Udyo Logo

Udyo

Get the Udyo Mobile App

Sign in to save your progress and access all features.

NIELIT Launches CYBER KUSHTI 2026: India's National Cybersecurity and AI Hackathon

On August 15, 2026, the National Institute of Electronics and Information Technology (NIELIT) under the Ministry of Electronics and Information Technology (MeitY) launched CYBER KUSHTI 2026. Organised alongside the 3rd National Conference on Cyber Security, Digital Forensics and Intelligence (NCCDFI 2026) with CERT-In as Knowledge Partner, this national hackathon tests human analytical judgment over automated detection speed. Contestants in three-member teams evaluate deliberately flawed, AI-generated security reports to prioritize genuine threats and eliminate false positives. The initiative addresses critical skill gaps in digital forensics, national cybersecurity architecture, and artificial intelligence validation.

What Happened

The National Institute of Electronics and Information Technology (NIELIT) unveiled CYBER KUSHTI 2026, an innovative cybersecurity and Artificial Intelligence hackathon. Unlike traditional Capture The Flag (CTF) contests that emphasize detection speed, this initiative specifically scores critical evaluation and threat prioritization. Participating teams analyze an identical, deliberately flawed Security Assessment Package containing AI-generated reports, code logs, duplicate findings, and omitted vulnerabilities. Participants are evaluated on their ability to eliminate false positives, identify genuine risks, and defend remediation strategies.

When & Where

The hackathon was officially launched on August 15, 2026, with online registrations open until September 10, 2026. The initial stages—The Akhada on September 15 and The Dangal on September 24—are hosted online nationwide. The final in-person stage, The Kesari, will take place on October 9, 2026, at the Dr. Ambedkar International Centre in New Delhi during the 3rd National Conference on Cyber Security, Digital Forensics and Intelligence (NCCDFI 2026).

Who Is Involved

  • NIELIT: Autonomous scientific society under MeitY and a Deemed to be University, leading the event execution.
  • ISAC Foundation: Information Sharing and Analysis Center, a Section 8 non-profit operating the National Security Database (NSD).
  • CERT-In: Indian Computer Emergency Response Team serving as the official Knowledge Partner.
  • Prof. (Dr.) M. M. Tripathi: Director General of NIELIT and Vice Chancellor of NIELIT Deemed to be University, who inaugurated the initiative.
  • Participants: Open free of charge to independent researchers and college students competing in teams of three.

How It Works

  • Controlled Distribution: Teams receive an identical, deliberately imperfect Security Assessment Package comprising AI-generated outputs, static analysis data, source code, and application logs.
  • Round 1 (The Akhada): An online evaluation round on September 15, 2026, where top-performing squads are shortlisted down to 50 teams.
  • Round 2 (The Dangal): A rigorous technical filtering on September 24, 2026, where the top 10 finalist teams are selected.
  • Round 3 (The Kesari): In-person final on October 9, 2026, in New Delhi, requiring finalists to defend their security triage on the main stage before an expert jury.
  • Safe Sandboxing: All testing runs within isolated, synthetic environments without interaction with live public infrastructure.

Why It Matters

  • Governance & Policy (GS-2): Strengthens national cyber-defense capacity building and reinforces institutional readiness against synthetic threats.
  • Internal Security (GS-3): Addresses critical workforce shortages by transforming raw discovery skills into strategic vulnerability management.
  • Science & Technology (GS-3): Establishes evaluation paradigms for auditing AI-generated code and managing algorithmic hallucinations in security operations.

Historical Background

  • 1994: DOEACC Society was formed to standardize computer education, later evolving into NIELIT.
  • 2000: The Information Technology Act, 2000 was enacted, creating the legal architecture for electronic commerce and cyber offences.
  • 2004: CERT-In became fully operational as the national incident response body.

Previous Related Events

  • 2020: Launch of the National Cyber Crime Reporting Portal under the Ministry of Home Affairs.
  • 2022: CERT-In issued binding cybersecurity directions mandating 6-hour incident reporting norms.
  • 2023: NIELIT was granted Deemed to be University status under distinct category by the Ministry of Education.

Static GK Connection

  • Section 70B of the IT Act, 2000: Grants CERT-In statutory authority to monitor, forecast, and respond to cybersecurity incidents across India.
  • Cybersecurity Triaging & Threat Modelling: Principles of evaluating Confidentiality, Integrity, and Availability (CIA Triad) and filtering false positive signals from genuine threat telemetry.

India & World Comparison

India achieved Tier 1 ("Role Model") status in the International Telecommunication Union (ITU) Global Cybersecurity Index (GCI) 2024, securing an overall score of 98.49 out of 100. India matches top international standards across legal and organizational parameters, yet bridging hands-on workforce skill deficits remains an essential priority alongside global leaders like the United States and the United Kingdom.

Future Impact

  • Institutionalization of human-in-the-loop security verification protocols across public digital infrastructure.
  • Pipeline expansion of verified ethical hackers recognized under the National Security Database.
  • Rollout of standardized curriculum frameworks for AI-assisted vulnerability triaging across technical universities.

🔑 Key Points for Revision

  • CYBER KUSHTI 2026 was launched on August 15, 2026, by NIELIT under MeitY.
  • The hackathon runs as the technical track for the 3rd NCCDFI conference.
  • Final round will be held at Dr. Ambedkar International Centre, New Delhi.
  • Registration remains open until September 10, 2026, for three-member teams.
  • Emphasizes analytical judgment over automated discovery speed.
  • Deliberately imperfect packages include AI hallucinations, false positives, and omitted vulnerabilities.
  • Round 1 is termed "The Akhada" on September 15, 2026.
  • Round 2 is termed "The Dangal" on September 24, 2026.
  • Final Round is termed "The Kesari" on October 9, 2026.
  • Winner receives the title "Cyber Kesari 2026" and a traditional Gada.
  • Runners-up are awarded the titles "Rustam" and "Pahalwan".
  • ISAC Foundation partners via the National Security Database initiative.
  • CERT-In functions as the official Knowledge Partner under the IT Act.
  • NIELIT operates 56 centers and holds Deemed to be University status.
  • Finalists defend technical decisions before a multi-sectoral expert jury.

🧠 Concept Link (Static GK Deep Dive)

Core Concept: National Cybersecurity Architecture of India

  • Definition: The institutional, statutory, and operational framework established to secure national cyberspace against threats.
  • Constitutional / Legal Basis: Union List (Entry 31 - Communication) and Information Technology Act, 2000 (notably Sections 43, 66, 69, 70, 70A, and 70B).
  • Scientific / Economic Principle: Threat triaging balance between False Positive Rates (FPR) and False Negative Rates (FNR) to secure digital economic infrastructure.
  • How it connects to this event: CYBER KUSHTI directly trains the human analytical layer required by CERT-In and national security frameworks.
  • Origin & History: Formalized following the enactment of the Information Technology Act, 2000.
  • Key milestone 1: Establishment and operationalization of CERT-In in 2004 as national incident response center.
  • Key milestone 2: Notification of the National Cyber Security Policy in 2013.
  • Related Acts / Schemes / Treaties: Information Technology Act 2000, Digital Personal Data Protection Act 2023, and Budapest Convention on Cybercrime (non-signatory).
  • Nodal Ministry / Body: Ministry of Electronics and Information Technology (MeitY) and National Cyber Security Coordinator (NCSC).
  • India-specific relevance: Protects digital public goods including Aadhaar, UPI, and critical power grid telemetry.
  • Global comparison: Matches the US CISA and UK NCSC frameworks in incident coordination and threat reporting.
  • Data point: India ranked in Tier 1 (Role Model) of the ITU Global Cybersecurity Index 2024 with a 98.49 score.
  • Common exam angle: Statutory powers of CERT-In under Section 70B, Critical Information Infrastructure under NCIIPC (Section 70A).
  • Easy memory hook: C-N-C (CERT-In for incidents, NCIIPC for critical assets, CYBER KUSHTI for talent skills).

❓ Practice MCQs

Q1. Which organization launched the national hackathon "CYBER KUSHTI 2026"? [Easy]

A) NITI Aayog

B) National Institute of Electronics and Information Technology (NIELIT)

C) Defence Research and Development Organisation (DRDO)

D) Centre for Development of Advanced Computing (C-DAC)

Answer: B

Explanation: NIELIT, an autonomous society under MeitY, launched the CYBER KUSHTI 2026 hackathon on August 15, 2026.


Q2. What is the designated title for the winning team of CYBER KUSHTI 2026? [Easy]

A) Cyber Dronacharya

B) Cyber Kesari 2026

C) Cyber Mahabali

D) Cyber Senapati

Answer: B

Explanation: The winning team will be awarded the title Cyber Kesari 2026 along with a traditional ceremonial Gada.


Q3. Under which section of the Information Technology Act, 2000 does CERT-In derive its statutory functions? [Moderate]

A) Section 43A

B) Section 66A

C) Section 70B

D) Section 79

Answer: C

Explanation: Section 70B of the IT Act, 2000 establishes CERT-In as the national nodal agency for incident response and monitoring.


Q4. What primary operational metric distinguishes CYBER KUSHTI 2026 from traditional Capture The Flag (CTF) hackathons? [Moderate]

A) Speed of breaking encryption keys

B) Human judgment, threat prioritization, and rejection of false positives

C) Number of physical servers deployed by participants

D) Total lines of malicious code generated

Answer: B

Explanation: CYBER KUSHTI focuses on evaluating, prioritizing, and defending security findings rather than raw discovery speed.


Q5. Which institution serves as the official Knowledge Partner for CYBER KUSHTI 2026? [Moderate]

A) Indian Computer Emergency Response Team (CERT-In)

B) National Critical Information Infrastructure Protection Centre (NCIIPC)

C) Data Security Council of India (DSCI)

D) Indian Cyber Crime Coordination Centre (I4C)

Answer: A

Explanation: CERT-In is the designated Knowledge Partner collaborating with NIELIT and ISAC Foundation.


Q6. Consider the following stages of CYBER KUSHTI 2026:

1. The Akhada
2. The Dangal
3. The Kesari
What is the correct sequential order of these stages from preliminary to final? [Tricky]

A) 1 — 2 — 3

B) 2 — 1 — 3

C) 3 — 1 — 2

D) 1 — 3 — 2

Answer: A

Explanation: The competition progresses from Round 1 (The Akhada) to Round 2 (The Dangal) and concludes with the final stage (The Kesari).


Q7. In the context of cybersecurity evaluation packages used in CYBER KUSHTI 2026, which of the following is intentionally incorporated into the dataset? [Tricky]

A) Real passwords extracted from live banking networks

B) AI-generated findings with deliberately omitted vulnerabilities and false reports

C) Zero-day exploits targeted against live government servers

D) Proprietary source codes of foreign defence contractors

Answer: B

Explanation: Organizers provide identical, deliberately imperfect datasets containing false, duplicate, and genuine findings with omitted vulnerabilities to test human validation.


Q8. What status was conferred on NIELIT by the Ministry of Education to expand its academic mandate in the E&ICT domain? [Tricky]

A) Institute of National Importance (INI)

B) Deemed to be University under distinct category

C) Central University under Central Universities Act

D) Autonomous Research Think Tank

Answer: B

Explanation: NIELIT has been granted Deemed to be University status under the distinct category with its main campus at Ropar, Punjab.


📜 Previous Year Question Style (PYQ)

PYQ 1:

With reference to Indian cybersecurity architecture, consider the primary mandate of CERT-In:

A) It acts as the nodal agency for collection, analysis, and dissemination of information on cyber incidents.

B) It functions exclusively as a military unit under the Integrated Defence Staff.

C) It is an intelligence agency operating under the Cabinet Secretariat.

D) It regulates telecommunication spectrum pricing across private service providers.

Answer: A

Explanation: CERT-In operates under MeitY to respond to cyber security incidents, forecast emergency response, and issue technical guidelines.


PYQ 2:

Consider the following statements regarding the national cybersecurity framework:

1. CERT-In is statutory under Section 70B of the Information Technology Act, 2000.
2. National Critical Information Infrastructure Protection Centre (NCIIPC) is designated under Section 70A of the IT Act.
3. CYBER KUSHTI 2026 permits live penetration testing on active public infrastructure.

Which of the above statements is/are correct?

A) 1 and 2 only

B) 2 and 3 only

C) 1 and 3 only

D) 1, 2 and 3

Answer: A

Explanation: Statements 1 and 2 are correct legal provisions. Statement 3 is incorrect because all hackathon activities are strictly confined to safe, controlled, synthetic environments without any live system access.


PYQ 3:

Match List-I (Body / Program) with List-II (Key Function / Association):

| List-I | List-II | | --- | --- | | A. NIELIT | 1. Deemed to be University under MeitY | | B. CERT-In | 2. National nodal body for cyber incident response | | C. ISAC Foundation | 3. National Security Database project operator |

Select the correct code:

A) A-1, B-2, C-3

B) A-2, B-1, C-3

C) A-3, B-2, C-1

D) A-1, B-3, C-2

Answer: A

Explanation: NIELIT is an autonomous scientific body and Deemed to be University, CERT-In handles incident response, and ISAC operates the National Security Database.


✍️ Mains Answer Pointers

Question 1 (150 words): In an era of automated code analysis and AI-driven scanners, evaluate how human analytical judgment remains critical to national cybersecurity defence.

The proliferation of Artificial Intelligence has transformed vulnerability detection from a scarcity of signals into an overabundance of noise. Automated security scanners and Large Language Models generate thousands of vulnerability findings within seconds. However, these tools frequently introduce hallucinations, duplicate alerts, and context-blind false positives while missing subtle architectural flaws.

Human analytical judgment provides the indispensable verification layer required to triage these automated outputs. Security practitioners must contextualize severity based on threat feasibility, organizational mission, and architectural dependencies rather than raw scanner metrics. Distinguishing true positives from benign anomalies preserves incident response bandwidth and prevents alert fatigue across critical national operations.

Initiatives like CYBER KUSHTI 2026 institutionalize this paradigm by training technical professionals to interrogate and defend security assessments. Building an agile workforce skilled in cognitive validation rather than simple discovery forms the bedrock of India's resilient digital sovereignty.


Question 2 (250 words): Analyze India's national cybersecurity architecture. How do institutional collaborations between academia, industry, and enforcement bodies address contemporary digital security challenges?

India's national cybersecurity architecture rests on statutory foundations anchored in the Information Technology Act, 2000. Under this legislative canopy, specialized bodies govern distinct vectors of cyberspace: CERT-In manages incident response under Section 70B, while the National Critical Information Infrastructure Protection Centre (NCIIPC) oversees vital national assets designated under Section 70A. Complementing these are operational mechanisms like the Indian Cyber Crime Coordination Centre (I4C) and strategic guidance from the National Cyber Security Coordinator.

Despite securing Tier 1 status in the ITU Global Cybersecurity Index 2024 with a 98.49 score, India faces sophisticated threat landscapes characterized by automated exploit generation, state-sponsored cyber espionage, and systemic workforce deficits. Addressing these multi-domain challenges requires seamless institutional convergence among government bodies, academic centers, and non-profit organizations.

Collaborative initiatives such as CYBER KUSHTI 2026—bringing together NIELIT, ISAC Foundation, and CERT-In—demonstrate the efficacy of this synergy. NIELIT leverages its nationwide footprint of 56 centers and Deemed to be University infrastructure to democratize high-level training across Tier-2 and Tier-3 institutions. Concurrently, industry standards through the National Security Database provide professional validation, while CERT-In aligns competitive challenges with actual frontline threat vectors.

The way forward requires institutionalizing regular cyber-drills across state agencies, expanding research fellowships in digital forensics, and standardizing AI auditing frameworks across academic curricula. Harmonizing institutional mandates ensures India translates international index rankings into robust, sovereign cyber deterrence.


⚠️ Examiner Trap

  • Trap 1: Students often confuse CERT-In (Section 70B, handling general cyber incident response) with NCIIPC (Section 70A, protecting designated Critical Information Infrastructure). The correct fact is that CERT-In is the Knowledge Partner for CYBER KUSHTI, operating under MeitY.
  • Trap 2: A common wrong assumption is that CYBER KUSHTI is a conventional Capture The Flag (CTF) race. The reality is that the hackathon evaluates human judgment, threat prioritization, and the correct rejection of false positives rather than automated speed.
  • Trap 3: Many students miss the distinction regarding competition environments and assume live government systems are tested. Always remember that all challenges take place exclusively within isolated, synthetic sandbox environments.

🧭 Exam Tip

  • Prelims Focus: Focus on institutional mandates, statutory sections of the IT Act (Sections 70, 70A, 70B), host ministries, and sequence names (Akhada, Dangal, Kesari).
  • Mains Focus: Structure answers around the shift from "threat discovery" to "threat validation/triaging", incorporating the challenges of AI-generated false positives and critical infrastructure protection.
  • Interview Perspective: Highlight why domestic capacity building and democratizing technical education across non-metro colleges is crucial for digital sovereignty.
  • High-Probability Prediction: Expect direct questions in upcoming exams on the statutory role of CERT-In under Section 70B or conceptual questions contrasting automated vs. human vulnerability triage in internal security papers.