+91 98186 32779
🎖️ 500+ Officers SelectedSince 2001Retired SSB Officer FacultyOwn 5-Acre GTO GroundSee Results →
NDA Current Affairs · Science & Security · 16 Aug 2026

CYBER KUSHTI 2026: A Hackathon That Scores Judgment, Not Detection Speed — An NDA Science & Security Explainer

On 16 August 2026, the National Institute of Electronics and Information Technology (NIELIT), under the Ministry of Electronics and Information Technology (MeitY), announced the launch of CYBER KUSHTI 2026 — a national cybersecurity and Artificial Intelligence hackathon launched on 15 August, designed to test and recognise human judgment in cybersecurity assessment.

It was launched by Prof. (Dr.) M. M. Tripathi, Director General of NIELIT and Vice Chancellor of NIELIT Deemed to be University, as the official parallel technical track of the 3rd National Conference on Cyber Security, Digital Forensics and Intelligence (NCCDFI 2026).

Most competitions of this kind are worth a paragraph. This one is worth an article, because its scoring rule inverts the usual one — and the reasoning behind that inversion is a genuinely good piece of science-and-technology material for the General Ability paper.

The format, and why it is unusual

Conventional cybersecurity competitions — Capture The Flag (CTF) events and vulnerability-discovery contests — reward finding things. Speed and volume win.

CYBER KUSHTI does something different. Every team receives an identical and deliberately imperfect Security Assessment Package, containing:

  • AI-generated findings
  • static analysis outputs
  • dependency and secrets scans
  • architecture documentation
  • source code
  • application logs

That package is rigged in two directions. It contains false findings and duplicated findings alongside genuine ones — and some real vulnerabilities are deliberately omitted.

Teams must produce a corrected and prioritised security assessment, and defend the decisions they made. Crucially, the competition rewards participants not only for identifying genuine issues but also for correctly rejecting false ones.

In the Director General's framing: for a generation the scarce skill was finding the problem; today machines generate findings faster than any team can read them, and what they cannot yet do reliably is say which findings are real, which matter most, and what must be fixed first.

There is a second design choice worth noticing. Because the same tool-generated material goes to every team simultaneously, the format deliberately neutralises the advantage of expensive security tooling — and participants may use any AI tools they choose. The stated intent is that a student from a college anywhere in the country competes on equal terms with a corporate team.

The concept underneath: false positives and triage

This is the part to actually learn, because it generalises far beyond a hackathon.

Any detection system produces four outcomes:

Threat is real Threat is not real
System flags it True positive False positive
System stays silent False negative True negative

A false positive is a false alarm. A false negative is a miss.

Tuning a detector is a trade-off between the two: make it more sensitive and you catch more real threats but raise more false alarms; make it stricter and you cut the noise but miss more. You cannot minimise both at once with the same detector — which is why "just make the scanner better" is not an answer.

The operational consequence has a name: alert fatigue. When a system generates thousands of alerts and most are false, analysts begin to discount all of them, and the real alert is dismissed alongside the noise. Every large breach post-mortem of the last decade contains some version of "the alert fired and nobody acted on it."

Generative AI has made this sharply worse in one specific way: it has collapsed the cost of producing plausible-looking findings while doing nothing for the cost of verifying them. The bottleneck has moved from generation to verification. A competition that scores correct rejection is training precisely the skill that has become scarce — and the same shift is visible in the scientific method and reasoning more broadly, where the ability to discard a wrong hypothesis is the harder half of the work.

That is also the honest limitation worth stating: this format tests assessment and triage, not the ability to discover a novel vulnerability from scratch. Both skills are needed. This competition is a corrective to an imbalance, not a replacement for offensive security training.

The rounds

Round Name Date Mode Outcome
1 The Akhada 15 September 2026 Online 50 teams advance
2 The Dangal 24 September 2026 Online 10 finalists selected
Final The Kesari 9 October 2026 In person Winner

The final is held at the Dr. Ambedkar International Centre, New Delhi, where the ten finalist teams work under supervision before presenting and defending their assessments.

Registration opened on 15 August 2026 and remains open until 10 September 2026. Participation is free, open to students and independent researchers, in teams of three.

The naming is drawn from traditional wrestling — akhada the training ground, dangal the bout, kesari the champion — which is a small thing, but the kind of detail that makes a fact stick.

Who is running it

  • NIELIT — the National Institute of Electronics and Information Technology, under MeitY, which conducts electronics and IT skilling and certification nationally, including the well-known O/A/B/C level courses.
  • ISAC Foundation — the Information Sharing and Analysis Center, under the National Security Database (NSD), as collaborating body.
  • CERT-In — as Knowledge Partner.

India's cyber security architecture

This is the standing syllabus material that the news item hangs on, and it is asked far more often than any hackathon will be.

CERT-In — the Indian Computer Emergency Response Team. The national nodal agency for cyber security incident response, operating under Section 70B of the Information Technology Act, 2000, under MeitY. Its remit covers the entire civilian internet ecosystem. Under directions issued in 2022, entities must report specified cyber incidents to CERT-In within six hours of noticing them, and retain ICT logs for 180 days within India.

NCIIPC — the National Critical Information Infrastructure Protection Centre. Designated under Section 70A, inserted by the IT (Amendment) Act, 2008, and notified in January 2014. Its remit is narrower and deeper: Critical Information Infrastructure — systems whose incapacitation would have a debilitating impact on national security, economy, public health or safety. It sits within the intelligence community, under the NTRO.

The clean way to remember the pair: CERT-In is broad and shallow; NCIIPC is narrow and deep. Section 70 itself deals with protected systems.

I4C — the Indian Cyber Crime Coordination Centre, under the Ministry of Home Affairs, which runs the National Cyber Crime Reporting Portal and the 1930 helpline. Note the division of labour: CERT-In handles incidents, I4C handles crime.

The Defence Cyber Agency, a tri-service agency raised in 2019, handles the military dimension.

Also worth carrying: the National Cyber Security Policy, 2013; the Cyber Swachhta Kendra for botnet cleaning; and the Digital Personal Data Protection Act, 2023 on the data-protection side.

🔑 Revision block

The launch. CYBER KUSHTI 2026, launched 15 August 2026 by NIELIT (under MeitY), announced by PIB on 16 August. Launched by Prof. (Dr.) M. M. Tripathi, DG NIELIT. It is the official parallel technical track of NCCDFI 2026 — the 3rd National Conference on Cyber Security, Digital Forensics and Intelligence.

Partners. ISAC Foundation, under the National Security Database (NSD) — collaborator. CERT-InKnowledge Partner.

Entry. Registration 15 August – 10 September 2026 · free · open to students and independent researchers · teams of three.

The format — what makes it novel. Every team receives an identical, deliberately imperfect Security Assessment Package: AI-generated findings, static analysis outputs, dependency and secrets scans, architecture documentation, source code, application logs. It contains false and duplicated findings, and some real vulnerabilities are deliberately omitted. Teams submit a corrected, prioritised assessment and defend it. Scoring rewards rejecting false findings as well as finding real ones. Identical material for all teams neutralises the advantage of expensive tooling; any AI tools are permitted.

The three rounds. The Akhada — online, 15 September 2026, 50 teams advance → The Dangal — online, 24 September 2026, 10 finalistsThe Kesari — in person, 9 October 2026, Dr. Ambedkar International Centre, New Delhi.

The concept to actually learn. True/false positive and negative — a false positive is a false alarm, a false negative is a miss. Sensitivity trades one against the other; both cannot be minimised at once. The operational failure mode is alert fatigue. Generative AI has collapsed the cost of producing plausible findings without reducing the cost of verifying them — so the bottleneck moved from generation to verification.

The honest limitation. This format tests assessment and triage, not discovery of a novel vulnerability. It corrects an imbalance; it does not replace offensive security skill.

CERT-In vs NCIIPC — the pair examiners test. CERT-InSection 70B, IT Act 2000, under MeitY, national nodal agency for incident response across the whole civilian internet; 2022 directions require reporting within 6 hours and 180-day log retention in India. NCIIPCSection 70A, inserted by the IT (Amendment) Act, 2008, notified January 2014, under NTRO, covering Critical Information Infrastructure only. Memory hook: CERT-In broad and shallow, NCIIPC narrow and deep. Section 70 = protected systems.

The rest of the architecture. I4C, under MHANational Cyber Crime Reporting Portal and the 1930 helpline (CERT-In = incidents, I4C = crime) · Defence Cyber Agency, tri-service, raised 2019 · National Cyber Security Policy, 2013 · Cyber Swachhta Kendra · DPDP Act, 2023.

🎯 Practice MCQs

Q1. CYBER KUSHTI 2026 was launched by: (a) NIELIT (b) C-DAC (c) CERT-In (d) NCIIPC → (a) — under MeitY.

Q2. CERT-In's role in CYBER KUSHTI 2026 is as: (a) Knowledge Partner (b) organiser (c) sponsor (d) evaluator only → (a).

Q3. Unlike a conventional CTF, CYBER KUSHTI also rewards teams for: (a) correctly rejecting false findings (b) fastest detection (c) most vulnerabilities found (d) best tooling → (a).

Q4. The first round of the hackathon is named: (a) The Akhada (b) The Dangal (c) The Kesari (d) The Maidan → (a) — Dangal is round 2, Kesari the final.

Q5. The final round will be held at: (a) Dr. Ambedkar International Centre, New Delhi (b) Bharat Mandapam (c) Vigyan Bhawan (d) IIT Delhi → (a).

Q6. A false positive in a detection system means the system: (a) flags a threat that is not real (b) misses a real threat (c) detects a real threat (d) stays silent correctly → (a).

Q7. A false negative means the system: (a) misses a real threat (b) raises a false alarm (c) detects correctly (d) duplicates a finding → (a).

Q8. The phenomenon where analysts begin ignoring alerts because most are false is called: (a) alert fatigue (b) alert cascade (c) signal drift (d) false convergence → (a).

Q9. CERT-In functions under which section of the IT Act, 2000? (a) Section 70B (b) Section 70A (c) Section 66A (d) Section 43A → (a).

Q10. NCIIPC is designated under: (a) Section 70A (b) Section 70B (c) Section 69 (d) Section 79 → (a) — inserted by the IT (Amendment) Act, 2008.

Q11. NCIIPC functions under the: (a) NTRO (b) MeitY (c) MHA (d) Ministry of Defence → (a) — CERT-In is under MeitY.

Q12. Under CERT-In's 2022 directions, specified cyber incidents must be reported within: (a) 6 hours (b) 24 hours (c) 72 hours (d) 7 days → (a) — with 180-day log retention.

Q13. The National Cyber Crime Reporting Portal and helpline 1930 are run by: (a) I4C, under MHA (b) CERT-In (c) NCIIPC (d) NIELIT → (a).

Q14. The Defence Cyber Agency was raised in: (a) 2019 (b) 2014 (c) 2013 (d) 2022 → (a) — it is a tri-service agency.

Q15. "CTF" in cybersecurity competitions stands for: (a) Capture The Flag (b) Cyber Threat Framework (c) Critical Threat Filter (d) Cyber Task Force → (a).

📋 How this gets asked (PYQ pattern)

Cyber security is a growing NDA area, asked in four ways. The agency-and-section item — CERT-In under Section 70B and NCIIPC under Section 70A, and which ministry each answers to; this pairing is the single most reliable question in the topic. The ministry-matching item — CERT-In and NIELIT under MeitY, I4C under MHA, NCIIPC under NTRO. The concept item — false positives and negatives, which also appears in general science and reasoning contexts and is worth learning as a four-cell table rather than two definitions. The initiative item — the current scheme, portal, helpline or competition, of which this hackathon is one. The fresh 2026 hook is CYBER KUSHTI 2026, its three named rounds, and the design principle of scoring correct rejection. We reference the pattern, not any exact past question.

Preparing for NDA or the SSB? The distinction between finding a problem and judging which problems matter is close to the definition of officer-like thinking — which is why this competition's design is worth being able to describe in an interview. Follow our daily NDA current affairs and prepare with our faculty in the upcoming Cavalier courses in Delhi.


✍️ Written by Col Vijyanat Thakur — Science, technology & security faculty at The Cavalier. Reviewed by the Cavalier Faculty Desk. The Cavalier, founded by ex-Army officers, has trained NDA/CDS/SSB aspirants since 2001 (Facebook · YouTube).

Source: PIB / Ministry of Electronics & IT, 16 August 2026. Facts cross-verified with independent sources.