Another exam leaked. Another familiar cycle begins.
On May 3, over 2.2 million students sat for the NEET-UG. Millions of hours of preparation, shattered because PDFs of the paper were being traded on Telegram for up to Rs 10 lakh. Now, students take to Jantar Mantar in protest. The exam gets scrapped, forcing a nationwide re-test weeks later on June 21.
Arrests are made. Committees are formed. Eventually, the outrage will fade. Until the next time.
The anger is entirely justified. Families bleed their savings for these entrance exams. A leak doesn’t just ruin a test. It fractures the basic belief that hard work actually matters.
But outrage isn’t a strategy.
If we held another national exam tomorrow, what would actually be different? That’s the only question that matters now. We spend years debating who to punish after a leak. We spend almost zero time building systems to stop the leak in the first place.
Nothing is 100% foolproof. Banks get robbed. Servers get hacked. But good system design isn’t about eliminating all risk. It’s about shrinking the target, spotting the breach instantly, and catching the culprits fast.
India runs the world’s largest elections. We manage digital payments for a billion people. We shoot satellites into orbit. We can secure a piece of paper. We just have to stop treating “secure it better” as the plan and start naming the actual mechanism.
Here are six, and they’re specific enough that you can check next year whether anyone bothered.
1. No single person should ever hold the whole paper.
Forget “keep the circle small” as a vague virtue. Steal the model banks use for vault access: split-knowledge control. Paper-setters draft in sealed modules — Section A, B, C — without ever seeing the assembled whole. Final assembly requires two independent authorisations, like a bank vault that needs two keys turned at once. The printing press becomes a bonded facility with biometric entry logs, not a CCTV camera someone forgot to check. The point isn’t “trust people less.” It’s that a leak requires someone who has the whole paper. Stop letting anyone have it.
2. Kill the single point of failure — and name which format actually does that.
In the NEET-UG case, a “guess paper” circulating online reportedly matched over 100 questions with the real exam. That’s not bad luck. That’s what happens when one final paper sits printed and waiting for weeks. Which is why the one genuinely good outcome of this year’s leak is that the government has actually committed to fixing the structural problem: Education Minister Dharmendra Pradhan has confirmed NEET-UG moves to computer-based testing from 2027, on the recommendation of the Radhakrishnan Committee, which named the paper-based OMR format itself as the core vulnerability. Good. That’s the right call.
But announcing CBT isn’t the same as building it well, and this is exactly the kind of promise that gets watered down once the cameras leave. JEE Main and CAT already run multi-shift CBT, pulling randomised questions from an encrypted bank the moment each shift begins — there’s no “the paper” to steal in advance because it doesn’t exist until seconds before it’s needed. NEET at 2.2 million candidates across roughly a thousand centres is a harder version of that problem: more shifts means more question sets, which means a normalisation formula deciding whose score counts for what — and that formula needs to be published and stress-tested in public before students sit the exam, not explained afterward when someone’s rank drops. The rural and small-town infrastructure gap that kept NEET on paper for over a decade doesn’t close because a minister announced a date. It closes with an audited, city-by-city rollout plan and a fallback that isn’t just “postpone it a year and call it 2028.”
CBT is the single biggest structural fix on this entire list. It’s also the one most likely to be announced loudly and executed into mediocrity. The job now isn’t to demand the fix — it’s already been promised. The job is to track whether it actually ships on time, at the promised scale, with the formula published in advance.
3. Stop auditing yourself. Rotate the vendor too.
Organisations are terrible at spotting their own flaws — everyone knows this, which is why it keeps happening anyway. Bring in independent cybersecurity and logistics red teams to actually try to break the system before every cycle, the way a bank pen-tests its own systems, and publish what they find, the way CAG audits get published. But there’s a second, quieter fix nobody mentions: rotate the printing vendor. A press that prints the same national exam year after year isn’t a trusted partner. It’s a known, cultivable target. Familiarity is the vulnerability, not the safeguard.
4. The law already exists. Use it like you mean it.
The Public Examinations (Prevention of Unfair Means) Act, 2024 is already on the books — three to five years in prison for individuals, and for organised rackets, fines running into crores plus a multi-year ban on the vendors involved. The problem was never that the law is too soft. It’s that certainty of punishment has been close to zero, because enforcement crawls. Fix that with fast-track courts carrying a fixed trial timeline for exam-fraud cases, and financial forensics teams built to trace the Telegram-to-UPI money trail the moment a leak is confirmed — before the money, and the trail, go cold. Selling PDFs to desperate aspirants isn’t a prank. It’s a profitable criminal enterprise, and it should be investigated like one.
5. Give students a deadline in writing, before they need it.
The worst part of a leak, for a student, is the limbo. The nine days between the May 3 exam and the May 12 cancellation announcement were brutal. Will it be cancelled? Do I have to study again? Nobody should have to find out by refreshing a news channel.
So publish the rules before the exam, not after the scandal: a plain trigger matrix — leaked content confirmed at one centre, that centre alone retests; confirmed nationally before the exam window closes, national retest is automatic — and a hard 48-hour deadline for the agency to announce its decision. Not “soon.” Forty-eight hours, or it’s a breach of its own published rule. That’s the difference between a playbook and a PR line.
6. Fund it like the infrastructure it is — and stop rotating its leadership like a punishment posting.
These exams decide who becomes India’s next generation of doctors, engineers, and officers. That’s not a logistics problem, that’s critical infrastructure, and we already have a template for what that looks like: bring exam bodies like the NTA under a security certification regime modelled on the one CERT-In already runs for power grids and financial networks. Give it a ring-fenced budget that survives a change of minister. And give it professionalised, fixed-term leadership, instead of rotating a generalist bureaucrat through the top job every couple of years, right as they’ve learned where the actual risks sit.
The baseline
Protests matter. They force the issue. But protest is the spark, not the blueprint.
If this latest disaster ends in just a few arrests and a dusty committee report, we’ll be right back here in two years, and the next op-ed will read almost exactly like this one.
Students accept that these tests will be brutal. They accept that success demands sweat. What they shouldn’t have to accept is competing against someone who simply bought the answers on their phone.
That’s the baseline. It’s time we delivered it.