Strategic Conversations
"Centralised Intent, Decentralised Execution"
The Guest
Maj. Gen. P. K. Mallick, VSM (Retd) is an electronics and telecommunication engineer from IIT Kharagpur and a veteran of the Corps of Signals with extensive operational experience in Jammu & Kashmir and the Northeast. A former Senior Directing Staff at the National Defence College, he has served as a consultant to the NTRO, held the COAS Chair of Excellence at CLAWS, and authored Mind Wars: The New Battlefield of Information Warfare. He currently curates leading Indian strategic intelligence and research portals.
An Interview with Maj. Gen. P. K. Mallick, VSM on AI, Cyber Resilience, and the Reality of Modern Combat
Seema Sanghosh English: You headed DIARA before it was reorganised into the Defence Cyber Agency. What structural gaps still remain in Bharat's cyber defence architecture, and are our military networks genuinely hardened against the kind of persistent intrusions China and Pakistan have demonstrated?
Maj. Gen. P. K. Mallick: India has a well-developed cyber defence architecture. The National Critical Information Infrastructure Protection Centre (NCIIPC) is responsible for the critical information infrastructures of Power & Energy, Banking, Telecom, Financial Services & Insurance, Transport, Government, Strategic & Public Enterprises and Health.Indian Computer Emergency Response Team (CERT-In) is responsible for the balance of the sectors.
Detailed policies and Standard Operating Procedures (SOP) have been issued on Risk Management, National Crisis Management, Incident Response & Reporting and how to mitigate or even avoid cyber attacks.
ITU ranked India among the top 10 cybersecure countries a few years ago. Our critical information infrastructure demonstrated its resilience during the recent Op Sindoor.
However, no system is perfect. There is always scope for improvement. The September 2019 cyber exploitation by the North Korean threat actor Lazarus atIndia's largest civil nuclear facility, the Kudankulam Nuclear Power Plant in Tamil Nadu, was certainly a wake-up call. There are other examples also. Critical information infrastructures such as defence, intelligence agencies, the Nuclear Power Corporation of India (NPCIL) under the AEC (Atomic Energy Commission), etc., which are self-audited, must be audited by a responsible agency like NCIIPC.
China has infiltrated U.S. critical infrastructure using the Volt Typhoon and Salt Typhoon. U.S. is worried as it is very difficult to delete Volt Typhoon from its systems. If China can do this to the U.S. surely they can do it to us as well. However, our cybersecurity agencies have not provided any information on any intrusion into our systems.
Private sector big players like, Infosys, TCS, HCL and others can be incorporated into our cyber defence architecture.
We may consider the Space, Election Commission, Social Media, and cloud services to be Part of CII and audited by NCIIPC.
The National Cyber Security Strategy should be published as soon as possible.
The private sector must be put under stringent cybersecurity controls. Telecom service providers routinely leak intelligence due to insufficient cybersecurity measures. NCIIPC and CERT-In should be given the power to take punitive action if the private sector fails to follow the procedures for cyber incident reporting.
AI-enabled Mythos, developed by Claude, has completely revolutionised cybersecurity by autonomously discovering and exploiting previously unknown vulnerabilities, including decades-old bugs, through multi-step operations requiring no human intervention. This has accelerated the rate at which existing weaknesses can be weaponised, posing severe risks to national security and digital infrastructure. Our Government and organisations must now overhaul their strategies to build resilience against this major AI threat.
Our military networks are very strongly hardened against cyberattacks. Strict SOPs and cyber defence processes are in place. They are constantly updated and audited for any breaches in the system. There have been no reports of breaches in military networks.
Interested people may read my paper on Protection of Critical Information Infrastructure, published by Vivekananda International Foundation, available at: https://www.vifindia.org/sites/default/files/Protection-of-Critical-Information-Infrastructure.pdf
Seema Sanghosh English: No-contact warfare effectively neutralises conventional military superiority. In your assessment, is Bharat's current force structure and doctrine adequately recalibrated for a conflict where the first and most decisive strikes will come through cyber, electronic, and space domains rather than across the Line of Control?
Maj. Gen. P. K. Mallick: Non-contact warfare, non-kinetic warfare, etc., are always part of conventional warfare. Two conflicts are going on. For four and a half years, Russia has beenfighting a war with Ukraine, and Israel has been waging war in Gaza and now in Lebanon for close to three years. All this cyber, electronic, information, space, drone, and missile warfare is going on as part of warfare. These two conflicts show that if you want to win a war, you have to fight on land. Others play a very important part,but on their own cannot win the war.
Emerging technologies are indeed levelling the playing field. Low-cost drones and missiles can take out far more expensive assets. The cost-benefit has shifted decisively in favour of drones. We need to produce more low-cost drones and interceptors and better adapt to the necessities of AI competition. We must developmore cost-effective ways to defend against the vast numbers of missiles and cheap drones that adversaries can launch.
Drones have dramatically raised the cost of movement in the open. It has forced infantry soldiers to dig deeper, disperse further and move only at night or under electronic concealment.
Taking full advantage of drone swarms will require radically rethinking military Command and Control (C2), organisational structures and how military commanders direct their forces on the battlefield. Military operators will command entire swarms of hundreds or thousands of drones, with the drones themselves autonomously coordinating their behaviour.
We have seen that Large Language Models (LLMs) are integrated into Palantir's Maven Smart System, which pools intelligence from multiple sources into a single interface for analysts to assess the battle space in the recent Iran conflict.
We need more cost-effective ways to defend against the vast numbers of missiles and cheap drones that adversaries can launch. We need time to innovate, experiment with AI and adapt our own organisations and doctrine to make the most of the latest technology.
However, large, conventional armed forces are not good at building anything cheaply, responding quickly or scaling up rapidly. They have their own bureaucratic system and procedures. It would take time.
Somehow, the importance of land forces is being downplayed. After every drone strike, after every armoured column destroyed from above, someone still has to walk across that field, occupy the tree line, clear the basement and stand in the rubble and say: This is ours now. The drone cannot do that. It never will. That is why the Israel Defence Forces (IDF), the Ukrainian army, and the Soviet army – all are crying out for more boots on the ground.
Christopher T. LaNeve, the present U.S. Army Chief, stated: "Every war is different. Geography is different. The enemy is different. The political objectives are different. We have to be careful about taking lessons from one conflict and assuming they apply everywhere." We should not learn the wrong lessons.
The Indian Armed Forces have taken cognisance of emerging technologies and theiruse in today's warfare through Jointness, Atmanirbharta, and Innovation (JAI). A large number of initiatives have been undertaken to acquire technology, develop indigenous technology, accelerate acquisition processes, develop doctrines and strategies, implement organisational changes, develop human resources, etc. Combining these with legacy systems and equipment is a big challenge. In due course, these difficult tasks will be achieved.
Seema Sanghosh English: Hostile information warfare targeting Bharat is now running continuously in peacetime, not just during conflict. Where exactly is the institutional gap: is it doctrine, coordination between agencies, or the absence of an offensive information warfare capability?
Maj. Gen. P. K. Mallick: Information Warfare comprises three components: Cyber Warfare, Electronic Warfare and Psychological Warfare. The question relates to Psychological Warfare. We are doing badly in Psychological Warfare.
For Psychological Warfare, the various stakeholders involved are the Ministry of Home Affairs and intelligence agencies, the Ministry of Defence, the Ministry of External Affairs, the Ministry of Information and Broadcasting, the Ministry of Electronics and Information Technology, the Ministry of Communications, the Ministry of Education, the Ministry of Law and Justice, among others. Close coordination between these Ministries will be necessary to conduct Psychological Operations against an adversary. However, as of now, there is no central agency to coordinate and direct such a task.
To conduct Psychological Operations at the strategic level, the Central Government must take a whole-of-government and whole-of-society approach. The strategy must be outlined at the highest level. In Indian conditions, the lead agency cannot be the MoD. It should be a specific organisation under the National Security Advisor working within the National Security Council Secretariat. The National Security Council Secretariat is the appropriate agency to be made responsible for Psychological Operations, given India's notoriously stove-piped bureaucracy. The organisation should have experts in psychology, sociology, media, area studies, language, law, the armed forces, political science, foreign affairs, country studies, communication, and social media.
Interested readers may like to read my book, Mind Wars: The New Battlefield of Information Warfare, available at: https://www.amazon.in/Mind-Wars-Battlefield-Information-Warfare/dp/B0G396XRB5
Seema Sanghosh English: Deepfakes, AI-generated propaganda, and algorithmic manipulation are being deployed against Bharat's internal cohesion. What specific legal and operational frameworks must be put in place now, before the next crisis, to counter this threat at speed?
Maj. Gen. P. K. Mallick: Artificial Intelligence (AI) tools can analyse vast datasets to predict behavioural patterns, generate hyper-realistic content and automate influence campaigns at scale. Large language Models (LLMs) capable of generating human-like text at scale could automate the creation of persuasive content across multiple languages and cultural contexts. Deepfakes and synthetic media will challenge the ability to discern truth from falsehood. The rapid pace of AI development necessitates an adaptive and forward-looking response, one that anticipates future developments rather than merely reacting to current threats. The stakes of this challenge are high, as failure to effectively counter AI-enabled radicalisation could lead to significant increases in extremist violence and social instability. Success will require extraordinary cooperation between technology companies, government agencies, academic institutions and civil society organisations. The general public must be sensitised against forwarding WhatsApp-type messages without verification.
However, these threats should not be over hyped. Today, technology is readily available to identify Deepfakes. The attention span for these messages is very short, at most two days. We have mechanisms like PIB to debunk these messages. We have adequate laws against this AI-generated propaganda. But against adversary nation states, these laws are not applicable. We should believe in the national motto of India, Satyameva Jayate, "Truth alone triumphs".
Seema Sanghosh English: Bharat has historically maintained strategic ambiguity on offensive cyber operations. Given the provocations of recent years, is that ambiguity still an asset, or has it become a liability that emboldens adversaries?
Maj. Gen. P. K. Mallick: An offensive cyber operation is an extremely sensitive issue. Very little information is available in open domain. Those in the know would never divulge information. Rightly so and should remain as such.
There are designated agencies that carry out this task. Standard operating procedures have been laid down for this operation. Permission to conduct an offensive cyber operation against the adversary's critical infrastructure is granted bythe highest government decision-making body.
Seema Sanghosh English: July 2026

No comments:
Post a Comment