Critical infrastructure in India is increasingly vulnerable through its private contractor ecosystem rather than direct state systems. Discuss with reference to recent cybersecurity incidents.

Q. Critical infrastructure in India is increasingly vulnerable through its private contractor ecosystem rather than direct state systems. Discuss with reference to recent cybersecurity incidents. (15 marks, 250-350 words)

Critical Information Infrastructure (CII) is protected under Section 70A of the IT Act, 2000 through the NCIIPC, whose notified sectors include power, energy and strategic public enterprises [3]. Yet recent incidents show the weakest perimeter now lies outside state systems — in the private vendor ecosystem that builds and services them.

Evidence of a shifting locus of vulnerability - Kudankulam leak (July 2026): nearly 19,000 files on KKNPP Units 3 & 4 surfaced on a dark-web extortion site. NPCIL clarified that the material pertained only to Balance of Plant (conventional) facilities, with no nuclear safety or security system compromised [1]. - The intrusion occurred not at NPCIL but at Reliance Infrastructure, its Balance of Plant contractor, through a third-party data centre — a fourth-party layer removed from state oversight [1]. - CERT-In reports a steep rise in cyber incidents handled nationally, with ransomware and extortion groups increasingly targeting vendors rather than hardened state networks [4].

Why the contractor layer is the soft underbelly - Diffused accountability: operator, contractor and data host each hold fragments of responsibility, so no single entity owns the risk. - Aggregation risk: engineering drawings, layouts and supplier records held by contractors offer reconnaissance value even when reactor systems stay air-gapped. - Disclosure lag: suspicious activity detected in late May became public only in mid-July, straining CERT-In's six-hour incident-reporting mandate under Section 70B(6) [2].

A necessary qualification State systems are not immune — the 2019 Dtrack malware infection of Kudankulam's administrative network showed direct intrusion remains possible, though isolation from operational networks contained it [1]. The shift is therefore one of relative exposure, not substitution.

India's air-gapping of core systems has held; the residual gap is contractual and organisational. Extending NCIIPC audit obligations, mandatory security clauses and breach-reporting duties down the entire subcontracting chain — with periodic CERT-In audits of vendors in strategic sectors [4] — would align the private ecosystem with the security standard the state already applies to itself.

(~315 words)

Sources: 1. Nuclear Power Corporation of India Limited — Press Releases (clarification on KKNPP Units 3 & 4 data reports, 16 July 2026) — Balance of Plant-only leak, no nuclear safety/security systems compromised; contractor and data-centre origin; 2019 administrative-network malware isolated from operational systems 2. Indian Computer Emergency Response Team (CERT-In) — Directions under Section 70B(6), IT Act, 2000 (28 April 2022) — six-hour mandatory cyber incident reporting obligation 3. National Critical Information Infrastructure Protection Centre (NCIIPC), Section 70A, IT Act, 2000 — CII mandate and notified critical sectors including power, energy and strategic enterprises 4. Press Information Bureau, "CERT-In: India's Frontline Defender against Cyber Threats" — rising volume of cyber incidents handled and CERT-In security audits of critical-sector entities