Critical infrastructure like nuclear power plants increasingly rely on private contractors, raising unique cybersecurity risks. Discuss with reference to recent incidents.

Q. Critical infrastructure like nuclear power plants increasingly rely on private contractors, raising unique cybersecurity risks. Discuss with reference to recent incidents. (15 marks, 250-350 words)

Critical information infrastructure is that whose incapacitation would debilitate national security; NCIIPC, created under Section 70A of the IT Act, 2000, treats "Power & Energy" as a critical sector [3]. As nuclear expansion is executed through private EPC contractors, the defensible perimeter now extends well beyond the operator's own network.

Why contractor dependence is growing - Capacity targets demand outsourcing: Kudankulam is being scaled toward 6,000 MW by 2027, with Units 3–6 under construction [2]. - Non-nuclear Balance of Plant (BoP) work — common services, civil and conventional systems — is routinely contracted out, as with Reliance Infrastructure at KKNPP Units 3&4 [1].

The unique risks this creates - Supply-chain attack vector: the operator may be hardened, but vendor and third-party cloud servers are not. In July 2026, the ransomware group "World Leaks" dumped roughly 19,000 Kudankulam-linked files taken from the contractor's systems, not NPCIL's [1]. - Aggregation risk: engineering drawings, supplier lists and inspection records are individually unclassified, yet together map site layout and the weakest link in the vendor chain — useful to a hostile actor even though reactor control systems stayed untouched [1]. - Accountability vacuum: NPCIL indicated no FIR was contemplated since the breached data legally belonged to the contractor [1] — illustrating how liability for strategic-project data blurs in outsourced contracts. - Precedent: in 2019, NPCIL confirmed malware on Kudankulam's administrative network, showing the IT-side threat is recurring, not isolated.

The Kudankulam episode was not a nuclear-safety failure, but it is a governance warning: security is only as strong as the least-protected vendor. Embedding mandatory cybersecurity audits and contractual data-security obligations for contractors, enforcing CERT-In's six-hour incident-reporting mandate [4], and notifying vendor-held project systems as "protected systems" under NCIIPC [3] would close this gap. Extending the state's security perimeter to every private partner is essential to make India's nuclear expansion both ambitious and secure.

(~320 words)

Sources: 1. Kudankulam 'data breach' unrelated to nuclear activity: Govt. — The Hindu, July 17, 2026 — contractor-side breach, ~19,000 files, BoP package, no FIR contemplated, reactor systems unaffected 2. Press Information Bureau — Ministry of Science & Technology / DAE release on Kudankulam units — Kudankulam units of 1000 MW each and 2027 completion timeline 3. NCIIPC, Government of India — About Us — Section 70A IT Act mandate, critical sectors including Power & Energy, protected systems 4. Indian Computer Emergency Response Team (CERT-In) — 2022 Directions mandating cyber-incident reporting within six hours