© NatStrat
A National Cyber Reserve Force provides strategic utility by enabling rapid mobilisation during crises, such as the May 2025 standoff, and fostering a culture of indigenous innovation essential for long-term sovereignty. However, the NCRF's effectiveness depends on the state's capacity to balance military secrecy with civilian collaboration and manage the tension between offensive requirements and the risk of escalation. In an era characterised by grey-zone warfare, leveraging India's civilian cyber capabilities forms the foundation for comprehensive national defence in the 21st century.
Executive Summary
Traditionally, the Indian Government and its defence establishments have largely relied on standing military units and centralised civilian agencies to address national security concerns. The conceptualisation of a National Cyber Reserve Force in India likely represents a fundamental pivot in the nation’s strategic approach to the cyberspace domain. Traditional hierarchical structures are proving inadequate given cyberspace’s unique characteristics, including its geographical indeterminacy, the blurred boundaries between civilian and military infrastructure, and the rapid technological advancement and the shifts in the threat landscape.
The rationale for establishing this National Cyber Reserve Force rests on creating a structured, legally sanctioned, and professionally vetted body of civilian cybersecurity experts, specialists, academics and researchers. This force could be mobilised to safeguard the state, and, under clearly defined mandates, undertake offensive measures during a high-intensity conflict or national emergencies to enhance cyber deterrence.
The rapid expansion of India’s digital footprint underscores the strategic imperative to establish such a force. By early 2025, internet connections in India surpassed 100 crores and average monthly internet usage per subscriber surpassed 24 GB, reflecting the deep integration of digital infrastructure in the economy and society[3]. The Carnegie Endowment for International Peace projects that by 2030, India's digital economy will account for one-fifth of its gross domestic product (GDP), significantly increasing the nation’s cyber attack surface[4]. This transformation is taking place amid a deteriorating regional security environment, in which state-sponsored actors, advanced persistent threats, and grey-zone warfare strategies have become the new normal [5].
The current institutional architecture, which includes the Ministry of Defence (MoD), Ministry of Home Affairs (MHA), Ministry of Electronics and Information Technology (MeitY), and the National Security Council Secretariat (NCSC), is marked by fragmented responsibilities for civil-military cyber coordination. Although the establishment of the Defence Cyber Agency (DCyA) in 2019 advanced tri-service collaboration, the agency is still constrained by the conventional military recruitment processes and faces challenges in attracting and retaining top technical talent from India’s private sector and global capability centres[8]. This report evaluates how India can establish a dedicated National Cyber Reserve Force by examining its feasibility, potential models, and strategic value.
Contemporary Threat Landscape
Understanding the need for establishing a reserve cyber force requires examining the unique challenges that India as a country has faced and is continuing to face in the evolving cyber threat landscape. Threat actors have advanced from conducting simple website defacements to executing complex attacks on Critical Information Infrastructure (CII).
A significant escalation occurred during the military standoff between India and Pakistan in May 2005, demonstrating how cyber operations can create strategic ambiguity and misinterpretation, undermining regional deterrence. In addition to influence operations conducted through automated social media accounts, offensive cyber operations now target unmanned combat aerial vehicles and nuclear command-and-control communications, potentially causing operational failures of essential digital assets.

Threat actor categories, strategic intent, and documented examples
A persistent structural challenge is posed by China’s cyber statecraft. Chinese activity groups such as RedEcho have escalated network breaches targeting India's power industry since the 2020 Galwan Valley conflict. According to Maharashtra Cyber, over 1.5 million attacks on critical infrastructure websites were executed by seven advanced persistent threat (APT) groups in 2025 following terror incidents. This demonstrates the scale of coordinated cyberattacks that exceed the response capacity of standing armies alone. By leveraging plausible deniability to avoid reprisal and sustain strategic disruption, these operations are designed to remain below the threshold of open conflict.
Existing Institutional Architecture and its Limitations
India's current cybersecurity architecture is a complex web of institutions, each with distinct but overlapping mandates and missions. The 2024 amendment to the Allocation of Business Rules (AoBR), which designated the National Security Council Secretariat (NSCS) as the nodal agency for overall coordination and strategic direction, sought to bring much-needed clarity to this landscape[4].
The operational arm of the Indian Armed Forces in cyberspace is the Defence Cyber Agency (DCyA), headquartered in New Delhi, and reports directly to the Chief of Defence Staff (CDS) [8]. Its personnel is drawn from all three services – the Army, Navy, and Air Force – reflecting the tri-service character. Despite notable progress, including the release of the “Joint Doctrine for Cyberspace Operations” in August 2025 and the successful establishment of Cyber Emergency Response Teams (CERTs) for each service, the agency continues to grapple with persistent scalability challenges [8]. Calls to upgrade the DCyA into a full-fledged cyber command, staffed with up to 5,000 security experts, have been made repeatedly; yet the military's ongoing "teeth-to-tail" ratio reforms, alongside the Agnipath scheme's emphasis on leaner force structures, complicates the prospects for such large-scale expansion [18].

Ex-CDS General Anil Chauhan at Exercise Cyber Suraksha – 2024 | PIB
Under Section 70B of the Indian Information Technology Act 2000, the Computer Emergency Response Team (CERT-IN) serves as the national nodal agency responsible for responding to cybersecurity incidents [20]. The scale of this task is considerable: CERT-In processed roughly 29 lakh incidents in 2025 alone, underscoring the sheer volume of cyber activity affecting even the residential and domestic sphere [3].
Complementing CERT-In is the National Critical Information Infrastructure Protection Centre (NCIIPC), which focuses on sectors such as banking, transportation, and power [21]. Yet, despite the depth and regularity of their operations, both agencies remain fundamentally defensive and reactive in orientation. Neither currently possesses the institutional authority or trained manpower to undertake “hunt forward” operations or “offensive cyber operations”—capabilities that are becoming increasingly vital to deterring state-sponsored actors and other adversaries [2].
On the domestic front, the Indian Cybercrime Coordination Centre (I4C), under the Ministry of Home Affairs, plays an active role in investigating organised fraud and disinformation campaigns [20]. To this end, several important tools have been developed, such as “Pratibimb,” which enables real-time the geospatial mapping of cybercriminals’ locations [6]. Furthermore, the “Cyber Multi Agency Centre” (CyMAC) functions as a unified platform bringing together agencies such as the DCyA, CERT-In, the Intelligence Bureau (IB), and the Research and Analysis Wing (R&AW). However, even this level of coordination is often restricted to government personnel, leaving the considerable expertise residing in the private sector largely untapped
The Talent Gap: Human Capital as a Strategic Vulnerability
The strongest argument in favour of a National Cyber Reserve Force (NCRF) is the shortage of advanced cybersecurity talent within government. Indian organisations continue to experience a significant skills deficit. In 2024, 92 per cent of Indian organisations reported security breaches, primarily attributed to inadequate training and competence [16]. Although India is recognised as a global IT leader, specialised skills essential for cyber warfare—such as vulnerability research, malware reverse engineering, and AI-driven threat hunting—are predominantly found in private-sector firms and global capability centres, where compensation and career advancement opportunities exceed those in the military or civil services [9].
The existing recruitment model for the Territorial Army (TA) presents a potential pathway for cyber specialists but is constrained by outdated regulations from 1976 and stringent eligibility criteria, including requirements for prior military experience or employment in specific government departments such as Railways [28]. Opportunities for TA cyber warfare specialists remain limited, with only six positions available in 2023 and four in 2024, which is inadequate given the strategic demand for a substantially larger force [19]. Moreover, the rigid hierarchy of the armed forces may hinder the innovative “hacker mindset” needed to advance in this domain.
Comparative International Models: Evaluating transferability
To assess the feasibility of an Indian NCRF, it is important to examine relevant international models and consider their applicability to India’s socio-political and legal context.
The Estonian model rests on national pride and professional networking. The Estonian Defence League's Cyber Defence Unit (EDL CDU) is staffed by volunteers drawn from the civilian ICT community, who retain their regular employment but remain available for training and activation in times of crisis [29]. This approach works particularly well for a small, highly digitised nation, where the civilian population has a direct and tangible stake in the state's digital resilience [31].
Transferability to India: The “national pride” motivation translates well, but scaling this model across India's vast geography would be difficult without a decentralised, state-level chapter system.
Israel identifies exceptional technical talent at the age of 18 through compulsory military service, with some recruits going to serve in Unit 8200 — Israel’s elite cyber warfare and signals intelligence (SIGINT) unit, and remaining committed to the reserves for life [32]. This creates a seamless talent pipeline between the military and the cybersecurity industry, with reservists bringing private-sector innovation back into the Israel Defense Forces (IDF) [32].
Transferability to India: Once again, the applicability of this model is low, given that India does not practise conscription. Adopting an “elite conscription” model would require a fundamental transformation of national education and recruitment practices. What is far more relevant to the Indian context, however, is the underlying principle of lateral entry — drawing industry specialists into reservist roles.

US Cyber Command | USNI News
The United States relies on its Guard and Reserve components to provide surge capacity for US Cyber Command (USCYBERCOM). These units are increasingly viewed as a means of retaining "preeminent military cyber personnel" who move fluidly between private-sector careers and military duty. Discussions are currently underway to establish a dedicated "Cyber Force" to better manage this hybrid workforce [35].
Transferability to India: Moderate to High. The TA already possesses a framework comparable to the US National Guard, though its terms of service and specialised trades would require significant modernisation.

Comparing global cyber reserve models against the proposed Indian NCRF
Legal, Institutional, and Operational Feasibility
Establishing a National Cyber Reserve Force in India is feasible, but it necessitates overcoming substantial structural constraints.
India's existing legal regime, anchored by the IT Act, 2000, remains predominantly civilian in orientation and lacks explicit provisions authorising civilian participation in military-executed cyber operations [37]. The “civilian-military” coordination essential to a reserve force is complicated by the Official Secrets Act (OSA), under which the classification of threat intelligence and offensive cyber tools is a tightly guarded domain within the Ministry of Defence (MoD) [39]. Compounding this is the ambiguity surrounding the legal status of civilian volunteers in armed conflict, who risk being classified as "unprivileged belligerents" under International Humanitarian Law (IHL) – a designation that could expose them to both prosecution and kinetic targeting [41].
An NCRF would need to operate within the “Joint Doctrine for Cyberspace Operations” released in 2025, which emphasises synchronised operations across the three services [17]. However, its command structure must be flexible enough to allow for “distributed authorship” and rank-agnostic courses that involve academia and industry [44]. A central question, then, is whether the force should sit under the DCyA (military) or the NSCS (civilian). A hybrid model, in which a civilian-military board raises and trains the force but DCyA retains operational control during a declared emergency, appears the most viable path forward.
A compelling economic case underpins the argument for a reserve force. High personnel turnover and the recurring cost of maintaining specialised skills make standing cyber units prohibitively expensive to sustain. A reserve force allows the state to “rent” competence, significantly improving the armed forces' "teeth-to-tail" ratio [19]. While INR 782 crore was earmarked for cybersecurity in 2025, this remains insufficient to create a standing force of 5,000 professionals [3]. The TA’s adoption of a lateral entry of “domain specialists” from mid-2025 marks a step in the right direction, but it will need to be scaled up considerably to meet the strategic requirement [45].
Strategic Value: Resilience, Surge Capacity, and Deterrence
The strategic value of an NCRF extends beyond technical support, serving as a force multiplier that enhances the state's overall capabilities in the digital domain:
A strong reserve force helps to “deter by denial” by showing that India has a “whole-of-society” approach to cyber resilience. If an enemy understands that a cyberattack on a power grid will be confronted with thousands of mobilised defenders who created those very systems in the private sector, then the perceived utility of such an attack goes down [23]. In addition, the NCRF offers a credible way of “signalling” in a crisis. Mass mobilisation of cyber reservists can be a non-kinetic signal of determination, perhaps de-escalating a situation before it crosses the kinetic threshold [23].
In a national emergency like the 2025 India-Pakistan impasse, the sheer volume of cyber incidents, ranging from disinformation to infrastructure probing, can rapidly overwhelm standing authorities [11].
An NCRF gives the “mass” the ability to monitor networks, conduct quick forensics, and restore services simultaneously across several sectors [48]. The surge capacity is critical to prevent the “cascading effects” of a cyberattack on public order and economic stability [6].
Technical reservists can support military operations, providing access to advanced technical and AI capabilities that regular forces cannot afford to maintain full-time [19]. They can be incorporated in research institutions such as Signals Technology Evaluation and Adaptation Group (STEAG) to innovate in next-generation communications and "Secure by Design" protocols [6]. This would ensure real “Atmanirbharta” (self-reliance) by ensuring Indian cyber defence is based on indigenous systems and intellectual property [6].
Risks and Mitigation: Managing the Downsides of a Reserve Force
Creating a hybrid force is not without significant risks, particularly in the sensitive domain of national security. Some of the challenges are highlighted below:
Deploying semi-civilian personnel in offensive operations further complicates the “attribution” dilemma. If a reserve unit goes on the counter-offensive, the enemy may have a hard time distinguishing a state act from a non-state “patriotic hacker” act, raising the potential of inadvertent escalation [49]. This is especially problematic in the South Asian context, where the misattribution of a cyberattack on NC3 systems could lead to a nuclear strike. To counter this, well-defined “Rules of Engagement” (RoE) need to be put in place, and offensive actions should be the sole prerogative of the regular military, with the reservists restricted to support and defensive missions [11].
Bringing private-sector personnel into the national security system increases “insider threat” dangers. Reservists can have their allegiance divided between the state and their business employers, or be targeted by foreign intelligence organisations for recruitment[40]. An in-depth, Multi-Stage Vetting Process requires “Pratibimb-style” geospatial monitoring and continuous background checks [6]. There are also concerns that agencies such as the NCCC and NTRO are not subject to parliamentary supervision, raising questions about widespread monitoring and infringement of civil liberties [53].
What if the reservist, while defending a private network under a government mandate, causes collateral damage to a third party? The current legal framework provides no "safe-harbour" or liability protection for such situations. A defined responsibility framework and state-backed indemnity insurance for mobilised reservists are prerequisites for private-sector engagement [54].
Actionable Policy Recommendations
To effectively build a National Cyber Reserve Force that advances India's strategic interests, the following recommendations are provided:
1. Enact a Cyber Reserve Act (CRA)
India requires a specific statutory framework to govern the NCRF. The CRA should:
2. Implement a "Specialised Technical Trade" in the Territorial Army
The MoD should move beyond the current 1976-era TA regulations and create a specific "Cyber and Emerging Tech" cadre.
3. Establish Regional Cyber Training Ranges (RCTR)
To keep the reserve force technically current, India should establish RCTRs in major technology hubs like Bengaluru, Hyderabad, and Pune.
4. Create a "Cyber National Guard" for CII Protection
The NCIIPC should be empowered to raise its own "Reserve Wing" comprising employees from designated critical sectors (Power, Banking, Telecom).
5. Develop an "AIBOM" and "Trusted Source" Vetting Protocol
Given the rise of AI-driven threats, the NCRF must be part of a "Trusted Telecom Portal" framework that audits not just hardware but the human elements of the supply chain.[3]
Conclusion: Toward a "Whole-of-Nation" Cyber Posture
The primary challenge is not the feasibility of establishing a National Cyber Reserve Force, but whether sufficient institutional and legal commitment exists to implement it. The 2025 Joint Theory for Cyberspace Operations has laid the groundwork for a unified military approach; however, essential human resources remain concentrated in the private sector. A legally robust, tiered, and professionally managed reserve force can address the skills gap, strengthen strategic deterrence, and ensure that digital transformation does not become a security vulnerability.
A National Cyber Reserve Force provides strategic utility by enabling rapid mobilisation during crises, such as the May 2025 standoff, and fostering a culture of indigenous innovation essential for long-term sovereignty. However, the NCRF's effectiveness depends on the state's capacity to balance military secrecy with civilian collaboration and manage the tension between offensive requirements and the risk of escalation. In an era characterised by grey-zone warfare, leveraging India's civilian cyber capabilities forms the foundation for comprehensive national defence in the 21st century.
[The article is exclusive to NatStrat. The views expressed by the author(s) are personal and do not necessarily reflect the views of the organisation.]
References