Examine the institutional mechanisms for cybersecurity in India's nuclear and strategic sectors. Are they adequate to address supply-chain vulnerabilities?

Q. Examine the institutional mechanisms for cybersecurity in India's nuclear and strategic sectors. Are they adequate to address supply-chain vulnerabilities? (15 marks, 250-350 words)

India's nuclear installations qualify as Critical Information Infrastructure (CII) — resources whose destruction would debilitate national security — protected under Section 70A of the IT Act, 2000 [2]. The July 2026 Kudankulam leak, where about 14.3 GB of Units 3 & 4 documents surfaced on a dark-web extortion site after a contractor's outsourced server was breached [1], shows an architecture that is firm at the core but porous at its vendor periphery.

The institutional architecture - NCIIPC, notified under Section 70A, is the national nodal agency for CII protection, covering nuclear and power sectors [2]. - CERT-In, under Section 70B, is the incident-response agency; its April 2022 Directions mandate reporting of cyber incidents within six hours and expressly bind data centres, cloud and VPS providers [3]. - The National Cyber Security Coordinator (NSCS) and National Cyber Coordination Centre supply threat awareness and inter-agency coordination [2]. - Sectoral defence-in-depth: NPCIL segregates reactor control from administrative networks — hence its clarification that only conventional Balance of Plant data was exposed [1]. - Capacity is expanding: CERT-In empanelled auditors conducted over 9,700 audits in 2024-25 [5].

Where supply-chain adequacy falls short - Fourth-party exposure: the intrusion occurred at a contractor's third-party data centre, entirely outside NPCIL's own perimeter [1]. - Enforcement gap: suspicious activity was detected in late May 2026 but became public only in mid-July, testing the six-hour norm in practice [1][3]. - Diffused accountability across operator, contractor and host, with no statutory vendor-security certification preceding award of strategic contracts. - Overlapping mandates: the Standing Committee on Home Affairs (2025) urged stronger inter-agency coordination and dedicated cyber capacity [4]. - Opacity: NCIIPC withholds breach details on national-security grounds, limiting sector-wide corrective learning [2].

India's nuclear cyber-defence is therefore legally robust at the reactor core but only partially adequate at its contractual edge. Extending CII compliance contractually to every vendor tier, pre-award security audits, zero-trust segregation and a dedicated nuclear-sector CERT would make resilient infrastructure, as envisaged in SDG-9, genuinely end-to-end.

(~325 words)

Sources: 1. Aroon Deep, "How serious is Kudankulam data leak?", The Hindu, 17 July 2026 — leak volume, contractor/data-centre origin, NPCIL's Balance of Plant clarification, detection–disclosure timeline 2. PIB, "Government of India Taking Measures to Protect Critical Infrastructure and Private Data Against Cyber Attacks" — NCIIPC under Section 70A, CERT-In under Section 70B, NCSC and NCCC; non-disclosure of breach details 3. CERT-In Directions under Section 70B(6), 28 April 2022 — six-hour incident reporting duty; applicability to data centres and cloud/VPS providers 4. PRS Legislative Research summary, Standing Committee on Home Affairs, "Cyber Crime: Ramifications, Protection and Prevention" (20 August 2025) — recommendations on inter-agency coordination and cyber capacity 5. PIB, "Government Strengthens Cybersecurity Across Critical Sectors; Over 9,700 CERT-In Audits Conducted in 2024–25" — audit capacity data