Examine the institutional mechanism in India for securing critical infrastructure from cyber threats. Suggest reforms.
Q. Examine the institutional mechanism in India for securing critical infrastructure from cyber threats. Suggest reforms. (15 marks, 250-350 words)
Critical Information Infrastructure (CII) is defined under Section 70A of the IT Act, 2000 as computer resources whose incapacitation would debilitate national security or the economy [1]. The July 2026 leak of Kudankulam-linked project files from a private contractor's servers shows an architecture that is legally sound at the core but porous at its contractual periphery [5].
Existing architecture - NCIIPC, notified in 2014 under Section 70A and housed in NTRO, is the nodal agency for CII protection across power, nuclear, telecom, transport and banking [1]. - CERT-In, under Section 70B, is the national incident-response agency; its Directions of 28 April 2022 mandate reporting of breaches within six hours and retention of logs for 180 days [2]. - National Cyber Security Policy, 2013 provides the umbrella framework, stressing supply-chain risk reduction and public-private partnership [3]. - Operator-level defence: reactor control systems are air-gapped, and NPCIL under the DAE handled the Kudankulam response alongside CERT-In [5].
Gaps the episode exposes - Vendor blind spot: the compromise lay in a contractor's Balance-of-Plant data, not NPCIL's systems — regulation effectively stops at the operator's perimeter [5]. - Liability vacuum: no FIR was contemplated since the breached data legally belonged to the contractor, leaving accountability unallocated [5]. - Doctrinal lag: the governing policy remains of 2013 vintage, and overlapping CERT-In and NCIIPC mandates blur command during incidents [3]. - Strategic risk of "non-sensitive" data: drawings and supplier lists retain value as the site scales towards 6,000 MW by 2027 [4].
Reforms - Extend NCIIPC audit and compliance obligations contractually to EPC vendors and their cloud providers. - Insert standard cybersecurity and breach-disclosure clauses in strategic-sector contracts, with defined liability. - Notify an updated National Cyber Security Strategy with a single accountable incident authority. - Build a sectoral CERT for nuclear and power, adopt zero-trust design, and expand the pool of certified cyber auditors.
India's cyber-defence problem is no longer statutory absence but institutional reach. Aligning contractor obligations with NCIIPC standards, and refreshing doctrine to match a rapidly expanding nuclear and digital footprint, would convert a reactive posture into resilience — securing the "sovereignty and integrity of India" that Article 51A and the IT Act alike seek to protect.
(~330 words)
Sources: 1. NCIIPC — national nodal agency under Section 70A, IT Act 2000 — legal basis and mandate for CII protection 2. CERT-In Directions under Section 70B(6), 28 April 2022 — six-hour incident reporting, log retention 3. National Cyber Security Policy, 2013 (MeitY) — umbrella framework, supply-chain and PPP objectives 4. PIB: Kudankulam units to be completed by 2027 (Ministry of Atomic Energy) — capacity expansion to 6,000 MW 5. The Hindu: "Kudankulam 'data breach' unrelated to nuclear activity: govt." (17 July 2026) — contractor Balance-of-Plant data breached, no FIR contemplated, NPCIL–CERT-In response