Kerala Home Minister Chennithala on Wednesday said any use of intrusive surveillance tools by the state must remain strictly lawful, underscoring the growing tension between digital security, policing powers and privacy rights in India's fast-expanding cyber landscape.
Speaking at c0c0n-2026, the annual cybersecurity conference that has become one of the country's most closely watched forums on digital defence, Chennithala framed the issue as a test of democratic accountability rather than a purely technical matter. His remarks come at a time when governments across India are expanding their reliance on advanced monitoring systems, forensic tools and network-level intelligence to counter cybercrime, online fraud and threats to critical infrastructure.
Lawful Surveillance
Chennithala's intervention is significant because it places legal restraint at the centre of the surveillance debate. In a policy environment where states are increasingly tempted to deploy powerful digital tools in the name of public safety, his message was that capability alone cannot justify use. Any intrusive measure, he said in substance, must be backed by law and governed by due process.
That position reflects a wider national conversation over how far the state can go in monitoring communications, devices and online activity. India's cyber governance architecture has grown more sophisticated in recent years, but so too have concerns about proportionality, oversight and the risk of mission creep. For civil society groups, the issue is not whether law enforcement should have access to modern tools, but whether those tools are deployed with adequate safeguards, audit trails and accountability.
The minister's remarks also carry practical implications for police forces that increasingly depend on digital intelligence. Surveillance technologies can help trace ransomware networks, identify phishing operations and map hostile activity across platforms. But they also raise the possibility of overreach if legal thresholds are vague or enforcement is uneven. By stressing legality, Chennithala signalled that Kerala intends to present itself as a state that combines technological ambition with procedural discipline.
Cyberdome Reset
Alongside the warning on surveillance, Chennithala announced plans to revitalise Cyberdome, the Kerala Police's public-private partnership initiative focused on cybersecurity. The move suggests the state wants to strengthen an institution that has long been seen as a bridge between law enforcement, industry and technical experts.
Cyberdome was designed to bring together police, researchers, private firms and security professionals to respond faster to emerging threats and build operational capacity. In practice, such partnerships can help governments access specialised expertise that is often difficult to retain inside conventional police structures. They can also improve threat intelligence sharing, incident response and training.
A revitalised Cyberdome could therefore become central to Kerala's cyber strategy, especially as attacks on individuals, businesses and public systems become more frequent and more complex. The challenge will be ensuring that the initiative does not become merely symbolic. For it to matter, it will need clearer mandates, stronger coordination with police units and measurable outcomes in prevention, detection and response.
The announcement also points to a broader governance model that Kerala appears keen to promote: one in which the state does not attempt to solve cyber risk alone, but instead builds structured collaboration with the private sector while keeping legal authority and public accountability firmly in government hands.
Balancing Power And Privacy
Chennithala's remarks arrive at a moment when cybersecurity policy is increasingly inseparable from questions of rights and state power. The same tools that help investigators track criminal networks can, if unchecked, create unease about surveillance of ordinary users, journalists, activists or political opponents. That is why the minister's emphasis on legality matters beyond Kerala.
For policymakers, the core challenge is to build systems that are effective without becoming opaque. That means clear authorisation, narrow purpose limits, independent review where appropriate and transparent internal controls. It also means investing in cyber capacity that is defensive first: securing networks, hardening public systems, training personnel and improving incident response before leaning on intrusive monitoring.
Kerala has often positioned itself as a state willing to experiment with public policy in technology and governance. The latest announcement suggests it is now trying to do the same in cybersecurity, but with a sharper emphasis on legitimacy. In a field where trust is as important as technical skill, that balance may prove decisive.
Chennithala's message at c0c0n-2026 was ultimately twofold: the state must modernise its cyber defences, and it must do so without abandoning the rule of law. In an era of expanding digital surveillance, that is likely to resonate well beyond Kerala's borders.
