Critical infrastructure in India is increasingly vulnerable to cyber threats emanating from third-party vendors rather than direct attacks. Discuss with reference to recent incidents in the nuclear energy sector.
In this answer
India's critical information infrastructure (CII) — facilities whose incapacitation would debilitate national security, protected under Section 70A of the IT Act, 2000 [4] — is today breached less through its hardened core than through the softer networks of the contractors that build and service it.
The vendor has become the attack surface
- In July 2026, NPCIL confirmed that leaked drawings relating to the Kudankulam project (KKNPP) came through a breach at its EPC contractor, Reliance Infrastructure, and not through NPCIL's own systems [1].
- The data sat with a third-party data-centre provider, adding a fourth-party layer well outside the plant operator's audit control.
- NPCIL clarified the files pertained to conventional "balance of plant" common service facilities, with no nuclear safety or security systems compromised [1].
- Contrast the 2019 KKNPP malware incident: infection stayed confined to the administrative network because plant control and instrumentation systems are connected to no external network [2].
Why the threat has migrated outward
- Air-gapping hardens reactor controls, so adversaries pivot to the least-defended holder of the same information — vendors, OEMs and cloud providers.
- Contractors hold blueprints, supplier lists and inspection records, enough to map support systems, entry points and dependencies.
- The Nuclear Energy Mission's 100 GW-by-2047 target [5] multiplies contracts, vendors and cross-border data exchange, widening the perimeter faster than oversight matures.
Institutional response and remaining gaps
- CERT-In's 2022 Directions require data centres and service providers to report cyber incidents within six hours [3]; NCIIPC is the nodal agency for CII protection [4].
- Yet vendor-side security remains largely contractual rather than audited, and classification norms for contractor-held drawings are weak.
The lesson is that India's cyber perimeter now ends at its last subcontractor, not at the plant gate. Extending mandatory security audits, zero-trust access and classification discipline to vendors and their data centres — and making cyber-compliance a tender condition — would safeguard both the nuclear expansion pathway and the clean-energy goals under SDG-7 that it serves.
Sources
- 1NPCIL statement on drawings/data leak through breach at M/s Reliance Infra Limited with respect to KKNPP, 16 July 2026 — NPCIL Press Releasescontractor-origin breach; balance-of-plant data only; nuclear safety/security systems unaffected
- 2Cyber attack on KKNPP — PIB, Department of Atomic Energy2019 malware limited to administrative network; control and instrumentation systems isolated from external networks
- 3CERT-In Directions under Section 70B(6), IT Act, 2000 (28 April 2022)six-hour mandatory incident reporting covering data centres and service providers
- 4National Critical Information Infrastructure Protection Centre (NCIIPC)Section 70A mandate and nodal role in protecting critical information infrastructure
- 5Nuclear Energy Mission, Union Budget 2025-26 — PIBtarget of 100 GW nuclear capacity by 2047