·The Hindu·15 marks·250–350 wordsPolityS&T

Examine the institutional mechanisms for cybersecurity in India's nuclear and strategic sectors. Are they adequate to address supply-chain vulnerabilities?

In this answer
  1. The institutional architecture
  2. Where supply-chain adequacy falls short

India's nuclear installations qualify as Critical Information Infrastructure (CII) — resources whose destruction would debilitate national security — protected under Section 70A of the IT Act, 2000 [2]. The July 2026 Kudankulam leak, where about 14.3 GB of Units 3 & 4 documents surfaced on a dark-web extortion site after a contractor's outsourced server was breached [1], shows an architecture that is firm at the core but porous at its vendor periphery.

The institutional architecture

  • NCIIPC, notified under Section 70A, is the national nodal agency for CII protection, covering nuclear and power sectors [2].
  • CERT-In, under Section 70B, is the incident-response agency; its April 2022 Directions mandate reporting of cyber incidents within six hours and expressly bind data centres, cloud and VPS providers [3].
  • The National Cyber Security Coordinator (NSCS) and National Cyber Coordination Centre supply threat awareness and inter-agency coordination [2].
  • Sectoral defence-in-depth: NPCIL segregates reactor control from administrative networks — hence its clarification that only conventional Balance of Plant data was exposed [1].
  • Capacity is expanding: CERT-In empanelled auditors conducted over 9,700 audits in 2024-25 [5].

Where supply-chain adequacy falls short

  • Fourth-party exposure: the intrusion occurred at a contractor's third-party data centre, entirely outside NPCIL's own perimeter [1].
  • Enforcement gap: suspicious activity was detected in late May 2026 but became public only in mid-July, testing the six-hour norm in practice [1][3].
  • Diffused accountability across operator, contractor and host, with no statutory vendor-security certification preceding award of strategic contracts.
  • Overlapping mandates: the Standing Committee on Home Affairs (2025) urged stronger inter-agency coordination and dedicated cyber capacity [4].
  • Opacity: NCIIPC withholds breach details on national-security grounds, limiting sector-wide corrective learning [2].

India's nuclear cyber-defence is therefore legally robust at the reactor core but only partially adequate at its contractual edge. Extending CII compliance contractually to every vendor tier, pre-award security audits, zero-trust segregation and a dedicated nuclear-sector CERT would make resilient infrastructure, as envisaged in SDG-9, genuinely end-to-end.

Sources

  1. 1Aroon Deep, "How serious is Kudankulam data leak?", The Hindu, 17 July 2026leak volume, contractor/data-centre origin, NPCIL's Balance of Plant clarification, detection–disclosure timeline
  2. 2PIB, "Government of India Taking Measures to Protect Critical Infrastructure and Private Data Against Cyber Attacks"NCIIPC under Section 70A, CERT-In under Section 70B, NCSC and NCCC; non-disclosure of breach details
  3. 3CERT-In Directions under Section 70B(6), 28 April 2022six-hour incident reporting duty; applicability to data centres and cloud/VPS providers
  4. 4PRS Legislative Research summary, Standing Committee on Home Affairs, "Cyber Crime: Ramifications, Protection and Prevention" (20 August 2025)recommendations on inter-agency coordination and cyber capacity
  5. 5PIB, "Government Strengthens Cybersecurity Across Critical Sectors; Over 9,700 CERT-In Audits Conducted in 2024–25"audit capacity data
Practice
7 questions on this article
Check the answer for each question, or reveal all at once.
Practice MCQs →

More from this note

More on Polity