Outsourcing of non-core functions in strategic public sector projects to private players: benefits and risks.
Q. Outsourcing of non-core functions in strategic public sector projects to private players: benefits and risks. (15 marks, 250-350 words)
Strategic projects in nuclear, space and defence increasingly hand over non-core functions — civil works, Balance of Plant (BoP), logistics, IT support — to private firms, while the state retains the core technology. The July 2026 Kudankulam contractor data leak shows this model delivers speed, but transfers new vulnerabilities.
Benefits
- Capacity and speed of execution: private engineering firms compress timelines; Kudankulam's BoP package for Units 3&4 was contracted out as the site moves towards its 6,000 MW target by 2027 [1].
- Optimal risk allocation: the Kelkar Committee (2015) on revitalising PPPs held that risk should rest with the party best able to manage it — construction and cost-overrun risk sits better with contractors [2].
- Core-competence focus: NPCIL concentrates scarce specialist manpower on the nuclear island, reactor safety and regulatory compliance, not on conventional infrastructure common to thermal plants [3].
- Industrial ecosystem: orders to Indian firms and MSMEs deepen indigenous manufacturing and employment, supporting self-reliance in strategic supply chains.
Risks
- Cyber and supply-chain exposure: a ransomware group published roughly 19,000 files (~14 GB) from a Kudankulam contractor's systems — engineering drawings, supplier lists, inspection records — even though reactor systems stayed unaffected [3].
- Strategic intelligence leakage: unclassified site layouts and vendor lists can still map a critical asset for hostile actors.
- Accountability and liability gaps: NPCIL did not contemplate an FIR since the breached data legally belonged to the contractor — exposing unclear liability in outsourced contracts [3].
- Weak vendor oversight: contractors often fall outside the security audit rigour applied to the operator itself, despite NCIIPC's mandate under Section 70A, IT Act 2000 [4].
Outsourcing is indispensable for timely capacity addition, but the perimeter of security must extend to the last vendor. Embedding mandatory cyber-audit and incident-reporting clauses in contracts, NCIIPC-supervised vendor accreditation, and clear liability provisions would let India retain efficiency gains while securing critical infrastructure — advancing resilient infrastructure under SDG-9.
(~325 words)
Sources: 1. PIB — "Four units of 1000 MW each of Kudankulam Nuclear Power Plant will be completed by 2027" — Units 1&2 operational, remaining units under construction, 6,000 MW site capacity target 2. PRS Legislative Research — Summary, Kelkar Committee Report on Revisiting & Revitalising the PPP Model (2015) — risk allocation and governance principles in PPP contracting 3. The Hindu — "Kudankulam 'data breach' unrelated to nuclear activity: govt." (17 July 2026) — contractor-side leak, BoP package scope, NPCIL's position on FIR 4. NCIIPC, Government of India — national nodal agency for critical information infrastructure under Section 70A, IT Act 2000