News · Defence & Security
State use of intrusive surveillance tools must be lawful, says Keralam Home Minister Chennithala
Kerala Home Minister Ramesh Chennithala said surveillance technology must not be used simply because it is available. State agencies should deploy intrusive tools only for lawful purposes, when they are necessary, and when their impact is proportionate to the threat. Institutional oversight should monitor those decisions. His comments came while inaugurating c0c0n-2026, Kerala Police’s annual cybersecurity conference in Kochi. He referred to continuing discussions about Pegasus, spyware associated with the Israeli digital intelligence firm NSO Group, and its reported operation in India. The example showed why powerful tools need safeguards. The principle he outlined places legal and institutional checks around surveillance. It seeks to prevent unchecked access to people’s devices and communications while allowing legitimate security work. Chennithala also announced plans to revitalise Cyberdome, Kerala Police’s public-private cybersecurity initiative, adding an institutional response to the wider technological challenge.
Based on reporting by The Hindu
What did Kerala Home Minister Ramesh Chennithala say about the State’s use of intrusive surveillance tools?
Kerala Home Minister Ramesh Chennithala said surveillance technology must not be used simply because it is available. State agencies should deploy intrusive tools only for lawful purposes, when they are necessary, and when their impact is proportionate to the threat. Institutional oversight should monitor those decisions.
His comments came while inaugurating c0c0n-2026, Kerala Police’s annual cybersecurity conference in Kochi. He referred to continuing discussions about Pegasus, spyware associated with the Israeli digital intelligence firm NSO Group, and its reported operation in India. The example showed why powerful tools need safeguards.
The principle he outlined places legal and institutional checks around surveillance. It seeks to prevent unchecked access to people’s devices and communications while allowing legitimate security work. Chennithala also announced plans to revitalise Cyberdome, Kerala Police’s public-private cybersecurity initiative, adding an institutional response to the wider technological challenge.
What is an intrusive digital surveillance tool, and how can spyware such as Pegasus access information on a device?
An intrusive digital surveillance tool is software or technology that gains deep access to a person’s device or communications. Unlike ordinary security tools, it can monitor activity, collect data, or activate functions without the user’s clear awareness. That makes it powerful for investigations but dangerous for privacy when used without safeguards.
Spyware such as Pegasus can reach a device through an exploited software weakness, a malicious message, or deceptive interaction. Once installed, spyware may use granted or stolen permissions to read messages and files, track location, or access microphones and cameras. The article identifies Pegasus as spyware but does not detail its technical operation.
Because this access can be hidden, users may not know what information has been collected. Chennithala cited discussions about Pegasus operating in India as a reason for concern. His proposed safeguards require the State to show that surveillance is lawful, necessary, proportionate, and subject to institutional oversight.
What do the principles of legality, necessity, proportionality, and institutional oversight require before the State uses surveillance technology?
Legality means surveillance must have a valid legal basis and follow applicable rules. Necessity means authorities should use it only when it is genuinely needed for a legitimate security purpose. These principles prevent surveillance from becoming routine, arbitrary, or driven by convenience.
Proportionality requires matching the level of intrusion to the seriousness of the threat. Authorities should avoid collecting more information, monitoring more people, or keeping data longer than required. Institutional oversight adds review by authorised bodies, creating accountability before, during, or after surveillance. The article does not specify which institutions should perform that role.
Together, these principles create safeguards around intrusive technology. They aim to protect privacy while allowing lawful security operations when justified. Chennithala said Kerala must ensure that the State’s use of such tools meets all four conditions, reflecting concern over spyware discussions involving Pegasus in India.
Why can the misuse of surveillance technology threaten both individual privacy and national security?
Surveillance technology can collect deeply personal information, including communications, activity, and device data. If authorities or operators misuse that access, individuals may lose control over private information. Such misuse can enable intimidation, unauthorised monitoring, or disclosure of sensitive details. The article therefore links intrusive tools directly with threats to individual privacy.
The national-security risk is broader. Devices and accounts connected to public institutions, companies, or officials may contain confidential information. A poorly controlled or compromised surveillance capability could expose that information, reveal security methods, or create opportunities for further attacks. The article does not provide a specific incident, but Chennithala warned that the issue affects national security as well as privacy.
That dual risk explains his call for tools that are lawful, necessary, and proportionate, with institutional oversight. Strong controls can reduce misuse and help ensure that security technologies do not become security weaknesses. The Pegasus discussions he cited illustrate the concern surrounding powerful spyware in India.
How many cybersecurity incidents were recorded in India in 2025, and how did that compare with 2024?
India recorded 29 lakh cybersecurity incidents in 2025, according to data from the Indian Computer Emergency Response Team. The comparable figure for 2024 was 20 lakh. The increase was therefore 9 lakh incidents, showing a sharp rise in the volume of reported cyber threats within one year.
T.V. Ravichandran, Deputy National Security Advisor to the Government of India, cited these figures at c0c0n-2026. The conference was organised by Kerala Police with the Information Security Research Association. More than 2,500 delegates from 23 countries attended the two-day event, placing the national figures in a wider cybersecurity discussion.
The figures show why cyber defence is an urgent policy issue. Ravichandran called for a shift from conventional cyber defence toward technological sovereignty and indigenous capabilities. The article also reports that 98% of cybersecurity issues and data breaches are traceable directly or indirectly to human errors, highlighting the need for stronger people and processes alongside technology.
Why are human errors—such as weak passwords, phishing, or mishandling data—responsible for so many cybersecurity breaches?
Human errors create openings that technology may not stop. People can choose weak passwords, fall for phishing, send information to the wrong recipient, or mishandle sensitive data. They may also ignore warnings or configure systems incorrectly. Because people operate accounts, devices, and security processes, one mistake can expose a much larger system.
For example, a phishing message may persuade someone to reveal a password or open a harmful attachment. An attacker can then use that trusted access to reach accounts or data. The article does not list specific examples such as passwords or phishing, but it reports CERT-In data stating that 98% of cybersecurity issues and data breaches are traceable directly or indirectly to human errors.
This figure means cybersecurity cannot rely only on software and equipment. Organisations also need careful procedures, staff awareness, and accountability. The conference discussion connected rising incidents with stronger national capabilities, while the human-error figure shows that everyday behaviour remains a central part of national cyber defence.
What does technological sovereignty mean in cybersecurity, and why might a country want to develop its own standards, talent, and security technology?
Technological sovereignty in cybersecurity means a country can develop and control the capabilities it relies on for protection. It includes standards, skilled people, technologies, and security products developed or directed within the country. The goal is not merely to defend networks, but to retain strategic control over how that defence is designed and operated.
T.V. Ravichandran said national cybersecurity does not develop on software provided by foreigners. He connected cybersecurity capacity with standards, talent, technology, products, and sovereignty. In practical terms, a country that builds these areas can reduce dependence on outside suppliers and strengthen its ability to respond to threats.
The need is more urgent as incidents rise. India recorded 29 lakh cybersecurity incidents in 2025, compared with 20 lakh in 2024. Ravichandran called for a shift from conventional cyber defence toward technological sovereignty and indigenous capabilities. That approach points toward sustained investment in local expertise, research, products, and national standards.
Key Facts:
📌 Chennithala demanded lawful, necessary, and proportionate surveillance.
📌 He called for institutional oversight of intrusive tools.
📌 He announced plans to revitalise Kerala Police’s Cyberdome.
📌 Intrusive tools can secretly monitor devices or communications.
📌 Spyware may exploit vulnerabilities or misuse device permissions.
📌 The article names Pegasus as an Israeli digital intelligence firm’s spyware.
📌 Legality requires a valid legal basis for surveillance.