Anilkumar Ambalam
9 Sept 2026 9 min read

This article aims to discuss the developing legal aspect of cyber-hygiene and analyze if the current Indian laws provide sufficient obligation for organizations handling personal and sensitive information while also considering the impracticality of such obligations for average users. It argues that cyber-hygiene practices must be incorporated within the risk-based liability framework for companies handling personal data while not subjecting individuals to unwarranted obligations. Keywords: Cyber Hygiene; Cybersecurity; Data Protection; Information Technology Act, 2000; Digital Personal Data Protection Act, 2023; Legal Responsibility. Internet has become so much a part of our lives that today, it is hard to imagine living without it. Individuals use the internet for shopping, banking, education, emails, work, communication, storing personal data, and for a variety of other purposes. With increased reliance on the digital ecosystem, the risks posed by digital threats, and more importantly, the consequences of such digital threats are also escalating. It may not be necessary for an organization to fall prey to an elaborate cyber-attack; often poor “cyber hygiene” such as using weak passwords, reusing passwords across multiple online accounts, falling victim to phishing emails, not installing software updates, not protecting devices, or not exercising caution while browsing can lead to damaging consequences. It is therefore imperative to adopt and maintain good “cyber hygiene practices” in order to reduce the likelihood that an organization’s systems or data may be compromised and that users’ devices or confidential information may be placed at risk. While often considered as simply an aspect of user awareness, good cyber-hygiene practices have significant legal and policy implications, both for individuals and organizations. The lack of cyber-safety precautions on the part of an individual may have ramifications for other organizations, individuals, and customers. Thus, while individual cyber-hygiene practices are commonly advocated as optional measures to enhance cybersecurity, it is worth considering the extent to which such conduct ought to be mandated by law and/or regulated by organizations. There is a need to determine if and to what extent, poor cyber-hygiene on the part of individuals should be legally mandated or regulated.
In India, the Information Technology Act 2000, CERT-In directions, and the Digital Personal Data Protection Act, 2023 reflect diverse legal and regulatory frameworks concerning cybersecurity and data privacy. Yet, there exists no all-encompassing legal framework that specifically addresses the aspect of “basic cyber-hygiene”. This article seeks to highlight and examine the developing legal obligations concerning basic cyber-hygiene and evaluates the legal lacunae in this space. It further endeavors to discuss why legal responsibility concerning cyber-hygiene should be contextualized in terms of the risk it entails.
CYBER HYGIENE AND ITS LEGAL SIGNIFICANCE
Cyber hygiene may be described as the basic measures taken by individuals and organizations to safeguard their devices, accounts, networks, and data. It is usually composed of best practices such as installation of updates, using strong and unique passwords, protecting one’s credentials, securing backup information, and avoiding phishing activities and spam clicks. These measures are generally implemented to reduce the likelihood of intrusion, illegal access, or cyber-attack on one’s system and data. Cyber hygiene and cybersecurity are not synonyms although they may appear to be used interchangeably. Cybersecurity entails a broad range of strategies, systems, or safeguards designed to protect networks and electronic devices from attacks, intrusion, damage, or unauthorized access, while cyber hygiene is a set of best practices that every user must implement to enhance cybersecurity. The relevance of cyber hygiene in the law emerges when a lack of appropriate caution threatens or causes damage to another person. For instance, failing to adopt the necessary procedures in securing a device may lead to a data breach causing an individual’s private information to be unlawfully accessed and used. As a result, it is increasingly becoming mandatory for organizations that collect or control personal data to comply with cybersecurity requirements to avoid exposing their data subjects to cybercrimes.
CYBER HYGIENE UNDER INDIAN LAW
India does not have any particular Cyber Hygiene Act, but there are various laws and regulatory authorities which impose certain responsibilities, which are in a way related to cyber hygiene. This indicates that cyber hygiene is slowly being incorporated within the legal framework through various laws and regulations and adhering to the minimum standards of cyber security practices has become mandatory for organizations and individuals dealing with digital information and systems. In this section, the relevant Indian laws relating to cyber hygiene and their implications have been discussed. Here, it must be borne in mind that various laws have been discussed which are more or less related to cyber hygiene but for elaboration, only a few relevant acts and sections of the acts have been discussed.
1. Information Technology Act, 2000
This Act, 2000 provides the legal framework for addressing various cybersecurity and unauthorized access issues. The unauthorized access, damage or disruption of computer systems, and related matters fall under the jurisdiction of Section 43 of the IT Act, 2000. Further, the term ‘compensation for damage caused due to the negligence of body corporate handling sensitive personal data or information’ is covered under Section 43A of the IT Act, 2000. It must further be noted that the IT Act 2000, especially its Section 43A, is a significant step towards regulating the responsibility of organizations and individuals for maintaining adequatecybersecurity practices.
2. CERT-In Directions
The Indian Computer Emergency Response Team, established under Section 70Bof the Information Technology Act, plays an important role in responding to cybersecurity incidents. The directions issued by CERT-In require specified entities to follow measures relating to incident reporting, maintenance of logs, and other cybersecurity practices. These requirements demonstrate that organizations are expected to take preventive and responsive measures instead of waiting until a cyber incident occurs. Such regulatory requirements form an important part of the emerging legal concept of cyber hygiene.
3. Digital Personal Data Protection Act, 2023
Digital Personal Data Protection Act, 2023 furthers the legal significance of cybersecurity practices by Section 8 which obligates a Data Fiduciary to take reasonable measures to secure personal data against unauthorized access and data breaches. The role of cybersecurity practices is highlighted by their ability to prevent such incidents which imposes a normative obligation for data fiduciaries who determine the processing purpose and means of personal data to apply cyber hygiene measures. However, the current legislative framework does not offer a uniform standard or definition of cyber hygiene.
CYBER HYGIENE AS A LEGAL RESPONSIBILITY
The current legal practice suggests that cybersecurity is gradually shifting from a technical issue to a punishable offense. However, such a punished offense should be defined in accordance with the activity type and the potential risks that an organization or a person can encounter. Moreover, different levels of responsibility should be established depending on the extent of involvement and the opportunities for prevention. The organizations that collect, store, or process personal information should be held accountable for upholding cyber hygiene. Such companies should be enforced to provide employees with cybersecurity knowledge, ensure the implementation of appropriate protective measures, conduct regular updates of systems and programmers, introduce protocols for addressing cyber incidents, and take a range of other actions. If an organization fails to address cybersecurity issues, various negative consequences can follow, ranging from the loss of customers’ trust to the damage of employees’ and other stakeholders’ financial well-being. Therefore, cyber hygiene should be considered a shared responsibility. The organizations that control or hold personal data should have legal responsibility, but individuals should make a reasonable effort to protect themselves.
CRITICAL EVALUATION AND LEGAL GAPS
Despite the growing emphasis on the importance of cybersecurity, Indian laws do not currently provide a clear and comprehensive framework concerning the basic cybersecurity or cyber hygiene standards. The major problem is that the primary laws, regulations, and directions addressing the issue seem to be fragmented and contradictory, which results in ambiguity in defining the minimal standards of cybersecurity for various types of organizations. Another challenge is that the principle of individual responsibility seems to be unclear in the current framework. On the one hand, human error is often a factor that aggravates the adverse consequences of a cyber incident. However, not every mistake made by an employee can be defined as a crime. For instance, one cannot penalize a person for being a victim of a well- organized phishing campaign that deceives even the most experienced IT-specialists. It is crucial to establish whether a crime was committed and what level of negligence is appropriate in a particular case. The minimal level of cybersecurity is different for various types of organizations depending on their size and resources. Thus, large organizations such as banks possess stronger technical capabilities to protect their data compared to small businesses or educational institutions. It would be unfair to hold the latter accountable for failing to meet the same cybersecurity standards as the big corporations. In addition, an effective implementation of the legal provisions is essential, considering that most of the organizations that suffer from cyber-attacks often lack the technical expertise, tools, and opportunities to ensure robust cybersecurity.
RECOMMENDATIONS
The emerging concept of cyber hygiene needs to be further developed in India: First, standards for minimum cyber-hygienic practices for organizations processing or collecting personal data need to be evolved, with appropriate standards for different categories of organizations, with a focus on cybersecurity aspects such as passwords, multifactor authentication, software updates, access controls, training of personnel, backups, and reporting of cyber incidents.
Second, the degree of responsibility of organizations for cyber-incidents should be commensurate with their risk profile. More stringent requirements would be needed for organizations handling highly sensitive or large volumes of personal data, processing such data in complex ways, or having weaker governance structures.
Third, organizations and individuals need to be encouraged to undertake regular cybersecurity awareness training and education since human error continues to be a major contributor to cyber incidents.
Fourth, the law needs to draw a clear distinction between deliberately wrongful acts or omissions and human errors, and responsibilities need to be calibrated according to the risk profile of the organization and the measures it could reasonably be expected to adopt to prevent cyber-incidents.
Cyber hygiene is gaining increasing importance and significance as a responsible practice in cyberspace. While India does not currently have a specific law on cyber hygiene, the Information Technology Act, 2000, CERT-In guidelines, and the Digital Personal Data Protection Act, 2023, indicate a growing recognition of the need for organizations to adopt measures to secure digital systems and personal data. While there is a legal framework beginning to take shape, the current approach is fragmented and lacks a comprehensive understanding of the duties of organizations and individuals as far as cybersecurity practices are concerned. Cyber hygiene needs to be framed as a reasonable obligation, based on the risk posed, and not as an absolute duty. Organizations that possess or process other entities’ data and systems must be held responsible, while individuals should be expected to take due care as well. A more coherent and proportional legal framework, as discussed above, will provide better cybersecurity, personal data protection, and promote a responsible digital culture in India.
Anilkumar Ambalam
School of Excellence in law, The Tamilnadu Dr Ambedkar law University
Sign in to join the discussion.

Indian criminal courts have, since the mid-1990s, protected survivors of sexual violence from a peculiar demand: that trauma be remembered like an invoice, in perfect order, down to the make of a car or the exact hour of an assault. Courts now accept that delay in reporting and gaps in a victim's account do not, by themselves, indicate falsehood.

Consider a criminal case where there are clear video evidence and distinct audio evidence. This kind of evidence is considered to be very credible. However, what if the evidence is a deepfake?