CBSE Cybersecurity Lapses in On-Screen Marking System: Governance and Data Privacy Concerns

Updated 7 Jun 2026

Contents4

Hindustan Times - India · 7 Jun 2026 · 2 min read
Prelims · Polity Mains · GS2 Governance High relevance

Coempt Edu Teck submitted expired and misrepresented cybersecurity certificates to CBSE for its On-Screen Marking (OSM) system, which later revealed critical vulnerabilities exposing student data, raising serious governance and privacy issues.

Key points

Coempt Edu Teck submitted two cybersecurity certificates to CBSE for its OSM system tender, both of which were either expired or misrepresented, failing to meet procurement standards.

Prime Infoserv LLP certificate from November 2023 was nearly two years old when submitted in August 2025, and its validity had lapsed as per its own terms.

A3S Tech & Company certificate from October 2025 audited a different application (OneX) in a pre-production environment, not the actual CBSE deployment, indicating a lack of proper validation.

CERT-In acknowledged critical vulnerabilities in the OSM system to a parliamentary panel, including unauthorized access to student marks, answer scripts, and evaluator banking details.

SQL injection attack vulnerability allowed researcher Tirth Parmar to gain administrator-level access to sensitive databases, exposing systemic security failures in Coempt's software.

[GS2-Governance] This incident highlights systemic flaws in government procurement processes, where inadequate verification of vendor claims can compromise critical systems.

[GS3-Security] The data breaches underscore India's weak cybersecurity infrastructure, particularly in educational institutions handling sensitive student information.

Way Forward: CBSE must implement mandatory third-party audits for all IT procurements, establish a dedicated cybersecurity compliance cell, and enforce stricter penalties for vendor misrepresentation to prevent future lapses.

Key terms

On-Screen Marking (OSM)
A digital evaluation system where examiners mark answer scripts electronically. For UPSC, its governance implications include transparency concerns, technological reliability, and data privacy issues under the Digital Personal Data Protection Act 2023.
SQL Injection Attack
A code injection technique that exploits vulnerabilities in database-driven applications, allowing unauthorized access. Relevant for GS3 (security) as it demonstrates India's cybersecurity challenges in critical systems like education and finance.
Government Procurement Rules
The framework regulating public sector purchases, including technical qualifications and vendor compliance. For UPSC, this connects to GS2 governance reforms, transparency in tendering, and accountability mechanisms to prevent fraud.
CERT-In
The Indian Computer Emergency Response Team (CERT-In) is the national nodal agency for cybersecurity under MeitY, mandated to handle cyber threats and advisories. Its role is critical for UPSC as it intersects with GS3 (security) and GS2 (governance) topics, particularly in digital infrastructure protection.

Practice question

Critically analyze the governance and cybersecurity challenges highlighted by the CBSE's On-Screen Marking system vulnerabilities. (250 words, 15 marks)

GS2 15 marks 250 words Mains

Key terms to include: Government Procurement Rules CERT-In On-Screen Marking (OSM) SQL Injection Attack Digital Personal Data Protection Act 2023 vendor accountability third-party audits data privacy

Answer framework

Introduction

Briefly introduce the CBSE OSM system and the recent cybersecurity lapses, linking it to broader governance and data privacy concerns in public sector IT procurement.

Governance Failures in Procurement

Lack of due diligence in verifying vendor cybersecurity certificates (expired/misrepresented certificates from Coempt Edu Teck).

Absence of third-party audits for critical IT systems handling sensitive student data.

Systemic flaws in government procurement processes leading to vendor accountability issues.

Cybersecurity Vulnerabilities

SQL injection attacks exposing administrator-level access to sensitive databases.

Inadequate validation of software in actual deployment environments (A3S Tech certificate auditing a different application).

Role of CERT-In in identifying vulnerabilities but delayed response mechanisms.

Data Privacy and Institutional Trust

Exposure of student marks, answer scripts, and evaluator banking details.

Non-compliance with Digital Personal Data Protection Act 2023 provisions.

Impact on public trust in digital education infrastructure.

Conclusion

Suggest a way forward: mandatory third-party audits, stricter vendor compliance penalties, and a dedicated cybersecurity cell for educational institutions to restore trust and ensure robust data protection.

Fact check

All facts verified