securitylinkindia

India Risk Outlook 2025

The year gone by was marked with geopolitical changes and turbulence of a high order. The events in Syria, Lebanon, Ukraine and closer home in Bangladesh, Myanmar and surrounding geographies will cast a telling shadow on the events of 2025. A multitude of elections across the globe and in India, have thrown up diverse results which challenge the old order. While the Narendra Modi-led Bharatiya Janata Party (BJP) emerged from the 2024 General Elections weakened, Donald Trump in the United States of America (USA) came out much stronger and with an agenda which threatens to challenge and reshape the world order. The year ahead is likely to be challenging for India both domestically and in the geostrategic domain. Conversely it would also be a year of multidimensional opportunities which will not only demand deft handling but may also result in new alignments and need for course correction.Economic paradigms may need a fresh approach should President-elect Trump go ahead with his policies of punitive/ reciprocal tariffs and mass deportation of illegal migrants. On the geostrategic front, a more muscular QUAD is at odds with an expanding BRICS and the two may be on a collision trajectory.With the QUAD leaders’ summit planned in 2025 in India, strong anti-China posturing may strain India’s prominence both in SCO and BRICS. The geopolitical tightrope that India has to walk can be gauged by the likely visit of Vladimir Putin to India in first quarter of 2025, followed by PM Modi traveling to China for the SCO summit and hosting the QUAD leaders in October 2025. One misstep or a belligerent statement can derail or alter the outcome of these significant events. In a similar vein India’s image abroad was dented by accusations of targeted killings/attempted murder by alleged government agencies, coupled with bribery allegations against the biggest business house of India.On the domestic front, peaceful elections in J&K and a smooth transition to power of an opposition led government bodes well for the overall security dynamics of the sensitive region and its continued progress in 2025 would be a big boost to stability. The vigorous efforts taken by the BJP-led government to root out Left-Wing Extremism (LWE) would continue in 2025 and may result in weakening this antinational movement significantly.The overthrow of the Sheikh Hasina government has been a big setback as India had backed her government fully. The relations currently are rather fragile with a widening trust deficit on the back of reports of attacks on minorities, and their places of worship. The recent visit of the Foreign Secretary of India has smoothened some issues but more needs to be done in 2025 to bring the relations back to a semblance of normalcy. However, tense relations between the two neighbours in 2025 are likely to continue. On the more complex Indo-China front the disengagement and pull back by both armies from Ladakh has been a very positive development. The recent visit of the National Security Advisor (NSA) to China has given further momentum to an improvement in ties. No dramatic development or normalisation of relations are likely in 2025 and few baby steps to rebuild trust can at best be expected.On the internal front, the BJP-led government is weaker, and despite all odds the opposition INDI alliance has posed significant challenges to the government. This has led to further polarization and widening of communal fault lines. If this remains unchecked, it may lead to social unrest in some historically sensitive areas. The farmers protest continues and will not give much room to the government in 2025 to address the much-needed agricultural reforms.Despite all this 2025 will be a pivotal year for India as it will become the fourth largest economy growing at a rate of 6.5-7 percent in the coming years. Artificial Intelligence (AI) and quantum-based technologies and semi conductor manufacturing will play a big part in the economic resurgence of India, the problems of wealth distribution, population, climate risks and inflation will continue to pose challenges. Overall, a year of stability, steady growth, some geopolitical risks mixed with opportunities is forecast for 2025. Executive Summary The year 2024 was characterized by elections in more than 70 countries and persistence of several geopolitical conflicts. With the series of elections that too k place, the discussion on the spirit and quality of democracy took center stage as leaderships in these countries either used elections to tighten grip on power, gain legitimacy or display illiberal tendencies. The Russia-Ukraine and Israel-Palestine conflicts continued to worsen and have spillover effects in other states, impeding any global efforts towards restoring peace. The Global economy is riddled with stagnant major economies and growing global debt which is already at a record level due to the COVID-19 pandemic. Several governments are offering increased spending and tax cuts as a part of political campaigns, which will only add on to the global debt. There are alarming trends of increasing cost of living, increasing defense expenditure, backsliding on international commitments, and increasing vulnerability to climate variability. Against the backdrop of global disorder, multiplying geopolitical complications and internal challenges, India successfully conducted its general elections. India took strategic measures to protect its integrity, propel its regional influence and maintain a considerable global presence while facing new risks and threats. On the geopolitical front, the diplomatic friction between India and Canada has heightened after the Canadian government accused the Indian High Commissioner and five other diplomats of being ‘persons of interest’ in the murder case of Hardeep Singh Nijjar, a Canadian citizen allegedly involved in Khalistani activities. India responded by recalling its diplomats and by expelling the Canadian High Commission in India, citing its interference in internal affairs as the reason. There are speculations that this diplomatic fallout between the two nations could have spillover effects in other domains, particularly in trade. In late October, India and China established a temporary truce regarding the ongoing conflict along the Line of Actual Control (LAC), with a border disengagement agreement. There will be pulling back of…

Read More

Synergizing Artificial Intelligence and Human Analysis in Corporate Threat Intelligence

Lt. Col. Sushil Pradhan (R)Executive Director and COO, MitKat Advisory, Certified Data Centre Professional Co-authors Introduction Amid an evolving global environment characterized by socio-political turbulence, economic changes, supply chain disruptions, and climate change, businesses face various risks that threaten their operational capability. The need to continuously monitor relevant events and threat indicators has emerged to mitigate these risks promptly and effectively. Corporate threat intelligence is an essential tool to this end. It emphasizes proactive identification and mitigation of risks and enables timely reactions. Risks can be generated by regulatory changes, economic sanctions, upcoming civil unrest, extremism, terrorism, political changes etc. Modern threat intelligence integrates the capabilities of artificial intelligence (AI) and human analytical capabilities to address these issues. AI processes vast amounts of information and datasets through various sources like social media, open-source intelligence (OSINT), and government sources. In parallel, human analytical skill complements AI by interpreting, analyzing and contextualizing filtered information, and presenting it in the form of actionable intelligence that can enable viable options for decision-making. Corporate Threat Intelligence Today’s interconnected world features a dynamic and unpredictable operational environment. Dimensions like domestic politics, international relations, technological advancements, and civil unrest come into play, affecting a business environment. To adapt to these changes, corporations and businesses need a robust threat intelligence system to track, monitor, and manage these risks. Corporate threat intelligence has evolved beyond cybersecurity and now includes climate change, governance, political and economic stability, as well as regulatory policies. Businesses, especially MNCs, face diverse political and economic landscapes that pose adaptability issues as well as operational interruptions. Regime changes, sudden tariffs or sanctions, and regional conflicts are common in sensitive regions and impact business operations. For example, Houthis attacking commercial vessels in the Red Sea region has previously impacted the maritime trade route, adding to transportation and logistics costs. Corporate threat intelligence assists businesses in tracking and monitoring such events, thereby enabling effective risk mitigation strategies. Role of Artificial Intelligence in Threat Intelligence Productive threat analysis is an outcome of deciphering a vast amount of information within a specified timeframe. AI helps declutter irrelevant information, reduce noise, and provide relevant data. Threat intelligence traditionally relies on human analysts who used to surf the web, aggregate OSINT and analyze data manually. This approach was useful in providing depth and conceptual understanding but is labor-intensive and cannot keep up with the pace of the changing operational environment. The introduction of AI has provided a credible counter to these challenges. AI enables automated data collection and curation at an incredible speed. Synergizing Artificial Intelligence and Human Analysis Furthermore, AI also features 24/7 monitoring of relevant events, pattern and trend recognition, and regulatory compliance. AI’s integration with mass notification tools provides real-time updates, which nearly simultaneously enhances organizational awareness. For example, in the case of protests, AI continuously monitors media and social media to look for patterns and possible anomalies. AI can then notify the organization regarding possible supply chain disruptions due to the blockage of national highways, roads, or railway tracks, informing speedy decision-making. Role of Human Intelligence in Threat Intelligence AI has indeed revolutionized threat intelligence with its scalability and speed in processing vast amounts of data in a short period, as well as pattern and trend recognition. However, the role of human analysts remains irreplaceable. The human element of threat intelligence adds cultural context, deeper understanding, and strategic insight. Human analysts can identify the root causes of an event through cultural and contextual understanding while AI provides relevant data. AI excels at processing vast amounts of data and generating pattern analysis, which is difficult for a human analyst in the age of information overload. A human analyst focuses on building strategies and actionable steps to mitigate the risks based on the data provided by AI. For example, in case of a ransomware attack, AI will quickly identify the entry points and systems affected by the attack, while human analysts will focus on strategizing mitigation of the risk. Despite these advancements, vulnerabilities exist, thus making human collaboration an integral part of corporate threat intelligence. An important shortfall of AI integration in threat intelligence is the spread of disinformation and misinformation, which can be eliminated with human involvement, which includes verification of sources, checking patterns and inconsistencies, and flagging of issues considered false. This helps to bring in authenticity, reliability, and conceptualization, overcoming the deficiencies of AI. Future Applications Future applications of AI in threat intelligence include advancements like dynamic risk mapping and Geographic Information Systems (GIS), which will assist businesses in exposing geopolitical and geographical vulnerabilities, leading to a better understanding of the region of interest. One of the most important features of AI is Natural Language Processing (NLP), which enhances the language and dialect understanding of AI. It will help businesses to understand contextual and localized dynamics on a deeper level. Upcoming AI advancements like scenario simulations and advanced sentiment analysis will provide a deeper understanding of public opinion, predict upcoming events, and simulate them to effectively mitigate the risk early on. However, ethical concerns like data privacy and AI bias still cloud the capability of AI. Advancements like Explainable AI (XAI) can build transparency and trust, but the collaboration between AI and analysts will remain crucial, with humans contextualizing and conceptualizing information that AI refines through data made available to it. Conclusion Threat Intelligence has proved to be essential for businesses globally. Dynamically evolving operational environments necessitate innovative threat intelligence protection to safeguard critical assets, business operations, and reputation. AI has been a revolutionary part of corporate threat intelligence, and its scalability and speed have changed how we process the increasingly interconnected global risk landscape. AI has enabled real-time data analysis, pattern and trend recognition, sentiment analysis, and predictive modeling to identify risks early on. The synergy between AI and humans creates a feedback loop that enhances the relevance and accuracy of solutions to upcoming risks. This paves the way for a hybrid model which will allow for more accurate information as well as the most…

Read More

Digital Arrest: The Modern-Day Cyber Scam

Maj Sadhna Singh, Consultant What once began as harmless pranks in the early days of computers and the internet-where hackers focused on defacing websites and posting jokeshas transformed into a full-fledged, ever-evolving industry. Over the years, cybercriminals have honed their tactics, adapting to new technologies and devising increasingly sophisticated methods. The year 2024 witnessed a surge in cyber scams, employing a wide range of strategies to swindle people out of their hard-earned money under the guise of Digital Arrest. No one was spared, as the targets ranged from high-ranking officials and journalists to security personnel and innocent elderly individuals. From basic online scams to large-scale operations reminiscent of ‘Jamtara,’ and with the emergence of high-profile digital arrests, cybercrime is no longer a distant threat – it has become a pervasive reality. Digital Arrest is an elaborate scam designed to extort victims of their savings through intimidation, deceit and blackmail. Fraudsters often pose as law enforcement officials, using fear as their primary weapon. The larger the amount they aim to steal, the more sophisticated their operation becomes. Surprisingly, it all begins with a seemingly innocent phone call. Many of us, regardless of our backgrounds, have encountered such calls. They might start with a casual claim like a parcel booked in your name being sent to Taiwan, threats of your phone number being blocked due to unpaid bills, or requests for KYC verification. Others may offer tempting work-from-home opportunities. However, if you continue engaging, these calls often take a sinister turn, luring victims into traps that could lead to significant financial loss. Common Modus-Operandi used by scamsters India’s Fight against Cyber Crime and Digital Arrest The Central Government has strengthened its efforts to combat cybercrimes through a series of coordinated initiatives. Key measures include: Through these efforts, the government is building a robust framework to prevent and address cybercrimes, fostering a safer digital environment for all. Our contribution: Fight against Digital Arrest The government, police, and various agencies play a crucial role in combating cybercrime, but the greater responsibility lies with us, the citizens of India. To protect ourselves and our communities, we must prioritize education and awareness, especially among the most vulnerable – the young and elderly and the rural population, who are at higher risk of falling prey to digital arrest scams. Awareness is our strongest defence. By openly discussing how these scams operate and what actions to take if targeted, we can collectively strengthen our resistance against such cyber frauds. Cyber scams and digital arrest frauds can affect anyone, from students to professionals and social media influencers, with no one immune to these threats. Instead of blaming victims, we must foster a supportive environment where they feel safe to share their experiences without fear of judgment or reputational harm. The rise of digital arrest scams in India is largely driven by society’s tendency to shame victims, who, even when innocent, face doubt, blame, and social stigma, which discourages them from reporting the crime. This silence enables scammers to thrive, as many victims, fearing the damage to their social standing, choose to stay silent, allowing cyber fraud to grow unchecked. It’s time to change this narrative. Support, not shame, is the way forward in fighting digital fraud. Let’s encourage open discussions, break the silence, and empower victims to come forward. Awareness, education, and a united effort from both authorities and citizens are key to combating cyber fraud and protecting individuals from becoming victims and together, they can turn the tide against digital fraud – empowering victims, exposing scammers, and building a safer digital world for all.

Read More

Cyber-Physical Convergence: A New Frontier in Risk Mitigation

BY ANIL PURI, CMD, APS GROUP A first generation serial entrepreneur, thought leader and an action catalyzer rolled into one – Anil Puri is a rare combination of a visionary, an innovator and a strategic thinker. He has used this combination to innovate and implement on-ground many new business ideas. His rich experience in various businesses has enabled him to nurture & mentor innovative ideas and scale them up. Introduction Cyber-physical convergence is reshaping the landscape of risk mitigation, integrating digital and physical security systems into a unified framework. As cyber threats increasingly impact physical assets and vice versa, security professionals must adopt a holistic approach to risk management. The rapid evolution of digital technologies and the increasing interconnectivity of physical infrastructure have given rise to a new era of cyber-physical threats. No longer confined to distinct domains, cyber and physical security have merged into a single, complex ecosystem where vulnerabilities in one realm can directly impact the other. From critical infrastructure and smart cities to industrial control systems and defense networks, cyber-physical systems now form the backbone of modern society. However, this interdependence has also expanded the attack surface, making security breaches more sophisticated, far-reaching, and potentially catastrophic. Cyberattacks targeting power grids, autonomous vehicles, healthcare facilities, and financial institutions highlight the growing risks associated with this convergence. As adversaries leverage AI-driven cyber intrusions, deepfake technology, and weaponized drones, the need for integrated security frameworks has never been more pressing and critical. The traditional siloed approach to cybersecurity and physical security is no longer viable – organizations must adopt a holistic, intelligence-driven strategy that ensures resilience against emerging threats. The evolution of cyber-physical security Proliferation of Internet of Things (IoT), Artificial Intelligence (AI), and cloud computing have necessitated their convergence. The increasing interconnectivity of security systems, from access controls to surveillance and industrial automation, has introduced both opportunities and vulnerabilities. Traditionally, physical security operated in isolation, relying on access control, surveillance, and manpower, while cybersecurity was confined to protecting digital assets from breaches. However, with the rise of Industry 4.0, IoT, AI, and cloud computing, the attack surface has expanded, making physical and digital threats inseparable. The proliferation of smart cities, automated industrial control systems (ICS), and connected supply chains has necessitated a holistic security model that integrates cyber risk management with traditional security protocols. Today, adversaries leverage cyber vulnerabilities to manipulate physical systems, causing disruptions in power grids, transportation networks, and critical infrastructure. The Stuxnet attack on nuclear facilities and ransomware targeting hospital equipment underscore the urgency for unified cyber-physical security architecture. In response, modern security frameworks emphasize real-time threat intelligence, predictive analytics, and AI-driven automation to preempt cyber-physical breaches. Zero-trust architecture, behavioral analytics, and digital twins are now deployed to simulate and mitigate threats before they manifest in rereal- world operations. Regulatory frameworks, including the NIST Cybersecurity Framework and ISO 27001, are evolving to integrate physical security considerations, ensuring a layered defense mechanism. Organizations are adopting Security Operations Centers (SOCs) with a cyber-physical focus, merging IT and OT (Operational Technology) security to enhance resilience against sophisticated threats. As AI-driven cyber-physical attacks become more prevalent, the future of security lies in adaptive, self-learning systems capable of neutralizing threats autonomously. This paradigm shift signifies that security is no longer just about preventing unauthorized access but ensuring the resilience of interconnected ecosystems where digital vulnerabilities can have catastrophic physical consequences. The convergence of cyber and physical security has evolved from a fragmented approach to an integrated, intelligence- driven framework, responding to the increasing interconnectivity of critical infrastructure, enterprises, and smart ecosystems. “The convergence of cyber and physical security is no longer a choice but a necessity in an era where digital threats can have real-world consequences” Emerging threats and risk adaptation The evolving threat landscape is increasingly characterized by hybrid risks, where cyber, physical, and geopolitical dimensions intersect, creating unprecedented security challenges. Emerging threats such as AI-driven cyberattacks, deepfake-enabled disinformation campaigns, quantum computing vulnerabilities, and autonomous weaponized drones are reshaping security paradigms. The rise of cyber-physical attacks on critical infrastructure, including power grids, transportation systems, and smart cities, demonstrates how interconnected digital ecosystems amplify vulnerabilities. Ransomware-as-a-Service (RaaS), supply chain disruptions, and state-sponsored cyber espionage further compound these risks, demanding a proactive and dynamic security posture. Moreover, the increasing reliance on AI and machine learning in decision-making raises concerns about algorithmic bias, adversarial AI, and the exploitation of automated systems. With the integration of 5G, IoT, and cloud-based architectures, the attack surface continues to expand, necessitating a shift from traditional defense mechanisms to predictive and intelligence-driven risk mitigation strategies. To adapt to these emerging risks, organizations and governments are embracing resilience-based security models, integrating cyber threat intelligence (CTI), zero-trust architectures, and real-time monitoring systems. Advanced encryption methods, including post-quantum cryptography, are being explored to counter the future risks posed by quantum computing. AI-powered Security Operations Centers (SOCs) are enhancing real-time threat detection and response, leveraging behavioral analytics to preemptively neutralize attacks. The adoption of digital twins for cybersecurity simulations enables organizations to stresstest their systems against evolving threats. Additionally, regulatory frameworks and compliance standards are evolving to address the convergence of cyber and physical threats, with increased emphasis on public-private partnerships for intelligence sharing. As adversarial tactics become more sophisticated, a paradigm shift toward adaptive security – where systems learn, predict, and autonomously respond to threats – is imperative. The future of risk adaptation lies in continuous innovation, strategic foresight, and the seamless integration of AI-driven security measures to safeguard interconnected ecosystems against both known and emerging threats. “In the cyber-physical domain, risk is no longer just a number; it is an evolving battlefield“ Dynamic risk matrix: A strategic framework A Dynamic Risk Matrix (DRM) helps organizations identify, assess, and prioritize risks based on real-time data. Unlike static models, DRM adapts to changing threat landscapes, integrating data from cyber and physical security domains. Risk Dimensions in Cyber-Physical Security Risk Type Cyber Impact Physical Impact Mitigation Strategies Data Breach Unauthorized access to sensitive data Compromised biometric authentication Multi-factor authentication, encryption System Hijacking…

Read More

The Smart Way in: Innovations in Vehicle Access Control Management

Vehicle access control systems are no longer just about security; they have become a cornerstone of modern urban living. As our cities grow and technology advances, the systems that manage vehicle access in residential complexes have continued to evolve. This blog explores the trends and necessities driving the update of these systems to meet the developing needs of urban communities. Urbanization and technological progress have forced us to reimagine security and convenience in modern living. This is particularly evident in the vehicle access control market, which is experiencing significant growth. According to MarketsandMarkets, the global vehicle access control market is going to surge from USD10.8 billion in 2020 to USD22.6 billion by 2027. One reason why traditional access methods are being forced to evolve is the rise in the number of vehicles per household. This creates a demand for robust systems that are able to manage entry and exit efficiently in order to reduce congestion and, therefore, resident frustration. But it’s not just about quantity – it’s also about quality. For example, a white paper from the Association for Smarter Homes & Buildings (ASHB), observed that residents today expect a frictionless living experience. Waiting in line to scan cards or having to buzz in guests individually no longer meets these expectations. What’s more, as MarketsandMarkets highlights, there is a growing need for streamlined operations that cater to residents and visitors alike, ensuring quick and secure access without manual intervention. Moreover, like many parts of society, residential complexes are under pressure to become more sustainable and reduce their carbon footprint. A US Department of Energy report reveals that personal-vehicle idling wastes about 3 billion gallons of fuel, generating around 30 million tons of CO2 annually in the US alone. Efficient access systems can help minimize idling and reduce energy consumption. Beyond the barrier: Innovations in vehicle access control The good news is that technological advancements offer effective solutions to these challenges, bringing efficiency, enhanced experience, and sustainability. Smart barrier gates integrated with ANPR cameras These combine Automatic Number Plate Recognition (ANPR) with intelligent barrier systems and radar sensors to accurately detect and control vehicle movements. ANPR cameras automatically recognize and verify vehicle number plates, allowing registered vehicles to enter without manual intervention. This accelerates traffic flow and lightens the workload for facility managers. These systems also provide valuable data collection capabilities, enabling better traffic flow optimization and enhancing the resident experience. Safety features such as anti-fall, anti-collision, and automatic lift functions ensure the safety of residents and their vehicles. Visitor management systems These enhance convenience and security by allowing residents and management to manage visitor access directly from their smartphones. Residents can remotely grant or deny access, simplifying visitor management and ensuring authorized access only. Centralized management platforms These integrate various access control systems into a single dashboard, enabling facility managers to monitor traffic, authorize entry, and generate reports with ease. This optimizes operational efficiency and supports data-driven decisions to improve resident satisfaction. Proven success: The Arboretto Residential Complex The real-world applicability of these solutions is demonstrated by the Arboretto Residential Complex in Bogotá, Colombia. Faced with access control challenges due to high vehicle and visitor traffic, Arboretto collaborated with Hikvision to overhaul its vehicle access system. Key improvements included the deployment of a dual- barrier setup featuring 4MP ANPR Intelligent Entrance Cameras (DS-TCG405-E) and 5 Series Straight-Arm DC Frequency-Conversion Barrier Gates (DS-TMG510-H). This configuration enhances security through license plate recognition and secondary driver authentication, ensuring seamless vehicle access control. The DC frequency-conversion technology ensures quiet and precise gate operations, while the Video Intercom Kit (DS-KIS602(B)) with an integrated indoor station and ID card reader facilitates efficient visitor management. Managed through HikCentral Professional, Hikvision’s integrated platform, the system offers real-time monitoring and data analysis, streamlining operations for all users. During high-traffic events, pre-registered guests receive QR codes for swift, secure entry, enhancing both security and efficiency. The new system significantly reduced access errors, bolstering security and lowering operational costs by minimizing manual labor. Residents experienced shorter wait times and heightened security, leading to increased satisfaction and a safer, more convenient environment. Read More

Read More

Certifying Trust: The Pertinence of STQC in the Indian Security and Surveillance Landscape

ADITYA KHEMKAMD, Aditya Infotech Ltd. Standards are not merely guidelines; they are the foundation of trust in a rapidly evolving technological world. In India, the IoTSCS Essential Requirements (ER) Certification for Security administered by STQC under the Ministry of Electronics and Information Technology (MeitY), has emerged as a cornerstone of credibility in the surveillance industry. It assures quality, security, and compliance with the stringent requirements of the nation’s digital ecosystem. For security and surveillance products, the certifications by STQC-certified labs signify a commitment to excellence, especially in combating cyber threats and ensuring adherence to the Public Procurement Order (PPO) and BIS Compulsory Registration Order (CRO) guidelines. Regulatory Frameworks Governing CCTV Certification CCTV manufacturers and suppliers in India are now subject to two key regulatory frameworks that dictate compliance requirements: Both frameworks aim to ensure cybersecurity compliance, but they differ in scope, timelines, and mandates. Differences between PPO and BIS Mandates Aspect PPO BIS CRO Scope Government procurement General sales in the Indianmarket Effective Date June 6, 2024 April 9, 2025 Certifications Required Essential Requirements(ER) Essential Requirements(ER) & Safety Requirements Impact of Non-Compliance Disqualification from government contracts Ineligibility for generalsales in India What is the Essential Requirements (ER) Certification for Security About? The ER Certification is more than a mark of quality; it’s a comprehensive evaluation of a product’s ability to withstand the challenges of the modern security landscape. In the surveillance industry, it focuses on critical domains like cybersecurity standards, safeguarding against vulnerabilities like unauthorized access, hacking, or data breaches and supply chain mitigations. Security testing evaluates the resistance of hardware and software to cyber threats and unauthorized access, while supply chain verification ensures compliance with PPO guidelines for essential requirements. Together, these measures create a fortified framework for ensuring the reliability and integrity of surveillance solutions. Objectives of the Essential Requirements (ER) Certification The primary objectives of the ER Certification in the surveillance sector include: Enhancing Cybersecurity: Ensuring that surveillance systems are resilient to cyber threats and unauthorized intrusions. Promoting Trust: Providing assurance to stakeholders that certified products meet stringent quality and security benchmarks. Compliance with PPO & CRO Guidelines: Verifying the supply chain to ensure adherence to the Essential Requirements (ERs) outlined by the government. Boosting Indigenous Manufacturing: Encouraging Makein- India initiatives by certifying products developed within the country. Scope of Essential Requirements (ER) Certification In the surveillance industry, the scope of the ER Certification encompasses: Security Testing: Assessing hardware and software for vulnerabilities, resistance to cyberattacks, and ensuring robust data encryption. Supply Chain: Trusted supply chain verification to ensure that the critical components are sourced from trusted source and are not counterfeited. For instance, surveillance systems employed in traffic management projects – such as ANPR cameras at toll booths or facial recognition systems in airports – rely on the ER Certification to guarantee their performance and reliability. Importance of Essential Requirements (ER) Certification in India In an era where data breaches and cyber threats are rampant, the significance of the ER Certification cannot be overstated. For the surveillance industry, it: Strengthens Cybersecurity: By mandating rigorous security testing, it ensures that surveillance systems are equipped to protect sensitive data. Builds Credibility: Certified products gain a competitive edge in government and private sector projects.Enforces Accountability: Through supply chain verification, it ensures that all components and processes comply with national standards. Supports National Security: By certifying systems resistant to tampering and breaches, it safeguards critical infrastructure. Impact of these Mandates on the Industry Manufacturers: Manufacturers must align their production and testing processes to ensure all CCTV products meet the Essential Requirements and safety standards. This involves partnering with STQC-certified labs, updating software, and possibly redesigning products to eliminate cybersecurity risks. Distributors and Retailers: Distributors and retailers need to be vigilant about sourcing compliant products. Non-compliant stock will become unsellable after the April 2025 deadline in the market, leading to potential losses.End Users: Government agencies are already required to procure compliant products, while general consumers will benefit from enhanced security features in CCTVs once the BIS mandate is fully enforced. Certification Process The ER Certification process is rigorous, involving: Application Submission: Manufacturers provide detailed documentation on product specifications and compliance with ERs. Testing and Evaluation: Comprehensive security testing of hardware and software to identify vulnerabilities and ensure resilience. Supply Chain Mitigation Verification: Scrutinizing the origin and compliance of components with PPO guidelines. Final Approval: Upon meeting all requirements, certification is granted, reinforcing trust and credibility. Key Areas of Testing In the surveillance industry, STQC testing primarily focuses on: Security Testing: Examines resistance to cyber threats, unauthorized access, and data breaches. It ensures robust encryption and secure communication protocols. Supply Chain Mitigation Verification: Evaluates adherence to PPO guidelines, ensuring transparency and compliance in sourcing components. Essential Requirements (ER) Certification in the Surveillance Industry The surveillance industry, being critical to national security, benefits immensely from the ER Certification. By certifying products against cyber threats and ensuring compliance with supply chain guidelines, its aimed at creating a robust framework for safeguarding sensitive areas such as: Smart Cities: Certified surveillance systems play a vital role in monitoring urban areas. Critical Infrastructure: Ensures the security of airports, railways, and power plants. Public Safety: Enhances law enforcement capabilities with secure and reliable CCTV systems. STQC Certified CP PLUS Product Line An industry leader, CP PLUS demonstrates the transformative potential of the ER Certification in the security and surveillance landscape. With an extensive range of STQC-certified products, the company sets new benchmarks in quality and reliability. Certified Models Revolutionizing Surveillance CP-UNC-TE21ZL6C-VMDS-Q: ● High-resolution imagery and advanced AI-enabled analytics. ● Designed for traffic management and public safety applications. CP-UNP-F4521L30-DPQ: ● Compact yet powerful, ideal for indoor environments like retail and banking. ● Features cutting-edge motion detection and cloud integration. CP-UNC-VE21ZL4C-VMDS-Q: ● Built for extreme weather with IP67 certification. ● Perfect for industrial and outdoor applications. By integrating STQC-certified products into its portfolio, CP PLUS not only meets but exceeds the expectations of government and private stakeholders. These models exemplify the perfect balance of cutting-edge technology and unwavering security,…

Read More

Physical Security Threats to Data Centres and Leveraging Mobile Technology With AI and ML For Mitigation

What is a Data Centre? A data centre is a specialized facility designed to house computer systems, telecommunications equipment and storage systems, supported by the necessary infrastructure to ensure their efficient operation. These facilities consist of several core components including computing equipment like servers and mainframes, storage systems such as hard drives and tape systems, and a robust network infrastructure comprising routers, switches, firewalls, and cabling. The infrastructure includes power distribution systems, cooling mechanisms, fire suppression tools, and security measures for both physical and cybersecurity. Critical infrastructure in a data centre is vital for uninterrupted functionality. Power systems include uninterruptible power supplies (UPS), backup generators, multiple power feeds, and power distribution units (PDUs). Cooling systems rely on Computer Room Air Conditioning (CRAC) units, chillers, hot/ cold aisle containment, and raised floors to manage airflow. Environmental controls ensure optimal conditions through temperature and humidity monitoring, air filtration, and fire detection and suppression systems. Data centres come in various types, including: (i) Enterprise centres – Operated by companies for their own use, (ii) Colocation centres – That rent space to multiple customers, (iii) Cloud centres – Managed by cloud service providers, (iv) Edge facilities – Located closer to end-users, and (v) Hyperscale centres – Operated by tech giants. They are also classified into tiers based on their capacity and redundancy: (i) Tier 1 provides basic capacity with a single path for power and cooling, (ii) Tier 2 offers redundant components, (iii) Tier 3 includes multiple paths for concurrent maintainability, and (iv) Tier 4 achieves fault tolerance with the highest redundancy level. Data centres serve numerous critical purposes such as hosting websites and applications, storing and processing data, supporting cloud computing services, enabling business continuity, providing backup and recovery solutions, and supporting telecommunications infrastructure. They also facilitate content delivery networks, process business transactions, support artificial intelligence and machine learning, and enable big data analytics. The evolution of data centres is driven by trends toward greater energy efficiency, higher density computing, increased automation, enhanced security measures, and sustainable operations. Innovations include integrating edge computing, adopting AI-driven management, and implementing modular design approaches. These facilities are essential to modern digital infrastructure, underpinning global digital economies, business operations, internet connectivity, and digital services worldwide. Like all assets of value, apart from facing cyber threats, data centres increasingly face physical security threats because damage, sabotage or outages to data centres can cause catastrophic damage amounting to millions of dollars, loss of brand value and potentially ruinous litigations. To set context, as per a 2023 survey, roughly 54 percent of data centre operators said their latest most significant outage cost over USD100,000. A further 16 percent of respondents said the most recent crucial system outage caused them monetary damage of over USD1 million. Physical Security Threats The physical security threats faced by data centres encompass a wide range of challenges that require comprehensive protection strategies. Let us examine a few of these threats/ challenges. The most common threats are given in the Fig 2 below and thereafter are described in detail. Unauthorized physical access At the forefront of these concerns is unauthorized physical access, which can manifest through various methods including social engineering attempts, tailgating through secure entrances, impersonation of authorized personnel or contractors, theft of access credentials, forced entry attempts, and insider threats from disgruntled employees. These access-related threats are particularly concerning as they can lead to more severe security breaches if successful. Infrastructure sabotage Infrastructure sabotage represents another critical threat category, involving deliberate damage to essential systems such as power distribution units, network cables, cooling systems, backup generators, and server racks. Such attacks can cripple data centre operations and lead to significant service disruptions. The risk of vandalism to security systems themselves must also be considered, as damage to these protective measures can create vulnerabilities that malicious actors might exploit. Environmental threats Environmental threats pose a significant risk to data centre operations and require robust mitigation strategies. These include fire and smoke damage, water damage from flooding or leaks, extreme temperature fluctuations affecting equipment, humidity issues that can damage hardware, natural disasters such as earthquakes and hurricanes, chemical contamination, and electromagnetic interference. These environmental factors can cause catastrophic damage to sensitive equipment and disrupt critical services. Power-related threats Power-related threats are particularly concerning given the data centre’s reliance on consistent, clean power. These include grid power failures, UPS system failures, generator malfunctions, power surges or spikes, disruption to fuel supplies for backup systems, and potential sabotage of electrical systems. The interconnected nature of power systems means that a failure in one component can cascade through the entire facility. Theft Theft remains a persistent threat to data centres, targeting valuable assets such as server and network equipment, storage devices, copper wire, backup media, personal property, and maintenance equipment. These theft attempts can be opportunistic or carefully planned operations, potentially involving insider knowledge. The financial impact of theft extends beyond the immediate loss of equipment to include service disruption and potential data breaches. Service disruption attempts Service disruption attempts represent a broad category of threats aimed at preventing normal data centre operations. These can include blocking physical access to facilities, disrupting cooling systems, interfering with power delivery, cutting communication lines, combining DDoS attacks with physical intrusion, and jamming wireless systems. Such attacks can be particularly effective if coordinated across multiple vectors simultaneously. Malicious surveillance and intelligence gathering activities Malicious surveillance and intelligence gathering activities pose a significant threat as precursors to more direct attacks. These can include photography of facilities, drone surveillance, dumpster diving for sensitive information, social engineering to gather facility information, recording of security patrol patterns, and monitoring of staff movements. This information can be used to identify vulnerabilities and plan more targeted attacks. Vehicle-based threats Vehicle-based threats present unique challenges for data centre security including the potential for ramraid attacks, car bombs, unauthorized parking near critical infrastructure, blocking of emergency access routes, vehicle- borne surveillance, and hijacking of delivery vehicles. These threats require specific countermeasures such as vehicle barriers, bollards, secure parking areas, and…

Read More

Beware of the Dark Age of the Digital Era

GARIMA GOSWAMYCEO and Co-FounderDridhg Security International Pvt. Ltd. The rapid advancement of technology has brought unprecedented convenience, but it has also opened doors to ethical dilemmas and potential misuse. One of the most alarming possibilities lies in the hypothetical misuse of technology for unauthorized data retrieval, particularly from sensitive repositories like Aadhaarlinked databases and the sale of objectionable non consensual pictures produced by using deepfake technologies via nudify apps. Deepfake Technology and Nudify Apps: A Looming Threat Deepfake technology, which uses generative AI models to create realistic but fake images, videos, or audio, has become a significant concern. Once exclusive to media professionals, these tools are now widely accessible, and their potential for misuse is immense – from of ‘nudify’ apps, which claim to remove clothing from images, often targeting women. These apps, available for as little as INR199 on platforms like Telegram, enable anti-social elements to exploit technology for financial and reputational harm. Tutorials for these tools are freely available online, making them even more dangerous. The combination of deepfake tools with apps like Microsoft’s VASA – which generates lifelike, audio-driven talking faces – further heightens the risk of identity theft and reputational damage. These technologies, when misused, create opportunities for exploitation on a scale previously unimaginable. Unauthorized Data Retrieval: A Growing Concern Imagine an application capable of instantly retrieving personal details – such as names, phone numbers, or Aadhaar-linked addresses – by simply pointing a smartphone camera at an individual. While this may sound like science fiction, the rapid evolution of technologies like artificial intelligence (AI), augmented reality (AR), and centralized databases makes such scenarios increasingly plausible. This highlights the urgent need to address privacy and security risks associated with emerging technologies. The Role of Ethics in Technological Advancements The integration of ethics into the development and deployment of advanced technologies is no longer optional – it is a necessity. Without ethical guidelines, the misuse of such tools could lead humanity down a perilous path. Technology, when unbridled by ethics, has the potential to create a dystopian reality where privacy, security, and human dignity are continuously compromised. Developers, organizations, and governments must work collectively to ensure that technology serves the betterment of humanity. Safeguards, transparency, and strict regulatory oversight must be in place to prevent exploitation and misuse. The Need for Corrective Action It is not just governments and regulatory bodies that bear the responsibility of preventing the misuse of emerging technologies. Private organizations must also play their part by investing in solutions to counter these threats. For example, while tools to create deepfakes are widely accessible, reliable detection mechanisms remain scarce. Companies like Sensity, ResembleAI, and DridhG Security International are leading the way in developing tools to identify and counteract the misuse of these technologies. Such innovations are critical in ensuring that the digital world remains safe and secure for everyone. Conclusion The allure of technological advancements should not blind us to their potential risks. Without the integration of ethics, innovation could become a double-edged sword, capable of both immense progress and devastating harm. The time to act is now – by fostering collaboration between governments, private organizations, and ethical technologists, we can ensure that technology remains a force for good. Without immediate corrective measures, we risk entering a digital dark age where innovation outpaces our ability to control its consequences.

Read More
Police

The Public Want Clear Rules on Police Use of Facial Recognition

There is public support for the police’s use of facial recognition to solve and prevent crimes – even in traditionally more skeptical countries as Denmark. Here, a new opinion poll shows that 84 percent have a positive attitude. However, trust in the technology depends on politicians and authorities establishing clear rules for the protection of data and privacy. Whether it is recorded video material used to solve crimes, or live images that, for example, can identify unwanted hooligans at a football stadium, public support for the use of facial recognition is quite significant. In Denmark 84 percent support the use of facial recognition in connection with the prevention and solving of crime and terrorism. The support spans across age, gender, and geography, according to a nationally representative analysis conducted by Norstat for Milestone Systems. But the support has strings attached. 70% of Danes see clear rules, data protection, and transparency about how and where the technology is used as the most important factor for their trust. Additionally, 51% consider it crucial that data is deleted as soon as it is no longer relevant to a case. “The support for facial recognition also obliges. Therefore, politicians and authorities must get started on creating clarity about rules, responsibility, and protection of our data. It is fine that they are currently operating within a pilot scheme, but it is urgent to look at more permanent regulation of facial recognition,” said Thomas Jensen, CEO of Milestone Systems. Danish Milestone Systems develops and sells data-driven video technology and analysis tools used in, for example, airports, by police, traffic control, companies, hospitals, and stadiums worldwide. “It is crucial to have clear and transparent regulation if we are to maintain the public’s support and trust in the technology and the authorities. At the same time, there must be security for how facial recognition data is stored and deleted when it is no longer relevant. It could be 30-60 days,” said Thomas Jensen. The technology is used today for everything from verification – such as when you open your iPhone, show a badge, or go through passport control – to recognizing a specific person at, for example, a sports venue. The support for facial recognition also obliges. Therefore, politicians and authorities must get started on creating clarity about rules, responsibility, and protection of our data. It is fine that they are currently operating within a pilot scheme, but it is urgent to look at more permanent regulation of facial recognition Thomas Jensen CEO, Milestone Systems “In addition to all the practical and well-known applications, modern AI-driven facial recognition is also a powerful tool that can help both solve and prevent crimes,” said Thomas Jensen. Although the publics knowledge of the technology behind facial recognition is relatively low, the attitude is positive. The new survey shows significant support for using facial recognition technology in cases of murder (88%) and serious violence and rape (87%). Likewise, 81% believe that facial recognition should be used to prevent and solve terrorism by quickly identifying known terrorists. Technology is not always perfect – this also applies to facial recognition. Therefore, two trained operators should verify with their own eyes when the software finds a face match – a picture in a database that matches a picture from a video recording of, for example, a wanted criminal or a hooliganThomas Jensen CEO, Milestone Systems Clear rules and regulations are one thing. There is still a need for common sense and human judgment, says Thomas Jensen. “Technology is not always perfect – this also applies to facial recognition. Therefore, two trained operators should verify with their own eyes when the software finds a face match – a picture in a database that matches a picture from a video recording of, for example, a wanted criminal or a hooligan,” said Thomas Jensen. He emphasizes that although most respondents in the survey support the police’s use of facial recognition in their work to protect citizens, prevent, and especially solve crimes. “But that trust and support also obliges to create clarity and frameworks,” he emphasized. Facts about facial recognition ● Today, AI – artificial intelligence – is used to train facial recognition software and convert images into anonymous signatures/ numbers. These signatures are compared with anonymous signatures in a database based on images of faces from, for example, the police, Interpol, FBI etc. ● Only when there is a potential match between the signatures are the images retrieved from the database for comparison. ● The technology is used today for everything from verification – such as when you open your iPhone, show a badge, or go through passport control – to recognizing a specific person at, for example, a football stadium. ● The technology behind facial recognition was developed in 1965 by the American mathematician Woodrow Wilson Bledsoe (1921–1995) to identify or confirm a person’s identity based on facial features. ● Post-event facial recognition analyzes video recordings after the event has taken place, instead of live. Investigators can use recognition software on recorded video from cameras to identify suspects by matching their face/signatures with known databases. ● Real-time facial recognition is the immediate analysis of a live video feed, where faces are compared with a database to generate instant alerts when a match is found. At large public events such as sports stadiums, real-time facial recognition can be used to detect wanted or banned individuals – for example, known hooligans. Read more posts

Read More

7 Advanced Technologies That Optimize The Performance of Hikvision’s PTZ Cameras

Hikvision has integrated seven advanced technologies that drive stability, precision, and efficiency in video monitoring with Pan-Tilt-Zoom (PTZ) cameras. In this blog, we will explore how these innovations – such as image stabilization, rapid focusing, and dual-view capabilities – enable Hikvision’s PTZ cameras to provide unmatched performance in various environments. Numerous real-world challenges face security professionals who need to deliver reliable and efficient video monitoring solutions. Sometimes, it is finding a way to focus on critical issues that occur within a video stream. At other times, they need to be able to ‘see’ in very adverse weather conditions. To cope with these different challenging scenarios, security solutions must be able to adapt and respond with precision and intelligence. Hikvision’s PTZ cameras bring together dedicated technologies designed to address these needs, ensuring optimal performance in the most demanding conditions. 7 innovations that enable Hikvision’s PTZ cameras to be trusted in diverse real world scenarios 1. Stabilizing images against vibrations When PTZ cameras are installed on bridges or in areas with strong winds, they are prone to vibration. This can cause the image to show signs of shaking, especially when the lens is extended to its maximum focal length. To address this problem, Hikvision has developed unique Optical Image Stabilization (OIS) and Gyroscope Image 7 Advanced Technologies That Optimize The Performance of Hikvision’s PTZ Cameras Stabilization (GIS) technologies for its PTZ cameras. Both technologies use a gyroscope to detect and measure camera vibrations. The OIS technology compensates for the camera motion by moving the lens in the optical path, ensuring that the lens always stays focused on the sensor. The GIS technology, meanwhile, counterbalances the camera’s motion digitally. 2. Seeing through fog When monitoring long distances, fog can be a significant issue. Hikvision’s defog technology measures fog density based on the level of grayness in the live video feed and automatically activates a proper defog mode. In light fog, the Algorithmic Defog mode enables the camera to digitally recover and enhance image details to produce colored video. In more challenging, thick fog conditions, the Optical Defog mode is activated. This mode uses infrared light, which can penetrate the fog to generate black-and-white video. Despite the absence of color, the video is of high quality thanks to advanced Image Signal Processing (ISP), which significantly reduces noise. 3. Focusing at lightning speed while zooming Just as eagles can spot small animals from high in the sky, Hikvision’s PTZ cameras can sharply focus on distant objects, even as their zoom level changes. This capability is powered by Hikvision’s Rapid Focus technology. By creating a 3D model of the camera’s surroundings, the system pre-calculates the coordinates and zoom ratio for every point in the scene. When the camera needs to focus on a specific point, it uses this pre-calculated data to quickly achieve sharp focus, dramatically reducing focusing time. 4. Keeping track of moving objects In some situations, it is essential to continuously track a moving object. In a chemical park, for example, it is crucial to monitor trucks transporting hazardous materials to ensure they follow the designated entrances and routes. In such cases, Hikvision’s Auto Tracking 3.0 technology provides an effective solution. By leveraging Automatic Number Plate Recognition (ANPR), the PTZ camera can identify, lock onto, and accurately follow a specific vehicle. The camera’s pan and tilt capabilities allow it to maintain focus on the vehicle as long as it remains within coverage, even if it is temporarily obscured by other objects. 5. Delivering dual, smartlylinked views at once When a traditional PTZ camera moves or zooms in, incidents outside its current field of view may be missed, creating gaps in coverage. In environments such as critical facilities or infrastructures, maintaining complete, uninterrupted coverage is vital in ensuring no incident goes unnoticed. Hikvision’s TandemVu PTZ cameras tackle this challenge by integrating multiple lenses, offering panoramic and close-up views simultaneously. The innovative Smart Linkage technology ensures that when an object is detected in the panoramic view, the PTZ lens automatically activates to track and identify it. If it identifies a trespasser, the camera can even issue visual and auditory warnings. This dual-view capability allows users to focus on details or respond to specific events while maintaining a wider overview, ensuring effective situational awareness. 6. Extending operational life with an upgraded slip ring for pan-tilt PTZ cameras undergo countless pan and tilt movements throughout their lifespan, which can lead to mechanical wear and decreased reliability in standard models. Hikvision’s Dual-Track Slip Ring is designed to address this challenge by offering enhanced durability and redundancy. The dual-track design ensures that the camera remains operational even if one track experiences damage, providing up to 10 years of reliable performance. The gold-plated tracks further enhance smoothness and resistance to wear, ensuring continuous and stable operations necessary for demanding applications. 7. Automatic recovery from lens direction drift In high-traffic environments, such as busy intersections, PTZ cameras must continually pan and tilt to provide complete coverage, which can lead to gradual lens direction drift. Hikvision’s Smart Pan-Tilt Correction technology solves this problem by automatically keeping the camera lens aligned with the intended direction, even during prolonged operation or when affected by external forces. This technology detects and corrects any directional drift, ensuring precise monitoring and accurate privacy masking. As a result, users are guaranteed the exact coverage needed for dependable security. Hikvision’s PTZ cameras are crafted with one goal in mind: to address a diverse range of challenges with precision, reliability, and intelligence. Whether it’s through ensuring stable video in windy environments, tracking moving vehicles as they travel through high-security zones, or providing clear visibility even in dense fog, these tailored technologies guarantee the powerful performance of PTZ cameras that users demand. They work together to reduce maintenance needs and costs, enhance operational efficiency, and ensure that no critical moment is missed. Read more posts

Read More