Daybreak - India trains more ethical hackers than anywhere else. It just can't give them a reason to stay
Episode Date: August 23, 2026When Nisarga Adhikary found critical flaws in CBSE's exam portal, the board denied it. So he broke back in, filmed it, and left anime videos running on their servers.IIT Kanpur hired him the ...same week it launched India's first undergraduate cybersecurity degree — one that recruits through hackathons and sends students to work at government security agencies for two of the four years.India produces a quarter of all researchers on global bug bounty platforms. The bounties come almost entirely from foreign companies. The RBI is now hiring cybersecurity talent on three-year contracts with no renewal path.California is still winning.Daybreak is produced from the newsroom of The Ken, India’s first subscriber-only business news platform. Subscribe for more exclusive, deeply-reported, and analytical business stories.
Transcript
Discussion (0)
When Nassarka Adhikari found critical security flaws in CBSE's Class 12 board exam portal,
CBSC publicly denied it.
And so, the 19-year-old broke back in, filmed himself doing it,
and just to prove his point, left memes and anime videos running on the board's own servers.
Since then, he has filed about 30 more vulnerability reports with certain,
which is India's cybersecurity agency.
The complaints cover public sector banks, several government bodies a cafe chained and two dating apps.
He told my colleague Mutasem Khan that most of those reports are still unpatched or ignored.
He said that the sure incompetence of our authorities baffles him.
He claims that this is the kind of stuff that if left to him, he could fix in just a matter of hours.
And turns out he is not the only one finding these gaps.
In May, the Ken reported that Indian enterprises were being left dangerously exposed in a post-LLM world.
Within weeks, attackers had leaked classified Apple Tesla schematics from data electronics,
exposed blueprints tied to India's largest nuclear plant, and breached hospitals, power grids,
telecom firms and even e-rishas.
Meanwhile, in June, the RBI asked India's biggest banks what were it the most.
and at the top of the list was AI-powered cyber attacks.
This has resulted in the government,
finally looking for talent in places it has ignored for a long time.
In fact, right after the CBSE breach,
IIT Kanpur hired Adikari as a threat intelligence engineer.
That same week, the institute launched a first of its kind
undergraduate cybersecurity program,
one that recruits hackers through hackathons instead of just J.E.
E-A-advanced course and actually send students to work at government security organizations
for two out of the four-year program.
But like many of India's best cybersecurity researchers, Adikari is already weighing offers from
California.
And his story aptly captures India's cybersecurity paradox.
The country trains more young ethical hackers than anywhere else in the world, but is still
short of nearly a million cybersecurity professionals.
The RBI, the Home Ministry's cybercrime unit, and certain are all hiring to close that gap.
But many of these roles are contractual with no path to a permanent job.
Which means against Silicon Valley and global capability centers,
India isn't struggling to find talent.
It's struggling to give that talent a reason to stay.
Welcome to Daybreak, a business podcast from the Ken.
I'm your host, Trey Chavu Kis, and every day of the week,
my co-host, Sintasram and I will bring you one news story that is worth a
understanding and worth your time. Today is Monday, the 24th of August.
Cyber Warriors of the Future. That's how Manindra Agraval, the director at IIT
Kanpur, described the institute's new Bachelor of Cybersecurity Program at its June launch.
He said that future wars will be fought as much online as on the ground. That language is
pretty much the same as the governments. Prime Minister Narendra Modi has long called cyber
attacks a bloodless war and has pushed for cyber commandos. And as cyber attacks grow more frequent
and more sophisticated, the government is looking beyond the conventional engineering pipelines
for talent. That's the idea that the Bachelor in Cybersecurity program is built around. But the
degree is unlike any other IIT undergraduate degree because no other course mandates work
experience as an actual part of its requirements. A former consultant who has worked on government,
government cybersecurity audits told Mutasim that the course might work like a direct pipeline
into government institutions. And along with the IIT prestige, it also gives cybersecurity a kind
of nationalist identity. The consultant also believes that it is just a matter of time before
other IITs and engineering institutes follow the same path. In fact, IIT Madras is already
set to launch the same program from the academic year of 2026 to 27.
The thing is, the talent pool is already there.
It's large and untapped.
And our research shows that Indians consistently make up the largest share of submissions
on global bug bounty platforms,
where companies pay independent researchers to find security flaws.
For instance, Indians make up roughly a quarter of all researchers on a popular website called Hacker 1.
But the bounties themselves come almost entirely from foreign companies.
Only a handful of Indian firms run them, which leaves India's ethical hackers to earn millions
protecting global tech giants while remaining largely ignored at home.
This situation is what is leaving the government in a bind right now.
The consultant said that on one hand, the government runs the most systematically important
infrastructure accessed by hundreds of millions.
Think about it. Railways, telecom, payments, Adhar are all digitized and online.
On the other hand, though, the government has to compete with GCC's or global capability centres
for the same talent that keeps these platforms safe.
Now, the competition itself isn't really new.
Clearly, the system that exists has been around for a while.
But what is new is the rising cost of coming second in this competition,
because attacks are just growing more frequent.
And actually, even if by some miracle the hiring does happen,
retention of that talent is even harder.
Because apparently, India's cybersecurity job market has long been what one recent paper calls
structurally distorted.
More on this in the next segment.
The distortion goes back to more than a decade ago.
As American companies built GCCs across India, cybersecurity followed the same path as customer
support and finance.
A junior compliance analyst who costs a U.S. employer $60,000 to $85,000.
a year costs roughly $5,000 to $10,000 in India,
which means the company gets the same work for a fraction of that price.
And the employee still earns more than what they would at an Indian firm.
Everyone wins except the domestic industry.
And the scale itself is striking.
A PWC report says that about a third of global organizations
now have more than half their cybersecurity teams based in India.
Mutasem spoke to Kostub Medhi, the chief product officer at an intelligence firm called Saibl,
which has more than 650 global clients.
He said that it is mostly the MNCs and GCCs who end up cornering the bulk of the good candidates.
One reason, of course, is pay.
The other, Medhi said, is that the industry has stopped training freshers.
He blames cost-cutting and operational pressure, pointing towards how most job openings in the field
now demand three to five years of experience. How could a fresher ever get a job if that is the base
threshold? What's missing, he said, is apprenticeship. And that is exactly what the government is
trying to set up now. For example, in June, the RBI advertised 12 young professional roles in
cybersecurity, AI, quantum tech and climate risk, paying around 18 lakh rupees a year. That's a salary
that is actually competitive with a mid-level GCC analyst in Bangalore.
But there's a catch.
These jobs are contractual, only three years long, extendable to five,
and with no benefits provided beyond the stipend itself.
Now, by Méthe's estimate,
it takes at least two years for a fresher to actually become productive.
If we go with that math,
the RBI gets only one productive year out of each young professional,
who then leaves with no other next step,
climb in the organization's ladder.
The same pattern is also repeating in other places.
Take the Home Ministry Cybercrime Center, which has 195 openings paying up to
$2.5 lakh rupees a month.
These are also three-year contracts.
And where the government does offer permanent jobs, it pays far less.
For example, certain scientists B-posts, which are based on gate or graduate
aptitude test in engineering scores, pay 11 to 12,
lakh rupees a year, which is about a third of typical GCC pay. So it seems like right now,
the state can only offer two options, competitive pay or a long-term career, not both. But at least
it's actually taking the problem more seriously now. When Sandeep Shukla returned to India,
he had finished over a decade of teaching computer engineering at Virginia Tech. At the time, he used
a government grant to set up IIT Kanpur's C3I Center, which is India's first academic
center for the cybersecurity of critical infrastructure. A decade later, he now directs IIT
Hyderabad and sits on cybersecurity committees at the RBI, NPCI, Sebi and other important
regulators. He told the Ken that the government is taking the AI cybersecurity threat quite
seriously. There are cross-ministerations, a war room for reporting major incidents within six
SARS and from the RBI, a shift in what it is asking banks to build for, resilience rather than
prevention alone.
But the bigger shift, he said, is happening inside the institutions themselves.
Until recently, Indian banks would outsource most of their cybersecurity work to consultancies,
usually one of the big four, Deloitte, KPMG, EY or PWC.
That was partly because the same talent shortage that pushed everyone into GCCs made it cheaper to buy
the capability than build it.
But that model had its own problem.
What a recent paper by Venkata Gutula, an independent cybersecurity consultant, calls title
inflation.
Let me explain what that is.
You see, US clients wanted senior level expertise offshore but only wanted to pay the cheap offshore rates.
So, Indian consultancies, to work out those thin margins, filled senior titles with juniors instead.
people only two or three years into their careers doing work that once needed a decade of experience.
The paper argues that title inflation did two things at once.
One, it kept the workers from leaving despite the low pay and two, let the firms build senior rates for junior work.
It's basically a zero-cost retention strategy.
The difference even shows up in the job listings.
For example, a senior manager, GRC role asked for 8 to 12 years of experience.
in the US. In India, on the other hand, the same title often appears at two to five years.
Of course, this shapes what audits can catch or miss. In fact, last March, regulators flagged
Deloitte's Indian arm for insufficient evaluation of the competence, capability,
objectivity and work of the auditor's expert that the firm relied on. Also, two of India's
biggest recent finance failures, which is UCO Bank's 820 crore rupees immediate payment service,
glitch in 2023 and Star Health's leak of 31 million records the next year were both traced
to lapses in IT audits.
Shukla, who I mentioned earlier, explained that banks have drawn their own conclusions from
this.
The ones he has talked to like HDFC, Kotak used to have 20 internal and 80 external employees.
Now, he said, they are trying to flip that.
The irony is that banks have learned what the state hasn't, that cybersecurity is.
that cybersecurity is no longer a project to staff, but a capability to own.
And India is fighting an ongoing threat with an employment model designed for temporary work.
Daybreak is produced from the newsroom of the Ken, India's first subscriber-focused business news platform.
What you're listening to is just a small sample of our subscriber-only offerings.
A full subscription offers daily long-form feature stories, newsletters and a whole bunch of premium podcast.
To subscribe, head to the ken.com and click on the red subscribe button on the top of the Ken website.
Today's episode was hosted and produced by my colleague Rachel Vargis and edited by Rajiv Sien.
