Having completed three full years and now into its fourth, IITB Trust Lab has evolved from just a simple vision , establishing core institutional foundations and interdisciplinary and translational research facilities. By bringing together academia, industry leaders, and policymakers, the Lab is actively addressing the most pressing digital security challenges.
As India digitizes across critical infrastructure and public services, the nation’s surface area for cyber threats is expanding exponentially. The increase of Internet of Things (IoT) devices, digital financial systems, and AI creates too many unmonitored, vulnerable endpoints. Concurrently, modern cyber threats have escalated beyond isolated malware attacks into weaponized cyber warfare, in some cases even state-sponsored, attaking everything, from personal devices to supply chains.
Compounding this threat landscape is a severe, widening global cybersecurity skills gap, grossly insufficient to counter sophisticated, AI-driven zero-day attacks or low-level hardware security breaches.
Addressing these systemic vulnerabilities requires a model that bridges theoretical research, real-world technology deployment, and nationwide talent cultivation to ensure long-term digital sovereignty and trust – the three main pillars of focus for IITB Trust Lab.
Research serves as the fundamental bedrock of Trust Lab, addressing emerging digital vulnerabilities by uniting world-class expertise across cryptography, hardware security, network security, privacy, and the intersection of AI with security. This is done through many different avenues.

Cybersecurity research often faces significant funding bottlenecks, as foundational security concepts require a lot of capital before producing practical applications. Without targeted academic grants, promising security research remains purely theoretical rather than evolving into deployable tools.
The Trust Lab and Mphasis Grant program provides strategic financial support to ambitious researchers. Over three years, the initiative has funded 27 research projects with a total allocation of INR 3.30 Crore. This capital injection accelerates high-impact exploration in critical digital trust domains, enabling research teams to turn raw concepts into validated prototypes and peer-reviewed contributions.

Academia faces a continuous brain drain toward private industry, particularly in specialized fields like applied cryptography and hardware security where market compensation is exceptionally high. Retaining exceptional faculty in academic research is necessary for maintaining a long-term national pipeline of advanced security knowledge.
The Shridhar Shukla Chair in Digital Trust is awarded to faculty with a large body of impactful research, while the Early Career Awards recognize and incentivize outstanding young scholars across India who are making foundational contributions to cybersecurity.


Many prospective researchers lack exposure to full-scale research environments prior to committing to multi-year PhD programs, creating drop-offs in the research talent pipeline. The 1-year Pre-doctoral Program provides selected candidates with early immersion in advanced labs, allowing them to gain hands-on research and exposure, along with the opportunity to work with the best faculty, contributing to research.
Till now we have had more than 20 enrollments, with those who have completed going on to various doctoral programs and positions in industry.

These short talks bring international experts to share their knowledge on the most recent breakthroughs and problems in the field, and provide an opportunity for conversation and collaboration.
Academic security insights often struggle to cross the “valley of death” between published papers and operational enterprise deployment. Trust Lab aims to bridge academia and industry by translating theoretical breakthroughs into functional platforms serving many varied purposes.

Modern security monitoring tools are frequently resource-intensive and complex to deploy, making them inaccessible for smaller organizations. Additionally, students rarely get opportunities to train on enterprise-grade, live monitoring setups during their academic training.
The Trust Lab Security Operations Centre (SOC) addresses both challenges as an open-source, agentless platform engineered for real-time security monitoring and threat analysis. By consolidating log collection, anomaly detection, and interactive visual analytics into a unified environment, it simplifies enterprise deployment. Operationally, it serves as an active defense layer while also being a live sandbox where students analyze real network traffic patterns.
Traditional security education relies heavily on theoretical lectures, leaving students unprepared for live incident response. Passive learning models are inadequate to tackle complex, fast-evolving real-world cyber attacks.
PULSE solves this by delivering graduate-level, Capture-The-Flag (CTF) style security labs through an integrated desktop client running on IIT Bombay’s BodhiTree infrastructure. Utilizing containerized lab runtimes, PULSE provides structured exercises spanning encryption, network reconnaissance, DNS attacks, privilege escalation, steganography, and web security—giving learners hands-on exposure to live attack vectors within controlled environments.

Technologies Under Development
VPNVerif: A framework designed to audit and verify VPN security claims made by providers;
Project SiSham (in collaboration with IIT Kharagpur): which focuses on secure hardware architectures for automotive systems;
Agentic SOC: Integrating AI agents into security operations for automated threat identification.

Beyond technical R&D, interactive workshops conducted in close collaboration with industry partners form a vital pillar of our technology strategy. These serve multiple strategic purposes—ranging from educating industry professionals on emerging hardware and software vulnerabilities (such as Rowhammer and API exploits) to co-designing practical mitigation frameworks tailored for complex enterprise environments.
Furthermore, these industry-aligned workshops act as a place for collaborative innovation and technology transfer. Problem owners from sector leaders (such as banking, fintech, and enterprise IT) get a chance to work directly alongside Trust Lab researchers.
Building a resilient digital defense infrastructure requires democratizing high-quality security education, fostering open-source development, and creating national institutional partnerships to scale impact.

The cybersecurity skills gap cannot be closed solely through classroom lectures; students need early, practical engagement with actual production code bases, real-world data streams, and active research challenges under direct expert mentorship.
The Lab addresses this gap through its two-month onsite internships and the Summer of Code program. Interns work alongside IITB faculty on advanced and relevant security problems, while Summer of Code participants actively write code for the open-source SOC platform—working with tools like Apache Kafka and the ELK Stack to build both rule-based and machine-learning-driven anomaly detection models.


The Lab runs 1–2 week seasonal schools to offer rigorous deep dives into core cybersecurity subjects, because mastering complex cybersecurity topics requires immersive, focused study alongside competitive environments that simulate the intense pressure of real-world incidents. Standard academic pacing often fails to match the speed and gamified nature of modern security work.

These learning initiatives are complemented by national Capture-The-Flag (CTF) competitions. By gamifying complex security puzzles, CTFs encourage critical thinking, out-of-the-box problem solving, and rapid decision-making under pressure— all skills needed in real-world cybersecurity positions, while simultaneously acting as an effective mechanism for discovering top security talent across the country.

Updating and upgrading national security education requires upskilling educators first. If college faculty lack exposure to modern security paradigms, thousands of engineering graduates enter the workforce with outdated skills. Similarly, working professionals require continuous upskilling to adapt to shifting threat landscapes.
Through its Faculty Development Program (FDP), held in conjunction with ICAN, the Lab trains educators from institutions across the country, enabling them to better their own institutional curricula.

Collaborative initiatives must also extend to the level of institutions, and so to eliminate fragmentation, the Lab has recently launched its hub-and-spoke model. In the short time since its launch, there are already 10 partner institutions in this network, which will help accelerate applied research, and fosters a collaborative national culture around technology and cybersecurity.

While educating students is vital for nurturing talent in the long run, thousands of active industry professionals are defending live systems right now. Cybersecurity upskilling cannot remain restricted to traditional university classrooms.
That is why the Lab launched specialized Professional Certificate Programs in Software Development and Cybersecurity. These programs extend high-impact security education directly to industry practitioners and mid-career engineers. By combining hands-on defensive training, practical secure coding practices, and applied cryptography with real-world threat scenarios, these courses equip professionals with immediate, market-relevant skills.
IITB Trust Lab has transformed into an anchor of Digital Trust — demonstrating the power of unifying deep academic research, open-source technology translation, and nationwide security education.
This momentum is only picking up pace, accelerated by strategic expansions such as the new Mphasis AI & Cybersecurity Research Co-Lab. Partnerships of this caliber signal moving beyond traditional academic boundaries to build dynamic research environments that directly address industry scale and emerging threat vectors.
Yet, despite these significant milestones, there is still a long way to go. Securing India’s sovereign digital future demands sustained commitment because of our heavy reliance on foreign hardware, software, and cybersecurity tools. Reports highlight that nearly 80 percent of India’s electronic components—including semiconductors, printed circuit boards (PCBs), and critical hardware infrastructure—are imported.
This deep foreign reliance introduces severe supply-chain vulnerabilities and hidden backdoors into the very core of national defense. A single foreign update or vulnerability can compromise critical infrastructure across the country during geopolitical tensions.
True strategic autonomy cannot exist without technological self-reliance — and our goal at Trust Lab over the next years is to help with this transformation of India into a self-reliant architect of its own digital destiny.