On August 15, 2026, the National Institute of Electronics and Information Technology (NIELIT) under the Ministry of Electronics and Information Technology (MeitY) launched CYBER KUSHTI 2026. Organised alongside the 3rd National Conference on Cyber Security, Digital Forensics and Intelligence (NCCDFI 2026) with CERT-In as Knowledge Partner, this national hackathon tests human analytical judgment over automated detection speed. Contestants in three-member teams evaluate deliberately flawed, AI-generated security reports to prioritize genuine threats and eliminate false positives. The initiative addresses critical skill gaps in digital forensics, national cybersecurity architecture, and artificial intelligence validation.
The National Institute of Electronics and Information Technology (NIELIT) unveiled CYBER KUSHTI 2026, an innovative cybersecurity and Artificial Intelligence hackathon. Unlike traditional Capture The Flag (CTF) contests that emphasize detection speed, this initiative specifically scores critical evaluation and threat prioritization. Participating teams analyze an identical, deliberately flawed Security Assessment Package containing AI-generated reports, code logs, duplicate findings, and omitted vulnerabilities. Participants are evaluated on their ability to eliminate false positives, identify genuine risks, and defend remediation strategies.
The hackathon was officially launched on August 15, 2026, with online registrations open until September 10, 2026. The initial stages—The Akhada on September 15 and The Dangal on September 24—are hosted online nationwide. The final in-person stage, The Kesari, will take place on October 9, 2026, at the Dr. Ambedkar International Centre in New Delhi during the 3rd National Conference on Cyber Security, Digital Forensics and Intelligence (NCCDFI 2026).
India achieved Tier 1 ("Role Model") status in the International Telecommunication Union (ITU) Global Cybersecurity Index (GCI) 2024, securing an overall score of 98.49 out of 100. India matches top international standards across legal and organizational parameters, yet bridging hands-on workforce skill deficits remains an essential priority alongside global leaders like the United States and the United Kingdom.
Core Concept: National Cybersecurity Architecture of India
Q1. Which organization launched the national hackathon "CYBER KUSHTI 2026"? [Easy]
A) NITI Aayog
B) National Institute of Electronics and Information Technology (NIELIT)
C) Defence Research and Development Organisation (DRDO)
D) Centre for Development of Advanced Computing (C-DAC)
Answer: B
Explanation: NIELIT, an autonomous society under MeitY, launched the CYBER KUSHTI 2026 hackathon on August 15, 2026.
Q2. What is the designated title for the winning team of CYBER KUSHTI 2026? [Easy]
A) Cyber Dronacharya
B) Cyber Kesari 2026
C) Cyber Mahabali
D) Cyber Senapati
Answer: B
Explanation: The winning team will be awarded the title Cyber Kesari 2026 along with a traditional ceremonial Gada.
Q3. Under which section of the Information Technology Act, 2000 does CERT-In derive its statutory functions? [Moderate]
A) Section 43A
B) Section 66A
C) Section 70B
D) Section 79
Answer: C
Explanation: Section 70B of the IT Act, 2000 establishes CERT-In as the national nodal agency for incident response and monitoring.
Q4. What primary operational metric distinguishes CYBER KUSHTI 2026 from traditional Capture The Flag (CTF) hackathons? [Moderate]
A) Speed of breaking encryption keys
B) Human judgment, threat prioritization, and rejection of false positives
C) Number of physical servers deployed by participants
D) Total lines of malicious code generated
Answer: B
Explanation: CYBER KUSHTI focuses on evaluating, prioritizing, and defending security findings rather than raw discovery speed.
Q5. Which institution serves as the official Knowledge Partner for CYBER KUSHTI 2026? [Moderate]
A) Indian Computer Emergency Response Team (CERT-In)
B) National Critical Information Infrastructure Protection Centre (NCIIPC)
C) Data Security Council of India (DSCI)
D) Indian Cyber Crime Coordination Centre (I4C)
Answer: A
Explanation: CERT-In is the designated Knowledge Partner collaborating with NIELIT and ISAC Foundation.
Q6. Consider the following stages of CYBER KUSHTI 2026:
1. The Akhada
2. The Dangal
3. The Kesari
What is the correct sequential order of these stages from preliminary to final? [Tricky]
A) 1 — 2 — 3
B) 2 — 1 — 3
C) 3 — 1 — 2
D) 1 — 3 — 2
Answer: A
Explanation: The competition progresses from Round 1 (The Akhada) to Round 2 (The Dangal) and concludes with the final stage (The Kesari).
Q7. In the context of cybersecurity evaluation packages used in CYBER KUSHTI 2026, which of the following is intentionally incorporated into the dataset? [Tricky]
A) Real passwords extracted from live banking networks
B) AI-generated findings with deliberately omitted vulnerabilities and false reports
C) Zero-day exploits targeted against live government servers
D) Proprietary source codes of foreign defence contractors
Answer: B
Explanation: Organizers provide identical, deliberately imperfect datasets containing false, duplicate, and genuine findings with omitted vulnerabilities to test human validation.
Q8. What status was conferred on NIELIT by the Ministry of Education to expand its academic mandate in the E&ICT domain? [Tricky]
A) Institute of National Importance (INI)
B) Deemed to be University under distinct category
C) Central University under Central Universities Act
D) Autonomous Research Think Tank
Answer: B
Explanation: NIELIT has been granted Deemed to be University status under the distinct category with its main campus at Ropar, Punjab.
PYQ 1:
With reference to Indian cybersecurity architecture, consider the primary mandate of CERT-In:
A) It acts as the nodal agency for collection, analysis, and dissemination of information on cyber incidents.
B) It functions exclusively as a military unit under the Integrated Defence Staff.
C) It is an intelligence agency operating under the Cabinet Secretariat.
D) It regulates telecommunication spectrum pricing across private service providers.
Answer: A
Explanation: CERT-In operates under MeitY to respond to cyber security incidents, forecast emergency response, and issue technical guidelines.
PYQ 2:
Consider the following statements regarding the national cybersecurity framework:
1. CERT-In is statutory under Section 70B of the Information Technology Act, 2000.
2. National Critical Information Infrastructure Protection Centre (NCIIPC) is designated under Section 70A of the IT Act.
3. CYBER KUSHTI 2026 permits live penetration testing on active public infrastructure.
Which of the above statements is/are correct?
A) 1 and 2 only
B) 2 and 3 only
C) 1 and 3 only
D) 1, 2 and 3
Answer: A
Explanation: Statements 1 and 2 are correct legal provisions. Statement 3 is incorrect because all hackathon activities are strictly confined to safe, controlled, synthetic environments without any live system access.
PYQ 3:
Match List-I (Body / Program) with List-II (Key Function / Association):
| List-I | List-II | | --- | --- | | A. NIELIT | 1. Deemed to be University under MeitY | | B. CERT-In | 2. National nodal body for cyber incident response | | C. ISAC Foundation | 3. National Security Database project operator |
Select the correct code:
A) A-1, B-2, C-3
B) A-2, B-1, C-3
C) A-3, B-2, C-1
D) A-1, B-3, C-2
Answer: A
Explanation: NIELIT is an autonomous scientific body and Deemed to be University, CERT-In handles incident response, and ISAC operates the National Security Database.
Question 1 (150 words): In an era of automated code analysis and AI-driven scanners, evaluate how human analytical judgment remains critical to national cybersecurity defence.
The proliferation of Artificial Intelligence has transformed vulnerability detection from a scarcity of signals into an overabundance of noise. Automated security scanners and Large Language Models generate thousands of vulnerability findings within seconds. However, these tools frequently introduce hallucinations, duplicate alerts, and context-blind false positives while missing subtle architectural flaws.
Human analytical judgment provides the indispensable verification layer required to triage these automated outputs. Security practitioners must contextualize severity based on threat feasibility, organizational mission, and architectural dependencies rather than raw scanner metrics. Distinguishing true positives from benign anomalies preserves incident response bandwidth and prevents alert fatigue across critical national operations.
Initiatives like CYBER KUSHTI 2026 institutionalize this paradigm by training technical professionals to interrogate and defend security assessments. Building an agile workforce skilled in cognitive validation rather than simple discovery forms the bedrock of India's resilient digital sovereignty.
Question 2 (250 words): Analyze India's national cybersecurity architecture. How do institutional collaborations between academia, industry, and enforcement bodies address contemporary digital security challenges?
India's national cybersecurity architecture rests on statutory foundations anchored in the Information Technology Act, 2000. Under this legislative canopy, specialized bodies govern distinct vectors of cyberspace: CERT-In manages incident response under Section 70B, while the National Critical Information Infrastructure Protection Centre (NCIIPC) oversees vital national assets designated under Section 70A. Complementing these are operational mechanisms like the Indian Cyber Crime Coordination Centre (I4C) and strategic guidance from the National Cyber Security Coordinator.
Despite securing Tier 1 status in the ITU Global Cybersecurity Index 2024 with a 98.49 score, India faces sophisticated threat landscapes characterized by automated exploit generation, state-sponsored cyber espionage, and systemic workforce deficits. Addressing these multi-domain challenges requires seamless institutional convergence among government bodies, academic centers, and non-profit organizations.
Collaborative initiatives such as CYBER KUSHTI 2026—bringing together NIELIT, ISAC Foundation, and CERT-In—demonstrate the efficacy of this synergy. NIELIT leverages its nationwide footprint of 56 centers and Deemed to be University infrastructure to democratize high-level training across Tier-2 and Tier-3 institutions. Concurrently, industry standards through the National Security Database provide professional validation, while CERT-In aligns competitive challenges with actual frontline threat vectors.
The way forward requires institutionalizing regular cyber-drills across state agencies, expanding research fellowships in digital forensics, and standardizing AI auditing frameworks across academic curricula. Harmonizing institutional mandates ensures India translates international index rankings into robust, sovereign cyber deterrence.