India’s Intelligence Grid and Counter-Terror Architecture: From Data Silos to Network Disruption

The strategic transformation from information collection to intelligence fusion

New Delhi/Jammu — A recent development in India illustrates how counter-terrorism is increasingly moving beyond the identification of individual attackers towards the disruption of entire terrorist networks.

In September 2026, a Special National Investigation Agency (NIA) Court in Jammu issued a non-bailable warrant against Pakistan-based Lashkar-e-Taiba (LeT) commander Saifullah alias Sajid Jatt. Indian investigators have linked him to several terrorist incidents, including the April 2025 Pahalgam attack, and allege that he provided weapons, funds and operational directions to militants in Jammu and Kashmir. The NIA has also referred to communication identifiers allegedly recovered from arrested operatives and used in developing the case against him.

The warrant itself is only one judicial step. Its wider significance lies in the investigative architecture behind it: intelligence collection, data correlation, communications analysis, local policing, central investigation and judicial processes are increasingly being connected into a single counter-terrorism chain.

India’s central objective has consequently evolved from simply asking, “Who carried out the attack?” to asking, “Who recruited them, who financed them, who supplied them, who communicated with them, who provided logistics, and who directed them?”

That is the fundamental difference between an incident-centred security system and a network-disruption system.

From information silos to intelligence fusion

The transformation accelerated after the November 2008 Mumbai terrorist attacks, which exposed serious gaps in the ability of different agencies to share and correlate information.

India subsequently developed the National Intelligence Grid, or NATGRID, as a secure intelligence-sharing platform connecting authorised agencies with multiple government databases. According to the Indian government, NATGRID now connects 11 Central User Agencies, police forces in all 28 states and eight Union Territories, and 11 data-providing organisations. Its information environment includes areas such as immigration, banking, telecommunications and travel records. India is also developing an Organised Crime Network Database to facilitate information sharing between the NIA and State Anti-Terrorism Squads.

The strategic principle is important.

The objective is not necessarily to create one enormous database containing everything about every citizen. Rather, authorised investigators should be able to obtain relevant information from different institutional databases and establish connections that would otherwise remain invisible.

A suspicious travel movement may mean little by itself.

A suspicious financial transaction may also mean little by itself.

A telephone contact may appear ordinary.

A criminal record may be unrelated.

But when travel, communications, financial activity, identity information, weapons recovery and known terrorist associations converge around the same individuals, the intelligence significance changes.

That is the essence of intelligence fusion.

GANDIVA and the analytical layer

India has also developed advanced analytical capabilities around NATGRID. The government describes GANDIVA as an advanced analytics tool supporting multi-source data collection and intelligence analysis.

The significance of such systems is not simply the use of artificial intelligence.

The real value lies in the ability to resolve identities, correlate apparently unrelated records, identify relationships and detect patterns across multiple datasets.

In traditional investigations, an officer may have to request information separately from immigration, police, telecommunications, financial institutions and other agencies.

The terrorist network, however, does not operate according to those bureaucratic boundaries.

A handler may communicate through one system, finance an operative through another, move the operative through a third jurisdiction and obtain weapons through an entirely different network.

Therefore, the state has to reconstruct the network in the same way that the network operates — across institutional boundaries.

Therefore, the state has to reconstruct the network in the same way that the network operates — across institutional boundaries.

PRAHAAR: turning capability into doctrine

India’s latest development is the formalisation of these capabilities into a national counter-terrorism doctrine.

On 23 February 2026, India’s Ministry of Home Affairs unveiled PRAHAAR, described by the government as India’s first comprehensive National Counter-Terrorism Policy and Strategy. The framework has seven pillars: prevention, swift and proportionate response, aggregation of internal capacities, human-rights and rule-of-law processes, reduction of conditions conducive to radicalisation, international cooperation, and recovery and whole-of-society resilience.

PRAHAAR explicitly places intelligence-led prevention at the centre of the national approach. It also calls for real-time intelligence sharing, stronger coordination between state agencies and specialised central forces, counter-terror financing measures, international cooperation and disruption of terrorist ecosystems.

This is significant because technology without doctrine does not necessarily produce security.

A country may possess enormous quantities of information and still fail if:

information is not shared;

warnings are not escalated;

agencies do not trust each other’s assessments;

operational commanders do not receive intelligence in time;

or intelligence is not converted into admissible evidence.

PRAHAAR attempts to connect these stages.

The NIA: converting intelligence into evidence

The National Investigation Agency provides another component of the architecture.

The purpose of an intelligence agency is not identical to that of a criminal investigation agency. Intelligence can identify a threat before sufficient evidence exists for prosecution. A criminal investigation must eventually establish facts capable of surviving judicial scrutiny.

The NIA therefore represents the bridge between intelligence and prosecution.

The Saifullah proceedings demonstrate this model. According to the NIA’s case, communication identifiers allegedly recovered from arrested operatives helped connect the Pakistan-based commander to the wider terrorist network. The court subsequently issued a non-bailable warrant because the accused was outside the ordinary reach of Indian investigators.

The important lesson is that the state is attempting to preserve the intelligence trail long enough to construct a legally sustainable case against the network’s higher-level actors.

Sri Lanka’s Easter Sunday warning: when information does not become action

For Sri Lanka, this development has an especially important historical context.

The Easter Sunday attacks of 21 April 2019 demonstrated that possessing intelligence is not equivalent to possessing security.

Sri Lankan Supreme Court proceedings established that intelligence concerning a potential terrorist threat had been received on 4 April 2019. The Court specifically examined the failure to convene a National Security Council meeting between receipt of the intelligence and the Easter attacks. It also examined failures in the transmission and assessment of the information within the national security structure.

The attacks subsequently killed and injured hundreds of people.

The central lesson was therefore not merely that the state lacked information.

It was that information did not move through the national-security system with sufficient speed, authority and operational consequence.

That distinction is fundamental.

A warning sitting inside an intelligence file is not yet national security.

A warning converted into an operational decision is national security.

The 2024 Ahmedabad case: a second and different lesson

The post-Easter period produced another case that is particularly relevant to intelligence cooperation between India and Sri Lanka.

In May 2024, Gujarat’s Anti-Terrorism Squad arrested four Sri Lankan nationals in Ahmedabad over suspected Islamic State links. Indian authorities said the suspects had contact with a Pakistan-based IS-linked figure. Investigators subsequently reported recovering an Islamic State flag and three pistols with ammunition, while information obtained from seized phones helped direct investigators towards additional evidence.

Indian authorities treated the suspects as suspected Islamic State operatives and investigated possible terrorist activity.

The case subsequently generated a significant difference in public interpretation between the two countries.

Sri Lanka’s then Defence Secretary Kamal Gunaratne said Sri Lankan authorities had examined the backgrounds of the four men and found no record identifying them as religious extremists, while describing them as persons involved with drugs.

This difference should not be simplified into “India was right” or “Sri Lanka was right.

“It illustrates a much more important intelligence principle:

Competing assessments must be investigated, not prematurely substituted for one another.

The existence of a narcotics or criminal background does not automatically disprove terrorist involvement.

Conversely, an arrest on suspicion of terrorism does not itself establish guilt.

The correct intelligence process is to test both propositions against the total evidence.

The Ahmedabad investigation therefore demonstrates the importance of combining:

travel records;communications;

foreign intelligence;criminal histories;

financial activity;digital evidence;

weapons recovery;

ideological material;

known associates;

and subsequent investigations in the country of origin.

The intelligence question is not whether one explanation sounds more plausible.

The question is which explanation survives corroboration.

The danger of analytical dismissal

This is particularly important for Sri Lanka because the country has already experienced the consequences of failing to give appropriate weight to credible terrorism intelligence.

There is a major difference between saying:

“We have not yet established that these individuals are terrorists”

and saying:”

These individuals are not terrorists”.

The first is an intelligence assessment reflecting incomplete evidence.

The second is a conclusion requiring substantially stronger evidentiary foundations.

Modern counter-terrorism systems must preserve this distinction.

A HUMINT report, foreign intelligence warning, intercepted communication, travel anomaly or financial irregularity may not independently establish criminal guilt.

But it can possess considerable intelligence value.

Its appropriate treatment is therefore:Source reliability → information credibility → corroboration → analytical assessment → operational decision → evidence development.

This prevents both extremes: blindly accepting intelligence and prematurely dismissing it.

From perpetrators to networks

The most important transformation in India’s system is therefore conceptual.

Traditional counter-terrorism often begins and ends with the perpetrator.

A network-centric system asks different questions.Who recruited the individual?

Who radicalised him?

Who financed the activity?

Who supplied weapons?

Who arranged transportation?

Who provided accommodation?

Who supplied communications?

Who gave operational instructions?

Who provided forged documents?

Who acted as an overground facilitator?Who maintained the relationship with a foreign handler?

Who replaced the operative after arrest?

The objective is to dismantle the network rather than merely arrest one participant.

That is why the combination of NATGRID, analytical systems, State ATS structures, the NIA, financial investigation and international cooperation is strategically important.

What Sri Lanka can learn

Sri Lanka does not need to reproduce India’s system in its entirety.

It needs to solve its own specific intelligence-fusion problem.

A Sri Lankan architecture could progressively connect authorised intelligence and law-enforcement functions involving:

immigration and border movements;

passport and visa information;

telecommunications metadata subject to law;

financial intelligence;criminal records;

vehicle registrations;firearms and explosives records;

prison and rehabilitation information;

terrorist and extremist watchlists;

maritime movements;corporate ownership;

suspicious financial transactions;and foreign intelligence reporting.

The objective should not be unrestricted surveillance.

The objective should be lawful, auditable and intelligence-led correlation of information relevant to defined national-security threats.

Every significant query should have an authorised purpose.

Every intelligence lead should be capable of being assessed.

Every operational decision should have an accountable authority.

And every criminal allegation should ultimately be tested through due process and evidence.

A Sri Lankan intelligence-fusion principle

The lessons from 2019 and 2024 can therefore be combined into a single national-security principle:

Do not allow intelligence to remain isolated,

and do not allow an intelligence assessment to become a conclusion before corroboration.

The first error produces intelligence failure.

The second produces analytical failure.

Both can be dangerous.

The required architecture is:

Detect → Fuse → Corroborate → Assess → Escalate → Act → Investigate → Prosecute → Disrupt.

India’s current trajectory demonstrates how a large state is attempting to institutionalise this cycle through NATGRID, advanced analytics, State ATS capabilities, the NIA and the PRAHAAR national strategy.

For Sri Lanka, the strategic lesson from Easter Sunday is even more direct.

The country did not suffer because no warning existed.

It suffered because warning did not become sufficiently effective national action.

The Ahmedabad case adds a second lesson: when a foreign partner identifies a possible terrorist network involving Sri Lankan nationals, the appropriate response is neither automatic acceptance nor automatic rejection. The information must enter a structured intelligence-fusion process in which foreign reporting, domestic intelligence, criminal records, financial information, communications and physical evidence are tested together.

The ultimate measure of an intelligence system is therefore not how much information it possesses.

It is whether the state can transform fragmented information into accurate understanding — and transform accurate understanding into timely, lawful action.

That is the movement from data silos to network disruption.

Leave a Reply

Your email address will not be published. Required fields are marked *