Outsourcing of non-core functions in strategic public sector projects to private players: benefits and risks.
Strategic projects in nuclear, space and defence increasingly hand over non-core functions — civil works, Balance of Plant (BoP), logistics, IT support — to private firms, while the state retains the core technology. The July 2026 Kudankulam contractor data leak shows this model delivers speed, but transfers new vulnerabilities.
Benefits
- Capacity and speed of execution: private engineering firms compress timelines; Kudankulam's BoP package for Units 3&4 was contracted out as the site moves towards its 6,000 MW target by 2027 [1].
- Optimal risk allocation: the Kelkar Committee (2015) on revitalising PPPs held that risk should rest with the party best able to manage it — construction and cost-overrun risk sits better with contractors [2].
- Core-competence focus: NPCIL concentrates scarce specialist manpower on the nuclear island, reactor safety and regulatory compliance, not on conventional infrastructure common to thermal plants [3].
- Industrial ecosystem: orders to Indian firms and MSMEs deepen indigenous manufacturing and employment, supporting self-reliance in strategic supply chains.
Risks
- Cyber and supply-chain exposure: a ransomware group published roughly 19,000 files (~14 GB) from a Kudankulam contractor's systems — engineering drawings, supplier lists, inspection records — even though reactor systems stayed unaffected [3].
- Strategic intelligence leakage: unclassified site layouts and vendor lists can still map a critical asset for hostile actors.
- Accountability and liability gaps: NPCIL did not contemplate an FIR since the breached data legally belonged to the contractor — exposing unclear liability in outsourced contracts [3].
- Weak vendor oversight: contractors often fall outside the security audit rigour applied to the operator itself, despite NCIIPC's mandate under Section 70A, IT Act 2000 [4].
Outsourcing is indispensable for timely capacity addition, but the perimeter of security must extend to the last vendor. Embedding mandatory cyber-audit and incident-reporting clauses in contracts, NCIIPC-supervised vendor accreditation, and clear liability provisions would let India retain efficiency gains while securing critical infrastructure — advancing resilient infrastructure under SDG-9.
Sources
- 1PIB — "Four units of 1000 MW each of Kudankulam Nuclear Power Plant will be completed by 2027"Units 1&2 operational, remaining units under construction, 6,000 MW site capacity target
- 2PRS Legislative Research — Summary, Kelkar Committee Report on Revisiting & Revitalising the PPP Model (2015)risk allocation and governance principles in PPP contracting
- 3The Hindu — "Kudankulam 'data breach' unrelated to nuclear activity: govt." (17 July 2026)contractor-side leak, BoP package scope, NPCIL's position on FIR
- 4NCIIPC, Government of Indianational nodal agency for critical information infrastructure under Section 70A, IT Act 2000
Practice
11 questions on this article
Check the answer for each question, or reveal all at once.