The COVID-19 pandemic brought to the fore digital technology that not only facilitated a swift response but also greased the wheels of the economy by enabling work from home and online business, among others. However, digitisation has accelerated the need for cybersecurity and its regulation. The article critically examines the technical meaning and legal definition of “cybersecurity.” The Information Technology Act of 2000 and rules made therein have, in an incremental manner, build the legal edifice for cybersecurity. Nevertheless, the rapid advancement in technology (IoT, AI, Cloud, 5G) and its diffusion has made the protection of “critical information infrastructure” vulnerable. There is a need to identify the “critical sectors”—health, space, election and assess the obligation on the private sector to share threat information and cyber incident demands recalibrating the current cybersecurity governance in India.