An Analytical Study of Legal Implications of Cyber Attack on Indian Defence System: Issues, Challenges and Redressal Dissertation

  • Akhil Kumar Mishra and Dr. Juhi Saxena
  • Show Author Details
  • Akhil Kumar Mishra

    Student at Amity Law School, Lucknow, Uttar Pradesh, India

  • Dr. Juhi Saxena

    Assistant Professor at at Amity Law School, Lucknow, Uttar Pradesh, India

  • img Download Full Paper

Abstract

The Global Defence Chain System (GDCS) – the interconnected network of defence contractors, sub-suppliers, logistics providers, and technology vendors – has become a primary target for sophisticated cyber operations. While the digitisation of supply chains enhances efficiency, it introduces systemic vulnerabilities that adversaries exploit to exfiltrate sensitive defence data, disrupt weapons production, or degrade military readiness. This dissertation provides an analytical study of cyber attacks targeting the GDCS, with a focus on the redressal mechanisms available to victims and the challenges that impede effective remedies. Adopting a mixed-methods approach combining doctrinal legal analysis, comparative case studies, and policy evaluation, the research examines three landmark incidents: the SolarWinds supply chain compromise (2020), the NotPetya malware attack (2017), and the 2023 MOVEit Transfer breaches. These cases illustrate the evolving tactics of state-sponsored and criminal actors, the cascading effects of supply chain compromises, and the inadequacy of existing legal frameworks. The study finds that redressal is hampered by four principal challenges: (i) the difficulty of technical and legal attribution to a responsible actor; (ii) jurisdictional fragmentation that complicates cross-border law enforcement and civil litigation; (iii) contractual and insurance mechanisms that either exclude state-sponsored attacks or fail to flow down liability to lower-tier suppliers; and (iv) the absence of a harmonised international legal framework specifically addressing cyber operations against defence supply chains. The dissertation concludes by proposing a multi-layered redressal framework. It recommends regulatory expansion to cover all supply chain tiers, the establishment of specialised cyber courts, clarification of the “cyber war” exclusion in insurance policies, and the pursuit of international norms that recognise systematic supply chain attacks as a breach of responsible state behaviour. Ultimately, strengthening the resilience of the GDCS requires not only technical improvements but also a fundamental rethinking of legal accountability and global cooperation.

Keywords

  • cyber supply chain security
  • defence industrial base
  • redressal mechanisms
  • cyber attribution
  • critical infrastructure protection
  • international cyber law

Type

Research Paper

Information

International Journal of Law Management and Humanities, Volume 9, Issue 2, Page 3559 - 3584

DOI: https://doij.org/10.10000/IJLMH.1111642

Creative Commons

This is an Open Access article, distributed under the terms of the Creative Commons Attribution -NonCommercial 4.0 International (CC BY-NC 4.0) (https://creativecommons.org/licenses/by-nc/4.0/), which permits remixing, adapting, and building upon the work for non-commercial use, provided the original work is properly cited.

Copyright

Copyright © IJLMH 2021