kavishias

New Offline Batches to start in Shakespeare Sarani Centre. Admissions open
UPSC Coaching in Kolkata

 Disaster Management in the Digital Age: Analyzing New Age Threats at our upsc coaching in kolkata

For years, disaster management in the UPSC syllabus meant cyclones, floods, earthquakes and the institutional response to them — NDMA, SDMA, NDRF, and a fairly predictable set of case studies. That’s changed. A hospital going offline because of ransomware, a power grid probed by hostile actors, a defence database exposed through a misconfigured server — these are now disasters too, and the exam has started treating them that way. If you’re preparing for Mains through any serious upsc coaching in kolkata, this shift is not optional reading. It’s becoming a recurring theme in GS Paper 3, and examiners are rewarding candidates who can connect classical disaster management theory to this newer, digital threat landscape.

This piece walks through what’s actually happening — the numbers, the policy response, and the technology — and how to turn it into an answer that stands out.

Why “Disaster” No Longer Means Just Cyclones and Earthquakes

The Disaster Management Act, 2005 was written after the 2004 tsunami, at a time when “disaster” meant a physical, visible event. But India’s digital public infrastructure has grown fast — the country now has over 86% of households connected to the internet and processes billions of UPI transactions every month — and that growth has created a parallel category of risk that the original Act never anticipated. A cyberattack on a hospital’s systems or a state’s power distribution network doesn’t look like a flood, but it produces the same outcome: disrupted essential services, panic, and a need for coordinated emergency response.

This is exactly why the syllabus and the exam have started pulling cybersecurity into the disaster management conversation, rather than treating it purely under “internal security.”

The New Threat Map: How Cyberattacks Became a Disaster Management Problem

The scale is worth sitting with for a moment. Seqrite’s India Cyber Threat Report 2026 recorded more than 265 million cyberattacks in India through 2025, and nearly 60% of that hostile activity has been traced to a China–Pakistan axis. A year earlier, Quick Heal’s India Cyber Threat Report 2025 had already logged 369 million incidents in 2024, with healthcare bearing the brunt at close to 22% of all attacks. Hospitals, in other words, are now a frontline disaster-management concern in a way they never used to be.

Geopolitical events have made this sharper still. After the Pahalgam attack in April 2025 and India’s Operation Sindoor strikes that followed, more than 40 pro-Pakistan hacktivist groups launched a coordinated campaign against Indian infrastructure and public services, claiming over 256 attacks under a single operation. Maharashtra Cyber alone recorded over a million attempted intrusions in the immediate aftermath, with government portals, banks, power systems, telecom networks and railways all facing sustained probing. Two real incidents illustrate the stakes well: AIIMS Delhi was hit twice within seven months during 2022–23, disrupting hospital operations, and the SPARSH portal breach in January 2024 exposed defence personnel data — not through a sophisticated hack, but through a simple misconfigured cloud bucket. That last detail is worth remembering for an answer: a lot of India’s digital vulnerability isn’t exotic malware, it’s basic oversight.

Looking ahead, Kaspersky’s research team expects India to see a further rise in attacks on critical infrastructure and government systems in 2026, driven by geopolitical tension and the continuing digitisation of operational technology.

What Changed on Paper: The Disaster Management (Amendment) Act, 2025

Parliament didn’t ignore this shift. The Disaster Management (Amendment) Act, 2025 expanded the definition of “disaster management” to explicitly include disaster risk reduction, and introduced the concept of a national and state-level “disaster database” covering risk assessment, fund allocation, and preparedness data. It also cleaned up an old ambiguity — the amendment clarifies that “man-made causes” of disaster do not extend to ordinary law and order situations, so the Act can’t be misused for routine policing matters.

On the institutional side, NDMA and the State Disaster Management Authorities now prepare their own disaster management plans directly, rather than routing them through the earlier National and State Executive Committees, and their role has widened to include periodic risk assessment, technical assistance, and minimum relief standards. States have also been given the option to set up dedicated Urban Disaster Management Authorities for large cities, which matters a great deal for a metro like Kolkata where a single disaster — flooding, a fire, or now a cyber incident — can cut across multiple municipal boundaries.

AspectDM Act, 2005DM (Amendment) Act, 2025
Who prepares disaster plansNational/State Executive CommitteesNDMA and SDMAs directly
Scope of “disaster management”Response-focusedIncludes disaster risk reduction
DataNo central database mandateMandatory disaster database
Urban governanceNo dedicated bodyUrban Disaster Management Authorities enabled

Technology Cuts Both Ways

Here’s the part that makes this such a good Mains theme: the same digital infrastructure that creates new vulnerabilities is also what’s making India’s disaster response faster. After the 2024 Kerala landslides and the 2025 Uttarakhand and Northeast floods, in which collapsed telecom towers and power outages badly delayed rescue coordination, disaster planners have leaned harder into AI-enabled and satellite-linked communication networks that don’t depend entirely on ground infrastructure. These Space-Air-Ground Integrated Networks, along with AI-driven prioritisation built around NDMA’s “Golden 24–72 hours” window for rescue, are meant to keep information moving even when local networks go down — and they align with global commitments under the Sendai Framework.

The catch is that every one of these systems — early warning apps, satellite links, AI-based monitoring — is itself digital infrastructure, and therefore itself a potential target. A candidate who can articulate this dual nature — technology as both mitigation tool and new attack surface — is writing a far more sophisticated answer than one who treats disaster management and cybersecurity as separate boxes.

Turning This Into a GS Paper 3 Answer

This is where preparation strategy matters more than raw reading. Disaster management is a compact part of the GS3 syllabus, but examiners have started asking questions that deliberately blend it with internal security and science and technology — a cyberattack on a power grid, a ransomware hit on a hospital, or the resilience of India’s Critical Information Infrastructure. A candidate who only knows the NDMA-SDMA-DDMA structure from a textbook will miss these links.

What actually works is building a small, current toolkit: know the institutional framework cold, know the 2025 amendment’s key changes, and keep two or three recent incidents ready to use as examples rather than generic statements. That’s the difference between an answer that sounds memorised and one that sounds informed — and it’s the kind of habit good upsc coaching in kolkata programmes try to build early rather than leaving it to the last few months before Mains.

How We Approach This at IAS Kavish

At IAS Kavish, we don’t treat current affairs as a separate subject to be read once and forgotten — it’s woven directly into how we teach static topics like disaster management. Our Answer Writing League has consistently shown a strong match with actual Mains questions year on year, largely because we track exactly these kinds of policy shifts (the 2025 amendment, CERT-In advisories, NDMA updates) as they happen, rather than compiling them into a bulky revision file at the end. As one of the more current-affairs-focused UPSC coaching in Kolkata options, with centres on Hazra Road and VIP Road, our faculty — many of whom have cleared the UPSC exam themselves — work one-on-one with students to convert these live developments into exam-ready answers, without burying them in more reading than any aspirant actually needs.

A Few Questions Students Ask

Is cybersecurity really part of the Disaster Management syllabus, or is it Internal Security?
Technically, cybersecurity threats sit under GS3’s internal security theme, but the exam has increasingly used them as case studies within disaster management answers too — especially when the question involves critical infrastructure, hospitals, or government systems. It’s worth preparing the overlap rather than keeping the two strictly separate.

Do I need to remember exact attack statistics for Mains?
Not word for word. Examiners reward you for showing awareness of scale and trend — knowing that cyberattacks on Indian infrastructure have grown sharply through 2025, and that healthcare and government systems have been repeatedly targeted, matters more than memorising an exact figure.

How recent should my examples be?
As recent as possible. The 2025 amendment to the DM Act, the post-Pahalgam hacktivist campaign, and the SPARSH portal breach are all strong, current examples that show you’re reading beyond static notes.

The Takeaway

Disaster management used to be a fairly self-contained topic. It isn’t anymore — cybersecurity, infrastructure resilience, and disaster governance have started overlapping in ways the exam clearly expects candidates to notice. Reading one good editorial a week on this intersection, and practising how to write it into a structured answer, will do more for your Mains score than another round of static notes. If you’re weighing your options for upsc coaching in kolkata, this is exactly the kind of current-to-static linkage worth asking a prospective institute about before you commit your year to them.

Scroll to Top