Cyber Security Policy OPG
Cyber Security Policy OPG
1 Introduction:
The Department of Electronics, IT & BT, Government of Karnataka has announced the Cyber Security
Policy 2024 vide Government Order no. ITBT 48 ADM 2021, dated:16-03-2024.
There are two parts to the Cyber Security Policy – an outward facing public part and an inward facing
government part.
Vision:
To make Karnataka the leading cyber security hub in the country by instilling a culture of cyber security
and data privacy amongst citizens and businesses and promoting a thriving cyber security industry and
start-up ecosystem in the state.
This Cyber Security Policy focuses on five main pillars, representative of the main stakeholders of the
cyber security ecosystem – citizens of the state, technology professionals, researchers, industry, and the
government.
These are:
1. Building awareness
2. Skill building
3. Promoting research and innovation
4. Promotion of Industry and Start-ups
5. Partnerships and Collaborations for Capacity Building
2|P a g e
Cybersecurity Policy 2024 - OPG
1.2. Public Cyber Security Awareness Campaigns for vulnerable groups such as women,
children, youth, first-time users and the elderly
Objective: Raise public awareness about cyber security through campaigns and promote emergency
contact numbers for cyber-crime incidents.
The Department of Electronics, IT, BT & ST shall undertake the following activities:
- Create a calendar for regular cyber security campaigns targeting the general public.
- Utilize social media platforms, interactive technologies, and public events to disseminate
information.
- Collaborate with industry experts, academic institutions, and influencers to reach a broader
audience.
- Highlight the importance of reporting cyber-crime by promoting the use of Dial 112 and Dial 1930.
- Monitor and analyse the reach and impact of the campaigns to adjust strategies as needed.
1.4 Tailored Cyber Security workshops for Karnataka based MSME’s and start-ups
Objective: Conduct specialized awareness campaigns for MSME’s and start-ups that are particularly
vulnerable to cyber threats.
The Department of Electronics, IT, BT & ST shall undertake the following activities:
- Identify Karnataka based MSME’s and start-ups, that can benefit from the program.
- Design targeted awareness programs that address the specific needs and risks faced by smaller
organisations such as MSMEs and start-ups.
- Conduct cyber security training sessions, workshops, and camps by partnering with local
incubators, accelerators, industry associations and chambers of commerce.
3|P a g e
Cybersecurity Policy 2024 - OPG
2.1 Promote cyber security as a future career option among school and college
students
Objective: To raise awareness among college and university students about cyber security as a career
option and to inform them about available high-quality training and certifications.
The Electronics, IT, BT & ST Department in association with the Department of Higher Education will
undertake the following activities:
1) Create a specialized cyber security course for students interested in cyber security specialization
within the framework of the New Education Policy, 2020.
a) Department of Electronics, IT, BT along with KITS and KDEM to constitute a working group on
Cyber security to form a course curriculum. The Working group will constitute of the following
members:
4|P a g e
Cybersecurity Policy 2024 - OPG
b) Based on the recommendations of this working group course curriculum to be developed and
introduced in higher education institutes (engineering colleges, polytechnics, vocational
courses, etc.).
c) The courses shall be credit based.
d) Faculty to be trained as per the requirements of the new course curriculum.
e) The course can be a mix of online training and in-classroom training.
f) Introduction of an online cyber security module that offers a range of courses from
introductory to advanced levels, targeting various demographics including students,
professionals, and general enthusiasts.
2.2 Internship for undergraduate and graduate students in the field of cyber security
Objective: This incentive aims to create industry-academia linkages by bridging the gap between
academic skills and cyber security industry requirements and developing skilled cyber security talent pool.
The Department of Electronics, IT, BT & ST will provide an internship reimbursement to Companies
(MNCs, MSMEs working in Cyberspace, Start-ups) providing cyber security solutions and hiring students
for cyber security roles.
Please see fiscal incentives section for details.
2.3 Establishment of a Regional Centre of Excellence in Cyber Security
Objectives of the COE:
1) Expertise Development: To develop and consolidate regional expertise in cyber security by
fostering research, education, and training programs.
2) Collaboration Hub: To facilitate collaboration among government entities, industry, academia,
and research institutions to share knowledge, resources, and best practices in cyber security.
3) Innovation and Research: To promote innovation and conduct cutting-edge research in cyber
security to address current and emerging threats and challenges.
4) Education and Training: To provide high-quality education and training programs that build a
skilled cyber security workforce equipped to handle the region's specific needs.
5) Policy and Strategy Development: To assist in the development of regional cyber security policies,
strategies, and frameworks that enhance the security posture of the region.
6) Public Awareness: To raise public awareness about cyber security risks and promote safe cyber
practices among citizens and organizations.
7) Resource Centre: To act as a repository of cyber security knowledge, best practices, and tools that
can be accessed by stakeholders in the region.
8) International Cooperation: To engage in international cooperation and partnerships to enhance
global cyber security efforts and learn from global best practices.
9) Standardization and Certification: To contribute to the development of regional cyber security
standards and certification programs that ensure quality and consistency in cyber security
products and services.
10) Technology Transfer: To facilitate the transfer of cyber security technologies and innovations
from research to market, benefiting regional industries and organizations.
11) Cyber security Ecosystem: To build a robust cyber security ecosystem that supports a resilient
and secure digital infrastructure for the region.
5|P a g e
Cybersecurity Policy 2024 - OPG
6|P a g e
Cybersecurity Policy 2024 - OPG
security measures, catering to national needs and expanding its software product exports globally. To
further enhance the reputation of Brand Karnataka, it is crucial to nurture and support the region's cyber
security sector and burgeoning start-ups.
4.1 Start-up mentorship and incubation programs
Objective: The objective of this policy is for the State Government to commit to fostering innovation
within the cyber security domain.
This initiative will identify high-potential start-ups in the cyber security field to benefit from a
comprehensive support system. The selected start-ups will gain access to expert mentorship tailored to
their growth stage, assistance in intellectual property rights management, and opportunities for industry
engagement via strategic partnerships. The program aims to create a conducive environment for these
emerging companies to flourish, contributing to the state's technological advancement and economic
growth. COE to execute.
4.2 Pilot projects for solutions developed by start-ups will be executed with support from the State
Government
Objective: To position the government as a proactive participant in the validation and adoption of
innovative cyber security solutions emerging from start-ups.
The government aims to provide Karnataka based start-ups with a platform to demonstrate the
effectiveness of their products or services through proof of concept or pilot implementations within
suitable government agencies. This initiative is designed to not only empower start-ups but also to
enhance the government's cyber security infrastructure with cutting-edge technologies.
The ultimate goal is to foster a symbiotic relationship where start-ups receive critical market exposure
and feedback, while the government benefits from early access to innovative security solutions, thereby
reinforcing the state's commitment to supporting the local cyber security ecosystem. COE to execute.
4.3 Prioritize procurement of services provided by Karnataka based start-ups
Objective: To prioritize the procurement of cyber security solutions for government departments from
start-ups based in Karnataka.
By offering preferential treatment to Karnataka-based start-ups, the policy aims to encourage innovation
within the region, support the development of a robust cyber security infrastructure, and create a
competitive advantage for local enterprises in the government procurement process. Start-ups to be
empanelled through the preferential market access program.
4.4 Reimbursement to start-ups undertaking regular cybersecurity audits
Objective: The objective of the policy is to create an environment of cyber security awareness and
promote the regular cyber security audits and incident management activities in smaller organizations
such as start-ups.
The Government of Karnataka will reimburse the cost up to a maximum of INR 1 lakh towards engagement
of Karnataka-based, CERT-In empaneled service providers by start-ups registered with Karnataka Start-up
Cell for cyber security audit, incident management and incident response activities. This may be availed
by a start-up once over the policy period.
This benefit will be provided to 100 start-ups each year.
Please refer the fiscal incentive section for details.
4.5 Mentorship opportunities for business innovators in the state in particular start-ups and MSMEs
Objective: To cultivate a widespread awareness of cyber risks among business innovators in Karnataka,
particularly targeting start-ups and Micro, Small, and Medium Enterprises (MSMEs) working on cyber
space.
7|P a g e
Cybersecurity Policy 2024 - OPG
The aim is to mentor these entities in integrating "security by design" and "privacy by design" principles
into their business models and product development processes. This initiative seeks to embed a proactive
approach to cyber security and data privacy from the outset, ensuring that these critical aspects are not
afterthoughts but foundational elements of their business strategies. By doing so, the policy intends to
enhance the overall resilience of the state's digital ecosystem against cyber threats and to foster a culture
of responsible innovation that prioritizes the protection of user data and system integrity.
4.6 Fund and support the building of testing infrastructure and facilities within Regional Centers of
Excellence
Objective: To provide financial backing and support from the State Government for the development of
advanced testing infrastructure and facilities within designated Regional Centres of Excellence.
This initiative aims to create a robust framework for innovation and quality assurance in the field of
technology and cyber security. By investing in such infrastructure, the government intends to equip these
centers with the necessary tools to rigorously test and refine cyber security solutions, fostering a culture
of excellence and reliability. The ultimate goal is to enhance the state's technological capabilities,
encourage research and development, and ensure that products and services developed within the region
meet the highest standards of security and efficiency, thereby reinforcing Karnataka's position as a leader
in the cyber security domain.
5. Partnerships and collaborations for capacity building (Pillar 5)
Increasingly sophisticated cyber-attacks and their widespread impact require coordinated and
synchronised efforts across various segments of society. The expansive IT industry and infrastructure
located in Karnataka necessitates the establishment of appropriate state level institutions to orchestrate
such coordinated efforts.
5.1 Cyber Security Steering Committee Formation and Operation
Objective: To establish a committee that will oversee the implementation of the Cyber Security Policy.
Guidelines:
Identify and appoint representatives from key State Government departments, industry, and
academia.
Define the roles and responsibilities of the committee members.
Establish a regular meeting schedule (e.g., quarterly) and procedures for the committee.
Develop a charter that outlines the committee's decision-making process, reporting structure,
and communication plan.
Ensure that the committee has the authority to guide and make recommendations on cyber
security matters.
5.2 Establishment and Functioning of K-CERT
Objective: To create a state-level coordination center for cyber security incident response.
Guidelines:
8|P a g e
Cybersecurity Policy 2024 - OPG
Objective: To enhance the capabilities of the K-tech Centre of Excellence in Cyber Security.
Guidelines:
Guidelines:
Identify key cyber security topics for technical and managerial training.
Collaborate with industry and academia to develop and deliver training programs.
Schedule and conduct regular training sessions.
Monitor and evaluate the effectiveness of the training programs.
Objective: To establish cyber security standards for suppliers and vendors working with the state.
Guidelines:
Objective: To develop protocols for the safe and secure use of online resources by State Government
officials.
Guidelines:
Create detailed protocols for online interactions, including email and social media use.
Mandate the use of official email IDs for all government communications.
Prohibit the use of personal email IDs for official communications.
Provide training on the protocols to all State Government officials.
Objective: To train select groups in handling cases related to contraventions of the IT Act.
Guidelines:
Identify and select adjudicators, mediators, and conciliators for specialized training.
Leverage existing CoEs and cyber ranges for training purposes.
9|P a g e
Cybersecurity Policy 2024 - OPG
Objective: To maintain a list of qualified cyber security professionals who can advise on specific cases.
Guidelines:
Guidelines:
Objective: To ensure that all initiatives comply with the National Cyber Security Policy.
Guidelines:
These operating guidelines should be reviewed and updated regularly to reflect changes in technology,
threats, and best practices in cyber security. Additionally, they should be communicated effectively to all
relevant stakeholders to ensure smooth implementation and adherence to the policy.
Policy Clause no Category Incentive / Benefit
2.9 Internship A stipend of Rs. 10,000 per month will be provided, for
maximum of 3 months, to Karnataka-based undergraduate
interns who are doing internship related to cyber security.
A stipend of Rs. 15,000 per month will be provided, for
maximum of 3 months, to Karnataka-based postgraduate
interns who are doing internship related to cyber security.
This will be provided to 200 undergraduate interns and 40
postgraduate interns in year 1 and year 2 of the policy
applicability, with 400 undergraduate interns and 80 post
graduate interns from year 3 onwards.
10 | P a g e
Cybersecurity Policy 2024 - OPG
1. APPROVAL COMMITTEE
An approval Committee will be formed to review applications based on the evaluation criteria and their
decision will be deemed final.
The approval committee will constitute of the following members:
Sl. No. Designation Role
1 Managing Director, KITS Chairman
2 Representative from International Institute of Information Technology Member
(IIIT), Bangalore
3 Representative from Indian Institute of Science (IISc), Bangalore Member
4 Representative from National Association of Software and Service Member
Companies (NASSCOM)
5 Representative from Centre for e-Governance (CeG) Member
6 Representative from Software & Technology Parks(STPI) India Member
In addition to this, an industry expert or a domain expert may be invited as a committee member on a
case-to-case basis.
11 | P a g e
Cybersecurity Policy 2024 - OPG
1. Internship for undergraduate and graduate students in the field of cyber security
(2.9)
Objective: This incentive aims to create industry-academia linkages by bridging the gap between
academic skills and cyber security industry requirements and developing a skilled cyber security talent
pool.
The Department of Electronics, IT, BT & ST will provide an internship reimbursement to Companies
(MNCs, MSMEs, working in cyberspace, Start-ups) providing cyber security solutions and hiring students
for cyber security roles.
KITS will evaluate application and provide recommendations to the Approval Committee. The Approval
Committee will review the recommendations and sanction the incentive.
Terms & Conditions:
1. Reimbursement of internship stipend to companies for hiring students as interns in the industry
will be provided as follows:
Applicant Incentive
GoK will reimburse INR 10,000 per month for a maximum period
Karnataka- based companies of three months, to companies hiring Karnataka based
(MSMEs, SMEs, start-ups, MNCs undergraduate cyber security interns.
etc.) working in Cyberspace and GoK will reimburse INR 15,000 per month for a maximum period
providing cyber security of three months, to companies hiring Karnataka based
solutions. postgraduate cyber security interns.
This will be provided to 200 undergraduate interns and 40
postgraduate interns in year 1 and year 2 of the policy
applicability, with 400 undergraduate interns and 80 post
graduate interns from year 3 onwards.
2. The incentive will be provided for a maximum of up to 30 undergraduate students and 10 post
graduate students to each company under a single application cycle for year 1 and year 2 and 60
undergraduate students & 10 post graduate students to each company year 3 onwards.
3. All applicants should be registered with KITS or in Karnataka under Shops and Establishment Act.
4. KITS shall be the implementation partner for the incentive.
5. Companies can hire students from only Karnataka based academic institutes, universities,
colleges, polytechnics, etc. to be eligible for this incentive.
Application Process
1. The applicant must be a Karnataka-based company i.e. start-ups, company, MNC, MSMEs working
in Cyberspace and providing cyber security solutions. Application will be accepted on a rolling
basis.
2. Applications will no longer be accepted once the upper limit of providing the incentive to 200
undergraduate and 40 postgraduate interns in year 1 & 2 of policy applicability, and 400
undergraduate interns and 80 post graduate interns from year 3 onwards has been reached.
3. Applicants shall apply online and submit their application to KITS.
4. Applicants in their application should details the number of interns to be engaged by them and
the internship stipend and the activities to be conducted during the internship period.
5. The Applicant shall pay a monthly stipend to interns and on completion of the internship shall
award certificate of completion.
6. Post completion of the internship, the applicants are required to submit the application to KITS
along with the CA certified supporting documents for internship stipend paid.
12 | P a g e
Cybersecurity Policy 2024 - OPG
Release of Funds
KITS shall release funds to the applicant, based on the number of interns successfully completing
the internship and the recommendation placed by the approval committee.
List of Documents
1. Application form issued by KITS
2. Internships Claim Form
3. CA certified document detailing the stipend paid to the students
4. Proof of Stipend paid
5. List of the students provided internship by the Applicant as per the incentive criteria
6. Bank Account Information of the company
7. Statutory bonafide declaration from the company stating that the internship was conducted in
the field of cyber security only.
13 | P a g e
Cybersecurity Policy 2024 - OPG
14 | P a g e
Cybersecurity Policy 2024 - OPG
2. The applicant should be a start-up working jointly in collaboration with an academic institution on
cutting-edge research in the cyber security domain. The start-up has to be registered with KITS, based
in Karnataka & should provide cyber security services, while the preference will be given to all academic
institutions in Karnataka.
3. The project shall be executed within Karnataka.
4. Application can also be submitted for projects in the Beta Site stage (the interim stage between R&D
and marketing).
5. The Applicant should have the required expertise and team capacity to manage the proposed project.
Benefits
What benefits is the project expected to yield to the applicant
company and the national economies, societies, and
environment?
What are the possibilities of generating Intellectual Property (IP)
and after that Commercialization potential?
3 Quality and Capabilities of the applicants 20%
efficiency The credentials of past projects experience & achievements from
of the projects
implement The qualification of the core project team and their ability to
ation successfully carry out the development objectives.
The Budget
15 | P a g e
Cybersecurity Policy 2024 - OPG
o Manpower: The number of employees or contractors hired and the associated labour
costs.
o Space: The cost of leasing or owning the physical space used for business operations.
o Equipment: The expenses incurred for purchasing or leasing equipment necessary for the
startup's activities.
o Software: The costs associated with acquiring software licenses or developing custom
software solutions.
o Seed fund raised: Grant raised from industry, institutions, government grants or loans or
any which falls under seed funding.
16 | P a g e
Cybersecurity Policy 2024 - OPG
7. The committee reviews the full project proposal and conducts an on-site evaluation, if required. In
addition, the evaluator can ask the company for supplementary material, if needed. The financial
check of the companies is conducted in parallel.
8. After reviewing the proposal the R&D committee will give its suggestions to the Approval
Committee. Based on the recommendations of the R&D committee the Approval committee will
make the final decision.
9. The final decision will be conveyed in an email to Applicants. If funding has been approved, the
applicants will materialize this approval by signing Project Funding Agreement (PFA). This agreement
must be signed by the CEO of the company and KITS.
10. A Sanction Letter shall be issued for approved project.
17 | P a g e
Cybersecurity Policy 2024 - OPG
Release of Funds
• KITS will share cost in the joint development by supporting approved applicants through a conditional grant
totaling upto 50% of the Project Budget or Upto INR 50 Lakhs whichever is lower.
• The grant will be released in tranches, with each tranche contingent upon the successful completion of
predefined project milestones.
• The first tranche will be released upon the approval of the project and the provision of proof of secured matching
funds as mentioned in the project guidelines (Matching Grants). Subsequent tranche will be released based on
project progress reports, milestone achievements, and continued compliance to the grant conditions.
• Agreement will be signed with the grant utilization condition and tranche plan.
The Government of Karnataka will reimburse the cost up to a maximum of INR 1 lakh towards engagement
of Karnataka-based, CERT-In empaneled service providers by start-ups registered with Karnataka Start-up
Cell for cyber security audit, incident management and incident response activities. This may be availed
by a start-up once a year over the policy period.
This benefit will be provided to 100 start-ups each year.
The approval committee will review the applications and make recommendations to the Governing
Council. The Governing Council will be the final decision-making authority.
Terms and Conditions:
1. The applicant should be a Startup registered with KITS.
2. The start-up can use the services of only CERT-in empaneled service providers for cyber security audit,
incident management and incidence response activities.
3. Certificate issued by the service provider of availment of cyber security audit to be submitted.
4. Eligible Startups shall make payment to the CERT-in empaneled service providers and later claim
reimbursement of the same subject to terms and conditions mentioned herein.
5. Maximum reimbursement amount per start-up is Rs. 1 lac per year for the policy period excluding GST.
6. The reimbursement may be availed by a start-up only once over the policy period.
7. This benefit will be provided to 100 start-ups each year.
18 | P a g e
Cybersecurity Policy 2024 - OPG
8. The reimbursement incentive will only apply to supply of services (cyber security audits, incident
management, incidence response activities, etc.) undertaken during the policy period i.e. 16th March 2024
onwards to 15th March 2029 or till the new policy announced.
Mandatory Documents:
1. Application form as in Annexure
2. Detailed invoice of the services availed by the start-up and provided by the CERT-in empaneled service
provider.
3. Payment details, receipt and confirmation of the payment made by the start-up to the service provider.
4. Bank details of the start-up for funds disbursal.
5. Any other information as required.
19 | P a g e
Cybersecurity Policy 2024 - OPG
Application Forms:
Field Description
Entity Type
Technology Sector
Industry Sector
Registered Address
Corporate Address
Address in Karnataka
Registration Number
Company Logo
Company URL
PAN Number
GST Information
Field Description
Department
Position/Designation
E-mail Address
Field Description
20 | P a g e
Cybersecurity Policy 2024 - OPG
Field Description
Duration of Internship
For PG students
Field Description
Duration of Internship
Bank Details
21 | P a g e
Cybersecurity Policy 2024 - OPG
List of Documents
1. Application form issued by KITS
2. Internships Claim Form
3. CA certified document detailing the stipend paid to the students
4. Proof of Stipend paid
5. List of the students provided internship by the Applicant as per the incentive criteria
6. Bank Account Information of the company
7. Statutory bonafide declaration from the company stating that the internship was conducted in the field of
cybersecurity only.
Declaration and Submission
[Include a section for the company to declare the information provided is true and consent for verification]
22 | P a g e
Cybersecurity Policy 2024 - OPG
Project Information
Applicant’s Bank Details (Bank Name, Branch Name, Branch Address, Branch
IFSC Code, Account Number, Name of Account Holder)
23 | P a g e
Cybersecurity Policy 2024 - OPG
Funding Information
Information Required Details
R&D Grant Amount Claimed by the Applicant
R&D Fund secured from the Industry Partner
Utilization of the R&D Fund secured from the Industry
Partner
Utilization of the R&D Grant received from KITS/Department
Bank Details
24 | P a g e
Cybersecurity Policy 2024 - OPG
Financial Information
Supporting Documents
Document Required
25 | P a g e
Cybersecurity Policy 2024 - OPG
26 | P a g e