layer

Who actually operates it, and what that means for testing
A state data centre, a national facility or a cloud tenancy procured centrally. The infrastructure is not yours to test, but the tenancy configuration is — and that boundary needs to be written down before the engagement, not discovered during it.

Integrations with other departments

Who actually operates it, and what that means for testing
Data moves between departments over interfaces nobody owns end to end. Each side assumes the other validates. This is the single most productive place to look and the hardest to get scoped, because it needs two organisations to agree.

Whatever the last project left behind

Who actually operates it, and what that means for testing
Pilot environments, migration staging, a vendor demo instance still holding real data. Government estates accumulate these because decommissioning is nobody's deliverable. External discovery finds them faster than an asset register does.

The requirement

The audit is a procurement condition before it is a security exercise

In most sectors a security assessment is bought because somebody wants to know the answer. In government it is usually bought because a go-live will not be approved without one, and that changes what the deliverable has to do. It has to be defensible to a reviewer who was not in the room, from an auditor whose empanelment can be checked independently, on a timetable set by a launch date rather than by the estate. None of that lowers the bar on the testing — it raises the bar on the reporting, because every finding has to survive being read by somebody with no context and no stake in the project. Departments that treat the assessment as a form to be filled get a report that clears the gate and tells them nothing. The ones that treat the gate as the deadline and the findings as the point get both.

How it runs

Getting from tender to a report that clears

The order matters here more than in most sectors, because two of these steps involve organisations that are not you.

Where this goes wrong

What assessments of public-sector estates keep finding

Nobody owns the old portal

It was delivered, signed off and left running. The contract that built it has expired, the integrator has moved on, and there is no budget line for changing it — so the finding is real, reproducible and unfixable until somebody funds it.

Roles that only ever grew

Access was granted per reorganisation and never withdrawn. Officials hold entitlements from two postings ago, and the system has no concept of a leaver because staff transfer rather than leave.

Test data that is not test data

Staging environments seeded from production, reachable, and outside whatever protects the real system. The data is identical; only the URL is different.

Interfaces trusted by position

A departmental API accepts a call because it arrived from an address on the internal range, and validates nothing further. Reach that range once and the trust is inherited.

Documents where they should not be

Scanned citizen records in a directory served directly by the web server, indexed and retrievable without authentication. Almost always a convenience during a migration that outlived the migration.

Frequently Asked Questions

Our system is hosted centrally. Is there anything left for us to test?

Yes, and it is usually where the findings are. The hosting provider secures the platform; the application, its configuration, its user roles and its integrations are yours. A central facility does not validate your authorisation logic or notice that a staging instance is public. Write the boundary into the scope explicitly, name the hosting provider in it, and the engagement will run without stalling.

The tender asks for a CERT-In empanelled auditor. Does that change the testing?

It changes who can sign the report, not what good testing looks like. Treat the empanelment as a threshold that has to be met before anything else is assessed, then choose on the depth of the methodology and the quality of the reporting — because the empanelment is common to everyone who can bid, and the difference between a report that clears a gate and one that improves the estate is not.

Secure Your Government Organisation

One scoping call to align on scope, methodology, and timing.

Request a Scoping Call →