Defence · Cyber

The Invisible Front: Cyber and Electronic Warfare in India's Defence

By Siddhant Kumar·4 June 2026·18 min read

Indian Army soldiers on a field exercise
Photograph: U.S. Army (Sgt. Michael J. MacLeod), Public Domain, via Wikimedia Commons.

The most consequential battles of the coming decades may leave no craters and make no sound. They will be fought in the invisible domains — across the world's computer networks and through the electromagnetic spectrum — where a single well-placed intrusion can blind a military, silence its communications, empty a bank, or plunge a city into darkness. These are the frontiers of cyber warfare and electronic warfare, and they have become as central to national security as tanks and fighter jets, and in some ways more dangerous, because they can be waged in peacetime, deniably, and against civilians as easily as soldiers.

India, one of the most connected large nations on earth and one of the most digitally ambitious, is acutely exposed on this invisible front — and increasingly serious about defending it. From a dedicated cyber defence agency to indigenous electronic-warfare systems to the hardening of the critical infrastructure on which modern life depends, the country is building its defences in domains that most citizens never see and rarely think about. This is the story of the invisible war, why it matters so much, and how India is preparing to fight it.

Two invisible domains

It helps to distinguish the two closely related but different arenas. Electronic warfare is the struggle for control of the electromagnetic spectrum — the invisible waves that carry radar, radio, satellite signals and every wireless link a modern military depends on. It means jamming an enemy's radars so his air defences go blind, spoofing his navigation so his weapons miss, intercepting his communications to learn his plans, and protecting your own signals against the same. Since virtually every modern weapon and sensor relies on the spectrum, whoever controls it controls the battlefield's nervous system.[1]

Cyber warfare is the struggle over computer networks and the data and systems they carry. It means penetrating an adversary's networks to steal information or sabotage his systems, disrupting the software that runs his military and his economy, and defending your own networks against the same. Unlike almost any previous form of conflict, cyber operations can reach across the world instantly, strike civilian and military targets alike, and be conducted below the threshold of open war — an intrusion that steals secrets or plants a dormant capability in an enemy's power grid can happen in peacetime, without a shot fired or an attacker's identity confirmed.[2]

The most dangerous weapon of the age fires no round and crosses no border. It arrives as a packet of data, and it can turn out the lights.

Why India is so exposed

India's vulnerability on this front is a direct consequence of its success. The country has undergone one of the fastest digital transformations in history — hundreds of millions brought online, a world-leading digital payments system, government services and identity delivered digitally, and an economy increasingly run on networks. This connectivity is a triumph, but every connection is also a potential point of attack, and a society that runs on digital systems is a society that can be attacked through them.[3]

The threats are real and constant. India's networks — governmental, military, financial and industrial — face a relentless stream of cyber intrusions, probing and attacks, some from criminals, some from hostile states, some from the murky space between. Critical infrastructure is a particular worry: the power grids, water systems, ports, telecommunications and financial networks whose disruption could cause enormous harm. Incidents affecting power supply and critical systems have underscored that these are not hypothetical dangers, and that a determined adversary could seek to hold a nation's essential services hostage through its networks alone.

Building the cyber shield

India's response has been to build, steadily, the institutions and capabilities of cyber defence. At the military level, it established a tri-service Defence Cyber Agency to coordinate the armed forces' cyber operations — both defending military networks and developing the capacity to operate offensively in cyberspace. This agency, widely seen as the embryo of a future full cyber command, reflects the recognition that cyber is now a domain of military operations as real as land, sea and air, requiring dedicated forces and doctrine.[4]

Beyond the military, India has built national institutions for cyber security — bodies to coordinate the response to cyber incidents, to protect critical information infrastructure, and to set the standards and policies that harden the nation's digital defences. It has developed national cyber security strategies, worked to secure the critical sectors most at risk, and sought to build the skilled workforce that effective cyber defence demands. The challenge is immense and never finished — cyber defence is a continuous contest against adversaries who constantly adapt — but the architecture of a serious national effort is in place and growing.

The electronic-warfare edge

On the electronic-warfare side, India has invested in developing indigenous capabilities to contest the spectrum. Its defence research establishment has developed electronic-warfare systems for all three services — equipment to detect, intercept, jam and deceive across the electromagnetic spectrum, protecting Indian forces while degrading an adversary's ability to sense, communicate and target. Systems to jam enemy radars and communications, to protect aircraft and ships from radar-guided threats, and to conduct electronic surveillance form an increasingly important part of the arsenal.[5]

The importance of this capability has been underscored by every recent conflict. In Ukraine, electronic warfare has been decisive in the drone war, with each side racing to jam the other's drones and communications; the side that wins the spectrum wins the fight. The same lesson applies across the board: an air force whose radars are jammed cannot see, a missile whose guidance is spoofed cannot hit, a unit whose radios are silenced cannot coordinate. India's investment in electronic warfare is an investment in the ability to keep its own systems working while denying the enemy the same — a contest as decisive as any fought with conventional weapons, and one that unfolds invisibly.

The convergence of the invisible domains

Increasingly, the cyber and electromagnetic domains are converging, and with them the wider world of information warfare. Modern militaries speak of "cyber-electromagnetic activities" as a unified domain, because the boundaries blur: a cyber attack might be delivered through a wireless link controlled by electronic warfare, and control of the spectrum enables both the sensing and the intrusion. Add to this the manipulation of information itself — disinformation, propaganda, the shaping of populations' beliefs through digital means — and the invisible front becomes a single, integrated contest over the flow and integrity of information in all its forms.[2]

This convergence is exactly why India's theatre-command reforms and its investments in these domains matter together. A future conflict will not have separate cyber, electronic and information battles running independently; it will have a single struggle for information dominance in which all three intertwine. The nation that can defend its own networks and spectrum while contesting the enemy's, and that can protect the integrity of its own information environment against manipulation, holds an advantage that reaches into every other domain of war. Building that integrated capability is among the most important and least visible tasks facing India's defence planners.

The defender's dilemma

The invisible front poses a peculiarly hard problem for a defender, and it is worth naming honestly. In cyber especially, the attacker enjoys structural advantages: he needs to find only one vulnerability while the defender must protect against all of them; he can operate deniably, hiding his identity behind layers of misdirection; and he can strike in peacetime, in the grey zone below open conflict, where the rules are unclear and retaliation is fraught. Attribution — proving who did it — is genuinely difficult, and without confident attribution, deterrence and response are hard to calibrate.[3]

This means cyber defence can never be a matter of building a wall and declaring victory. It requires constant vigilance, rapid detection and response, resilience so that systems can survive and recover from attacks, and the assumption that some intrusions will always get through. It requires securing not just military systems but the sprawling civilian critical infrastructure that a modern nation depends on and that is often owned and operated outside the government's direct control. And it requires the difficult diplomatic and strategic work of establishing norms, deterrence and the credible threat of consequences for those who attack — work that the whole world is still, imperfectly, attempting.

In the cyber war the attacker needs one open door; the defender must lock every one, forever, without knowing who is trying the handles.

Critical infrastructure: the softest target

Of all the vulnerabilities the cyber age creates, none is more worrying than the exposure of critical infrastructure — the power grids, water systems, transport networks, telecommunications, financial systems and industrial controls on which modern life utterly depends. These systems were, for the most part, designed and built in an era before pervasive digital connectivity, and many were never intended to withstand deliberate cyber attack. As they have been connected to networks for efficiency and control, they have become reachable by adversaries, and a successful attack on them could cause harm on a scale that dwarfs the theft of any secret.[3]

The nightmare scenarios are concrete and have partial precedents around the world: an attacker who penetrates a power grid's control systems and plunges a region into darkness; who disrupts the systems that manage water, transport or finance; who plants dormant capabilities in critical systems to be activated at a moment of crisis. Incidents affecting power supply and critical systems in various countries — including episodes touching India — have demonstrated that these dangers are not hypothetical, and that a determined and capable adversary could seek to hold a nation's essential services hostage through its networks, causing physical and economic harm without a single conventional weapon.

Defending critical infrastructure is peculiarly difficult because much of it lies outside direct government control, owned and operated by private companies and state utilities with varying levels of security and resources. Protecting it requires coordinated national effort — setting standards, sharing threat information, hardening the most vital systems, and building the resilience to survive and recover from attacks that inevitably get through. India has moved to protect its critical information infrastructure through dedicated national bodies and strategies, recognising that the security of the power grid or the financial system is now as much a matter of national defence as the security of the border. But the task is vast, the attack surface enormous, and the work never finished — critical-infrastructure defence is among the hardest and most consequential challenges of the entire invisible front.

The lessons of the drone war's spectrum battle

The war in Ukraine has served as a laboratory for many things, but nowhere more strikingly than in the domain of electronic warfare, and the lessons have been absorbed closely by India's planners. In that conflict, the contest over the electromagnetic spectrum became decisive to the drone war that came to define much of the fighting. Each side raced to jam the other's drones — severing the radio links that control them and the satellite-navigation signals that guide them — and to develop drones and tactics that could resist the jamming. Control of the spectrum, it turned out, could decide whether a drone reached its target or fell uselessly from the sky.[1]

The broader lesson is that electronic warfare, long a somewhat neglected and unglamorous discipline, has returned to the center of the battlefield with a vengeance. Every modern system that senses, communicates or navigates depends on the electromagnetic spectrum, and every such system is therefore vulnerable to an adversary who can contest the spectrum — jamming radars so air defenses go blind, spoofing navigation so weapons miss, silencing communications so units cannot coordinate. The side that can protect its own use of the spectrum while denying the enemy's holds a decisive advantage that reaches into every other domain of the fight.

India's investment in indigenous electronic-warfare systems for all three services — equipment to detect, intercept, jam and deceive across the spectrum — is a direct response to these lessons. In a future conflict, the ability to keep Indian radars, communications and navigation working while degrading an adversary's would be as decisive as any conventional capability, and the contest would unfold invisibly, in the electromagnetic waves that no one can see but everyone depends on. The spectrum battle is not a sideshow to modern war; increasingly, it is one of the arenas where modern war is won or lost, and India has moved to be a serious contestant in it.

The grey zone and the problem of attribution

Perhaps the most vexing feature of cyber conflict is that it unfolds largely in the grey zone — the ambiguous space below the threshold of open, declared war, where hostile acts occur but their authorship is deniable and the appropriate response unclear. A nation can suffer a serious cyber intrusion — the theft of vital secrets, the penetration of critical systems, the planting of dormant capabilities — without any clear act of war having been declared, and often without being able to prove with confidence who was responsible. This ambiguity is not incidental; it is a deliberate feature that attackers exploit.[2]

The problem of attribution — determining who actually carried out a cyber attack — is genuinely hard, because sophisticated attackers hide behind layers of misdirection, routing their operations through compromised systems in other countries, mimicking the tools and techniques of others, and exploiting the fundamental anonymity of the networked world. Without confident attribution, the whole apparatus of deterrence and response falters: it is difficult to retaliate against, sanction, or deter an attacker you cannot confidently identify, and difficult to build international norms and consequences when responsibility can always be denied. This attribution problem is one of the deepest challenges of cyber security and one of the reasons cyber conflict has proven so hard to govern.

The grey-zone character of cyber conflict means that India, like every connected nation, faces a constant, low-intensity contest that never quite rises to the level of war but never ceases either — a permanent background of probing, intrusion and attack, conducted deniably by a mix of criminals, hostile states and the murky actors between them. Managing this reality requires not a single decisive victory but continuous vigilance, resilience, and the slow, difficult work of building the capacity to detect, attribute where possible, respond proportionately, and deter through the credible threat of consequences. It is a form of conflict without clear beginning or end, fought in the shadows, and it defines the strategic reality of the invisible front.

The information war for the mind

The invisible front extends beyond networks and the spectrum into a third and increasingly important arena: the contest over information itself, and over the beliefs and perceptions of populations. Modern conflict is fought not only with weapons and code but with narratives — with propaganda, disinformation, and the deliberate shaping of what people believe to be true. In an age when information flows instantly and globally through digital networks, and when populations form their views of events through those networks, the ability to influence the information environment has become a form of power in its own right.[2]

The danger is acute for an open, diverse and highly connected democracy like India. Adversaries can seek to sow division, spread falsehood, inflame tensions, and manipulate perceptions through coordinated campaigns of disinformation, exploiting the very openness and connectivity that are among a democracy's strengths. False narratives can spread faster than the truth, deepen existing fault lines in a diverse society, and undermine the trust and cohesion on which a nation depends. Defending against this form of attack is peculiarly difficult, because it targets not systems but minds, and because the remedies — countering falsehood, building resilience against manipulation — must be pursued without compromising the freedoms that make an open society worth defending.

This information dimension converges with the cyber and electronic domains into a single, integrated struggle over the flow and integrity of information in all its forms. A modern adversary might combine a cyber intrusion, an electronic attack, and a disinformation campaign into a coordinated assault on a nation's information environment — stealing or corrupting data, disrupting communications, and manipulating perceptions, all at once. Defending against this integrated threat requires an integrated response, weaving together cyber security, electronic warfare, and the harder, more delicate work of protecting the information environment against manipulation — a challenge that spans technology, policy and the fundamental values of an open society.

The contest for talent

Underlying every dimension of the invisible front is a resource more fundamental than any technology: skilled people. Cyber and electronic warfare are, above all, contests of human expertise — of the engineers, analysts, coders and specialists who build the defences, hunt the intrusions, contest the spectrum, and devise the countermeasures. A nation's capability on the invisible front is ultimately bounded by the depth and quality of its pool of such talent, and the competition for that talent is one of the quiet but decisive contests of the age.[3]

Here India possesses a genuine and considerable advantage, for it is home to one of the largest and most capable pools of information-technology and software talent in the world, a thriving technology sector, and a young population deeply fluent in the digital world. If any domain of security competition plays to India's natural strengths, it is one built on software, mathematics and digital skill rather than on heavy industry. The challenge is to channel that formidable civilian talent into the service of national security — to build the pathways, the institutions and the incentives that bring skilled people into the difficult, often unglamorous work of defending the nation's networks and contesting the invisible domains.

This is easier said than done. The best cyber talent is in enormous demand in the private sector, which can often offer rewards and freedoms that government service struggles to match; building a national cyber-security workforce means competing for people who have many attractive options. It requires investment in education and training, the cultivation of expertise over years, and the creation of careers and institutions that can attract and retain the skilled. India has recognised the imperative and worked to build its cyber workforce, but the contest for talent is continuous and the demand relentless, and a nation's long-term security on the invisible front will depend heavily on how well it develops, attracts and keeps the skilled people the domain requires. In the end, the invisible war is won or lost not by machines but by the minds that wield them.

Resilience: the real measure of security

As cyber defenders have gained hard experience, a crucial shift in thinking has taken hold, and it is one India's approach increasingly reflects: the recognition that perfect prevention is impossible, and that the true measure of cyber security is not whether attacks can be kept out entirely — they cannot — but whether systems can withstand, survive and recover from the attacks that inevitably get through. This is the principle of resilience, and it represents a mature and realistic understanding of what security in the cyber age actually means.[3]

The older mental model of cyber defence imagined building a wall — a perimeter that would keep attackers out. But experience has taught that determined and capable attackers will eventually find a way through any wall, that the defender must protect against every vulnerability while the attacker needs only one, and that the assumption of an impenetrable defence is dangerous precisely because it is false. The resilient approach assumes instead that intrusions will occur, and focuses on limiting the damage they can do, detecting them quickly, containing and expelling them, and recovering essential functions rapidly — ensuring that a successful attack is survivable rather than catastrophic.

Resilience is especially vital for critical infrastructure and essential services, where the goal must be to ensure that even a successful attack cannot cause lasting or catastrophic harm — that the power grid, the financial system, the essential networks can absorb an attack and keep functioning or recover quickly. Building this resilience requires redundancy, the ability to operate through disruption, rapid detection and response, well-rehearsed recovery plans, and systems designed from the outset to fail gracefully rather than catastrophically. It is less glamorous than the image of hackers duelling in real time, but it is the real foundation of security in a domain where perfect prevention is a fantasy. India's cyber-security effort, in emphasising the protection and resilience of critical systems alongside the prevention of attacks, reflects this mature understanding — that in the invisible war, the nation that endures is not the one that is never attacked, which is impossible, but the one that can take a blow and keep standing.

The offensive question and deterrence in the shadows

Discussion of cyber security tends to focus on defence — on protecting one's own networks and systems — but a complete national cyber capability includes the offensive dimension as well, and this raises difficult questions that India, like every serious cyber power, must confront. The Defence Cyber Agency and comparable bodies are understood to be responsible not only for defending military networks but for developing the capacity to operate offensively in cyberspace — to penetrate an adversary's systems, gather intelligence, and, if necessary, disrupt or degrade them. The offensive and defensive dimensions are deeply intertwined, since understanding how to attack is essential to understanding how to defend, and vice versa.[4]

The offensive capability raises the question of deterrence in cyberspace, which is one of the hardest and least resolved problems in the field. Deterrence rests on the credible threat of consequences — the ability to make an adversary believe that an attack would bring a response painful enough to outweigh any gain. But cyberspace complicates every element of this logic. The attribution problem makes it hard to identify whom to deter or retaliate against. The deniability of cyber operations blurs the line between war and peace, making it unclear when and how to respond. And the difficulty of demonstrating capability without using it — since revealing a cyber weapon often renders it useless — makes it hard to establish the credible threat on which deterrence depends.

These difficulties mean that deterrence in cyberspace cannot simply copy the logic of nuclear or conventional deterrence but must be built through different means — through resilience that denies an attacker the benefits he seeks, through the demonstrated capacity and will to respond, through the slow construction of norms and expectations about acceptable behaviour, and through the credible if unspoken threat of consequences that reach beyond cyberspace itself. India, in building both its defensive and offensive cyber capabilities, is developing the tools that a posture of cyber deterrence requires, even as the theory of how deterrence works in this domain remains contested and incomplete. Navigating the offensive dimension responsibly — building the capability that deterrence and defence require while managing the escalatory risks that offensive cyber operations carry — is among the delicate challenges of the invisible front, and one that the whole world is still learning to meet.

The front that never sleeps

The invisible front differs from every traditional theatre of war in one crucial respect: it is always active. There is no peacetime pause in cyberspace, no ceasefire in the contest over the spectrum and the networks. India's systems are probed and attacked continuously, its adversaries' capabilities grow constantly, and its defences must therefore be permanently manned and endlessly updated. This is a war without declared beginning or end, fought every day by people most citizens will never hear of, protecting systems most citizens take for granted.

India has recognised the stakes and is building — the cyber agency, the national institutions, the indigenous electronic-warfare systems, the hardening of critical infrastructure, the workforce and the doctrine. The work is far from complete, and in a domain that evolves as fast as this one, it never will be. But the direction is clear and the seriousness is real. In an age when a nation can be blinded, silenced or darkened without a single soldier crossing its border, the invisible front is not a sideshow to national defence. It is increasingly the main event — and India, connected and ambitious and exposed, cannot afford to lose it.

Sources & further reading

  1. "Electronic warfare," Wikipedia.
  2. "Cyberwarfare," Wikipedia.
  3. "Cyberwarfare and India," Wikipedia.
  4. "Defence Cyber Agency," Wikipedia.
  5. Ministry of Defence, Government of India — mod.gov.in.

Siddhant Kumar

Poet and author of Guardians in the Gale, a collection of 21 poems on the armed forces, sacrifice, and remembrance.