Now streaming अगस्त 6, 2026
Hot pulse
India

CBSE OSM whistleblower Nisarga Adhikary hired by IIT Kanpur with ‘decent salary’ but…

Christopher Thomas - theindiapostdaily.com 4 mins read 11 views

Nisarga Adhikary, CBSE OSM Whistleblower, Joins IIT Kanpur with Decent Salary CBSE OSM whistleblower Nisarga Adhikary hired - Nisarga Adhikary, the

CBSE OSM whistleblower Nisarga Adhikary hired by IIT Kanpur with ‘decent salary’ but…

Nisarga Adhikary, CBSE OSM Whistleblower, Joins IIT Kanpur with Decent Salary

Theindiapostdaily.com – Nisarga Adhikary, the 19-year-old cybersecurity expert who exposed critical vulnerabilities in the Central Board of Secondary Education’s Online School Management (OSM) portal, has been hired by the Indian Institute of Technology Kanpur (IIT Kanpur) under a contractual agreement. This move has sparked discussions about the value of Adhikary’s contributions to education technology security, despite the initial surprise over his salary, which Adhikary described as “decent” but lower than expected. The hiring reflects a growing recognition of his role in identifying security flaws that could have jeopardized student data across millions of Class XII examinations.

Background and Discovery of Vulnerabilities

Adhikary, hailing from West Bengal, gained national attention after independently uncovering several security vulnerabilities in the CBSE OSM portal. His findings, which were later confirmed by experts, included issues such as the bypassing of one-time passwords (OTP), the use of a hardcoded master password that allowed unauthorized access to examiner accounts, and the potential for data leakage from answer sheets. These issues raised concerns about the portal’s ability to securely handle sensitive academic information, especially during high-stakes exams like the Class XII results.

Adhikary’s New Role at IIT Kanpur

Following his discovery, Adhikary was invited to join IIT Kanpur’s cybersecurity team. His new role involves analyzing publicly accessible data to detect security weaknesses in digital platforms, with a particular focus on educational systems. The institute aims to leverage his expertise in identifying and mitigating cyber threats before they escalate into major breaches. Adhikary’s decision to accept the position highlights his commitment to contributing to institutional cybersecurity efforts, even though he initially expressed some disappointment over the salary.

Adhikary remarked in a recent interview, “The salary is decent, but I was expecting a bit more. I’m used to working on projects with US-based companies, and I do miss the financial benefits that come from earning in dollars due to the USD-INR exchange rate.” This statement underscores the broader challenge of aligning competitive salaries with the value of cybersecurity professionals in India, especially when their work can prevent significant data compromises.

Adhikary’s work at IIT Kanpur is expected to focus on both research and practical security audits. His expertise in identifying vulnerabilities through independent testing has been described as a model for how such issues can be detected early. The institute plans to integrate his findings into its cybersecurity protocols, ensuring that future projects benefit from his insights. This marks a significant step toward improving the security infrastructure of educational institutions in India.

OSM Portal’s Testing and Audit Process

The OSM portal, developed by private vendor Coempt Eduteck, was under scrutiny following Adhikary’s revelations. A panel of experts from IIT Kanpur reviewed the system and found that it had not undergone thorough testing. Despite passing initial checks and receiving approval from an auditor, the portal’s security was questioned. One panel member, speaking to ANI under anonymity, noted, “It was not thoroughly tested. While an auditor was hired by CBSE and gave approval, a comprehensive analysis was missing. The auditing was not sufficient.”

Adhikary’s discovery of the hardcoded master password and OTP bypassing issues revealed gaps in the portal’s design that could have allowed unauthorized access to student records. However, the panel clarified that there was no evidence of data being leaked or misused. “Nisarga downloaded some data but deleted it. We haven’t seen any evidence of information being taken outside the system,” the panel member added. This reassurance comes as the CBSE continues to work on improving the OSM portal’s security framework.

Implications for Educational Cybersecurity

Adhikary’s case has become a case study in the importance of proactive cybersecurity measures in educational institutions. His work underscores the need for more rigorous testing of digital platforms that handle student data, particularly those used for high-stakes assessments. The IIT Kanpur team is now working to ensure that such vulnerabilities are not overlooked in future projects. Adhikary’s involvement also highlights the potential for young cybersecurity professionals to make a meaningful impact in the education sector.

Experts in the field have praised Adhikary’s initiative, noting that his independent discovery of flaws in the OSM portal sets a precedent for transparency in technology-driven education. The report, which was compiled with input from news agencies, emphasizes the urgency of deeper security evaluations for systems handling critical academic data. As the IIT panel prepares to submit its findings to the Ministry of Education, the case of Nisarga Adhikary serves as a reminder of the delicate balance between innovation and security in digital education platforms.

Gabung diskusi