Critical infrastructure in India is increasingly vulnerable to cyber threats emanating from third-party vendors rather than direct attacks. Discuss with reference to recent incidents in the nuclear energy sector.

Q. Critical infrastructure in India is increasingly vulnerable to cyber threats emanating from third-party vendors rather than direct attacks. Discuss with reference to recent incidents in the nuclear energy sector. (15 marks, 250-350 words)

India's critical information infrastructure (CII) — facilities whose incapacitation would debilitate national security, protected under Section 70A of the IT Act, 2000 [4] — is today breached less through its hardened core than through the softer networks of the contractors that build and service it.

The vendor has become the attack surface - In July 2026, NPCIL confirmed that leaked drawings relating to the Kudankulam project (KKNPP) came through a breach at its EPC contractor, Reliance Infrastructure, and not through NPCIL's own systems [1]. - The data sat with a third-party data-centre provider, adding a fourth-party layer well outside the plant operator's audit control. - NPCIL clarified the files pertained to conventional "balance of plant" common service facilities, with no nuclear safety or security systems compromised [1]. - Contrast the 2019 KKNPP malware incident: infection stayed confined to the administrative network because plant control and instrumentation systems are connected to no external network [2].

Why the threat has migrated outward - Air-gapping hardens reactor controls, so adversaries pivot to the least-defended holder of the same information — vendors, OEMs and cloud providers. - Contractors hold blueprints, supplier lists and inspection records, enough to map support systems, entry points and dependencies. - The Nuclear Energy Mission's 100 GW-by-2047 target [5] multiplies contracts, vendors and cross-border data exchange, widening the perimeter faster than oversight matures.

Institutional response and remaining gaps - CERT-In's 2022 Directions require data centres and service providers to report cyber incidents within six hours [3]; NCIIPC is the nodal agency for CII protection [4]. - Yet vendor-side security remains largely contractual rather than audited, and classification norms for contractor-held drawings are weak.

The lesson is that India's cyber perimeter now ends at its last subcontractor, not at the plant gate. Extending mandatory security audits, zero-trust access and classification discipline to vendors and their data centres — and making cyber-compliance a tender condition — would safeguard both the nuclear expansion pathway and the clean-energy goals under SDG-7 that it serves.

(~330 words)

Sources: 1. NPCIL statement on drawings/data leak through breach at M/s Reliance Infra Limited with respect to KKNPP, 16 July 2026 — NPCIL Press Releases — contractor-origin breach; balance-of-plant data only; nuclear safety/security systems unaffected 2. Cyber attack on KKNPP — PIB, Department of Atomic Energy — 2019 malware limited to administrative network; control and instrumentation systems isolated from external networks 3. CERT-In Directions under Section 70B(6), IT Act, 2000 (28 April 2022) — six-hour mandatory incident reporting covering data centres and service providers 4. National Critical Information Infrastructure Protection Centre (NCIIPC) — Section 70A mandate and nodal role in protecting critical information infrastructure 5. Nuclear Energy Mission, Union Budget 2025-26 — PIB — target of 100 GW nuclear capacity by 2047