Cyber Warfare and Cyber Terrorism
Cyber terrorism is a crime under section 66F; cyber warfare is conflict between states. Banks sit in the line of fire of both.
Cyber terrorism and cyber warfare both aim at the systems a country runs on: power grids, telecom, payment networks, banks. The difference is who is behind it and which law answers it. Cyber terrorism is a crime committed by any person or group to threaten a nation's security or strike terror; in India it is an offence under section 66F of the IT Act. Cyber warfare is conflict between states carried out through computer networks, and is governed mainly by international law and national defence policy rather than a criminal statute.
Banks matter here because finance is part of what the law calls critical information infrastructure. A long outage of payment or core banking systems would hit the whole economy, which is exactly what makes them a target.
You save ₹300
- Full 120-question mocks
- Cyber law coverage
- Module-wise practice
One payment, no subscription · Valid for 2 months
Cyber Terrorism vs Cyber Warfare
Who
Cyber terrorism
Individuals or groups, including those with foreign backing
Cyber warfare
States, or groups acting on behalf of a state
Aim
Cyber terrorism
Threaten unity, integrity, security or sovereignty; strike terror
Cyber warfare
Military, political or economic advantage over another state
Typical acts
Cyber terrorism
Disrupting essential services, attacking critical infrastructure, stealing restricted state data
Cyber warfare
Sabotage of infrastructure, espionage, disruption during a wider conflict
Legal answer in India
Cyber terrorism
IT Act section 66F (up to life imprisonment); section 70 for protected systems
Cyber warfare
International law and diplomacy; domestically, the same IT Act offences where they fit
| Cyber terrorism | Cyber warfare | |
|---|---|---|
| Who | Individuals or groups, including those with foreign backing | States, or groups acting on behalf of a state |
| Aim | Threaten unity, integrity, security or sovereignty; strike terror | Military, political or economic advantage over another state |
| Typical acts | Disrupting essential services, attacking critical infrastructure, stealing restricted state data | Sabotage of infrastructure, espionage, disruption during a wider conflict |
| Legal answer in India | IT Act section 66F (up to life imprisonment); section 70 for protected systems | International law and diplomacy; domestically, the same IT Act offences where they fit |
Section 66F in Plain Words
Section 66F has two limbs. The first covers anyone who, intending to threaten the unity, integrity, security or sovereignty of India or to strike terror in the people, denies access to authorised users, penetrates a computer resource without authorisation, or introduces a computer contaminant, and by doing so causes or is likely to cause death or injury, damage to property, disruption of essential supplies or services, or harm to critical information infrastructure.
The second covers anyone who knowingly accesses a computer resource without authorisation and obtains information restricted for reasons of state security or foreign relations, with reason to believe it may be used to injure India's interests. Committing or conspiring to commit cyber terrorism is punishable with imprisonment which may extend to imprisonment for life, the heaviest punishment in the IT Act.
Terms the Exam Uses
- Critical Information Infrastructure (CII)
- Under the explanation to IT Act section 70, a computer resource whose incapacitation or destruction would have a debilitating impact on national security, economy, public health or safety.
- Protected system
- A computer resource affecting CII that the government has notified under section 70. Unauthorised access or an attempt is punishable with up to 10 years and a fine.
- National nodal agency
- The body designated under section 70A for protecting CII. That role is held by NCIIPC; CERT-In (section 70B) is the national agency for incident response.
- Terrorist act (BNS section 113)
- The Bharatiya Nyaya Sanhita's general terrorism offence, which explicitly includes threats to India's economic security and disruption of essential services.
Quick practice on banking operations. No signup.
What This Means Inside a Bank
- check_circlePayment and core banking systems should be treated as critical assets with the strictest access control and monitoring.
- check_circleRBI requires banks to have a board-approved cyber crisis management plan. Its 2016 cyber security framework pointed banks to CERT-In, NCIIPC, RBI and IDRBT guidance when drafting it, and the July 2026 Directions that replaced that framework keep the plan.
- check_circleState-backed attackers are patient. Detection controls (monitoring, anomaly alerts, threat intelligence) matter as much as prevention.
- check_circleAn attack on a bank may look like ordinary fraud or ransomware at first. Classify by impact and report through the normal incident channels; attribution comes later.
How the IIBF Exam Tests This
Likely MCQs: the punishment for cyber terrorism (imprisonment which may extend to life, not a fixed term or a fine), the section number (66F, not 66E, which is privacy), and the definition of critical information infrastructure. The trap is confusing section 70A (the CII nodal agency, NCIIPC) with section 70B (CERT-In, incident response).
FAQs
What is the punishment for cyber terrorism under the IT Act?expand_more
Under section 66F, whoever commits or conspires to commit cyber terrorism is punishable with imprisonment which may extend to imprisonment for life.
What is the difference between cyber warfare and cyber terrorism?expand_more
Cyber terrorism is a crime by individuals or groups to threaten a nation or strike terror, punished under IT Act section 66F. Cyber warfare is conflict between states through networks, governed mainly by international law.
Is banking critical information infrastructure?expand_more
The IT Act defines CII by impact: systems whose incapacitation would have a debilitating impact on national security, economy, public health or safety. Core banking and payment systems fit that description, and specific systems can be notified as protected under section 70.
Which agency protects critical information infrastructure in India?expand_more
NCIIPC, the national nodal agency designated under section 70A of the IT Act. CERT-In, under section 70B, handles incident response across all sectors.
Next steps
Take a full IIBF Cyber Crimes mock test120 questions, 2 hours, scored instantly.
