Government Cybersecurity
CERT-In empanelled cybersecurity services for Government organisations. 6,700+ assessments delivered since 2006.
Challenges
Security challenges in Government
CERT-In empanelled audit requirements for all central and state government IT infrastructure
Citizen data protection at population scale — Aadhaar, DigiLocker, UMANG, and e-governance platforms
Critical infrastructure protection across power, water, transport, and telecom sectors
Legacy system modernization with security debt accumulated over decades
Supply chain risk from multiple vendors, system integrators, and managed service providers
Trusted by
The estate
Most of a government estate is run by somebody else
A department is accountable for systems it did not build, does not host and cannot patch without raising a ticket with a vendor.
| What it is | Who actually operates it, and what that means for testing |
|---|---|
| The citizen-facing portal | Usually built by an empanelled systems integrator on a fixed-price contract that ended years ago. It is the most reachable thing the department owns and the least likely to have anyone assigned to it. Testing it is straightforward; getting a fix deployed is the part that needs planning before the assessment starts. |
| Departmental applications | Internal workflow systems, often a decade old, frequently the only place a given record exists. Authorisation between roles is where the findings are, because roles accumulated as the department reorganised and nothing was ever removed. |
| The hosting layer | A state data centre, a national facility or a cloud tenancy procured centrally. The infrastructure is not yours to test, but the tenancy configuration is — and that boundary needs to be written down before the engagement, not discovered during it. |
| Integrations with other departments | Data moves between departments over interfaces nobody owns end to end. Each side assumes the other validates. This is the single most productive place to look and the hardest to get scoped, because it needs two organisations to agree. |
| Whatever the last project left behind | Pilot environments, migration staging, a vendor demo instance still holding real data. Government estates accumulate these because decommissioning is nobody's deliverable. External discovery finds them faster than an asset register does. |
The citizen-facing portal
- Who actually operates it, and what that means for testing
- Usually built by an empanelled systems integrator on a fixed-price contract that ended years ago. It is the most reachable thing the department owns and the least likely to have anyone assigned to it. Testing it is straightforward; getting a fix deployed is the part that needs planning before the assessment starts.
Departmental applications
- Who actually operates it, and what that means for testing
- Internal workflow systems, often a decade old, frequently the only place a given record exists. Authorisation between roles is where the findings are, because roles accumulated as the department reorganised and nothing was ever removed.
The hosting layer
- Who actually operates it, and what that means for testing
- A state data centre, a national facility or a cloud tenancy procured centrally. The infrastructure is not yours to test, but the tenancy configuration is — and that boundary needs to be written down before the engagement, not discovered during it.
Integrations with other departments
- Who actually operates it, and what that means for testing
- Data moves between departments over interfaces nobody owns end to end. Each side assumes the other validates. This is the single most productive place to look and the hardest to get scoped, because it needs two organisations to agree.
Whatever the last project left behind
- Who actually operates it, and what that means for testing
- Pilot environments, migration staging, a vendor demo instance still holding real data. Government estates accumulate these because decommissioning is nobody's deliverable. External discovery finds them faster than an asset register does.
The requirement
The audit is a procurement condition before it is a security exercise
In most sectors a security assessment is bought because somebody wants to know the answer. In government it is usually bought because a go-live will not be approved without one, and that changes what the deliverable has to do. It has to be defensible to a reviewer who was not in the room, from an auditor whose empanelment can be checked independently, on a timetable set by a launch date rather than by the estate. None of that lowers the bar on the testing — it raises the bar on the reporting, because every finding has to survive being read by somebody with no context and no stake in the project. Departments that treat the assessment as a form to be filled get a report that clears the gate and tells them nothing. The ones that treat the gate as the deadline and the findings as the point get both.
How it runs
Getting from tender to a report that clears
The order matters here more than in most sectors, because two of these steps involve organisations that are not you.
-
Scope
Establish what you are allowed to test
The application is yours. The platform underneath it usually is not. Write the boundary into the scope with the hosting provider named, so nothing stalls mid-engagement waiting for a permission that was never sought.
-
Verify
Confirm the empanelment before the work, not after
Where a tender names a CERT-In empanelled auditor, the empanelment is part of what is being bought. A technically excellent report from a firm that does not hold it will not clear the condition it was commissioned to clear.
-
Test
Authorisation first, on the interfaces that cross departments
The reachable perimeter gets attention because it is easy to point at. The findings that matter are usually one role boundary inside it, on a workflow that assumed the caller had already been checked.
-
Close
Retest, and keep the evidence with the report
A finding that was fixed and never retested is an open finding with optimism attached. The retest record is what a reviewer actually needs, and it is the part most often missing when a department is asked to show its work a year later.
Where this goes wrong
What assessments of public-sector estates keep finding
Nobody owns the old portal
It was delivered, signed off and left running. The contract that built it has expired, the integrator has moved on, and there is no budget line for changing it — so the finding is real, reproducible and unfixable until somebody funds it.
Roles that only ever grew
Access was granted per reorganisation and never withdrawn. Officials hold entitlements from two postings ago, and the system has no concept of a leaver because staff transfer rather than leave.
Test data that is not test data
Staging environments seeded from production, reachable, and outside whatever protects the real system. The data is identical; only the URL is different.
Interfaces trusted by position
A departmental API accepts a call because it arrived from an address on the internal range, and validates nothing further. Reach that range once and the trust is inherited.
Documents where they should not be
Scanned citizen records in a directory served directly by the web server, indexed and retrievable without authentication. Almost always a convenience during a migration that outlived the migration.
Services
Recommended Services for Government
CERT-In empanelled security services for government agencies and PSUs
Web Application Penetration Testing
CERT-In empanelled WAPT for citizen-facing portals, e-governance platforms, and public service applications.
Learn More →Network Penetration Testing
Internal and external VAPT for government networks, data centres, and inter-department connectivity.
Learn More →Secure Code Review
Source code analysis for government-developed applications including DigiLocker, UMANG, and state-level e-governance systems.
Learn More →Cloud Security Assessment
Security posture review for government cloud deployments on MeghRaj, NIC cloud, and state data centres.
Learn More →OT and SCADA Security
IEC 62443-aligned assessment for critical infrastructure — power grids, water treatment, and smart city deployments.
Learn More →Compliance
Frameworks that matter to Government
Frequently Asked Questions
Our system is hosted centrally. Is there anything left for us to test?
Yes, and it is usually where the findings are. The hosting provider secures the platform; the application, its configuration, its user roles and its integrations are yours. A central facility does not validate your authorisation logic or notice that a staging instance is public. Write the boundary into the scope explicitly, name the hosting provider in it, and the engagement will run without stalling.
The tender asks for a CERT-In empanelled auditor. Does that change the testing?
It changes who can sign the report, not what good testing looks like. Treat the empanelment as a threshold that has to be met before anything else is assessed, then choose on the depth of the methodology and the quality of the reporting — because the empanelment is common to everyone who can bid, and the difference between a report that clears a gate and one that improves the estate is not.
Secure Your Government Organisation
One scoping call to align on scope, methodology, and timing.
Request a Scoping Call →