Independent , Honest and Dignified Journalism

AUDIT FAILURE SPARKS OUTAGE

At a time when governments are moving rapidly toward digital governance and integrated citizen services, the inability of key departments, including even those tasked with promoting e-governance, to comply with the mandatory security audit protocols laid down by the Ministry of Electronics and Information Technology (MeitY) is nothing short of alarming. It is not merely a case of websites going offline temporarily; it is a manifestation of systemic complacency toward cyber hygiene, institutional accountability, and ultimately, public service delivery.

MeitY has long mandated that all government websites undergo an annual security audit through CERT-In empanelled agencies. These audits are not just bureaucratic rituals—they are essential mechanisms designed to detect vulnerabilities, prevent cyber intrusions, and safeguard the integrity and availability of online public services. Despite repeated circulars, including a stern directive issued, departments continued to disregard these instructions. The consequences of such disregard are now on full display: a string of public-facing portals rendered inaccessible, affecting service delivery and eroding public trust in digital governance. The irony is stark. Agencies like the Jammu and Kashmir e-Governance Agency (JaKeGA), which are supposed to guide and assist other departments in maintaining secure digital infrastructure, have themselves failed to maintain compliance, with their websites also offline due to non-certification. What message does this send about our preparedness to manage the increasing dependency on digital platforms? If the watchdogs themselves are compromised, who then ensures the security and functionality of our digital ecosystem? The fallout of this negligence extends beyond administrative embarrassment. Ordinary citizens, many of whom depend on these websites for accessing vital services, ranging from land records to grievance redressal, are now caught in a limbo. For a daily wager seeking labour registration, or a student applying for a scholarship, the unavailability of these websites is not an inconvenience; it is a direct denial of rights. The cost of inaction is borne by the people, not by the erring officials. It is important to understand that cyber threats are no longer distant possibilities; they are imminent, evolving, and increasingly sophisticated. In the absence of periodic audits, departmental websites become low-hanging fruit for malicious actors, potentially exposing sensitive personal data, official correspondence, and backend administrative control systems. In such a high-risk environment, the UT administration’s failure to institutionalize cybersecurity protocols reflects not only a technological shortfall but a failure of governance. So, where do we go from here? Firstly, there needs to be a culture shift within the administrative machinery—cybersecurity cannot be treated as a peripheral concern or an IT department’s headache. It must become a core priority embedded within each department’s functioning, backed by accountability measures. Annual audits should not be reminders but deliverables tied to performance reviews of departmental heads. Secondly, the Information Technology Department should move from being an advisory body to a proactive enforcer of cybersecurity protocols. This includes maintaining a live dashboard of certification statuses across departments, issuing red flags in real-time, and even initiating partial suspension of non-compliant services until rectification. Support should be made available in the form of centralized resources, empanelled vendor rosters, and rapid-response audit facilitation teams. Thirdly, a public disclosure mechanism should be introduced. Citizens deserve to know which websites are audited and compliant and which are not. Moreover, it will allow users to make informed decisions when engaging with digital platforms. Fourth, we must look beyond audits alone. Training programs for departmental staff on cyber hygiene, information security, and data protection need to be institutionalized. 

The current situation is a wake-up call. One hopes it will not be muffled by excuses or short-lived fixes but will instead spark a comprehensive rethinking of how cyber readiness is approached within our public institutions. The time to act was yesterday. The cost of further delay will be paid not only in service disruption but in the loss of public faith—a price far too high for any democracy to afford.

WhatsApp Channel