Examine the institutional mechanisms for cybersecurity in India's nuclear and strategic sectors. Are they adequate to address supply-chain vulnerabilities?
India's nuclear installations qualify as Critical Information Infrastructure (CII) — resources whose destruction would debilitate national security — protected under Section 70A of the IT Act, 2000 [2]. The July 2026 Kudankulam leak, where about 14.3 GB of Units 3 & 4 documents surfaced on a dark-web extortion site after a contractor's outsourced server was breached [1], shows an architecture that is firm at the core but porous at its vendor periphery.
The institutional architecture
- NCIIPC, notified under Section 70A, is the national nodal agency for CII protection, covering nuclear and power sectors [2].
- CERT-In, under Section 70B, is the incident-response agency; its April 2022 Directions mandate reporting of cyber incidents within six hours and expressly bind data centres, cloud and VPS providers [3].
- The National Cyber Security Coordinator (NSCS) and National Cyber Coordination Centre supply threat awareness and inter-agency coordination [2].
- Sectoral defence-in-depth: NPCIL segregates reactor control from administrative networks — hence its clarification that only conventional Balance of Plant data was exposed [1].
- Capacity is expanding: CERT-In empanelled auditors conducted over 9,700 audits in 2024-25 [5].
Where supply-chain adequacy falls short
- Fourth-party exposure: the intrusion occurred at a contractor's third-party data centre, entirely outside NPCIL's own perimeter [1].
- Enforcement gap: suspicious activity was detected in late May 2026 but became public only in mid-July, testing the six-hour norm in practice [1][3].
- Diffused accountability across operator, contractor and host, with no statutory vendor-security certification preceding award of strategic contracts.
- Overlapping mandates: the Standing Committee on Home Affairs (2025) urged stronger inter-agency coordination and dedicated cyber capacity [4].
- Opacity: NCIIPC withholds breach details on national-security grounds, limiting sector-wide corrective learning [2].
India's nuclear cyber-defence is therefore legally robust at the reactor core but only partially adequate at its contractual edge. Extending CII compliance contractually to every vendor tier, pre-award security audits, zero-trust segregation and a dedicated nuclear-sector CERT would make resilient infrastructure, as envisaged in SDG-9, genuinely end-to-end.
Sources
- 1Aroon Deep, "How serious is Kudankulam data leak?", The Hindu, 17 July 2026leak volume, contractor/data-centre origin, NPCIL's Balance of Plant clarification, detection–disclosure timeline
- 2PIB, "Government of India Taking Measures to Protect Critical Infrastructure and Private Data Against Cyber Attacks"NCIIPC under Section 70A, CERT-In under Section 70B, NCSC and NCCC; non-disclosure of breach details
- 3CERT-In Directions under Section 70B(6), 28 April 2022six-hour incident reporting duty; applicability to data centres and cloud/VPS providers
- 4PRS Legislative Research summary, Standing Committee on Home Affairs, "Cyber Crime: Ramifications, Protection and Prevention" (20 August 2025)recommendations on inter-agency coordination and cyber capacity
- 5PIB, "Government Strengthens Cybersecurity Across Critical Sectors; Over 9,700 CERT-In Audits Conducted in 2024–25"audit capacity data